Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Welcome! Election and Voting and the use of Technology, Poorly written apps and Bad Chrome Extension and more on Tech Talk with Craig Peterson on WGAN

    Welcome!  

    We are going to hit a number of topics today from the world of Technology. Primaries and Caucuses are underway and with that always comes the topic of technology and security and it is no different this year.  Apps are being developed and brought to market without being fully tested.  Extensions are being created that have ulterior purposes and are being downloaded by thousands and even more, on Tech Talk With Craig Peterson today on WGAN.  It is a busy show -- so stay tuned.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Related Articles:

    Four States Use A Flaw Filled Mobile Voting App 

    Iranian Hackers Exploit VPNs Worldwide

    IT Disaster Recovery/Business Continuity Exacerbated by Coronavirus 

    Be Careful of Extensions on Chrome - Many found to Upload Your Private Data. 

    Sharp Increase in Exposed Records by Third-Party Applications

    Automotive Apps originally designed for Personal Owners cause headaches for rental agencies.

    1.77 Billion  - That is how much Businesses lost last year to Business Email Compromises 

    Encrypted Communications for the Masses

    ---

    Automated Machine Generated Transcript:


    Hey, welcome, everybody. Craig Peterson here on WGAN. And we're live on Facebook. And we, of course, can be found over my website as well Craig Peterson, calm. We got a lot of topics for today's show. But we're going to start with the one that is really on everybody's minds right now is we see more of these primary elections beginning to come up, and we see problems. Well, I don't know, or are they problems or features? I guess they are problems with some of the election technology that has been used over in Iowa. New Hampshire's technology was rather straightforward as the Secretary of State in New Hampshire says, and it's hard to hack a pencil, although they're not using pencils. In New Hampshire. They are using felt pens, which are hard to hack as well. And these cards can like the cardboard that you would have in the back of a shirt when you purchase it.


    It's that type of cardboard that is not shiny or glossy, and then it goes through an optical reader that scans the ballot and places it in the bottom of that machine. An election official stands there to make sure that the balance legitimate. That you are not trying to stuff the ballot box, and that machine counts your vote. Now the unfortunate thing is those machines are kind of old in most states, some of them, I think maybe all of them are still running Windows XP, but there's no easy way to get it the operating system. It's never connected to a network. Even though some of these machines that have been examined and have patch levels zero or in other words, no patches of Windows XP, which is quite surprising when you get down to it. That is a big problem in many many cases. In New Hampshire, the primary went pretty well. Of course this weekend, the next one coming up, which is in Nevada. The Nevada caucuses. I don't know what to believe anymore because

    I've heard both sides of this. One that voting in Nevada is using the same technology that was used over in Iowa, which to me would be just a shocker and a whole big dismayed because it was just so terrible. As I've said on the radio before, in fact, this week when I was on with Ken and Matt, I think it was, might have been with Jim, I'm trying to remember who it was, which show. I pointed out how in when we're looking at some of this technology, we all well, not all of us, but some of us love the latest greatest technology. I'm one of those guys that like to stick with something that I know works and explore current technologies and newer things. But so many times we get just bamboozled as taxpayers because the people that are in control of the purse strings, they like the latest coolest stuff. They buy equipment from people they know hence the app and iOS.

    Former Hillary Clinton staffers ran the company chosen for use in Iowa, and I don't know how much vetting they did. We do know that the code wasn't checked. Homeland Security had offered. We also had offers coming in from Federal Investigation Bureaus and from several security companies saying, Hey, listen, we'd be glad to have a look at this. It was all closed source. It wasn't open-source where you can have a look at that software and say, yes, indeed, everything's legit. That is excellent software. People can find bugs in it. If they find a bug, they can report it, and it can get fixed, right? There are so many different things that they could have done when we're talking about trying to make this secure. I see Mary just joined us here on the Facebook Live and which is cool. She and I have worked several elections in the pas,t and we've been monitoring them. I have a son that's been one of these election officials. You know, part-time people that get pulled in to watch the voter checklist and things in New Hampshire, you have to have an ID to vote, which is weird, you know. I liked the way we did it here, Maine's doing the same thing. Most New England states are in fact as northern New England are doing the same thing where we have a felt pen, we have a piece of paper, we mark it down on that piece of paper, and we can then count it later on. If there's a problem, right? You can just go to that paper that sits in the closet, pull out the stack, bring it with you. And once you've done that, you can have a bunch of people sit around and think about Florida 20 years ago and what happened there with the hanging chads. They at least had a physical card they could look at although you know pregnant chats, hanging chads got to be quite the mess. So now we're getting concerned because of this new voting app that's out there. It's called Votz.

    V-O-T-Z is how they spell it. It's not the same one that was used the caucuses in Iowa. The app that the Democratic Party was using was trying to take the tabulations that were made by the people who were at all of these different precincts and figure out what the vote tallies were and then supposedly put it into the app and it gets sent up. This vote app that we're talking about right now goes a few steps beyond that. They want military personnel, and people are overseas to use it when they can't necessarily vote when they want to vote. It's, you know, panacea, maybe it's something we can get to in someday, but four states are going to use it this year. It has not undergone the trials that really should have gone down. And it's using a buzzword that I think got people's attention.

    And they're saying, Oh yeah, this is going to be safe because it's using this buzzword called blockchain technology. Blockchain technology is what used behind various cryptocurrencies, like Bitcoin and some of the others, to help secure the transaction. So the whole log is it signed each record inside the register is signed. Just because it has blockchain doesn't mean it's secure and doesn't make it properly designed. I've got a quote here in this article from MIT, is computer science artificial intelligence lab saying the whole thing is sloppy. It looks sloppy. It's in Georgetown Law. It's awe-inspiring. They were able to find such a pervasive set of vulnerabilities, said Matt Blaze and election security expert and computer science professor at Georgetown Law School. But we should also remember it's ultimately unsurprising that they would be able to do so because of every expert has warned against Internet voting as being vulnerable to flaws exactly like this goes on.

    The University of Michigan here Alex Halderman, saying that it makes vote seemed like a sham. So it is a sham. I think I think it's a real problem. But we're going to do it anyways and four states, including West Virginia, this year is going to be a mass. We've already seen what happened in Iowa. We saw excellent voting happen in New Hampshire. We're not sure what's happening this weekend in Nevada, then Super Tuesday is right on the heels. Some of these states are using these voting apps. Some of them are using the apps used in caucuses. I think thank goodness there aren't very many caucuses in the country. And we'll see, but one thing is guaranteed, and that is it will be quite the debacle. It is going to end up being a problem for everybody involved because they didn't vet this technology. Now, I reported on this a couple of weeks ago, this $10 million grant set aside by the Department of Defense grant, ultimately, and it was to design a voting machine that would be secure. A voting machine that we could trust. I think that's just wonderful. It hasn't really been tested yet. They brought it last year to one of these conferences like Black Hat and Defcon. They brought it out there. Every year there is a voting machine village where they have all kinds of voting machines there. They are asking people to go ahead and try and hack into the voting machines. We had a 15-year old that was able to hack a voting machine right there, and they compromised every voting machine except for the device under development on this $10 million contract. Now, that might seem impressive, and that might be kind of encouraging to some of us. I think it kind of is in some ways. However, the reason they did not hack it was it didn't work.

    They were not able to get it online and did not get it online until Sunday, which was the last day of the conference. And so no one got to test it out. But that was last year. Let's get them a little real a little bit under their belt, a little water under that bridge sometime, and they will be able to do it. And you know, I think they'll be able to do it ultimately, but I still will be the biggest proponent of a pencil and a piece of paper or a felt tip pen. The software, By the way, those votes VOATz software is being used in Denver, parts of Oregon, Utah and Washington State, we'll see what happens. West Virginia, as I said, is going to use it. But for disabled voters, the federal government requires all states to have electronic voting machines that can be used by disabled voters. I know here where I live in New Hampshire, we have a thing I don't know they might have passed. Now they're kind of getting old. Twins, twin women, and one of them was pretty much deaf, and the other one was pretty much blind. So they were able to help each other out in a massive way, which is kind of cool and get right down to it. But what they did is they kind of both helped each other to vote, but we all have in every precinct people who are there who can help people with disabilities. I don't like this requirement to have electronic voting machines. But the MIT researchers, these other researchers all agree with me. I'm very
    concerned about the Android phone and Android as a platform for people to use. I don't know if you are if you're using Android, you know, I'm always saying use iPhones much, much more secure. But I also am not looking at an iOS as being the problem. Cure-all for some of the voting machines. Anyhow, we are live on Facebook, as I'm putting the show together and shout out to everybody who is on there and asking questions. I appreciate it. And I will go back in and answer questions for anybody a little bit later on who has them, and I want you to stick around. I will be back here after the commercial break. We're going to be talking more about the latest in technology. We're going to be getting into these Iranian hackers that have been hacking VPN. If you think your VPN is safe. We've got another thing coming. So we're going to shut this one down. And we will be right back. Thanks for joining us, of course, Craig Peterson dot com.


    Hello, everybody. Welcome back. Craig Peterson here on WGAN and affiliates. You'll find me online at Craig peterson.com. And, of course, online at Facebook. I'm doing this Live on Facebook, and also out at YouTube. And we're going to talk right now about VPN. So hopefully, you have some understanding of them. But some exciting statistics came up this week from our friends in government. The FBI has been warning us a lot lately about what's been happening over in Iran what they've been doing, and we don't have kinetic war. In other words, we're not shooting at each other, which is a good thing, right? But Iranian hackers have been right at the forefront of trying to hack into our systems, and they've been relatively successful.


    I have a few clients that are in the defense industry, because we do, of course, the higher security stuff, right. And they have been under constant attack from Iran for about six, eight weeks now ever since the last little tussle with Iran might have been longer than that. And we're seeing sustained efforts to hack into them. Well, now we're getting a report from our friends over at ZD net here about Iranian hackers targeting these VPN services. So I thought I'd start by kind of explaining to everybody a little bit more about VPN services, what they are, what they offer. And because I'm hearing ads about this all the time, and frankly, it's driving me crazy, because the ads are telling me that Yeah, Craig you need a VPN because it's the only way you're going to be safe. It's the only way you're going to be secure in your day.


    You've got companies out there that used to be known for anti-virus, which of course nowadays we know antivirus software is zero percent effective against the latest hacks that are out there. So antivirus software companies are trying to figure out what's another way that we can make some money because people are starting to realize that this is a scam. And it's been a scam for a lot of years. You know, antivirus worked pretty well 15 years ago. It doesn't work at all today, as I just mentioned for the latest now malware nastiness that's out there. So some of these companies one that comes to mind.


    It was purchased not too long ago by another anti-malware company is running a lot of ads. They're saying this we need our VPN you need our credit watch. They've tied in, with one of these companies that watch your credit looking for transactions, it might be a bad guy, and I'm a little concerned because here's what usually is going on in the VPN industry. Running a good VPN is expensive. When you are using a VPN, all of your data, depending on what type of a VPN, how it's employed is encrypted from point to point. We're talking about the right ones and not those that you hear the ads for when you're using those types of VPNs. Your data is transmitted up to the VPN service provider. Then once it gets there, it is sent out to the internet. So let's say you're trying to go to my site, Craig Peterson, dot com. If you're using a VPN, your web browser is going to ask the VPN server Hey, can I get the Craig Peterson dot com? What's the best way to do it? How can I get there, and the VPN server will say Hold on a second. I'll get that page for you. Then the VPN server goes out to Craig Peterson dot com gets the page and sends it back to you.

    Now, that would be a caching or proxy VPN server. And some of them will just pass packets through. But the big concern I have is twofold. One of them is this whole Iran thing, and we'll get into that in just a minute. Because it isn't only Iran. But the other one remembers if something is free, or if it's inexpensive, who's the product? You the product! And since you're the product, what do you think they're making money off of selling your personal information, that's how they make their money. And that is a big problem as far as I'm concerned. So what some of these VPN services are doing is they are tracking you online. Some of them go the next step, and they're actually acting as full proxies, and they are sometimes acting as a man in the middle attacks.


    They're injecting things into your data stream that you weren't expecting. So where you think you're getting the VPN to have some security, and to have some privacy. Some of these VPN services are the exact opposite. They are reducing your privacy because what they're doing now is taking your data and selling it to the highest bidder that's out there, right. So I think that's a problem. And if you think it's a problem, maybe you shouldn't use some of these cheap VPN services. And I haven't gotten any I actually like, okay, I've heard advertisements on these radio stations, my shows airing on and I've checked them out, and I'm not comfortable with any of them. And the only VPNs I use or VPNs that I run, but remember, your data still has to hit the internet at some point. Remember, you're using one of these VPN services.


    versus your data is going to the VPN service provider. And at that point, it hits the internet. So it's now out on the internet. Well, if you're trying to make sure your data doesn't get on the internet, and people aren't hacking you, you've lost because your information does have to get to the internet. How are Internet Service Providers supposed to get to your bank? How are they supposed to get to my website? How did they suppose to get to Facebook or Google or YouTube? They have to go over the whole internet as well. If you're using one of these services, and they're going out to the internet. What do you think is a bigger target you at home, using the internet via your cable company or your telco or maybe your smart device. Is that one device a big target, or do you think that perhaps its the VPN service providers that are the bigger target, right? I'm not sure I need an answer because it's kind of a rhetorical question. The most significant marks out there when it comes to VPNs are these VPN service providers. And we're seeing warnings out there right now that Iranian hackers have targeted pulse secure, which has VPN software that they sell to businesses, shown to be insecure. Pulse Secure for the net. Another example of one of these security companies, right that has a VPN service, Palo Alto Networks, a company I have never used and never recommended either. I haven't recommended any of these companies to anybody ever. We've gone up against Palo Alto Networks in some proposals and contracts and, and they won them because of all the whiz-bang, not because they were the best of the safest, and so


    So there you go, Paul secure Fortinet, Palo Alto, and Citrix VPN are now being used to provide a back door into larger companies. So if you're a business person, I'm going to put these right now into this channel so that you can look it up for you or business and seeing and write this in as a comment over here in the Facebook Live that you can find online. Yes, go to Craig Peterson, calm slash Facebook. It'll take you to my Facebook channel. But there's the list of them. It is from an article that's out there on ZDnet. I think they have been publishing some great information lately. I've been using them in a number of my alerts that I send out as part of my Saturday morning emails. But some of these attacks have happened according to this firm called clear sky that Iranian hackers have targeted companies.


    From the IT telecommunications, oil, gas, aviation government and security sectors, why because that's where all the real money is. The particular report is dispelling frankly, the notion that it's their Russian and Chinese hackers or maybe North Korean because the Iranian hackers don't know what they're doing right. I've heard that before all Iran, don't worry about it. They know what they're doing. When in fact, yes, within hours of being disclosed, the Iranian hackers were right in there. It's terrifying. So keep an eye out. I look. Again, online at Craig Peterson, calm you'll find this article, and a whole lot more. Make sure you ask your IT department if you're using any of these VPN services or software. And by the way, in most of these cases, you can get patches to fix it. When we come back. We're going to be talking about Coronavirus and the new challenges right here on WGAN.

    Hey, welcome back Craig Peterson here WGAN and online at Craig Peterson dot com, of course, on Facebook as well. I am live on Facebook, and you can ask questions there you can watch this whole show as it unfurls, and you will find me there. You can ask questions almost anytime. We try and keep you up to date on what is happening out there in the world of technology. Well, you might not have thought of coronavirus as anything more than just a piece of nastiness, right. The virus I know some people are saying well you know we haven't had as many deaths from the Coronavirus, also known as covin-19. I was trying to remember the name little earlier. We haven't had as many deaths from that as we have from our regular flu virus every year. Right now is the peak of flu season in the northeast and

    Anyways, and in many parts of the country, and what is there to worry about, right? Is it going to hit us? It seems to be slowing down. We don't have a whole lot of information from our socialist friends in China. Like most socialist governments, they play things very close to the chest. They don't want people to know what's happening, including their citizens. But we have some new fears now, and this is a great little article that I have found over on dark reading. It's pointing out some of the security challenges that we're facing, because of the whole Coronavirus thing. Everybody's heard about it, everybody's scared of it. And when you get right down to it, you're watching me right now listening to me talking about the Coronavirus because it is an exciting thing to understand. The CDC has not only maps of where the Coronaviruses hitting right now, but the CDC also has information about general flu viruses this time of year. There are outbreaks of different diseases, what's happening where CDC.gov now I've seen some fake stuff like CDC, dash gov.org, just all kinds of fake sites. With phishing, we've got to make sure that all of our employees, family, friends, know not to click on any of those links. Don't click on them. However, people do and when you click on them, who knows what's going to happen, you might be downloading malware, you might just be confirming this is a valid email address for more and future spamming, right there might be a lot of different things that it can do to you. Don't do that. The next one I think that that's very interesting is something most businesses have not addressed. What would happen if maybe covid-19, or something else, actually becomes a pandemic? What if it is not even a pandemic. What if you have an office with five or ten people in it and everybody comes down with the flu or cold? At the same time?


    Have you prepared for a business continuity challenge? And it isn't just what might happen if you're sick. It might also be a little bit further than that. What might happen if the business burns down? Or there's flooding, or no one can get into the office for a day or two because of some natural disaster? Maybe, it's just a really nasty ice storm like we had here? What a decade ago, where there were portions of New England that had no power for six weeks, in the middle of winter. That's a very, very big deal. What would your business do? Most people will haven't had a good hard look at business continuity, just in general, although we really should.


    And when we've got the cyber attackers coming after us, it also brings to mind what would happen if they got through, and let's say it was a version of ransomware that encrypted all of your data or deleted all of your data and demanded a ransom. Are you going to be able to handle that? Right? It's a big question.


    Will you be able to continue with your IT people, whether they're outsourced or in-house? How about your security operations people?


    It could be a huge problem.


    Let's move it up-scale because I know we've got a lot of people listening, who have more substantial companies. Maybe a 200 person company, perhaps something more prominent and it would be interesting to know you can just drop it in the channel like to know a little bit. But if you've got to hundred people working in one building and it's a contagious virus that's getting spread, the odds are pretty darn good, that 10 to 15% of your workforce is going to get nailed with that bug. Okay. Here's an example from the article.

    If it's by the way, if it's something that might be pandemic, there's an excellent chance the government's going to quarantine everybody anyways, whether the people get sick or not. Okay, and what's that going to do to your business? It is a consultant over Accenture working in Mexico City during the h1 in one virus spread ten years ago.

    They were saying that the current quarantine protocols are 14 days. So think about that. What happens if your business if your employees are out for 14 days if you've got a large outsource facility. Your security management, any facility, with a large number of people and you probably don't want to bring 100 people together and put them in a small room unless you-yourself have evidence that none of them have been affected. The second part of the challenges they may not be able to get there even want to get there. Now, this is the business continuity side. Can your business continue if there is a spread of these types of diseases, this could be huge? Some Indian companies have reported, according to dark reading, they've reported disruptions because of stoppages and shipments from China. They've got 45,000 Plus Now I don't know what the number is confirmed infections over 1000 deaths. So if you part of your supply chain now is affected, in this case with the Covid-19. Of course, most businesses are worried about the supply chain from China. There's supply chain manufacturing the low-cost components from China to Indonesia and all kinds of places in Southeast Asia what happens if that goes away too? If you have parts being made anywhere in the world, keep in mind that businesses are starting to move if they haven't already. Then with all of the phishing that's going on, It can get to be a very big problem. Proof point and Cisco Talos have reported messages purporting to provide tips for virus protection. They appeared to be sent not only by official government organizations but by the own businesses itself, upper management. So there's an example of spearfishing going after a specific company, and the messages get used to stealing credentials drop malware like mo tap, and in lures specifically targeting manufacturing and shipping industries. The nano core remote access software, these are back doors, like the kind I've talked about on the show that we have found in business and that is before backdoors get put in there by China or that Iran now has become a big player in all of this. So very, very big problems. Hey, if you have joined me on Facebook for the Facebook Live Welcome, welcome. I appreciate the comments, like seeing the thumbs up, so please do give that to me. Otherwise, you can find me online at Craig Peterson dot com. I post all of everything we talked about every week, right there Craig Peterson dot com and I started sharing videos and, and other things as well on YouTube and a little bit more on Facebook. When we come back after the break, we've got more to discuss. Next up. We're going to talk about these 500 Chrome extensions that have been secretly uploading people's information. How's that for a scary thing? So stick around because we'll be right back. If you are on Facebook Live. We're going to end this Facebook Live and start another one with our new topic in about five minutes on the radio. We'll be back even quicker than that. So stick around.

    Hold on one sec. Here we go, everybody. Welcome. Welcome Craig Peterson here on WGAN and elsewhere. Of course, also on Facebook, Facebook live is where you'll find me there. Just go to Craig Peterson dot com slash Facebook. You can sign up for my weekly newsletter, where I make sure you have all of the latest news, everything that you need to know. And right now we're going to talk about everybody's favorite browser while except for mine. One of the companies that we use goes by the name of Duo and what they have recently found out about our friends over at Google and Chrome. If you are a big follower of mine, and you've attended some of my pop-up training, I do quite a few of them.

    Those are always free and, and I have some tutorials as well. I talk a lot about extensions because there are quite several extensions that can be fantastic. And I use them all of the time. If I were to bring up my browser here, you would see a whole bunch of extensions that I use continually. I use them to block certain advertising types, and I use them to prevent various kinds of malware. I have some extensions that use artificial intelligence to figure out what is this page trying to do? Because we've got things like pop-unders, where it opened something up, and it has little timer was saved for an hour, and then it pops up to this big scary message that you need to update windows or update something now


    Because it's out of date, and there are hackers out there that are trying to get you. And that's called, by the way, scareware.


    But it comes through your browser, and you have no idea. So some of these extensions that I use are specifically designed to look at the source code on the page, look at not just the HTML, obviously, but look at the JavaScript or so much stuff is hidden. So it pulls in all these pieces of JavaScript. Usually, they're removed in from multiple sites and assembles them has a look at them, and will even change them based on what it finds. Now, those are beneficial extensions. Then on the other side, there are these toolbar extensions. I don't know if you've used these before, man, these used to be all of the rages, and I still see them installed in people's computers. And these toolbar extensions give you a little bit of extra something sooner, just a call right in

    These extensions going to track you when you're online and shopping and tell you where the best deal is? Well, yeah, it's following you, right? It knows that you're on a shopping site because you give that extension access to all of your browsing history. Then it knows what you're looking at up the site and knows what you are searching. Because so many of these extensions come with their little search bar up top right. Yahoo was one of the big guys out there in this browser bar extension business. And every last one of them at the very least, despite you. Now, that's bad, right that it's bad enough. But now we're looking at this same mo wait a minute here. We have now uncovered 500 Chrome extensions that have been secretly uploading the private data from millions of users.


    Huge deal. An article in Ars Technica, if you are over on the Facebook Live, you'll see the article, right there has a direct link to it. But this is very bad. It was just discovered on Thursday here. It's been just about just over a week. And we found out from these guys, that what had happened is that these website extensions had more than 1.7 million installations. It was an independent researcher who worked with Cisco's own Duo Security. And they found all of these things. They then reported it privately to Google and the researchers and found 71. Google looked at what the researchers had seen, and how those extensions were coded up and how they we're behaving. Then Google found an additional 430 extensions. And Google has removed all known extensions that were doing this. So that's the right side of it. But that's the known extensions. Those are the extensions that we're doing something that looks suspicious that Google and the security researchers could identify. In this case, reported here, the Chrome extension creators and specifically made extensions that obfuscated the underlying advertising functionality from users. Now it did say advertising in this quote because here's another thing that they do. If you visit a website, and you have an extension installed, that has access to the websites that you're visiting, here's what they've been doing. They look for ads from their customers, so you've got a bad guy, Inc. Okay. And then what better guy he does is he goes out and says, Hey, listen, I can get you 1000 collects of thousand new views of your page, just pay me up. Then what they'll do is they will play some ads for you. These are pay-per-click ads.


    Every time someone clicks on an ad, they have to pay, right, and some of these ads are cheap at five cents. You don't see that too much anymore. Some of them are $500 for a single click. That money then goes to Google, who then shares it with whoever had the website where the click originated. Okay, so it's a pretty lucrative business if you as a bad guy that could guarantee clicks on these expensive websites That is what they're doing with some of these extensions.


    They are watching the pages you're visiting to look for an ad from one of these sites that they get some money fro, but now they can have your browser click on the ad unbeknownst to you. Your browser now clicks on that ad. They make some money because they have the fake ads that are up so all kinds of nastiness. The other side of this is let's say the bad guys want their competitors to stop advertising online. Let's say they make cups, and I make this glass. Other companies out there that make a blue glass kind of like this. They find out what are the ads this other blue glass company is running. They have their little extensions out there. They hire these people that only extension to then clicks on the competitor's ads automatically for them. The competitor might have a five hundred dollar a day limit with Facebook ads, and all of a sudden now that five hundred whatever it is they're spending where they've put a cap on it, right? So whatever it is they're spending is being 100% wasted, because you don't even see the ad. There are so many ways that the bad guys are using these extensions. It is a maze of redirects, malware, and more. Some of these plugins will do Bitcoin mining or other types of blockchain cryptocurrency mining out there.


    Man, there's just all kinds of them hardcoded control servers, which by the way, I've got another tutorial coming out telling you how to stop your computer from going on to some of these command and control servers. And that's going to be phenomenal for you. So keep an eye out for that coming up in a couple of weeks.


    Many the redirections because they're using redirections, as well as part of this, go to ads for products or Macy's, Dell, Best Buy
    large volume of ad content, as many as 30 redirects, the deliberate concealment of most ads from end-users and the use of the ad redirect streams to send infected browsers to malware and phishing sites. It goes on the bottom line, beware of extensions, but I also want you to be aware of apps, right? What are the apps that you are using? What are those apps providing you with? Now I'm talking about apps that are on your smartphone or on your tablet, maybe some programs that are on your computers. Okay, they're out there? What are those apps

    Are those apps something that you need? Many of them spy on you, which is another dangerous thing. They're stealing your data. They're taking the information they're sending to the bad guys. Right? It just goes on and on. So make sure you don't do that it is dangerous stuff. All right, I am doing this radio show on Facebook Live. If you want to follow me on Facebook, it's easy enough to do Craig Peterson comm slash Facebook. And if you are not a Facebook fan, and there are a lot of reasons not to be a Facebook fan, then you can also see a lot of these videos up on YouTube. I do YouTube lives, as well. You'll find that at Craig Peterson comm slash YouTube. And of course, you're listening on the radio, and you're going to find me on pretty much every streaming service that's out there. So I want to quickly ask a question - which browser do you use? If I say create a poll? What's going to happen here? Oh, there it is. I'm going to publish it right now. I see. Okay. All right. So far it's showing up. I should have clicked this a little bit earlier. So Facebook Live, you have a poll. Do you prefer Google Chrome, Firefox, Microsoft Edge, or Opera? And I personally use Firefox and Opera, Google Chrome and edge I don't trust particular Google Chrome, however,


    There are times when you have to use one of those two browsers, because your company might be using a website that's specifically programmed to only work with that particular browser. There. There might be other reasons, but let me know. Click on it there. If you are not watching me on facebook right now Facebook Live, go ahead and answer that poll. I'd really like to know or just drop me an email me at Craig Peterson calm. Let me know what your favorite browser is and why. And make sure that you delete every extension you don't need. Every app you don't use and don't need. We've got to cut back because it just presents such a broad attack surface to the bad guys. All right. Okay, so let's see end of this segment. When we come back, we of course, have a whole lot more to talk about. We're going to talk about third party breaches, what's been happening. It's increased sharply in 2019. If you are a business person, this is for you. Your listening to Craig Peterson WGAN and online at Craig Peterson dot com


    hello everybody welcome back Craig Peterson here on WGAN or also on Facebook Live if you have any questions, by all means drop them right here into the channel can always ask me a question to online anytime. Just email me and he had Craig Peterson calm more than happy to respond. You might have to have a little bit of patients I do try and get back ASAP. But if someone or my staff is not noticing or final notice Don't feel bad. It's not as though we hate you. But we do try and answer every question that comes our way just me at Craig peterson.com. We're going to talk right now about third party risks whether you are a small business or a little


    large business, this is a huge deal. very huge deal. And it's also a huge deal if you are an individual, because you are dealing with everything from Cloud services through


    a milk delivery company. All of these are third party services provided by third party companies. And many of them have information about us.


    And I've heard from so many businesses lately, that are now required under the new federal standards, the CMC standards, that they don't think that they really apply to them because they're not a primary government contractor. It's they don't have a whole lot or any personally identifiable information. You know, why? Why would you come after me? I just don't matter in the whole big scheme of things. So it's not something that I should have to worry about.


    When the law is clear, they do have to worry about it, but they're still not worried about it.


    And I think the biggest reason is because people just don't understand the risks involved. You're using Google spreadsheets, for instance, Google docs for me, you know, Microsoft Word replacement. And, and Google also has kind of a PowerPoint thing called Google Sheets, I think it is, or slides, Google Slides that you can use in order to put the presentation together. And even to show a presentation. It's, it's really rather cool stuff all the way around. But this is an example of a third party vendor. We already know that Google is looking at all of those documents and trying to figure out what a can use from that and in order to sell us stuff, right or do seller information to third parties. And in that's obviously a bit of an issue. But when we're talking about these smaller businesses that might be selling to


    Another government contractor that might be selling to Raytheon who's selling to the Department of Defense, just as an example. They wonder, why does it matter? That I'm really secure, because I'm making something that's completely passive. It's not as though I'm making the software that controls a missile in flight. Right? It is not doing any of those sort of things. So why should it matter?


    And I think that it's a good question, but here's why it matters. There were some huge hacks of the Department of Defense last year, and those hacks a good 50% of them came from their vendors. We're talking about a third party risk.


    That third party that vendor you're using, whether it's Google Docs and Dr. Mike, you might be using a version of Dropbox as


    Just a regular end user version might be using an unsecured or improperly secured as your instance or Amazon Web Services instance. You could be using any of those types of things. And guess what's going to happen if you're using those.

    All of those people who have your data could be used as a way into your computer's think for a minute. We spoke earlier today about these 500 plus Google Chrome extensions that were leaking your data there, the data is actually being stolen by third parties because of those. If you have software installed that's being used to manage your supply chain, and that supply chain software is tied into this third party vendor. Your network is is is exposed


    Now you may have tried to tighten it down, I might be as tight as could possibly be. And there's no problem here. But if you're like an average business, none of that is true. None of that is true at all. All of your data is potentially accessible by the third party. So some interesting stats that came out. And I again, I have this up on my website. I will post let me post this right now here in the Facebook Live channel. Okay. It's in there now to you can see that right at the end of my comment. They're showing that there were about 43% of businesses this last year 44% were, in fact, attacked and hacked via third party breaches. So in other words, the bad guys did not come in directly


    This wasn't a phishing attack attack necessarily directly against them. This wasn't a ransomware attack directly against them. It was against a third party. So it was a vendor who might have had all of their customer information they might have had to how to manufacture certain things. It could be all kinds of different types of information. And that information was then used against them. That's a very big deal. Think about billing. Think about your, your employees and their paychecks, their w 210 99. Since you send out all of these things to target so we talked earlier about these VPN services that are right now huge, they're huge attack vector. Now this number is up by the way 35% over the last two years.


    The number of records exposed in the breaches skyrocketed. Almost


    300% last year, the cost of the breaches have gone up substantially as well. And you're going to find all of this up on my website, Craig peterson.com. But that's huge. So 44% of all firms that were surveyed had experienced a significant data breach caused by third party vendor. And remember, these are firms that know that they were breached. So let's look at an IBM study. This IBM study says it takes an average of 197 days for a company to identify that they have had a data breach almost 200 days to even identify even know that they had a breach and another 69 days to contain it. Fat is inexcusable. In excuse inexcusable, it really is. You know, so many people have fallen through


    victim to vendors that say, hey, we've got the solution for you Don't worry about it. This is this is going to be so easy, not a big deal. We'll take care of it for you and they don't that's the only explanation I can come up with here. For what 265 ish days, from the time a breach occurs to the time that they've contained it. 265 days, that's two thirds of a year. Now I believe me I'm this is not I'm not trying to sell you our services here. Okay. If you want to buy him great. I just want to let you guys know 250 days on average to contain it with what we do on average. It is this from this. From the time it happens


    to the time is discovered to the time it's


    contain. So from the very beginning of a breach to the time it's contained. With us, it's typically six hours. That's why I say this is in excusable, if you're a company with 200 employees with 1000 employees, and you're not using the right stuff. Whose fault is it?


    And I gotta tell you another number that I've seen before when when I was one of the FBI infragard programs that I ran, I had an expert on, and he was talking about breaches, and you know how many months it takes to discover and then to try and close the hole.


    If you take less than 30 days to stop the breach, on average, you save $1 million,


    a million dollars. So think about that when you're thinking about the cost of security. If you are


    slightly bigger company, you have a few hundred employees up into thousands of employees. And you can shave that whole massive number of 250 days, down to 30 days or less, you've saved yourselves a million bucks. So the million dollars that you might spend on security and by the way, it takes you quite a bit to spend a million dollars to even to get the kind of security I was just talking about, with the six hour to recovery stuff. A million bucks goes a long way now and that's plus, by the way, you know, all of your other costs, the loss of reputation that you get, so you're going to lose clients, you're not going to pick them up, you're not gonna be able to charge as much as you could before. People aren't going to trust you. All this is happening because of these third party breaches. So keep that in mind next time.


    You are auditing your business, right? You've got auditors and think about all of the people downstream from you


    who maybe you should be paying some attention to, because they have data that you might find to be sensitive. They might be used as a conduit to break into your systems as well as have their systems breached. Okay. So I know many companies now that are, are auditing their providers, their upstream downstream partners, for very, very good reason. So if you want to find out more, let me know just email me at Craig peterson.com. Be glad to punch in the right direction. You can find this particular order article over and dark reading and it's written by Jay v. JOHN, and you can find it as well at Craig Peterson calm Of course I post all of that stuff online. And if you have my newsletter, you get that


    Every Saturday morning, links to it there too. So stick around. We'll be right back. We got a lot more to talk about here. In this last hour of the show. We're going to talk about a rental car risk you might not be aware of. So stick around.


    Hey, welcome back. Craig Peterson here WGAN and and elsewhere. We are live on Facebook Live as well. out on YouTube. You can find me and Craig Peterson calm. And of course, listen to my podcasts on pretty much any platform out there. podcast platforms from one platform. I just been doing this for too long. I guess this is the problem. They've all found me. Oh no. So this is a great little article from our friends over at Ars Technica. I don't know if you're familiar with it. It's one of those websites that I follow fairly closely because they have so many great things out there. But this one is talking about the rental cars and I want


    you to think about cars for a moment because well, I like cars. Hopefully you do too. But what are the problems that we're seeing today that are actually caused by this latest, newest, most wonderful technology? And there are a lot of them frankly. And some of them have to do shoes me with our phones, right? We plug our phones into the cars, the cars will automatically say, Okay, I want the contacts, people will just blindly say okay, go ahead and upload the contacts.


    And all of your contacts are uploaded, and now the car has them and the next driver comes in I love doing this comes into the car and scrolls through all of the phones and sees all of the contacts people have their home addresses in their status home. So you just look up home on the on the cars GPS and and just some poor fool who uploaded all of his contacts into the car, right use


    seen that before a music downloads, just all kinds of stuff. So I'm always careful, I never let the car upload my contacts you were probably kind of conscious about that as well. If you're not making sure that that doesn't happen right to the car doesn't have your contacts. You You might also do what I do, which is after I'm done with the car, I go into the Bluetooth settings and disconnect my phone or with Apple Car Play. I make sure my phone is disconnected.


    Excuse me. So those are all things I think that most people would know about and think about.


    Well, here's the problem that we're starting to see today. These cars are getting smarter and smarter and have more and more features on them, don't they? So there there's been some research here. Ars Technica did a little dive into it as well. And this Dan Goodin ended up writing an article about


    This where he found that the previous driver to his car could start and stop the engine lock and unlock the doors and track the location of the vehicle because you remember again these cars are designed by my guys right and gals obviously but by guys who are not thinking about all of the use cases for the car you know man I had such a fight of one of my my eldest sons who works with me he's he's one of the employees and works with a company that is fire jumpers certified for not fire jumper as in the fire department, although he does have a firefighting certificate including tight spaces on ships, but he's a fire jumper for security when something bad happens. Or please, please have us design the network before something bad happens. He gets some old us all of those. Well. We have all of


    Our clients emails run through a set of high end filters provided by Cisco. So all of the emails coming in our filters, look at it, and they are phenomenal. They have cut my email, I was 5000 emails a day. And now I'm down to about 100 hundred and 50 emails a day just by the Cisco filters. So and by the way, I have, I think, in the last year had maybe one false positive, maybe one it's just these things are so smart the way they work, right? They're not just looking for keywords or other things are really looking at behavior. Because Cisco sees so much of the internet, right? Cisco runs the internet backbone, but then they see so much of that traffic plus they see so much of the email traffic they can, they can just be phenomenal. So we have all of our customers emails running through our data center and it's properly secure.


    Of course, and running through these special Cisco email filters. And then we take those emails and we forward them on to our customers mail servers. Well, one of the services that is used by quite a few of our customers, because it's inexpensive, relatively speaking, is the Microsoft Office 365. Now, there's a lot of levels of old 3065. It's their cloud services, right? But that's cloud is in the cloud, right? And we're not going to get into that right now. But they have a whole bunch of services. And Microsoft had an internal grey list against our Cisco email host that was doing all of the filtering. And Microsoft, you know, they said, Well, you know, we can figure it out. It took us 24 hours to escalate it to people who knew what they were even talking about. We showed them their own tech article on this problem.


    them inside Microsoft with Office 365. And said, Here's your problem. You guys know about it, you have defined it, here it is. And yet, you know, they they start you with the people that say is a computer powered on type, right? Just so, so, so frustrating to me. Well, the problem here is that the Microsoft software did not consider all their software designers did not consider all of the uses usage cases. In this case, the Microsoft software people thought, Well, people using Office 365 they're just going to be real small businesses and they are going to have you know, dozen through 1000 email accounts maybe. And so the usage patterns are going to be consistent, etc, etc. That's not true in a case like us, where all of the emails coming in from all over the internet.


    To to us for all of our customers, including their deal D contractor customers, right? The people, the customers that have it are compliant, have PCI that have legal compliance issues, accounting compliance issues, right. So they all come to us where they are heavily heavily filtered. And then therefore it on to Microsoft. Well, that's not a usage case they thought of when they design the software. So we were fighting with them. We had thousands of messages queued up So the good news is, we didn't lose any of the email. We kept it our systems noticed right away that Microsoft was misbehaving, which they do frequently. And and then we got on the horn with Microsoft, we went the level two right away and then level three No, I'm air quoting levels two and three, because they're not real levels two and three, not by our standards. By the time you get to level three or somebody like me that or Steve, the fire jumper, somebody that really knows


    What's going on? Right? That's not the case of Microsoft.


    Anyhow, the problem in Ars Technica is found here is that these cars are designed with the idea that there is a single owner. Now there might be multiple drivers to the vehicle, but there's a single owner, right? She owns the Mustang. She drives it, but you know, the old man drives every once in a while the kids might drive it once in a while as well. Well, in this case, they looked at a Ford Explorer.


    And October last year, they put an article in about a guy that was able to remotely start, stop, lock, unlock and track a Ford Explorer that he had rented and returned five months earlier. And they're saying now something almost identical has happened again to the same enterprise rental car customers. customer. Four days after returning a Ford Mustang, the Ford pass app installed on the phone

    continues to give them control of the car. So here we have a usage case where the car is being rented, it was not part of the original design considerations. And the rental car company, in this case enterprise, and maybe it's just one unit of enterprise, I don't know. But enterprise is not properly clearing or resetting, whatever they have to do

    to that car after somebody has rented it. So it's a real problem. And it's something we need to be cautious of. Because it's, it's not even something we can necessarily do anything about. But personally, I would go into the menu on the console on the control system, you know, the entertainment system, and I wipe out every phone that's in there, just so that something like this can happen to me, right? But that's what I would do and that's what I advise you to do as well. Okay, stick around. When we get


    back. We're going to talk about a new FBI report that's talking about what happened to this $1.7 billion right here. Stick around. Craig Peterson and WGAN and live on Facebook.

    Hey, welcome back everybody, Craig Peterson here WGAN and and elsewhere. Hopefully you're able to join me on facebook live this week and we spend some time talking about the articles and answering questions for everybody. And of course you'll find that online right now kind of all over the place, make sure you get my weekly newsletter. It'll keep you up to date on all the latest security topics and some of the cooler new technology out there that I think is or maybe isn't ready for prime time. Going to have a cool guests next week too. I I used to do a lot of guests. I had like a dozen a show back when I had a three hour show. But next week we're gonna talk with a buddy of mine

    Mine, who is actually fairly well known, he's written a book about sugar. And you probably know if you've been listening to me for a while, not all that long. But a while you know that I have been very conscious about my health and doing the intermittent fasting thing and stuff. And so we'll talk to him about what he has found. You might remember I did the Atkins thing some years ago, but we'll be talking with him a little bit about that, too. I'm sure next week, so Barry Friedman will be my guest. And I will probably be next week. We've got to figure out the calendars first.

    No, I hate it when that happens. Sorry about that little bit of a coughing fit. Okay, so let's get into the article right now. And this has to do with email compromise. Now we all have email accounts, right? You got them. I got them, whether they're on Google

    Shame on you, or if they are Microsoft Office 365. Okay, depends on which level you have. Or if you host them yourself, which is what we've been doing for decades now for ourselves and our clients. I like that because they have more control. I don't have the problems like we had with Microsoft this week with Office 365 for some of our clients. But when you have email, there's a certain type of exposure that you have. We talked earlier about this whole problem with the coven 19 with the corona virus, and how they're using it right now to get you to click on links and phishing attacks. click on links in SMS. Those are called smishing. To get you to do something that ultimately you shouldn't do because they're using it to download nastiness. And it can be nastiness in the form of ransomware he'd be nastiness in the form of software that

    being installed on your computer to use your computer's resources, maybe as part of a denial of service attack, maybe to attack other people and other computers that are out there, right? It's all pretty darn evil. Well, the FBI put together some numbers because there's this thing called a business email compromise. That's only part of the problem. Because it isn't just business email, that can be a problem here. It's also our personal emails. So we're finding on the personal side that people are getting emails that are again from bad guys, but what they're trying to do is get you to go a little bit further. So a lot of them for instance, are based around dating sites. So people looking for companionship, they might be out on one of these websites and and they meet somebody.g more coughing meet somebody and as they've met that person, they kind of go back and forth and how are you? Oh my we have so much in common and they're trying to scam you. That is a very, very big and prevalent thing right now. Because so many people are just trying to find somebody that they can love someone they can spend some time with. And enjoy company and you know how I get that pardon my French but this is a real tough time in the world. There's so many people that are so ostracize that are blocked off from other people


    that are just looking for something anything right? Doesn't have to be love. As I said it can just be companionship. So the FBI has been warning about that. And then we've got these business email attacks, that what's happening here is oftentimes it's spearfishing. They're going

    After the owner of a company, and and frankly some of these dating things are spearfishing, too, because they know that somebody who's a little bit older might have some money that they can get out. Yeah. And they'll ask you Hey listen, I my uncle cousin has this medical bill and and we really need the money can I get $10,000 from you and people, people are sending it in the business email account account. It's a little bit different. So here's another article from our friends over dark reading this up on my website as well. But it's same back in 2013 scams often started with the spoofing of a CEO or CFO his email account, fraudsters send emails appearing to come from these execs to convince employees to send wire transfers to fake accounts. Now we know that within the last six months, this has gone to the next level. We're there we are using computers to imitate the bosses voice and they've been able to take millions anyhow the article goes on. Since then business email compromise has evolved to include the compromise a personal and vendor emails, spoofed lawyer email account and request for W two data. Of course, taxis and everybody. This is a big one w two right now the IRS is warning about that. Attackers often target the real estate sector and or make requests for expensive gift cards. In 2019. The Internet crime center


    saw an increase in business email compromised complaints related to the diversion of payroll money.


    So the attackers send a fake email to human resources or payroll department requesting an update to a specific employees direct deposit information. This is really really big and you look at these numbers. We're talking about


    1.7 billion in losses. That's absolutely huge amounts of money. The in 2019, they had a half a million complaints come in costing organizations three and a half billion dollars overall. That's up almost $3 billion from 2018.


    absolutely huge. So we have to be very, very careful.


    There are some reports out there email fraud and entity deception trends that are out there about the attackers what they're doing rise in hybrid attacks, which a victim receives an email making a request, and simultaneously receives a text message from a spoof number designed to seem to seem like the same person saying they just sent an email. It is highly targeted and also highly effective. So you got to be careful of all of this.


    We have to be careful of all of this and for business people, we have to be particularly careful about all of this government, government agencies. Did you see what happened with in Atlanta in the last year, how they got nailed multiple times. And it was ransomware. Getting in some of it was some business email compromises. We've had cities all over the country who have fallen victim to the business email compromise, and they have wire money to vendors that just don't exist, etc, etc. We have to be very careful. So how do you avoid this? First of all, don't send money to people that you really don't know. You know, you I'm thinking about those of us that are looking for companionship, friendship, maybe for a new lover, somebody that we can spend the rest of our lives with.


    Don't send them money really don't no matter how bad that sob story is. And then if we're business people be doubly careful.


    Verify everything via the phone. So the boss tells you that they need to move some money into another account. Call the boss you have their number, don't call the number in the email. If you are getting contact in HR from an employee's saying, hey, I want you to start direct deposited into my new account, here's the account number. Call back and verify it. Right That's always the case. You know, a police officer pulls you over the side of the road. You have a good chance that it's really police officer because they're an unmarked car. They have the blue lights going. They have a police officers uniform on. You just don't know even in that case. So be extra-extra cautious out there. Man. When we come back, we've got one more article for the day again, believe that it's gone so fast. We're going to talk about the most secure messaging app out there. Hi


    You can get it how you can use it. So stick around. You're listening to Craig Peterson and wg AN. And of course, Facebook Live in YouTube Live. Man, we're going overboard this week. Stick around because we'll be right back.


    Hey, welcome back, Craig Peters, Melanie or w g. N. and online Of course, we're doing a Facebook Live even as we speak, having a little fun there as the chuckles we're all about. Hey, I appreciate you guys joining me and I know that your time is valuable, and I don't want to waste one minute of it. So I'd love to get your feedback. What do you think of this show? What are the good parts, the bad parts? What do you want to see more of? What do you want to see less of let me know just email me and eat at Craig Peters. on.com. I'd really appreciate it and make sure that you are on my email list so that you get every week the latest in technology news.


    With a course in emphasis,


    as always from me on security, and what you can and should be doing for security in your home, and in your business, you know, I really focusing on business, because that's what I've been doing for so many years. You know, most businesses aren't in the cyber security business. And so they're trying to make their widgets provide their service, etc. And they're just left hanging when it comes to the security side cyber security. And I know that's true of you guys, too, who are in smaller businesses, even larger businesses and home users. But the answers the solutions are always the same, although you don't have as much money to spend so you're not going to be as well protected. Right? Do you also, hopefully don't have as many assets at risk. I know a lot of people who are high net worth individuals who come to me in order to get things secured, but as as a whole


    Most of the time is business Zilla. So I kind of aim at that. And then every month is well, we have a list of the top security vulnerabilities that there are patches out for telling you, hey, you need to update this software or that software. There's various vulnerabilities that you have to take care of immediately.


    Another coughing fit, man, hope this isn't assigned to something coming down with something. Here's the vulnerabilities you have to take care of right now. These are vulnerabilities that are seen in the wild, we know that these are being exploited. So I work with a number of different organizations, as we mentioned, the FBI infragard program, the sands people, NIST, the list goes on and on Homeland Security. They're all providing information so I boil it down. There is just too much to keep up with as I'm sure you can kind of guess right. survive.


    And so I boil that down, put it into one of my newsletters that you'll get for free. And it comes out once a month. And then once you've got that done, you know which Katie bar the door, right? Because now you're going to be safe against the worst things that are happening right now. So it's, it's really in, in in that interest is really easy. It's kind of a follow along things step by step. So I want to talk about this guy called marlinspike. I don't know if you've heard of marlinspike before that's one word. It's his name are marlinspike of course, I know having two kids who are three kids professional Mariners, actually, that's something to use is it on a knife that is used for weaving the ropes together, it's a little spike is called a marlinspike. Anyways,


    this guy launched an app called signal and the technology that he used and he developed


    Then he shared was also used by the WhatsApp people. And of course WhatsApp now is owned by Facebook. But it's signal that and that technology that's providing the end to end encryption for WhatsApp. Now, you know, I've talked on the show about what happened with Jeff Bezos and his information getting out and how the Saudi royal family Prince was supposedly involved in this. And, man, what a nasty mess that all is. The problem was not in this protocol that was developed and released by Mr. marlinspike. The problem was in the rest of the software that sat on top of it, that allowed access to the videos and the photos on the phone, and also had a bug in the software for some of those videos. So that's where the problem came from. So this


    Guy, Moxie marlinspike how's that for great name? Kind of reminds me of Who was that guy from New Zealand who had the


    that website I can remember changes his name to.com. Anyhow, Marlon Moxie marlinspike was on an airplane. He was sitting down next to a guy who said he while marlinspike said that he thought he was Midwestern in his mid 60s. And this guy asked him for help because you know what it was guys in the 60s do we have to ask young kids for help with technology right? Actually my case it's usually the opposite but anyways asked him for help. And the guy said he could not figure out how to enable airplane mode on his phone. So marlinspike looks at this Moxie and and he thought it was a setup. We thought this he was being trolled by this guy. Because right there on this guy's


    Home screen on his phone was signal signal is the number one secure app for sending and receiving messages. And they've added some more features to it recently. I actually haven't used it much for a while I've been using Apple messages, which is pretty darn secure but it's not signal. And he thought oh wait wait a minute here I'm being played he's playing me because he knows who I am. I'm Moxie marlinspike and and and so he was kind of wondering what was going on. But anyways marlinspike


    put this whole signal software together some years back, widely considered to be the most secure and encrypted messaging app. It's probably an old five years, and there is now a private foundation that maintains the code and that Moxie is the head of, but it turns out this 60 something guy next to him on the plane didn't know any of this stuff. And a Moxie showed him how to enable right airplane mode and gave him the phone back, and he says, I try to remember moments like that in building signal marlinspike told Wired, and this is from a Wired interview, you see this here in my Facebook Live, I put the link to it right there in the live channel.


    And he says the choices. We're making the app we're trying to create, it needs to be for the people who don't know how to enable airplane mode on their phone.


    You know, that's right. I can see that. It all goes back to UI design, right? User interface design, you have to design for the least common denominator. That's one of the reasons iPhones have been so popular. Steve Jobs just kept going after the designer say make it more simple, make it more simple, make it more simple. Think of that first iPod Could it have been more simple


    I had an mp3 player, and I still have it, it's like this big. And for those who aren't watching here on video on YouTube or Facebook, it was probably what would you say six inches long, and maybe three or four inches wide and a couple of inches thick. And it was phenomenal. The audio quality was better than those original iPods. But it was much more challenging to navigate. And there are so many more things you had to do to load it up and make it all work. Steve Jobs just made it simple. I have to emphasize that because if you're a business person, you have to make it easy for people to do business with you, not like me, and kind of make it hard, right? But make it easy for people to do business with you. And I'm trying to change that because there's a lot of things I could do to help people out that could pay my bills. So I'm not worrying about where my next checks going to come from right.


    So, five years later, today now Signal is reaching a much, much wider audience. It's reading the not reaching an audience that includes the 60-something-year-olds on through the younger kids. And I have to say, if you need secure messaging, and frankly, that's almost everybody. Take a look at Signal. It is free, absolutely free. It is available on iOS on Android. There are now versions for computers as well. And it lets you talk on like on the phone, and they'd let you make video conversations, share pictures, and of course, text back and forth.


    And that just goes to prove that it's not just for privacy diehards or activist because cybersecurity needs to be something that we think about all of the time and needs to be something foremost in our minds, just like everything else you talked about today, I hope that you take a few minutes and go through the whole show this week, you should do it every week. I'm always giving you tips and tricks, the tactics of things to do the strategies of overall what needs to get done out there. And some stories related to it so that hopefully you can see how it does apply in your life. And that's why I'm doing more and more the Facebook Lives, and YouTube lives. And I am putting together these courses. I've got tutorials now that I'm going to be releasing in a couple of weeks that we have spent weeks on I'm going to do some training, some more webinar training that again, that we've been spending weeks on because I want you guys to know this stuff, right? You have to know it. I don't want you to lose your businesses. I don't want you to lose your life. Saving


    Right, I want to be able to communicate. I want you to be able to communicate with your families. And you know, what was it two weeks ago I was on the radio with canon, madam on every Wednesday morning at 737 738. In the morning, during drive time for about half an hour. We talked about security. And I've been talking to Ken and Matt about security now for a year, two years. I'm not sure how long I've been on with at least a couple years now, maybe even three, and helping them to understand the security and what needs doing. You know, they asked questions is very, very interactive. It's like the whole reason I'm here. Over on Facebook Live. I'm taking questions as we're speaking as we're on the radio because it needs to be interactive. So after two years of speaking to them every week, about security things and things to do, and just talking with them two weeks ago.


    Go about the basics again, getting right down to, are you using password managers? Because I've given out information on them before free password managers paid password managers? And the answer from both of them was, No, they're not. And you know, that's one of the essential things that can be done. So it's evident to me that we still need to keep talking about this. And I understand how daunting this is. I know the guys selling you the antivirus software are lying to you, the guys that are selling you the VPN services, most of them are misrepresenting or lying to you. Okay, I get it. You've tried things they haven't worked. But I want you to know what you need to know, do what you need to do and be a success, frankly, getting all this together. All right. Hey, thanks for being with me. Make sure you visit me online. Craig Peterson comm check out the Facebook Lives, the training needs, the tutorials, the courses, the webinars, it's all there. It's all for you. It's all available home users through even large businesses. Have a great week. You've been listening to Craig Peterson on WGAN.

    Transcribed by https://otter.ai

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 31 min
  • Welcome! Election and Voting and the use of Technology, Poorly written apps and Bad Chrome Extension and more on Tech Talk with Craig Peterson on WGAN

    Welcome!  

    We are going to hit a number of topics today from the world of Technology. Primaries and Caucuses are underway and with that always comes the topic of technology and security and it is no different this year.  Apps are being developed and brought to market without being fully tested.  Extensions are being created that have ulterior purposes and are being downloaded by thousands and even more, on Tech Talk With Craig Peterson today on WGAN.  It is a busy show -- so stay tuned.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Related Articles:

    Four States Use A Flaw Filled Mobile Voting App 

    Iranian Hackers Exploit VPNs Worldwide

    IT Disaster Recovery/Business Continuity Exacerbated by Coronavirus 

    Be Careful of Extensions on Chrome - Many found to Upload Your Private Data. 

    Sharp Increase in Exposed Records by Third-Party Applications

    Automotive Apps originally designed for Personal Owners cause headaches for rental agencies.

    1.77 Billion  - That is how much Businesses lost last year to Business Email Compromises 

    Encrypted Communications for the Masses

    ---

    Automated Machine Generated Transcript:


    Hey, welcome, everybody. Craig Peterson here on WGAN. And we're live on Facebook. And we, of course, can be found over my website as well Craig Peterson, calm. We got a lot of topics for today's show. But we're going to start with the one that is really on everybody's minds right now is we see more of these primary elections beginning to come up, and we see problems. Well, I don't know, or are they problems or features? I guess they are problems with some of the election technology that has been used over in Iowa. New Hampshire's technology was rather straightforward as the Secretary of State in New Hampshire says, and it's hard to hack a pencil, although they're not using pencils. In New Hampshire. They are using felt pens, which are hard to hack as well. And these cards can like the cardboard that you would have in the back of a shirt when you purchase it.


    It's that type of cardboard that is not shiny or glossy, and then it goes through an optical reader that scans the ballot and places it in the bottom of that machine. An election official stands there to make sure that the balance legitimate. That you are not trying to stuff the ballot box, and that machine counts your vote. Now the unfortunate thing is those machines are kind of old in most states, some of them, I think maybe all of them are still running Windows XP, but there's no easy way to get it the operating system. It's never connected to a network. Even though some of these machines that have been examined and have patch levels zero or in other words, no patches of Windows XP, which is quite surprising when you get down to it. That is a big problem in many many cases. In New Hampshire, the primary went pretty well. Of course this weekend, the next one coming up, which is in Nevada. The Nevada caucuses. I don't know what to believe anymore because

    I've heard both sides of this. One that voting in Nevada is using the same technology that was used over in Iowa, which to me would be just a shocker and a whole big dismayed because it was just so terrible. As I've said on the radio before, in fact, this week when I was on with Ken and Matt, I think it was, might have been with Jim, I'm trying to remember who it was, which show. I pointed out how in when we're looking at some of this technology, we all well, not all of us, but some of us love the latest greatest technology. I'm one of those guys that like to stick with something that I know works and explore current technologies and newer things. But so many times we get just bamboozled as taxpayers because the people that are in control of the purse strings, they like the latest coolest stuff. They buy equipment from people they know hence the app and iOS.

    Former Hillary Clinton staffers ran the company chosen for use in Iowa, and I don't know how much vetting they did. We do know that the code wasn't checked. Homeland Security had offered. We also had offers coming in from Federal Investigation Bureaus and from several security companies saying, Hey, listen, we'd be glad to have a look at this. It was all closed source. It wasn't open-source where you can have a look at that software and say, yes, indeed, everything's legit. That is excellent software. People can find bugs in it. If they find a bug, they can report it, and it can get fixed, right? There are so many different things that they could have done when we're talking about trying to make this secure. I see Mary just joined us here on the Facebook Live and which is cool. She and I have worked several elections in the pas,t and we've been monitoring them. I have a son that's been one of these election officials. You know, part-time people that get pulled in to watch the voter checklist and things in New Hampshire, you have to have an ID to vote, which is weird, you know. I liked the way we did it here, Maine's doing the same thing. Most New England states are in fact as northern New England are doing the same thing where we have a felt pen, we have a piece of paper, we mark it down on that piece of paper, and we can then count it later on. If there's a problem, right? You can just go to that paper that sits in the closet, pull out the stack, bring it with you. And once you've done that, you can have a bunch of people sit around and think about Florida 20 years ago and what happened there with the hanging chads. They at least had a physical card they could look at although you know pregnant chats, hanging chads got to be quite the mess. So now we're getting concerned because of this new voting app that's out there. It's called Votz.

    V-O-T-Z is how they spell it. It's not the same one that was used the caucuses in Iowa. The app that the Democratic Party was using was trying to take the tabulations that were made by the people who were at all of these different precincts and figure out what the vote tallies were and then supposedly put it into the app and it gets sent up. This vote app that we're talking about right now goes a few steps beyond that. They want military personnel, and people are overseas to use it when they can't necessarily vote when they want to vote. It's, you know, panacea, maybe it's something we can get to in someday, but four states are going to use it this year. It has not undergone the trials that really should have gone down. And it's using a buzzword that I think got people's attention.

    And they're saying, Oh yeah, this is going to be safe because it's using this buzzword called blockchain technology. Blockchain technology is what used behind various cryptocurrencies, like Bitcoin and some of the others, to help secure the transaction. So the whole log is it signed each record inside the register is signed. Just because it has blockchain doesn't mean it's secure and doesn't make it properly designed. I've got a quote here in this article from MIT, is computer science artificial intelligence lab saying the whole thing is sloppy. It looks sloppy. It's in Georgetown Law. It's awe-inspiring. They were able to find such a pervasive set of vulnerabilities, said Matt Blaze and election security expert and computer science professor at Georgetown Law School. But we should also remember it's ultimately unsurprising that they would be able to do so because of every expert has warned against Internet voting as being vulnerable to flaws exactly like this goes on.

    The University of Michigan here Alex Halderman, saying that it makes vote seemed like a sham. So it is a sham. I think I think it's a real problem. But we're going to do it anyways and four states, including West Virginia, this year is going to be a mass. We've already seen what happened in Iowa. We saw excellent voting happen in New Hampshire. We're not sure what's happening this weekend in Nevada, then Super Tuesday is right on the heels. Some of these states are using these voting apps. Some of them are using the apps used in caucuses. I think thank goodness there aren't very many caucuses in the country. And we'll see, but one thing is guaranteed, and that is it will be quite the debacle. It is going to end up being a problem for everybody involved because they didn't vet this technology. Now, I reported on this a couple of weeks ago, this $10 million grant set aside by the Department of Defense grant, ultimately, and it was to design a voting machine that would be secure. A voting machine that we could trust. I think that's just wonderful. It hasn't really been tested yet. They brought it last year to one of these conferences like Black Hat and Defcon. They brought it out there. Every year there is a voting machine village where they have all kinds of voting machines there. They are asking people to go ahead and try and hack into the voting machines. We had a 15-year old that was able to hack a voting machine right there, and they compromised every voting machine except for the device under development on this $10 million contract. Now, that might seem impressive, and that might be kind of encouraging to some of us. I think it kind of is in some ways. However, the reason they did not hack it was it didn't work.

    They were not able to get it online and did not get it online until Sunday, which was the last day of the conference. And so no one got to test it out. But that was last year. Let's get them a little real a little bit under their belt, a little water under that bridge sometime, and they will be able to do it. And you know, I think they'll be able to do it ultimately, but I still will be the biggest proponent of a pencil and a piece of paper or a felt tip pen. The software, By the way, those votes VOATz software is being used in Denver, parts of Oregon, Utah and Washington State, we'll see what happens. West Virginia, as I said, is going to use it. But for disabled voters, the federal government requires all states to have electronic voting machines that can be used by disabled voters. I know here where I live in New Hampshire, we have a thing I don't know they might have passed. Now they're kind of getting old. Twins, twin women, and one of them was pretty much deaf, and the other one was pretty much blind. So they were able to help each other out in a massive way, which is kind of cool and get right down to it. But what they did is they kind of both helped each other to vote, but we all have in every precinct people who are there who can help people with disabilities. I don't like this requirement to have electronic voting machines. But the MIT researchers, these other researchers all agree with me. I'm very
    concerned about the Android phone and Android as a platform for people to use. I don't know if you are if you're using Android, you know, I'm always saying use iPhones much, much more secure. But I also am not looking at an iOS as being the problem. Cure-all for some of the voting machines. Anyhow, we are live on Facebook, as I'm putting the show together and shout out to everybody who is on there and asking questions. I appreciate it. And I will go back in and answer questions for anybody a little bit later on who has them, and I want you to stick around. I will be back here after the commercial break. We're going to be talking more about the latest in technology. We're going to be getting into these Iranian hackers that have been hacking VPN. If you think your VPN is safe. We've got another thing coming. So we're going to shut this one down. And we will be right back. Thanks for joining us, of course, Craig Peterson dot com.


    Hello, everybody. Welcome back. Craig Peterson here on WGAN and affiliates. You'll find me online at Craig peterson.com. And, of course, online at Facebook. I'm doing this Live on Facebook, and also out at YouTube. And we're going to talk right now about VPN. So hopefully, you have some understanding of them. But some exciting statistics came up this week from our friends in government. The FBI has been warning us a lot lately about what's been happening over in Iran what they've been doing, and we don't have kinetic war. In other words, we're not shooting at each other, which is a good thing, right? But Iranian hackers have been right at the forefront of trying to hack into our systems, and they've been relatively successful.


    I have a few clients that are in the defense industry, because we do, of course, the higher security stuff, right. And they have been under constant attack from Iran for about six, eight weeks now ever since the last little tussle with Iran might have been longer than that. And we're seeing sustained efforts to hack into them. Well, now we're getting a report from our friends over at ZD net here about Iranian hackers targeting these VPN services. So I thought I'd start by kind of explaining to everybody a little bit more about VPN services, what they are, what they offer. And because I'm hearing ads about this all the time, and frankly, it's driving me crazy, because the ads are telling me that Yeah, Craig you need a VPN because it's the only way you're going to be safe. It's the only way you're going to be secure in your day.


    You've got companies out there that used to be known for anti-virus, which of course nowadays we know antivirus software is zero percent effective against the latest hacks that are out there. So antivirus software companies are trying to figure out what's another way that we can make some money because people are starting to realize that this is a scam. And it's been a scam for a lot of years. You know, antivirus worked pretty well 15 years ago. It doesn't work at all today, as I just mentioned for the latest now malware nastiness that's out there. So some of these companies one that comes to mind.


    It was purchased not too long ago by another anti-malware company is running a lot of ads. They're saying this we need our VPN you need our credit watch. They've tied in, with one of these companies that watch your credit looking for transactions, it might be a bad guy, and I'm a little concerned because here's what usually is going on in the VPN industry. Running a good VPN is expensive. When you are using a VPN, all of your data, depending on what type of a VPN, how it's employed is encrypted from point to point. We're talking about the right ones and not those that you hear the ads for when you're using those types of VPNs. Your data is transmitted up to the VPN service provider. Then once it gets there, it is sent out to the internet. So let's say you're trying to go to my site, Craig Peterson, dot com. If you're using a VPN, your web browser is going to ask the VPN server Hey, can I get the Craig Peterson dot com? What's the best way to do it? How can I get there, and the VPN server will say Hold on a second. I'll get that page for you. Then the VPN server goes out to Craig Peterson dot com gets the page and sends it back to you.

    Now, that would be a caching or proxy VPN server. And some of them will just pass packets through. But the big concern I have is twofold. One of them is this whole Iran thing, and we'll get into that in just a minute. Because it isn't only Iran. But the other one remembers if something is free, or if it's inexpensive, who's the product? You the product! And since you're the product, what do you think they're making money off of selling your personal information, that's how they make their money. And that is a big problem as far as I'm concerned. So what some of these VPN services are doing is they are tracking you online. Some of them go the next step, and they're actually acting as full proxies, and they are sometimes acting as a man in the middle attacks.


    They're injecting things into your data stream that you weren't expecting. So where you think you're getting the VPN to have some security, and to have some privacy. Some of these VPN services are the exact opposite. They are reducing your privacy because what they're doing now is taking your data and selling it to the highest bidder that's out there, right. So I think that's a problem. And if you think it's a problem, maybe you shouldn't use some of these cheap VPN services. And I haven't gotten any I actually like, okay, I've heard advertisements on these radio stations, my shows airing on and I've checked them out, and I'm not comfortable with any of them. And the only VPNs I use or VPNs that I run, but remember, your data still has to hit the internet at some point. Remember, you're using one of these VPN services.


    versus your data is going to the VPN service provider. And at that point, it hits the internet. So it's now out on the internet. Well, if you're trying to make sure your data doesn't get on the internet, and people aren't hacking you, you've lost because your information does have to get to the internet. How are Internet Service Providers supposed to get to your bank? How are they supposed to get to my website? How did they suppose to get to Facebook or Google or YouTube? They have to go over the whole internet as well. If you're using one of these services, and they're going out to the internet. What do you think is a bigger target you at home, using the internet via your cable company or your telco or maybe your smart device. Is that one device a big target, or do you think that perhaps its the VPN service providers that are the bigger target, right? I'm not sure I need an answer because it's kind of a rhetorical question. The most significant marks out there when it comes to VPNs are these VPN service providers. And we're seeing warnings out there right now that Iranian hackers have targeted pulse secure, which has VPN software that they sell to businesses, shown to be insecure. Pulse Secure for the net. Another example of one of these security companies, right that has a VPN service, Palo Alto Networks, a company I have never used and never recommended either. I haven't recommended any of these companies to anybody ever. We've gone up against Palo Alto Networks in some proposals and contracts and, and they won them because of all the whiz-bang, not because they were the best of the safest, and so


    So there you go, Paul secure Fortinet, Palo Alto, and Citrix VPN are now being used to provide a back door into larger companies. So if you're a business person, I'm going to put these right now into this channel so that you can look it up for you or business and seeing and write this in as a comment over here in the Facebook Live that you can find online. Yes, go to Craig Peterson, calm slash Facebook. It'll take you to my Facebook channel. But there's the list of them. It is from an article that's out there on ZDnet. I think they have been publishing some great information lately. I've been using them in a number of my alerts that I send out as part of my Saturday morning emails. But some of these attacks have happened according to this firm called clear sky that Iranian hackers have targeted companies.


    From the IT telecommunications, oil, gas, aviation government and security sectors, why because that's where all the real money is. The particular report is dispelling frankly, the notion that it's their Russian and Chinese hackers or maybe North Korean because the Iranian hackers don't know what they're doing right. I've heard that before all Iran, don't worry about it. They know what they're doing. When in fact, yes, within hours of being disclosed, the Iranian hackers were right in there. It's terrifying. So keep an eye out. I look. Again, online at Craig Peterson, calm you'll find this article, and a whole lot more. Make sure you ask your IT department if you're using any of these VPN services or software. And by the way, in most of these cases, you can get patches to fix it. When we come back. We're going to be talking about Coronavirus and the new challenges right here on WGAN.

    Hey, welcome back Craig Peterson here WGAN and online at Craig Peterson dot com, of course, on Facebook as well. I am live on Facebook, and you can ask questions there you can watch this whole show as it unfurls, and you will find me there. You can ask questions almost anytime. We try and keep you up to date on what is happening out there in the world of technology. Well, you might not have thought of coronavirus as anything more than just a piece of nastiness, right. The virus I know some people are saying well you know we haven't had as many deaths from the Coronavirus, also known as covin-19. I was trying to remember the name little earlier. We haven't had as many deaths from that as we have from our regular flu virus every year. Right now is the peak of flu season in the northeast and

    Anyways, and in many parts of the country, and what is there to worry about, right? Is it going to hit us? It seems to be slowing down. We don't have a whole lot of information from our socialist friends in China. Like most socialist governments, they play things very close to the chest. They don't want people to know what's happening, including their citizens. But we have some new fears now, and this is a great little article that I have found over on dark reading. It's pointing out some of the security challenges that we're facing, because of the whole Coronavirus thing. Everybody's heard about it, everybody's scared of it. And when you get right down to it, you're watching me right now listening to me talking about the Coronavirus because it is an exciting thing to understand. The CDC has not only maps of where the Coronaviruses hitting right now, but the CDC also has information about general flu viruses this time of year. There are outbreaks of different diseases, what's happening where CDC.gov now I've seen some fake stuff like CDC, dash gov.org, just all kinds of fake sites. With phishing, we've got to make sure that all of our employees, family, friends, know not to click on any of those links. Don't click on them. However, people do and when you click on them, who knows what's going to happen, you might be downloading malware, you might just be confirming this is a valid email address for more and future spamming, right there might be a lot of different things that it can do to you. Don't do that. The next one I think that that's very interesting is something most businesses have not addressed. What would happen if maybe covid-19, or something else, actually becomes a pandemic? What if it is not even a pandemic. What if you have an office with five or ten people in it and everybody comes down with the flu or cold? At the same time?


    Have you prepared for a business continuity challenge? And it isn't just what might happen if you're sick. It might also be a little bit further than that. What might happen if the business burns down? Or there's flooding, or no one can get into the office for a day or two because of some natural disaster? Maybe, it's just a really nasty ice storm like we had here? What a decade ago, where there were portions of New England that had no power for six weeks, in the middle of winter. That's a very, very big deal. What would your business do? Most people will haven't had a good hard look at business continuity, just in general, although we really should.


    And when we've got the cyber attackers coming after us, it also brings to mind what would happen if they got through, and let's say it was a version of ransomware that encrypted all of your data or deleted all of your data and demanded a ransom. Are you going to be able to handle that? Right? It's a big question.


    Will you be able to continue with your IT people, whether they're outsourced or in-house? How about your security operations people?


    It could be a huge problem.


    Let's move it up-scale because I know we've got a lot of people listening, who have more substantial companies. Maybe a 200 person company, perhaps something more prominent and it would be interesting to know you can just drop it in the channel like to know a little bit. But if you've got to hundred people working in one building and it's a contagious virus that's getting spread, the odds are pretty darn good, that 10 to 15% of your workforce is going to get nailed with that bug. Okay. Here's an example from the article.

    If it's by the way, if it's something that might be pandemic, there's an excellent chance the government's going to quarantine everybody anyways, whether the people get sick or not. Okay, and what's that going to do to your business? It is a consultant over Accenture working in Mexico City during the h1 in one virus spread ten years ago.

    They were saying that the current quarantine protocols are 14 days. So think about that. What happens if your business if your employees are out for 14 days if you've got a large outsource facility. Your security management, any facility, with a large number of people and you probably don't want to bring 100 people together and put them in a small room unless you-yourself have evidence that none of them have been affected. The second part of the challenges they may not be able to get there even want to get there. Now, this is the business continuity side. Can your business continue if there is a spread of these types of diseases, this could be huge? Some Indian companies have reported, according to dark reading, they've reported disruptions because of stoppages and shipments from China. They've got 45,000 Plus Now I don't know what the number is confirmed infections over 1000 deaths. So if you part of your supply chain now is affected, in this case with the Covid-19. Of course, most businesses are worried about the supply chain from China. There's supply chain manufacturing the low-cost components from China to Indonesia and all kinds of places in Southeast Asia what happens if that goes away too? If you have parts being made anywhere in the world, keep in mind that businesses are starting to move if they haven't already. Then with all of the phishing that's going on, It can get to be a very big problem. Proof point and Cisco Talos have reported messages purporting to provide tips for virus protection. They appeared to be sent not only by official government organizations but by the own businesses itself, upper management. So there's an example of spearfishing going after a specific company, and the messages get used to stealing credentials drop malware like mo tap, and in lures specifically targeting manufacturing and shipping industries. The nano core remote access software, these are back doors, like the kind I've talked about on the show that we have found in business and that is before backdoors get put in there by China or that Iran now has become a big player in all of this. So very, very big problems. Hey, if you have joined me on Facebook for the Facebook Live Welcome, welcome. I appreciate the comments, like seeing the thumbs up, so please do give that to me. Otherwise, you can find me online at Craig Peterson dot com. I post all of everything we talked about every week, right there Craig Peterson dot com and I started sharing videos and, and other things as well on YouTube and a little bit more on Facebook. When we come back after the break, we've got more to discuss. Next up. We're going to talk about these 500 Chrome extensions that have been secretly uploading people's information. How's that for a scary thing? So stick around because we'll be right back. If you are on Facebook Live. We're going to end this Facebook Live and start another one with our new topic in about five minutes on the radio. We'll be back even quicker than that. So stick around.

    Hold on one sec. Here we go, everybody. Welcome. Welcome Craig Peterson here on WGAN and elsewhere. Of course, also on Facebook, Facebook live is where you'll find me there. Just go to Craig Peterson dot com slash Facebook. You can sign up for my weekly newsletter, where I make sure you have all of the latest news, everything that you need to know. And right now we're going to talk about everybody's favorite browser while except for mine. One of the companies that we use goes by the name of Duo and what they have recently found out about our friends over at Google and Chrome. If you are a big follower of mine, and you've attended some of my pop-up training, I do quite a few of them.

    Those are always free and, and I have some tutorials as well. I talk a lot about extensions because there are quite several extensions that can be fantastic. And I use them all of the time. If I were to bring up my browser here, you would see a whole bunch of extensions that I use continually. I use them to block certain advertising types, and I use them to prevent various kinds of malware. I have some extensions that use artificial intelligence to figure out what is this page trying to do? Because we've got things like pop-unders, where it opened something up, and it has little timer was saved for an hour, and then it pops up to this big scary message that you need to update windows or update something now


    Because it's out of date, and there are hackers out there that are trying to get you. And that's called, by the way, scareware.


    But it comes through your browser, and you have no idea. So some of these extensions that I use are specifically designed to look at the source code on the page, look at not just the HTML, obviously, but look at the JavaScript or so much stuff is hidden. So it pulls in all these pieces of JavaScript. Usually, they're removed in from multiple sites and assembles them has a look at them, and will even change them based on what it finds. Now, those are beneficial extensions. Then on the other side, there are these toolbar extensions. I don't know if you've used these before, man, these used to be all of the rages, and I still see them installed in people's computers. And these toolbar extensions give you a little bit of extra something sooner, just a call right in

    These extensions going to track you when you're online and shopping and tell you where the best deal is? Well, yeah, it's following you, right? It knows that you're on a shopping site because you give that extension access to all of your browsing history. Then it knows what you're looking at up the site and knows what you are searching. Because so many of these extensions come with their little search bar up top right. Yahoo was one of the big guys out there in this browser bar extension business. And every last one of them at the very least, despite you. Now, that's bad, right that it's bad enough. But now we're looking at this same mo wait a minute here. We have now uncovered 500 Chrome extensions that have been secretly uploading the private data from millions of users.


    Huge deal. An article in Ars Technica, if you are over on the Facebook Live, you'll see the article, right there has a direct link to it. But this is very bad. It was just discovered on Thursday here. It's been just about just over a week. And we found out from these guys, that what had happened is that these website extensions had more than 1.7 million installations. It was an independent researcher who worked with Cisco's own Duo Security. And they found all of these things. They then reported it privately to Google and the researchers and found 71. Google looked at what the researchers had seen, and how those extensions were coded up and how they we're behaving. Then Google found an additional 430 extensions. And Google has removed all known extensions that were doing this. So that's the right side of it. But that's the known extensions. Those are the extensions that we're doing something that looks suspicious that Google and the security researchers could identify. In this case, reported here, the Chrome extension creators and specifically made extensions that obfuscated the underlying advertising functionality from users. Now it did say advertising in this quote because here's another thing that they do. If you visit a website, and you have an extension installed, that has access to the websites that you're visiting, here's what they've been doing. They look for ads from their customers, so you've got a bad guy, Inc. Okay. And then what better guy he does is he goes out and says, Hey, listen, I can get you 1000 collects of thousand new views of your page, just pay me up. Then what they'll do is they will play some ads for you. These are pay-per-click ads.


    Every time someone clicks on an ad, they have to pay, right, and some of these ads are cheap at five cents. You don't see that too much anymore. Some of them are $500 for a single click. That money then goes to Google, who then shares it with whoever had the website where the click originated. Okay, so it's a pretty lucrative business if you as a bad guy that could guarantee clicks on these expensive websites That is what they're doing with some of these extensions.


    They are watching the pages you're visiting to look for an ad from one of these sites that they get some money fro, but now they can have your browser click on the ad unbeknownst to you. Your browser now clicks on that ad. They make some money because they have the fake ads that are up so all kinds of nastiness. The other side of this is let's say the bad guys want their competitors to stop advertising online. Let's say they make cups, and I make this glass. Other companies out there that make a blue glass kind of like this. They find out what are the ads this other blue glass company is running. They have their little extensions out there. They hire these people that only extension to then clicks on the competitor's ads automatically for them. The competitor might have a five hundred dollar a day limit with Facebook ads, and all of a sudden now that five hundred whatever it is they're spending where they've put a cap on it, right? So whatever it is they're spending is being 100% wasted, because you don't even see the ad. There are so many ways that the bad guys are using these extensions. It is a maze of redirects, malware, and more. Some of these plugins will do Bitcoin mining or other types of blockchain cryptocurrency mining out there.


    Man, there's just all kinds of them hardcoded control servers, which by the way, I've got another tutorial coming out telling you how to stop your computer from going on to some of these command and control servers. And that's going to be phenomenal for you. So keep an eye out for that coming up in a couple of weeks.


    Many the redirections because they're using redirections, as well as part of this, go to ads for products or Macy's, Dell, Best Buy
    large volume of ad content, as many as 30 redirects, the deliberate concealment of most ads from end-users and the use of the ad redirect streams to send infected browsers to malware and phishing sites. It goes on the bottom line, beware of extensions, but I also want you to be aware of apps, right? What are the apps that you are using? What are those apps providing you with? Now I'm talking about apps that are on your smartphone or on your tablet, maybe some programs that are on your computers. Okay, they're out there? What are those apps

    Are those apps something that you need? Many of them spy on you, which is another dangerous thing. They're stealing your data. They're taking the information they're sending to the bad guys. Right? It just goes on and on. So make sure you don't do that it is dangerous stuff. All right, I am doing this radio show on Facebook Live. If you want to follow me on Facebook, it's easy enough to do Craig Peterson comm slash Facebook. And if you are not a Facebook fan, and there are a lot of reasons not to be a Facebook fan, then you can also see a lot of these videos up on YouTube. I do YouTube lives, as well. You'll find that at Craig Peterson comm slash YouTube. And of course, you're listening on the radio, and you're going to find me on pretty much every streaming service that's out there. So I want to quickly ask a question - which browser do you use? If I say create a poll? What's going to happen here? Oh, there it is. I'm going to publish it right now. I see. Okay. All right. So far it's showing up. I should have clicked this a little bit earlier. So Facebook Live, you have a poll. Do you prefer Google Chrome, Firefox, Microsoft Edge, or Opera? And I personally use Firefox and Opera, Google Chrome and edge I don't trust particular Google Chrome, however,


    There are times when you have to use one of those two browsers, because your company might be using a website that's specifically programmed to only work with that particular browser. There. There might be other reasons, but let me know. Click on it there. If you are not watching me on facebook right now Facebook Live, go ahead and answer that poll. I'd really like to know or just drop me an email me at Craig Peterson calm. Let me know what your favorite browser is and why. And make sure that you delete every extension you don't need. Every app you don't use and don't need. We've got to cut back because it just presents such a broad attack surface to the bad guys. All right. Okay, so let's see end of this segment. When we come back, we of course, have a whole lot more to talk about. We're going to talk about third party breaches, what's been happening. It's increased sharply in 2019. If you are a business person, this is for you. Your listening to Craig Peterson WGAN and online at Craig Peterson dot com


    hello everybody welcome back Craig Peterson here on WGAN or also on Facebook Live if you have any questions, by all means drop them right here into the channel can always ask me a question to online anytime. Just email me and he had Craig Peterson calm more than happy to respond. You might have to have a little bit of patients I do try and get back ASAP. But if someone or my staff is not noticing or final notice Don't feel bad. It's not as though we hate you. But we do try and answer every question that comes our way just me at Craig peterson.com. We're going to talk right now about third party risks whether you are a small business or a little


    large business, this is a huge deal. very huge deal. And it's also a huge deal if you are an individual, because you are dealing with everything from Cloud services through


    a milk delivery company. All of these are third party services provided by third party companies. And many of them have information about us.


    And I've heard from so many businesses lately, that are now required under the new federal standards, the CMC standards, that they don't think that they really apply to them because they're not a primary government contractor. It's they don't have a whole lot or any personally identifiable information. You know, why? Why would you come after me? I just don't matter in the whole big scheme of things. So it's not something that I should have to worry about.


    When the law is clear, they do have to worry about it, but they're still not worried about it.


    And I think the biggest reason is because people just don't understand the risks involved. You're using Google spreadsheets, for instance, Google docs for me, you know, Microsoft Word replacement. And, and Google also has kind of a PowerPoint thing called Google Sheets, I think it is, or slides, Google Slides that you can use in order to put the presentation together. And even to show a presentation. It's, it's really rather cool stuff all the way around. But this is an example of a third party vendor. We already know that Google is looking at all of those documents and trying to figure out what a can use from that and in order to sell us stuff, right or do seller information to third parties. And in that's obviously a bit of an issue. But when we're talking about these smaller businesses that might be selling to


    Another government contractor that might be selling to Raytheon who's selling to the Department of Defense, just as an example. They wonder, why does it matter? That I'm really secure, because I'm making something that's completely passive. It's not as though I'm making the software that controls a missile in flight. Right? It is not doing any of those sort of things. So why should it matter?


    And I think that it's a good question, but here's why it matters. There were some huge hacks of the Department of Defense last year, and those hacks a good 50% of them came from their vendors. We're talking about a third party risk.


    That third party that vendor you're using, whether it's Google Docs and Dr. Mike, you might be using a version of Dropbox as


    Just a regular end user version might be using an unsecured or improperly secured as your instance or Amazon Web Services instance. You could be using any of those types of things. And guess what's going to happen if you're using those.

    All of those people who have your data could be used as a way into your computer's think for a minute. We spoke earlier today about these 500 plus Google Chrome extensions that were leaking your data there, the data is actually being stolen by third parties because of those. If you have software installed that's being used to manage your supply chain, and that supply chain software is tied into this third party vendor. Your network is is is exposed


    Now you may have tried to tighten it down, I might be as tight as could possibly be. And there's no problem here. But if you're like an average business, none of that is true. None of that is true at all. All of your data is potentially accessible by the third party. So some interesting stats that came out. And I again, I have this up on my website. I will post let me post this right now here in the Facebook Live channel. Okay. It's in there now to you can see that right at the end of my comment. They're showing that there were about 43% of businesses this last year 44% were, in fact, attacked and hacked via third party breaches. So in other words, the bad guys did not come in directly


    This wasn't a phishing attack attack necessarily directly against them. This wasn't a ransomware attack directly against them. It was against a third party. So it was a vendor who might have had all of their customer information they might have had to how to manufacture certain things. It could be all kinds of different types of information. And that information was then used against them. That's a very big deal. Think about billing. Think about your, your employees and their paychecks, their w 210 99. Since you send out all of these things to target so we talked earlier about these VPN services that are right now huge, they're huge attack vector. Now this number is up by the way 35% over the last two years.


    The number of records exposed in the breaches skyrocketed. Almost


    300% last year, the cost of the breaches have gone up substantially as well. And you're going to find all of this up on my website, Craig peterson.com. But that's huge. So 44% of all firms that were surveyed had experienced a significant data breach caused by third party vendor. And remember, these are firms that know that they were breached. So let's look at an IBM study. This IBM study says it takes an average of 197 days for a company to identify that they have had a data breach almost 200 days to even identify even know that they had a breach and another 69 days to contain it. Fat is inexcusable. In excuse inexcusable, it really is. You know, so many people have fallen through


    victim to vendors that say, hey, we've got the solution for you Don't worry about it. This is this is going to be so easy, not a big deal. We'll take care of it for you and they don't that's the only explanation I can come up with here. For what 265 ish days, from the time a breach occurs to the time that they've contained it. 265 days, that's two thirds of a year. Now I believe me I'm this is not I'm not trying to sell you our services here. Okay. If you want to buy him great. I just want to let you guys know 250 days on average to contain it with what we do on average. It is this from this. From the time it happens


    to the time is discovered to the time it's


    contain. So from the very beginning of a breach to the time it's contained. With us, it's typically six hours. That's why I say this is in excusable, if you're a company with 200 employees with 1000 employees, and you're not using the right stuff. Whose fault is it?


    And I gotta tell you another number that I've seen before when when I was one of the FBI infragard programs that I ran, I had an expert on, and he was talking about breaches, and you know how many months it takes to discover and then to try and close the hole.


    If you take less than 30 days to stop the breach, on average, you save $1 million,


    a million dollars. So think about that when you're thinking about the cost of security. If you are


    slightly bigger company, you have a few hundred employees up into thousands of employees. And you can shave that whole massive number of 250 days, down to 30 days or less, you've saved yourselves a million bucks. So the million dollars that you might spend on security and by the way, it takes you quite a bit to spend a million dollars to even to get the kind of security I was just talking about, with the six hour to recovery stuff. A million bucks goes a long way now and that's plus, by the way, you know, all of your other costs, the loss of reputation that you get, so you're going to lose clients, you're not going to pick them up, you're not gonna be able to charge as much as you could before. People aren't going to trust you. All this is happening because of these third party breaches. So keep that in mind next time.


    You are auditing your business, right? You've got auditors and think about all of the people downstream from you


    who maybe you should be paying some attention to, because they have data that you might find to be sensitive. They might be used as a conduit to break into your systems as well as have their systems breached. Okay. So I know many companies now that are, are auditing their providers, their upstream downstream partners, for very, very good reason. So if you want to find out more, let me know just email me at Craig peterson.com. Be glad to punch in the right direction. You can find this particular order article over and dark reading and it's written by Jay v. JOHN, and you can find it as well at Craig Peterson calm Of course I post all of that stuff online. And if you have my newsletter, you get that


    Every Saturday morning, links to it there too. So stick around. We'll be right back. We got a lot more to talk about here. In this last hour of the show. We're going to talk about a rental car risk you might not be aware of. So stick around.


    Hey, welcome back. Craig Peterson here WGAN and and elsewhere. We are live on Facebook Live as well. out on YouTube. You can find me and Craig Peterson calm. And of course, listen to my podcasts on pretty much any platform out there. podcast platforms from one platform. I just been doing this for too long. I guess this is the problem. They've all found me. Oh no. So this is a great little article from our friends over at Ars Technica. I don't know if you're familiar with it. It's one of those websites that I follow fairly closely because they have so many great things out there. But this one is talking about the rental cars and I want


    you to think about cars for a moment because well, I like cars. Hopefully you do too. But what are the problems that we're seeing today that are actually caused by this latest, newest, most wonderful technology? And there are a lot of them frankly. And some of them have to do shoes me with our phones, right? We plug our phones into the cars, the cars will automatically say, Okay, I want the contacts, people will just blindly say okay, go ahead and upload the contacts.


    And all of your contacts are uploaded, and now the car has them and the next driver comes in I love doing this comes into the car and scrolls through all of the phones and sees all of the contacts people have their home addresses in their status home. So you just look up home on the on the cars GPS and and just some poor fool who uploaded all of his contacts into the car, right use


    seen that before a music downloads, just all kinds of stuff. So I'm always careful, I never let the car upload my contacts you were probably kind of conscious about that as well. If you're not making sure that that doesn't happen right to the car doesn't have your contacts. You You might also do what I do, which is after I'm done with the car, I go into the Bluetooth settings and disconnect my phone or with Apple Car Play. I make sure my phone is disconnected.


    Excuse me. So those are all things I think that most people would know about and think about.


    Well, here's the problem that we're starting to see today. These cars are getting smarter and smarter and have more and more features on them, don't they? So there there's been some research here. Ars Technica did a little dive into it as well. And this Dan Goodin ended up writing an article about


    This where he found that the previous driver to his car could start and stop the engine lock and unlock the doors and track the location of the vehicle because you remember again these cars are designed by my guys right and gals obviously but by guys who are not thinking about all of the use cases for the car you know man I had such a fight of one of my my eldest sons who works with me he's he's one of the employees and works with a company that is fire jumpers certified for not fire jumper as in the fire department, although he does have a firefighting certificate including tight spaces on ships, but he's a fire jumper for security when something bad happens. Or please, please have us design the network before something bad happens. He gets some old us all of those. Well. We have all of


    Our clients emails run through a set of high end filters provided by Cisco. So all of the emails coming in our filters, look at it, and they are phenomenal. They have cut my email, I was 5000 emails a day. And now I'm down to about 100 hundred and 50 emails a day just by the Cisco filters. So and by the way, I have, I think, in the last year had maybe one false positive, maybe one it's just these things are so smart the way they work, right? They're not just looking for keywords or other things are really looking at behavior. Because Cisco sees so much of the internet, right? Cisco runs the internet backbone, but then they see so much of that traffic plus they see so much of the email traffic they can, they can just be phenomenal. So we have all of our customers emails running through our data center and it's properly secure.


    Of course, and running through these special Cisco email filters. And then we take those emails and we forward them on to our customers mail servers. Well, one of the services that is used by quite a few of our customers, because it's inexpensive, relatively speaking, is the Microsoft Office 365. Now, there's a lot of levels of old 3065. It's their cloud services, right? But that's cloud is in the cloud, right? And we're not going to get into that right now. But they have a whole bunch of services. And Microsoft had an internal grey list against our Cisco email host that was doing all of the filtering. And Microsoft, you know, they said, Well, you know, we can figure it out. It took us 24 hours to escalate it to people who knew what they were even talking about. We showed them their own tech article on this problem.


    them inside Microsoft with Office 365. And said, Here's your problem. You guys know about it, you have defined it, here it is. And yet, you know, they they start you with the people that say is a computer powered on type, right? Just so, so, so frustrating to me. Well, the problem here is that the Microsoft software did not consider all their software designers did not consider all of the uses usage cases. In this case, the Microsoft software people thought, Well, people using Office 365 they're just going to be real small businesses and they are going to have you know, dozen through 1000 email accounts maybe. And so the usage patterns are going to be consistent, etc, etc. That's not true in a case like us, where all of the emails coming in from all over the internet.


    To to us for all of our customers, including their deal D contractor customers, right? The people, the customers that have it are compliant, have PCI that have legal compliance issues, accounting compliance issues, right. So they all come to us where they are heavily heavily filtered. And then therefore it on to Microsoft. Well, that's not a usage case they thought of when they design the software. So we were fighting with them. We had thousands of messages queued up So the good news is, we didn't lose any of the email. We kept it our systems noticed right away that Microsoft was misbehaving, which they do frequently. And and then we got on the horn with Microsoft, we went the level two right away and then level three No, I'm air quoting levels two and three, because they're not real levels two and three, not by our standards. By the time you get to level three or somebody like me that or Steve, the fire jumper, somebody that really knows


    What's going on? Right? That's not the case of Microsoft.


    Anyhow, the problem in Ars Technica is found here is that these cars are designed with the idea that there is a single owner. Now there might be multiple drivers to the vehicle, but there's a single owner, right? She owns the Mustang. She drives it, but you know, the old man drives every once in a while the kids might drive it once in a while as well. Well, in this case, they looked at a Ford Explorer.


    And October last year, they put an article in about a guy that was able to remotely start, stop, lock, unlock and track a Ford Explorer that he had rented and returned five months earlier. And they're saying now something almost identical has happened again to the same enterprise rental car customers. customer. Four days after returning a Ford Mustang, the Ford pass app installed on the phone

    continues to give them control of the car. So here we have a usage case where the car is being rented, it was not part of the original design considerations. And the rental car company, in this case enterprise, and maybe it's just one unit of enterprise, I don't know. But enterprise is not properly clearing or resetting, whatever they have to do

    to that car after somebody has rented it. So it's a real problem. And it's something we need to be cautious of. Because it's, it's not even something we can necessarily do anything about. But personally, I would go into the menu on the console on the control system, you know, the entertainment system, and I wipe out every phone that's in there, just so that something like this can happen to me, right? But that's what I would do and that's what I advise you to do as well. Okay, stick around. When we get


    back. We're going to talk about a new FBI report that's talking about what happened to this $1.7 billion right here. Stick around. Craig Peterson and WGAN and live on Facebook.

    Hey, welcome back everybody, Craig Peterson here WGAN and and elsewhere. Hopefully you're able to join me on facebook live this week and we spend some time talking about the articles and answering questions for everybody. And of course you'll find that online right now kind of all over the place, make sure you get my weekly newsletter. It'll keep you up to date on all the latest security topics and some of the cooler new technology out there that I think is or maybe isn't ready for prime time. Going to have a cool guests next week too. I I used to do a lot of guests. I had like a dozen a show back when I had a three hour show. But next week we're gonna talk with a buddy of mine

    Mine, who is actually fairly well known, he's written a book about sugar. And you probably know if you've been listening to me for a while, not all that long. But a while you know that I have been very conscious about my health and doing the intermittent fasting thing and stuff. And so we'll talk to him about what he has found. You might remember I did the Atkins thing some years ago, but we'll be talking with him a little bit about that, too. I'm sure next week, so Barry Friedman will be my guest. And I will probably be next week. We've got to figure out the calendars first.

    No, I hate it when that happens. Sorry about that little bit of a coughing fit. Okay, so let's get into the article right now. And this has to do with email compromise. Now we all have email accounts, right? You got them. I got them, whether they're on Google

    Shame on you, or if they are Microsoft Office 365. Okay, depends on which level you have. Or if you host them yourself, which is what we've been doing for decades now for ourselves and our clients. I like that because they have more control. I don't have the problems like we had with Microsoft this week with Office 365 for some of our clients. But when you have email, there's a certain type of exposure that you have. We talked earlier about this whole problem with the coven 19 with the corona virus, and how they're using it right now to get you to click on links and phishing attacks. click on links in SMS. Those are called smishing. To get you to do something that ultimately you shouldn't do because they're using it to download nastiness. And it can be nastiness in the form of ransomware he'd be nastiness in the form of software that

    being installed on your computer to use your computer's resources, maybe as part of a denial of service attack, maybe to attack other people and other computers that are out there, right? It's all pretty darn evil. Well, the FBI put together some numbers because there's this thing called a business email compromise. That's only part of the problem. Because it isn't just business email, that can be a problem here. It's also our personal emails. So we're finding on the personal side that people are getting emails that are again from bad guys, but what they're trying to do is get you to go a little bit further. So a lot of them for instance, are based around dating sites. So people looking for companionship, they might be out on one of these websites and and they meet somebody.g more coughing meet somebody and as they've met that person, they kind of go back and forth and how are you? Oh my we have so much in common and they're trying to scam you. That is a very, very big and prevalent thing right now. Because so many people are just trying to find somebody that they can love someone they can spend some time with. And enjoy company and you know how I get that pardon my French but this is a real tough time in the world. There's so many people that are so ostracize that are blocked off from other people


    that are just looking for something anything right? Doesn't have to be love. As I said it can just be companionship. So the FBI has been warning about that. And then we've got these business email attacks, that what's happening here is oftentimes it's spearfishing. They're going

    After the owner of a company, and and frankly some of these dating things are spearfishing, too, because they know that somebody who's a little bit older might have some money that they can get out. Yeah. And they'll ask you Hey listen, I my uncle cousin has this medical bill and and we really need the money can I get $10,000 from you and people, people are sending it in the business email account account. It's a little bit different. So here's another article from our friends over dark reading this up on my website as well. But it's same back in 2013 scams often started with the spoofing of a CEO or CFO his email account, fraudsters send emails appearing to come from these execs to convince employees to send wire transfers to fake accounts. Now we know that within the last six months, this has gone to the next level. We're there we are using computers to imitate the bosses voice and they've been able to take millions anyhow the article goes on. Since then business email compromise has evolved to include the compromise a personal and vendor emails, spoofed lawyer email account and request for W two data. Of course, taxis and everybody. This is a big one w two right now the IRS is warning about that. Attackers often target the real estate sector and or make requests for expensive gift cards. In 2019. The Internet crime center


    saw an increase in business email compromised complaints related to the diversion of payroll money.


    So the attackers send a fake email to human resources or payroll department requesting an update to a specific employees direct deposit information. This is really really big and you look at these numbers. We're talking about


    1.7 billion in losses. That's absolutely huge amounts of money. The in 2019, they had a half a million complaints come in costing organizations three and a half billion dollars overall. That's up almost $3 billion from 2018.


    absolutely huge. So we have to be very, very careful.


    There are some reports out there email fraud and entity deception trends that are out there about the attackers what they're doing rise in hybrid attacks, which a victim receives an email making a request, and simultaneously receives a text message from a spoof number designed to seem to seem like the same person saying they just sent an email. It is highly targeted and also highly effective. So you got to be careful of all of this.


    We have to be careful of all of this and for business people, we have to be particularly careful about all of this government, government agencies. Did you see what happened with in Atlanta in the last year, how they got nailed multiple times. And it was ransomware. Getting in some of it was some business email compromises. We've had cities all over the country who have fallen victim to the business email compromise, and they have wire money to vendors that just don't exist, etc, etc. We have to be very careful. So how do you avoid this? First of all, don't send money to people that you really don't know. You know, you I'm thinking about those of us that are looking for companionship, friendship, maybe for a new lover, somebody that we can spend the rest of our lives with.


    Don't send them money really don't no matter how bad that sob story is. And then if we're business people be doubly careful.


    Verify everything via the phone. So the boss tells you that they need to move some money into another account. Call the boss you have their number, don't call the number in the email. If you are getting contact in HR from an employee's saying, hey, I want you to start direct deposited into my new account, here's the account number. Call back and verify it. Right That's always the case. You know, a police officer pulls you over the side of the road. You have a good chance that it's really police officer because they're an unmarked car. They have the blue lights going. They have a police officers uniform on. You just don't know even in that case. So be extra-extra cautious out there. Man. When we come back, we've got one more article for the day again, believe that it's gone so fast. We're going to talk about the most secure messaging app out there. Hi


    You can get it how you can use it. So stick around. You're listening to Craig Peterson and wg AN. And of course, Facebook Live in YouTube Live. Man, we're going overboard this week. Stick around because we'll be right back.


    Hey, welcome back, Craig Peters, Melanie or w g. N. and online Of course, we're doing a Facebook Live even as we speak, having a little fun there as the chuckles we're all about. Hey, I appreciate you guys joining me and I know that your time is valuable, and I don't want to waste one minute of it. So I'd love to get your feedback. What do you think of this show? What are the good parts, the bad parts? What do you want to see more of? What do you want to see less of let me know just email me and eat at Craig Peters. on.com. I'd really appreciate it and make sure that you are on my email list so that you get every week the latest in technology news.


    With a course in emphasis,


    as always from me on security, and what you can and should be doing for security in your home, and in your business, you know, I really focusing on business, because that's what I've been doing for so many years. You know, most businesses aren't in the cyber security business. And so they're trying to make their widgets provide their service, etc. And they're just left hanging when it comes to the security side cyber security. And I know that's true of you guys, too, who are in smaller businesses, even larger businesses and home users. But the answers the solutions are always the same, although you don't have as much money to spend so you're not going to be as well protected. Right? Do you also, hopefully don't have as many assets at risk. I know a lot of people who are high net worth individuals who come to me in order to get things secured, but as as a whole


    Most of the time is business Zilla. So I kind of aim at that. And then every month is well, we have a list of the top security vulnerabilities that there are patches out for telling you, hey, you need to update this software or that software. There's various vulnerabilities that you have to take care of immediately.


    Another coughing fit, man, hope this isn't assigned to something coming down with something. Here's the vulnerabilities you have to take care of right now. These are vulnerabilities that are seen in the wild, we know that these are being exploited. So I work with a number of different organizations, as we mentioned, the FBI infragard program, the sands people, NIST, the list goes on and on Homeland Security. They're all providing information so I boil it down. There is just too much to keep up with as I'm sure you can kind of guess right. survive.


    And so I boil that down, put it into one of my newsletters that you'll get for free. And it comes out once a month. And then once you've got that done, you know which Katie bar the door, right? Because now you're going to be safe against the worst things that are happening right now. So it's, it's really in, in in that interest is really easy. It's kind of a follow along things step by step. So I want to talk about this guy called marlinspike. I don't know if you've heard of marlinspike before that's one word. It's his name are marlinspike of course, I know having two kids who are three kids professional Mariners, actually, that's something to use is it on a knife that is used for weaving the ropes together, it's a little spike is called a marlinspike. Anyways,


    this guy launched an app called signal and the technology that he used and he developed


    Then he shared was also used by the WhatsApp people. And of course WhatsApp now is owned by Facebook. But it's signal that and that technology that's providing the end to end encryption for WhatsApp. Now, you know, I've talked on the show about what happened with Jeff Bezos and his information getting out and how the Saudi royal family Prince was supposedly involved in this. And, man, what a nasty mess that all is. The problem was not in this protocol that was developed and released by Mr. marlinspike. The problem was in the rest of the software that sat on top of it, that allowed access to the videos and the photos on the phone, and also had a bug in the software for some of those videos. So that's where the problem came from. So this


    Guy, Moxie marlinspike how's that for great name? Kind of reminds me of Who was that guy from New Zealand who had the


    that website I can remember changes his name to.com. Anyhow, Marlon Moxie marlinspike was on an airplane. He was sitting down next to a guy who said he while marlinspike said that he thought he was Midwestern in his mid 60s. And this guy asked him for help because you know what it was guys in the 60s do we have to ask young kids for help with technology right? Actually my case it's usually the opposite but anyways asked him for help. And the guy said he could not figure out how to enable airplane mode on his phone. So marlinspike looks at this Moxie and and he thought it was a setup. We thought this he was being trolled by this guy. Because right there on this guy's


    Home screen on his phone was signal signal is the number one secure app for sending and receiving messages. And they've added some more features to it recently. I actually haven't used it much for a while I've been using Apple messages, which is pretty darn secure but it's not signal. And he thought oh wait wait a minute here I'm being played he's playing me because he knows who I am. I'm Moxie marlinspike and and and so he was kind of wondering what was going on. But anyways marlinspike


    put this whole signal software together some years back, widely considered to be the most secure and encrypted messaging app. It's probably an old five years, and there is now a private foundation that maintains the code and that Moxie is the head of, but it turns out this 60 something guy next to him on the plane didn't know any of this stuff. And a Moxie showed him how to enable right airplane mode and gave him the phone back, and he says, I try to remember moments like that in building signal marlinspike told Wired, and this is from a Wired interview, you see this here in my Facebook Live, I put the link to it right there in the live channel.


    And he says the choices. We're making the app we're trying to create, it needs to be for the people who don't know how to enable airplane mode on their phone.


    You know, that's right. I can see that. It all goes back to UI design, right? User interface design, you have to design for the least common denominator. That's one of the reasons iPhones have been so popular. Steve Jobs just kept going after the designer say make it more simple, make it more simple, make it more simple. Think of that first iPod Could it have been more simple


    I had an mp3 player, and I still have it, it's like this big. And for those who aren't watching here on video on YouTube or Facebook, it was probably what would you say six inches long, and maybe three or four inches wide and a couple of inches thick. And it was phenomenal. The audio quality was better than those original iPods. But it was much more challenging to navigate. And there are so many more things you had to do to load it up and make it all work. Steve Jobs just made it simple. I have to emphasize that because if you're a business person, you have to make it easy for people to do business with you, not like me, and kind of make it hard, right? But make it easy for people to do business with you. And I'm trying to change that because there's a lot of things I could do to help people out that could pay my bills. So I'm not worrying about where my next checks going to come from right.


    So, five years later, today now Signal is reaching a much, much wider audience. It's reading the not reaching an audience that includes the 60-something-year-olds on through the younger kids. And I have to say, if you need secure messaging, and frankly, that's almost everybody. Take a look at Signal. It is free, absolutely free. It is available on iOS on Android. There are now versions for computers as well. And it lets you talk on like on the phone, and they'd let you make video conversations, share pictures, and of course, text back and forth.


    And that just goes to prove that it's not just for privacy diehards or activist because cybersecurity needs to be something that we think about all of the time and needs to be something foremost in our minds, just like everything else you talked about today, I hope that you take a few minutes and go through the whole show this week, you should do it every week. I'm always giving you tips and tricks, the tactics of things to do the strategies of overall what needs to get done out there. And some stories related to it so that hopefully you can see how it does apply in your life. And that's why I'm doing more and more the Facebook Lives, and YouTube lives. And I am putting together these courses. I've got tutorials now that I'm going to be releasing in a couple of weeks that we have spent weeks on I'm going to do some training, some more webinar training that again, that we've been spending weeks on because I want you guys to know this stuff, right? You have to know it. I don't want you to lose your businesses. I don't want you to lose your life. Saving


    Right, I want to be able to communicate. I want you to be able to communicate with your families. And you know, what was it two weeks ago I was on the radio with canon, madam on every Wednesday morning at 737 738. In the morning, during drive time for about half an hour. We talked about security. And I've been talking to Ken and Matt about security now for a year, two years. I'm not sure how long I've been on with at least a couple years now, maybe even three, and helping them to understand the security and what needs doing. You know, they asked questions is very, very interactive. It's like the whole reason I'm here. Over on Facebook Live. I'm taking questions as we're speaking as we're on the radio because it needs to be interactive. So after two years of speaking to them every week, about security things and things to do, and just talking with them two weeks ago.


    Go about the basics again, getting right down to, are you using password managers? Because I've given out information on them before free password managers paid password managers? And the answer from both of them was, No, they're not. And you know, that's one of the essential things that can be done. So it's evident to me that we still need to keep talking about this. And I understand how daunting this is. I know the guys selling you the antivirus software are lying to you, the guys that are selling you the VPN services, most of them are misrepresenting or lying to you. Okay, I get it. You've tried things they haven't worked. But I want you to know what you need to know, do what you need to do and be a success, frankly, getting all this together. All right. Hey, thanks for being with me. Make sure you visit me online. Craig Peterson comm check out the Facebook Lives, the training needs, the tutorials, the courses, the webinars, it's all there. It's all for you. It's all available home users through even large businesses. Have a great week. You've been listening to Craig Peterson on WGAN.

    Transcribed by https://otter.ai

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 31 min
  • AS HEARD ON: WGAN Mornings with Ken and Matt: Election and Voting Technology, Phishing and Coronavirus Covid-19

    Good morning everybody!

    I was on with Ken and Matt. We had a good discussion about the upcoming Nevada Caucus and if they will experience some of the same issues as in Iowa. We also discussed the cybercriminal phishing emails being sent out with the warnings about the Coronavirus that if clicked on will infect your machine and network and also why you should delete apps that you do not use to protect your privacy.

    These and more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig
    saying, Wow, cool new technology is going to be great. Hey, I have a buddy that worked for Hillary Clinton and ran this, and he's got this company, and he's got this voting software. That's what tends to happen. And they're looking for the latest the greatest the coolest the neatest and yeah, we can brag about how wonderful this all is. When in reality, it ain't there.

    Craig
    Hi everybody Craig Peterson here, of course, and I got into this thing. I don't know, and maybe it was too much this morning about technology. I was comparing what's been happening with some of the technology for voting to laserdiscs and Betamax, etc. But we went this morning with canon Matt talked about that couple of other things, including the Coronavirus. So here we go.

    Ken
    Back again 738 on the WGAN morning news with Ken and Matt. It's time now, ladies and gentlemen, to talk to Craig Peterson.

    Craig
    Is your phone working now?

    Ken
    Did that last-minute somebody was a tech expert series tell me how to fix his phone of a manufacturer.?We have a tech guru, and I would like to ask about that. But I am going to ask you a quick question. You know, we've had some primaries and the Nevada primaries coming up or the caucus, and it's looking like it's going to go smoothly, but there may be some security flaws. Can you tell us as a tech guru, what the hell is going on?

    Craig
    Well, you know, this whole thing with the voting and technology and what to do you know, we talked last week about you know, where the governor here in Maine and of course Secretary of State and John Richardson was on and on, I had said, you know, the, I think the smartest thing I think it was brilliant. Stick with an unhackable felt tip pen, Right? I still say that. I also get concerned when the government gets involved with consumer technology, and when they get involved with almost anything. But indeed what technology because the government ends up trying to pick winners or losers, right? And when I'm talking about tech, what's the best tech? And so the government gets involved and says, Oh, this is the best tech, or that's the best tech, and then you dig into it. And you find out that Hillary Clinton's former staffers are the people who founded and we're running the company that came up with a software that just thoroughly discredited the Iowa caucuses. This coming Saturday, as Matt was kind of jumping in there, looks like it's going to be a mess as well. How do we secure our elections because it's not like we can have the normal process of the best technology wins? Well, maybe that's not always the case because I'm sure Ken, you must have bought a Betamax video recorders

    Ken
    Betamax?

    Craig
    I don't know why anybody would buy a VHS Betamax was so superior to VHS.

    Ken
    I have had here this brand new mike 700

    Matt
    Am I correct? Betamax was better technology. There's no question, are we talking about the LaserDisc while we're at it? Oh yeah, that was even better. That was amazing that the laserdiscs amazing size CD that I had, you know, I had to put like seven of them just to watch a movie. Don't touch the surface. I remember for some reason, even though the school was crumbling, and a cockroach once fell from the ceiling and landed on my book. Okay, even with all that, they somehow found a way to buy a LaserDisc player, and I remember the occasional like, you know, Friday, you know, day, where you weren't, going to do anything. Where they would play a movie in class or whatever. They had to, like, take that thing out, and then put a new disk in like five times before the movie was over because it didn't have any sort of capacity to put a film on it. But I'm glad we spent all that money. It was worth it.

    Craig
    That's my point. Why did they buy the LaserDisc player? Because it was cool? Yeah, exactly. So now here we are looking at our Super Tuesday coming up. We're looking at all of these other elections that are happening. All of these people, these people, what do you mean, these people are out there saying, Wow, cool. New technology is going to be great. Hey, I have a buddy that worked for Hillary Clinton and ran this. And he's got this company, and he's got this voting software. That's what tends to happen. And they're looking for the latest, the greatest, the coolest, the neatest. And yeah, we can brag about how wonderful this all is. When in reality it ain't there. And now we're looking at another mobile voting app yet another one. It is being used in four different states this year, including West Virginia. What could possibly go wrong here? And this new voting mobile app, it's called Votez V-O-T-E-z. Isn't that cute? And it is just full of some of the most basic flaws ever. But you know what, guys? It's using blockchain technology, which is going to solve all of the world's security problems. This is sloppy. We need to stick with the standard. We need to have a government and a voting system people are confident in. The people say, yeah, our votes were counted. If there was a question about the tabulation or the ballots properly-being cast, you pull the silly things out of a closet, and you have a look at them. Let's not run headfirst. Over the cliff into some cool technology, and then with a whole bunch of Betamax tapes in our closet.

    Matt
    Do you know how many beta tapes I have in my closet?

    Ken
    I would say probably 500.

    Craig
    Yeah, yeah. And you know what those the quality of those is not quite DVD quality. It's still good, but you just can't find anything that well.

    Ken
    The other thing I don't have, I don't know where my Betamax is. Anymore. By the way, I don't want you to know I did not. I will bet every FBI instruction. I did not steal any movies. I just want you to know.

    Craig
    You know, you've got those things sitting there, Ken, and it was great technology for today, but it's gotten so much easier nowadays. Anyhow, that's my stance on voting. Stick with a piece of paper and unhackable pencil or felt tip pen. Keep the silly things after people have voted those wonderful little cards, keep those for at least a couple of years. Do spot audits, a lot of these states are their secretaries of state are not doing spot audits. I think that they have to do those just again to keep confidence in the system. And Matt, you're probably there with me. I am probably there with you, sir. We're talking to Craig Peterson, our tech guru. He joins us every once a while. Usually, Wednesdays, to talk about what's happening in the world of technology. Speaking of security, I have a lot of Chrome extensions on Chrome, and clearly, I am now surrendering all of my information to everyone. Tell me why.

    Craig
    Okay, my here's my general advice to everybody. I gave this out a little earlier in the week as well. The primary recommendation is not to have too many apps on your phones and other devices. Over the last couple of years, we have found that a lot of those apps are leaking data. And last weekend on my show, I talked about how the Department of Homeland Security is buying that data to track people say, Okay, so now we can find out where you are where you have been. It was about six, eight weeks ago, that the New York Times was able to track President Trump's whereabouts as he was moving around, because they were able to follow one of the phones of Secret Service personnel, according to the article that they wrote. This is a real problem. Now we've found that there are more than 500 browser extensions that have been secretly uploading our personal and private data to websites that are then selling it. The number one most evil thing to put onto your browser is one of those browser extensions, and it's a tab type thing. That gives you quicker searches and tells you there's a deal on this page on this site right now. A lot of people have installed those things. Well, if you have and I have seen so many people with this, get rid of them now. Delete your browser extensions, these Chrome extensions that you're not using, or that you don't need. Now, I've got some tutorials coming out in a couple of weeks about three Google Chrome, Safari, Firefox, Opera, browser extensions that I absolutely love, that are not stealing your data. I've got some training on how to know what's what. You know if that if you guys have one of these Chrome browsers, it is just overloaded with extensions. You got to delete these things, because some of them are evil. Some of them are even mining Bitcoin for bad guys in Eastern Europe, and you don't even know it. You know, here we are talking about having the privatization. I shouldn't say, of the two major electric companies in Maine, to save Maine taxpayers are ratepayers, in this case, some money, which is always great to save money. Still, we got to have an in-depth look at some of these things. And we have some of the highest electric rates in the country. Analyze things up. Why do we want to allow the browser extensions that will show us a cute little cat video every day? What do we want to have that browser extension burning our electricity to make Bitcoin money for somebody else? We've got to stop doing this sort of thing. Just delete any apps you're using. Remove the browser extensions you don't absolutely need and be a little safer online.

    Matt
    We are talking to our tech guru Craig joins us every Wednesday at 730 dot com. Get the information firsthand or to listen to him on w ga and in the afternoon on Saturday at one o'clock. Before we let you go, Craig, I don't know if you've heard about the Coronavirus, and please do not play the Mexican hat dance.

    Craig
    Whatever I do, I will not play the Mexican hat dance.

    Ken
    I was the last thing I will do. I will not play it. I don't want to trigger. Any technological issues for Mr. Peterson


    Craig
    One of my sons is a teetotaler. There was a joke going around about something about lime and salt being the cure. But anyway. Yeah, be very, very careful, everybody. I'm glad you brought this up. Ken, we're out of time. So really, really quickly. The bad guys always Take advantage of things in the news. And one of the big things in the news now, and I'll be talking about this more on my show on Saturday at one, is the Coronavirus, Of course, you know it is called now called covid-19. Don't open emails saying hey, here's a tracker for the Coronavirus. Don't do any of this stuff. There are so many fake emails and now fake text messages coming out from these people. It helped us to get overwhelmed. That's a really really bad thing. Don't do it. People the bad guys are saying Coronaviruses that trying to get your open stuff. If you want to g, the Coronavirus goes online to cdc.gov simple site to remember cdc.gov, not CDC dash org.gov. There are so many fake sites out there, just cdc.gov right at the top they've got stuff on covid-19 this respiratory disease, and they have trackers. Still, you know what right now you're more likely to die from the flu, and we are at the height of regular flu season, and they're even tracking [email protected] so there you can keep an eye on everybody.

    Ken
    All right, that's Greg Peterson ladies and gentlemen. I appreciate it as always, Craig, and we will talk to you again very soon.

    Craig
    Take care, guys. Bye. Thanks, all right. Why don't we take a quick break quick

    Craig 13:27
    A Shout out to all of you guys out there listening to me, of course, every week it kind of goes up, which is terrific, and it's so so appreciated. I had contact by the way from one of our listeners, a longtime listener, and a bit of a friend frankly always enjoy chatting with him. He's a little bit older kind of like me, and he has been out there freaking out about what to do now with his career. He went to a small school that taught cybersecurity stuff for a few months and put some money into that. Now he's out looking for a job. Is anybody else in that kind of a boat, because I think this might make a fascinating series or segment or segments or however it turns out for the listeners here, what if you are a little bit older in life? You are looking to change careers, maybe, perhaps you've always been interested in the whole security side of things. And you want to get involved with that. Let me know just send an email to me at Craig peterson.com. And we'll kind of go from there and see where this takes us. But I find this fascinating I I want to help you guys and gals out there with, you know, making your life a little bit better and helping you to make other people's lives a little bit better too because I suspect you're a lot like me, frankly. And that's why you're such great and regular listeners. Anyhow, take care and everybody. We're getting closer and closer to having some of those tutorials ready. I got another one edited yesterday, he says making a sigh, Oh my gosh this has been so painful I've had to learn a different video editor because I when I was using just can't handle the type of content that I'm generating here for these tutorials. It is on some of the best things you can do for cybersecurity for your family, for your business all free, even the tools tutoring alone are free. So this is going to be a huge one I think for pretty much everybody anyways, me at Greg Peterson calm or sign up for my mailing list just at Craig Peterson dot com slash subscribe. Take care, everybody. We'll be back with a weekend show again this week. Bye-bye.

    Transcribed by https://otter.ai

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    16 min
  • AS HEARD ON: WGAN Mornings with Ken and Matt: Election and Voting Technology, Phishing and Coronavirus Covid-19

    Good morning everybody!

    I was on with Ken and Matt. We had a good discussion about the upcoming Nevada Caucus and if they will experience some of the same issues as in Iowa. We also discussed the cybercriminal phishing emails being sent out with the warnings about the Coronavirus that if clicked on will infect your machine and network and also why you should delete apps that you do not use to protect your privacy.

    These and more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig
    saying, Wow, cool new technology is going to be great. Hey, I have a buddy that worked for Hillary Clinton and ran this, and he's got this company, and he's got this voting software. That's what tends to happen. And they're looking for the latest the greatest the coolest the neatest and yeah, we can brag about how wonderful this all is. When in reality, it ain't there.

    Craig
    Hi everybody Craig Peterson here, of course, and I got into this thing. I don't know, and maybe it was too much this morning about technology. I was comparing what's been happening with some of the technology for voting to laserdiscs and Betamax, etc. But we went this morning with canon Matt talked about that couple of other things, including the Coronavirus. So here we go.

    Ken
    Back again 738 on the WGAN morning news with Ken and Matt. It's time now, ladies and gentlemen, to talk to Craig Peterson.

    Craig
    Is your phone working now?

    Ken
    Did that last-minute somebody was a tech expert series tell me how to fix his phone of a manufacturer.?We have a tech guru, and I would like to ask about that. But I am going to ask you a quick question. You know, we've had some primaries and the Nevada primaries coming up or the caucus, and it's looking like it's going to go smoothly, but there may be some security flaws. Can you tell us as a tech guru, what the hell is going on?

    Craig
    Well, you know, this whole thing with the voting and technology and what to do you know, we talked last week about you know, where the governor here in Maine and of course Secretary of State and John Richardson was on and on, I had said, you know, the, I think the smartest thing I think it was brilliant. Stick with an unhackable felt tip pen, Right? I still say that. I also get concerned when the government gets involved with consumer technology, and when they get involved with almost anything. But indeed what technology because the government ends up trying to pick winners or losers, right? And when I'm talking about tech, what's the best tech? And so the government gets involved and says, Oh, this is the best tech, or that's the best tech, and then you dig into it. And you find out that Hillary Clinton's former staffers are the people who founded and we're running the company that came up with a software that just thoroughly discredited the Iowa caucuses. This coming Saturday, as Matt was kind of jumping in there, looks like it's going to be a mess as well. How do we secure our elections because it's not like we can have the normal process of the best technology wins? Well, maybe that's not always the case because I'm sure Ken, you must have bought a Betamax video recorders

    Ken
    Betamax?

    Craig
    I don't know why anybody would buy a VHS Betamax was so superior to VHS.

    Ken
    I have had here this brand new mike 700

    Matt
    Am I correct? Betamax was better technology. There's no question, are we talking about the LaserDisc while we're at it? Oh yeah, that was even better. That was amazing that the laserdiscs amazing size CD that I had, you know, I had to put like seven of them just to watch a movie. Don't touch the surface. I remember for some reason, even though the school was crumbling, and a cockroach once fell from the ceiling and landed on my book. Okay, even with all that, they somehow found a way to buy a LaserDisc player, and I remember the occasional like, you know, Friday, you know, day, where you weren't, going to do anything. Where they would play a movie in class or whatever. They had to, like, take that thing out, and then put a new disk in like five times before the movie was over because it didn't have any sort of capacity to put a film on it. But I'm glad we spent all that money. It was worth it.

    Craig
    That's my point. Why did they buy the LaserDisc player? Because it was cool? Yeah, exactly. So now here we are looking at our Super Tuesday coming up. We're looking at all of these other elections that are happening. All of these people, these people, what do you mean, these people are out there saying, Wow, cool. New technology is going to be great. Hey, I have a buddy that worked for Hillary Clinton and ran this. And he's got this company, and he's got this voting software. That's what tends to happen. And they're looking for the latest, the greatest, the coolest, the neatest. And yeah, we can brag about how wonderful this all is. When in reality it ain't there. And now we're looking at another mobile voting app yet another one. It is being used in four different states this year, including West Virginia. What could possibly go wrong here? And this new voting mobile app, it's called Votez V-O-T-E-z. Isn't that cute? And it is just full of some of the most basic flaws ever. But you know what, guys? It's using blockchain technology, which is going to solve all of the world's security problems. This is sloppy. We need to stick with the standard. We need to have a government and a voting system people are confident in. The people say, yeah, our votes were counted. If there was a question about the tabulation or the ballots properly-being cast, you pull the silly things out of a closet, and you have a look at them. Let's not run headfirst. Over the cliff into some cool technology, and then with a whole bunch of Betamax tapes in our closet.

    Matt
    Do you know how many beta tapes I have in my closet?

    Ken
    I would say probably 500.

    Craig
    Yeah, yeah. And you know what those the quality of those is not quite DVD quality. It's still good, but you just can't find anything that well.

    Ken
    The other thing I don't have, I don't know where my Betamax is. Anymore. By the way, I don't want you to know I did not. I will bet every FBI instruction. I did not steal any movies. I just want you to know.

    Craig
    You know, you've got those things sitting there, Ken, and it was great technology for today, but it's gotten so much easier nowadays. Anyhow, that's my stance on voting. Stick with a piece of paper and unhackable pencil or felt tip pen. Keep the silly things after people have voted those wonderful little cards, keep those for at least a couple of years. Do spot audits, a lot of these states are their secretaries of state are not doing spot audits. I think that they have to do those just again to keep confidence in the system. And Matt, you're probably there with me. I am probably there with you, sir. We're talking to Craig Peterson, our tech guru. He joins us every once a while. Usually, Wednesdays, to talk about what's happening in the world of technology. Speaking of security, I have a lot of Chrome extensions on Chrome, and clearly, I am now surrendering all of my information to everyone. Tell me why.

    Craig
    Okay, my here's my general advice to everybody. I gave this out a little earlier in the week as well. The primary recommendation is not to have too many apps on your phones and other devices. Over the last couple of years, we have found that a lot of those apps are leaking data. And last weekend on my show, I talked about how the Department of Homeland Security is buying that data to track people say, Okay, so now we can find out where you are where you have been. It was about six, eight weeks ago, that the New York Times was able to track President Trump's whereabouts as he was moving around, because they were able to follow one of the phones of Secret Service personnel, according to the article that they wrote. This is a real problem. Now we've found that there are more than 500 browser extensions that have been secretly uploading our personal and private data to websites that are then selling it. The number one most evil thing to put onto your browser is one of those browser extensions, and it's a tab type thing. That gives you quicker searches and tells you there's a deal on this page on this site right now. A lot of people have installed those things. Well, if you have and I have seen so many people with this, get rid of them now. Delete your browser extensions, these Chrome extensions that you're not using, or that you don't need. Now, I've got some tutorials coming out in a couple of weeks about three Google Chrome, Safari, Firefox, Opera, browser extensions that I absolutely love, that are not stealing your data. I've got some training on how to know what's what. You know if that if you guys have one of these Chrome browsers, it is just overloaded with extensions. You got to delete these things, because some of them are evil. Some of them are even mining Bitcoin for bad guys in Eastern Europe, and you don't even know it. You know, here we are talking about having the privatization. I shouldn't say, of the two major electric companies in Maine, to save Maine taxpayers are ratepayers, in this case, some money, which is always great to save money. Still, we got to have an in-depth look at some of these things. And we have some of the highest electric rates in the country. Analyze things up. Why do we want to allow the browser extensions that will show us a cute little cat video every day? What do we want to have that browser extension burning our electricity to make Bitcoin money for somebody else? We've got to stop doing this sort of thing. Just delete any apps you're using. Remove the browser extensions you don't absolutely need and be a little safer online.

    Matt
    We are talking to our tech guru Craig joins us every Wednesday at 730 dot com. Get the information firsthand or to listen to him on w ga and in the afternoon on Saturday at one o'clock. Before we let you go, Craig, I don't know if you've heard about the Coronavirus, and please do not play the Mexican hat dance.

    Craig
    Whatever I do, I will not play the Mexican hat dance.

    Ken
    I was the last thing I will do. I will not play it. I don't want to trigger. Any technological issues for Mr. Peterson


    Craig
    One of my sons is a teetotaler. There was a joke going around about something about lime and salt being the cure. But anyway. Yeah, be very, very careful, everybody. I'm glad you brought this up. Ken, we're out of time. So really, really quickly. The bad guys always Take advantage of things in the news. And one of the big things in the news now, and I'll be talking about this more on my show on Saturday at one, is the Coronavirus, Of course, you know it is called now called covid-19. Don't open emails saying hey, here's a tracker for the Coronavirus. Don't do any of this stuff. There are so many fake emails and now fake text messages coming out from these people. It helped us to get overwhelmed. That's a really really bad thing. Don't do it. People the bad guys are saying Coronaviruses that trying to get your open stuff. If you want to g, the Coronavirus goes online to cdc.gov simple site to remember cdc.gov, not CDC dash org.gov. There are so many fake sites out there, just cdc.gov right at the top they've got stuff on covid-19 this respiratory disease, and they have trackers. Still, you know what right now you're more likely to die from the flu, and we are at the height of regular flu season, and they're even tracking [email protected] so there you can keep an eye on everybody.

    Ken
    All right, that's Greg Peterson ladies and gentlemen. I appreciate it as always, Craig, and we will talk to you again very soon.

    Craig
    Take care, guys. Bye. Thanks, all right. Why don't we take a quick break quick

    Craig 13:27
    A Shout out to all of you guys out there listening to me, of course, every week it kind of goes up, which is terrific, and it's so so appreciated. I had contact by the way from one of our listeners, a longtime listener, and a bit of a friend frankly always enjoy chatting with him. He's a little bit older kind of like me, and he has been out there freaking out about what to do now with his career. He went to a small school that taught cybersecurity stuff for a few months and put some money into that. Now he's out looking for a job. Is anybody else in that kind of a boat, because I think this might make a fascinating series or segment or segments or however it turns out for the listeners here, what if you are a little bit older in life? You are looking to change careers, maybe, perhaps you've always been interested in the whole security side of things. And you want to get involved with that. Let me know just send an email to me at Craig peterson.com. And we'll kind of go from there and see where this takes us. But I find this fascinating I I want to help you guys and gals out there with, you know, making your life a little bit better and helping you to make other people's lives a little bit better too because I suspect you're a lot like me, frankly. And that's why you're such great and regular listeners. Anyhow, take care and everybody. We're getting closer and closer to having some of those tutorials ready. I got another one edited yesterday, he says making a sigh, Oh my gosh this has been so painful I've had to learn a different video editor because I when I was using just can't handle the type of content that I'm generating here for these tutorials. It is on some of the best things you can do for cybersecurity for your family, for your business all free, even the tools tutoring alone are free. So this is going to be a huge one I think for pretty much everybody anyways, me at Greg Peterson calm or sign up for my mailing list just at Craig Peterson dot com slash subscribe. Take care, everybody. We'll be back with a weekend show again this week. Bye-bye.

    Transcribed by https://otter.ai

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    16 min
  • AS HEARD ON: WGAN Mornings with Ken and Matt: Election and Voting Technology, Phishing and Coronavirus Covid-19

    Good morning everybody!

    I was on with Ken and Matt. We had a good discussion about the upcoming Nevada Caucus and if they will experience some of the same issues as in Iowa. We also discussed the cybercriminal phishing emails being sent out with the warnings about the Coronavirus that if clicked on will infect your machine and network and also why you should delete apps that you do not use to protect your privacy.

    These and more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig
    saying, Wow, cool new technology is going to be great. Hey, I have a buddy that worked for Hillary Clinton and ran this, and he's got this company, and he's got this voting software. That's what tends to happen. And they're looking for the latest the greatest the coolest the neatest and yeah, we can brag about how wonderful this all is. When in reality, it ain't there.

    Craig
    Hi everybody Craig Peterson here, of course, and I got into this thing. I don't know, and maybe it was too much this morning about technology. I was comparing what's been happening with some of the technology for voting to laserdiscs and Betamax, etc. But we went this morning with canon Matt talked about that couple of other things, including the Coronavirus. So here we go.

    Ken
    Back again 738 on the WGAN morning news with Ken and Matt. It's time now, ladies and gentlemen, to talk to Craig Peterson.

    Craig
    Is your phone working now?

    Ken
    Did that last-minute somebody was a tech expert series tell me how to fix his phone of a manufacturer.?We have a tech guru, and I would like to ask about that. But I am going to ask you a quick question. You know, we've had some primaries and the Nevada primaries coming up or the caucus, and it's looking like it's going to go smoothly, but there may be some security flaws. Can you tell us as a tech guru, what the hell is going on?

    Craig
    Well, you know, this whole thing with the voting and technology and what to do you know, we talked last week about you know, where the governor here in Maine and of course Secretary of State and John Richardson was on and on, I had said, you know, the, I think the smartest thing I think it was brilliant. Stick with an unhackable felt tip pen, Right? I still say that. I also get concerned when the government gets involved with consumer technology, and when they get involved with almost anything. But indeed what technology because the government ends up trying to pick winners or losers, right? And when I'm talking about tech, what's the best tech? And so the government gets involved and says, Oh, this is the best tech, or that's the best tech, and then you dig into it. And you find out that Hillary Clinton's former staffers are the people who founded and we're running the company that came up with a software that just thoroughly discredited the Iowa caucuses. This coming Saturday, as Matt was kind of jumping in there, looks like it's going to be a mess as well. How do we secure our elections because it's not like we can have the normal process of the best technology wins? Well, maybe that's not always the case because I'm sure Ken, you must have bought a Betamax video recorders

    Ken
    Betamax?

    Craig
    I don't know why anybody would buy a VHS Betamax was so superior to VHS.

    Ken
    I have had here this brand new mike 700

    Matt
    Am I correct? Betamax was better technology. There's no question, are we talking about the LaserDisc while we're at it? Oh yeah, that was even better. That was amazing that the laserdiscs amazing size CD that I had, you know, I had to put like seven of them just to watch a movie. Don't touch the surface. I remember for some reason, even though the school was crumbling, and a cockroach once fell from the ceiling and landed on my book. Okay, even with all that, they somehow found a way to buy a LaserDisc player, and I remember the occasional like, you know, Friday, you know, day, where you weren't, going to do anything. Where they would play a movie in class or whatever. They had to, like, take that thing out, and then put a new disk in like five times before the movie was over because it didn't have any sort of capacity to put a film on it. But I'm glad we spent all that money. It was worth it.

    Craig
    That's my point. Why did they buy the LaserDisc player? Because it was cool? Yeah, exactly. So now here we are looking at our Super Tuesday coming up. We're looking at all of these other elections that are happening. All of these people, these people, what do you mean, these people are out there saying, Wow, cool. New technology is going to be great. Hey, I have a buddy that worked for Hillary Clinton and ran this. And he's got this company, and he's got this voting software. That's what tends to happen. And they're looking for the latest, the greatest, the coolest, the neatest. And yeah, we can brag about how wonderful this all is. When in reality it ain't there. And now we're looking at another mobile voting app yet another one. It is being used in four different states this year, including West Virginia. What could possibly go wrong here? And this new voting mobile app, it's called Votez V-O-T-E-z. Isn't that cute? And it is just full of some of the most basic flaws ever. But you know what, guys? It's using blockchain technology, which is going to solve all of the world's security problems. This is sloppy. We need to stick with the standard. We need to have a government and a voting system people are confident in. The people say, yeah, our votes were counted. If there was a question about the tabulation or the ballots properly-being cast, you pull the silly things out of a closet, and you have a look at them. Let's not run headfirst. Over the cliff into some cool technology, and then with a whole bunch of Betamax tapes in our closet.

    Matt
    Do you know how many beta tapes I have in my closet?

    Ken
    I would say probably 500.

    Craig
    Yeah, yeah. And you know what those the quality of those is not quite DVD quality. It's still good, but you just can't find anything that well.

    Ken
    The other thing I don't have, I don't know where my Betamax is. Anymore. By the way, I don't want you to know I did not. I will bet every FBI instruction. I did not steal any movies. I just want you to know.

    Craig
    You know, you've got those things sitting there, Ken, and it was great technology for today, but it's gotten so much easier nowadays. Anyhow, that's my stance on voting. Stick with a piece of paper and unhackable pencil or felt tip pen. Keep the silly things after people have voted those wonderful little cards, keep those for at least a couple of years. Do spot audits, a lot of these states are their secretaries of state are not doing spot audits. I think that they have to do those just again to keep confidence in the system. And Matt, you're probably there with me. I am probably there with you, sir. We're talking to Craig Peterson, our tech guru. He joins us every once a while. Usually, Wednesdays, to talk about what's happening in the world of technology. Speaking of security, I have a lot of Chrome extensions on Chrome, and clearly, I am now surrendering all of my information to everyone. Tell me why.

    Craig
    Okay, my here's my general advice to everybody. I gave this out a little earlier in the week as well. The primary recommendation is not to have too many apps on your phones and other devices. Over the last couple of years, we have found that a lot of those apps are leaking data. And last weekend on my show, I talked about how the Department of Homeland Security is buying that data to track people say, Okay, so now we can find out where you are where you have been. It was about six, eight weeks ago, that the New York Times was able to track President Trump's whereabouts as he was moving around, because they were able to follow one of the phones of Secret Service personnel, according to the article that they wrote. This is a real problem. Now we've found that there are more than 500 browser extensions that have been secretly uploading our personal and private data to websites that are then selling it. The number one most evil thing to put onto your browser is one of those browser extensions, and it's a tab type thing. That gives you quicker searches and tells you there's a deal on this page on this site right now. A lot of people have installed those things. Well, if you have and I have seen so many people with this, get rid of them now. Delete your browser extensions, these Chrome extensions that you're not using, or that you don't need. Now, I've got some tutorials coming out in a couple of weeks about three Google Chrome, Safari, Firefox, Opera, browser extensions that I absolutely love, that are not stealing your data. I've got some training on how to know what's what. You know if that if you guys have one of these Chrome browsers, it is just overloaded with extensions. You got to delete these things, because some of them are evil. Some of them are even mining Bitcoin for bad guys in Eastern Europe, and you don't even know it. You know, here we are talking about having the privatization. I shouldn't say, of the two major electric companies in Maine, to save Maine taxpayers are ratepayers, in this case, some money, which is always great to save money. Still, we got to have an in-depth look at some of these things. And we have some of the highest electric rates in the country. Analyze things up. Why do we want to allow the browser extensions that will show us a cute little cat video every day? What do we want to have that browser extension burning our electricity to make Bitcoin money for somebody else? We've got to stop doing this sort of thing. Just delete any apps you're using. Remove the browser extensions you don't absolutely need and be a little safer online.

    Matt
    We are talking to our tech guru Craig joins us every Wednesday at 730 dot com. Get the information firsthand or to listen to him on w ga and in the afternoon on Saturday at one o'clock. Before we let you go, Craig, I don't know if you've heard about the Coronavirus, and please do not play the Mexican hat dance.

    Craig
    Whatever I do, I will not play the Mexican hat dance.

    Ken
    I was the last thing I will do. I will not play it. I don't want to trigger. Any technological issues for Mr. Peterson


    Craig
    One of my sons is a teetotaler. There was a joke going around about something about lime and salt being the cure. But anyway. Yeah, be very, very careful, everybody. I'm glad you brought this up. Ken, we're out of time. So really, really quickly. The bad guys always Take advantage of things in the news. And one of the big things in the news now, and I'll be talking about this more on my show on Saturday at one, is the Coronavirus, Of course, you know it is called now called covid-19. Don't open emails saying hey, here's a tracker for the Coronavirus. Don't do any of this stuff. There are so many fake emails and now fake text messages coming out from these people. It helped us to get overwhelmed. That's a really really bad thing. Don't do it. People the bad guys are saying Coronaviruses that trying to get your open stuff. If you want to g, the Coronavirus goes online to cdc.gov simple site to remember cdc.gov, not CDC dash org.gov. There are so many fake sites out there, just cdc.gov right at the top they've got stuff on covid-19 this respiratory disease, and they have trackers. Still, you know what right now you're more likely to die from the flu, and we are at the height of regular flu season, and they're even tracking [email protected] so there you can keep an eye on everybody.

    Ken
    All right, that's Greg Peterson ladies and gentlemen. I appreciate it as always, Craig, and we will talk to you again very soon.

    Craig
    Take care, guys. Bye. Thanks, all right. Why don't we take a quick break quick

    Craig 13:27
    A Shout out to all of you guys out there listening to me, of course, every week it kind of goes up, which is terrific, and it's so so appreciated. I had contact by the way from one of our listeners, a longtime listener, and a bit of a friend frankly always enjoy chatting with him. He's a little bit older kind of like me, and he has been out there freaking out about what to do now with his career. He went to a small school that taught cybersecurity stuff for a few months and put some money into that. Now he's out looking for a job. Is anybody else in that kind of a boat, because I think this might make a fascinating series or segment or segments or however it turns out for the listeners here, what if you are a little bit older in life? You are looking to change careers, maybe, perhaps you've always been interested in the whole security side of things. And you want to get involved with that. Let me know just send an email to me at Craig peterson.com. And we'll kind of go from there and see where this takes us. But I find this fascinating I I want to help you guys and gals out there with, you know, making your life a little bit better and helping you to make other people's lives a little bit better too because I suspect you're a lot like me, frankly. And that's why you're such great and regular listeners. Anyhow, take care and everybody. We're getting closer and closer to having some of those tutorials ready. I got another one edited yesterday, he says making a sigh, Oh my gosh this has been so painful I've had to learn a different video editor because I when I was using just can't handle the type of content that I'm generating here for these tutorials. It is on some of the best things you can do for cybersecurity for your family, for your business all free, even the tools tutoring alone are free. So this is going to be a huge one I think for pretty much everybody anyways, me at Greg Peterson calm or sign up for my mailing list just at Craig Peterson dot com slash subscribe. Take care, everybody. We'll be back with a weekend show again this week. Bye-bye.

    Transcribed by https://otter.ai

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    16 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Apps, tracking, selling info and election security

    Welcome!

    Good morning, everybody. I was on with Mr. Jim Polito this morning and as you know today is Primary Day in New Hampshire it is the Big Day for our State Sport - Politics.  That means it is the day to address voter manipulation, voter fraud, low tech solutions and why apps are not the answer. So, here we go with Mr. Polito.

    For more tech tips, news, and updates visit - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig
    You've got this free little cute little game, isn't this fun to play? Well, that game is tracking you everywhere you're going. They sell that information to Marketers. Now the Department of Homeland Security is even buying that data of where you are which apps you're using. Just because you have these apps installed on your phone.

    Craig
    Good morning, Craig Peterson, here. That's me with Danny, and it was pretty much all about voting technologies, the new stuff that's coming out the problems we have right now. And my predictions for not just this election, but frankly for the next two or three presidential cycles.

    Danny
    Yes, it is Tuesday. 840 You know what time that is? It is time for tech talk guru Craig Peterson. Hi Craig.

    Craig
    Hey, good morning, Danny.

    Craig
    I've got a little clarification about info from one of your former guests this morning. An earlier guest, I should say this morning. He was talking quite rightly by the about all of these apps and what's been in the news, in fact, just this week about apps and how dangerous they can be how they've been tracking, Google just removed a whole bunch of extensions from the Google Chrome Store. I want to go into slightly more detail if you want it to be secure. Don't download an app you don't need.
    Another thing I've said forever, Danny, is that you should go through your phone, at least every month, and delete apps you're not using. You know, most of us have a lot of apps. I think the last stat I SAW said that about 95% of the apps that we've downloaded only get used once. It's like we're never using them. Delete them off of your phone, off of your tablet, whatever it is you have. I want to add one more thing from a safety standpoint. Even if you are using an app fairly regularly, go ahead and delete it anyway, and then reinstall it. When you reinstall it now, it's going to ask for permission. You're going to be able to have a closer look at that app that again. It may be one you use every day like Google Maps. Believe that when you reinstall it and pay close attention to the permissions that it wants to access. By the way, just because it doesn't ask for permission to share some of your information doesn't mean it's not going to, all right. But as a general rule, those permissions are correct. It's more confusing on Android than it is iOS. Android kind of pushes you on to you the decision about whether or not you should be installing that app. On the iOS side, it's a lot more straightforward than Apple's a little bit better about it. He had some super points. But I go one step further. Just delete the silly things, mainly if you're not using them, as you mentioned, bringing up the app and permitting it.

    Danny
    So what kind of permission should people be looking for Craig to allow it not to?

    Craig
    Yeah, there you go. Well, let's have a look at the most costly divorce in history, which we talked about a couple of weeks ago. Right. So you have Bezos. Yeah, exactly. Billions of dollars in a divorce settlement. How did that all start? Well, that started because he was using WhatsApp, which is an app that is now part of Facebook's family. What WhatsApp had done here is accepted a video, and Jeff Bezos had allowed WhatsApp access to his photos and his videos. Even though you might think, oh, what's the harm and giving it access to my pictures or videos, maybe you're not going to get the virus the Jeff Besos got, but the app has access to your photos, your videos or other things. If there's a bug in the app, if there's something malicious going on, you're going to lose that data. What should you give an app permission to do? That? I think one of the worse things you can do is to permit access to know your location. That data is used and sold. You know, you've got this free little cute little game. Isn't this fun to play? And that game is tracking you everywhere you're going it's been sold to Marketers. Now the Department of Homeland Security is even buying that data of where you are which apps you're using, just because you have these apps installed on your phone. In answer directly to your question, do not give them access to your location unless you absolutely want to. I'm even reluctant to give Google Maps access to my location. Right? But slightly paranoid on that front. As far as photos and videos and things, again, just don't give them access. I think we're at the point now, where the bottom line is, you should only have a half a dozen apps on your phone on your tablet. And they should be apps from the big guys. You know Apple's apps, Microsoft apps, Google's apps, they are moderately trustworthy. And pretty much everything else. I think you shouldn't say bye-bye to them. ya know,

    Danny
    Ya know, that's kind of it sounds like a good plan. We are talking with Tech Talk Guru Craig Peterson, all about apps, and the security behind apps and then allowing permissions and them using your data to sell, and basically, you become the client. Correct. So these free apps not necessarily free, buddy.

    Craig
    No, they're not. And here's another trick, right? If you want to use something, and the app is available, most of the time, there's a website you can go to instead. So, for instance, you might download The let's use Iheart as an example. All right, so IHeart Radio has an app. I use it all the time, right? I'm, I listened to it to listen to my favorite radio shows listen to the gym in the morning. Iheart also has a website that you can visit. Okay, so rather than having the app, just use the browser that comes with your phone, use Safari, which is a good browser on iOS, use one of the Firefox browsers from Mozilla, those are all very good. If someone's twisting your arm with a gun to your head, use Google Chrome. Use the browser to get the data you want to you can stream music from your browser, you can listen to it hard from your browser, you can do all of the reading of news that you might want to do from your browser and avoid the cute apps. Aren't they wonderful? Aren't they fun? But you know what? There are so many Very few apps that can be classified as safe, that it's just not worth it.

    Danny
    Speaking of Google Chrome, speaking of extensions, speaking of people, basically using your uploading your private information, the Google Chrome extension, Craig. There were some issues there aren't there.

    Craig
    Yeah, absolutely. Now I've got some tutorials coming out starting next week, and about some extensions that you might want to use, and they will improve your browsing experience will improve your security, etc. What I think they're talking about here is a problem, Danny, where 500 Chrome extensions, Google Chrome extensions, were identified as secretly uploading people's data, millions of times. These things get downloaded. It's incredible what's happened, more than 1.7 million installations. So again, I still know people who are downloading browser bar extensions for Google Chrome for all of their different browsers, right. And it's a little browser bar extension that gives you a feature to search quickly or watch the stock market, etc. Those are the evilest things and prone to guys. Don't install, never install these little browser extensions that are just going to show you one or two things, because so many of them are sketchy. Many are fraudulent. Some of them are advertising as a service. Some of them will automatically, just from your browser, be clicking on ads on other websites you are not even visiting. Yes, they can click on an advertisement on a site you're not visiting just to increase their revenue. The estimate is that 40 to 60% of all paid advertising Non the internet pay per click advertising 20 60% of that is fraudulent. It's these. Yeah, these extensions, Danny, that we're installing that is supposedly giving us some sort of advantage or some neat little thing. Don't install those. Make sure if you're on my email list, you'll find out about this next week. But make sure you are on that list, which is just a Craig Peterson dot com. You can attend these tutorials for free. I'm not selling anything, right. It's all about the extensions that are going to make you safe. Not these 500 identified as making you less safe. You know what, Danny, some of them are even doing Bitcoin mining using your computer and slowing down your computer. They're making your browsing experience horrible because it's so slow. Things are happening in the background that you don't know are being done. They're using your electricity. We have some of the highest electric rates in the nation here in the northeast. And it's all for their benefit and gain and nothing for you. I'm glad you brought it up. Danny, don't install an extension unless you have to. It's kind of like the app thing.

    Danny
    Yeah, we try to keep yourself as safe as possible. But something you have to do is make sure it's something that isn't going to come and backfire on you ultimately. Because we are talking with our tech expert Craig Peterson. Craig, we only have a few minutes left. But the one story I did want to get into here, the mobile voting app. Who would have thought this is ever a good idea?

    Craig
    heard off and on about what's going to happen Saturday in Nevada with their caucuses. They paid I think it was $60,000 to the same company that completely messed up the Iowa caucuses and they're saying yeah, we're going to do it. No, we're not going to do it. You're going to do it with the latest I heard yesterday was there not going to do it again. But there is an app called a vote to VOA t z. And this is something that supposedly allows you to vote from home vote from overseas. They've been trying to sell this to the military, for our military personnel stationed overseas. And this is crazy. The election is promoting its use of blockchain technology, which is like a vast buzzword nowadays. And people associate blockchain technology with absolutely safe, nothing could go wrong. They ignore the man behind the curtain. It is not secure. There are four states right now that are still planning on using this votes app that is being used in West Virginia. And it has some of the most basic security flaws in it. It allows other people to Steve votes intercept votes change votes, as they're being transmitted from the mobile phones to the company's voting server. If you can This is absolutely crazy. MIT put together a research paper that was released last Thursday. We're not there yet. Don't use these things. You know, the only thing that's really safe is a pencil or maybe a felt tip pen. Because you can't hack, a felt tip pen and a piece of paper. Right, much harder to do, obviously, this imbalance studying before, but you can do it on a wholesale basis like you can with some of these voting apps.

    Danny
    Yeah, what's this one right here? Just say someone to be able just to change votes like that. It seems as though the security and some of the features and noted have a voting type app. They have far away from Craig.

    Craig
    Oh, yeah, end up partner of Homeland Security's warning against it New York Times, even covered on it. They were the first ones to report this research out of MIT. We're going to see a lot of problems of voting over the next few cycles, maybe ten plus years, frankly, as you know, You know, the idiocy tends to tie down in the money, right? Who owns the company, for instance, with the backhoe debacle that happened overnight Iowa, the disaster that was going to happen this weekend in Nevada and still may have been that company that made that software to tally the votes was owned and operated by Hillary Clinton staffers. Okay. So, yeah, accurately. And now the democratic Democratic Party says, Oh, it's great. We know you, Hey, buddy. Yeah, we're going to do it for you, right? Until we can get rid of this phony crony capitalism stuff, which exists all over the place, and we make real decisions. This voting stuff just isn't going to work. Right. And you know, Danny, I hold a zero trust. The government's going to be able to get this right. But you know, another five to 10 years, I think, maybe we will have a reasonably smooth roll road ahead of us. There's a $10 million funding project that came out of the Department of Defense to make an unhackable voting system. So I got my fingers crossed because I know these guys are on the right track.

    Danny
    Well, I'm sure when they come up with something, you'll have a forest Craig Craig is always some great stuff, unfortunately, to get to everything. If somebody wants to hear more, how do they do so?

    Craig
    Well, you can go to Craig Peterson, dot com or they can text Danny, to me at 855-385-5553. That's 855-385-5553.

    Danny
    As always, data rates do apply. Craig, thank you so much for the time. We'll talk to you next week.

    Craig
    Take care, Danny, bye-bye.

    Danny
    It's Craig, always with some great stuff can be scary. But Craig gets us through it. As he said, watch out for your extensions. Watch out for the app to clean up the apps, and yeah, what's the make you think that Hillary Clinton can get a voting app? Right? But yeah, our servers were secured in New York. Yeah, okay. Everyone believes that one. Anyways, I'll take one last time out. Well.

    Craig 
    We've been working on this now for six weeks, eight weeks, we've got some fantastic free tutorials coming up. Frankly, these are going to improve your security posture. By what at least 90%. I'm serious about that when you are online, so it's going to help with security transformation plus a course and everything else. So free stuff, and some paid material, but you are going to love it all. I guarantee it. I've never been so excited about something before. Anyhow, keep an eye out. Make sure you're signed up. Craig Peterson, dot com slash subscribe. We'll be back tomorrow. Bye-bye.

    Transcribed by https://otter.ai

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    15 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Apps, tracking, selling info and election security

    Welcome!

    Good morning, everybody. I was on with Mr. Jim Polito this morning and as you know today is Primary Day in New Hampshire it is the Big Day for our State Sport - Politics.  That means it is the day to address voter manipulation, voter fraud, low tech solutions and why apps are not the answer. So, here we go with Mr. Polito.

    For more tech tips, news, and updates visit - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig
    You've got this free little cute little game, isn't this fun to play? Well, that game is tracking you everywhere you're going. They sell that information to Marketers. Now the Department of Homeland Security is even buying that data of where you are which apps you're using. Just because you have these apps installed on your phone.

    Craig
    Good morning, Craig Peterson, here. That's me with Danny, and it was pretty much all about voting technologies, the new stuff that's coming out the problems we have right now. And my predictions for not just this election, but frankly for the next two or three presidential cycles.

    Danny
    Yes, it is Tuesday. 840 You know what time that is? It is time for tech talk guru Craig Peterson. Hi Craig.

    Craig
    Hey, good morning, Danny.

    Craig
    I've got a little clarification about info from one of your former guests this morning. An earlier guest, I should say this morning. He was talking quite rightly by the about all of these apps and what's been in the news, in fact, just this week about apps and how dangerous they can be how they've been tracking, Google just removed a whole bunch of extensions from the Google Chrome Store. I want to go into slightly more detail if you want it to be secure. Don't download an app you don't need.
    Another thing I've said forever, Danny, is that you should go through your phone, at least every month, and delete apps you're not using. You know, most of us have a lot of apps. I think the last stat I SAW said that about 95% of the apps that we've downloaded only get used once. It's like we're never using them. Delete them off of your phone, off of your tablet, whatever it is you have. I want to add one more thing from a safety standpoint. Even if you are using an app fairly regularly, go ahead and delete it anyway, and then reinstall it. When you reinstall it now, it's going to ask for permission. You're going to be able to have a closer look at that app that again. It may be one you use every day like Google Maps. Believe that when you reinstall it and pay close attention to the permissions that it wants to access. By the way, just because it doesn't ask for permission to share some of your information doesn't mean it's not going to, all right. But as a general rule, those permissions are correct. It's more confusing on Android than it is iOS. Android kind of pushes you on to you the decision about whether or not you should be installing that app. On the iOS side, it's a lot more straightforward than Apple's a little bit better about it. He had some super points. But I go one step further. Just delete the silly things, mainly if you're not using them, as you mentioned, bringing up the app and permitting it.

    Danny
    So what kind of permission should people be looking for Craig to allow it not to?

    Craig
    Yeah, there you go. Well, let's have a look at the most costly divorce in history, which we talked about a couple of weeks ago. Right. So you have Bezos. Yeah, exactly. Billions of dollars in a divorce settlement. How did that all start? Well, that started because he was using WhatsApp, which is an app that is now part of Facebook's family. What WhatsApp had done here is accepted a video, and Jeff Bezos had allowed WhatsApp access to his photos and his videos. Even though you might think, oh, what's the harm and giving it access to my pictures or videos, maybe you're not going to get the virus the Jeff Besos got, but the app has access to your photos, your videos or other things. If there's a bug in the app, if there's something malicious going on, you're going to lose that data. What should you give an app permission to do? That? I think one of the worse things you can do is to permit access to know your location. That data is used and sold. You know, you've got this free little cute little game. Isn't this fun to play? And that game is tracking you everywhere you're going it's been sold to Marketers. Now the Department of Homeland Security is even buying that data of where you are which apps you're using, just because you have these apps installed on your phone. In answer directly to your question, do not give them access to your location unless you absolutely want to. I'm even reluctant to give Google Maps access to my location. Right? But slightly paranoid on that front. As far as photos and videos and things, again, just don't give them access. I think we're at the point now, where the bottom line is, you should only have a half a dozen apps on your phone on your tablet. And they should be apps from the big guys. You know Apple's apps, Microsoft apps, Google's apps, they are moderately trustworthy. And pretty much everything else. I think you shouldn't say bye-bye to them. ya know,

    Danny
    Ya know, that's kind of it sounds like a good plan. We are talking with Tech Talk Guru Craig Peterson, all about apps, and the security behind apps and then allowing permissions and them using your data to sell, and basically, you become the client. Correct. So these free apps not necessarily free, buddy.

    Craig
    No, they're not. And here's another trick, right? If you want to use something, and the app is available, most of the time, there's a website you can go to instead. So, for instance, you might download The let's use Iheart as an example. All right, so IHeart Radio has an app. I use it all the time, right? I'm, I listened to it to listen to my favorite radio shows listen to the gym in the morning. Iheart also has a website that you can visit. Okay, so rather than having the app, just use the browser that comes with your phone, use Safari, which is a good browser on iOS, use one of the Firefox browsers from Mozilla, those are all very good. If someone's twisting your arm with a gun to your head, use Google Chrome. Use the browser to get the data you want to you can stream music from your browser, you can listen to it hard from your browser, you can do all of the reading of news that you might want to do from your browser and avoid the cute apps. Aren't they wonderful? Aren't they fun? But you know what? There are so many Very few apps that can be classified as safe, that it's just not worth it.

    Danny
    Speaking of Google Chrome, speaking of extensions, speaking of people, basically using your uploading your private information, the Google Chrome extension, Craig. There were some issues there aren't there.

    Craig
    Yeah, absolutely. Now I've got some tutorials coming out starting next week, and about some extensions that you might want to use, and they will improve your browsing experience will improve your security, etc. What I think they're talking about here is a problem, Danny, where 500 Chrome extensions, Google Chrome extensions, were identified as secretly uploading people's data, millions of times. These things get downloaded. It's incredible what's happened, more than 1.7 million installations. So again, I still know people who are downloading browser bar extensions for Google Chrome for all of their different browsers, right. And it's a little browser bar extension that gives you a feature to search quickly or watch the stock market, etc. Those are the evilest things and prone to guys. Don't install, never install these little browser extensions that are just going to show you one or two things, because so many of them are sketchy. Many are fraudulent. Some of them are advertising as a service. Some of them will automatically, just from your browser, be clicking on ads on other websites you are not even visiting. Yes, they can click on an advertisement on a site you're not visiting just to increase their revenue. The estimate is that 40 to 60% of all paid advertising Non the internet pay per click advertising 20 60% of that is fraudulent. It's these. Yeah, these extensions, Danny, that we're installing that is supposedly giving us some sort of advantage or some neat little thing. Don't install those. Make sure if you're on my email list, you'll find out about this next week. But make sure you are on that list, which is just a Craig Peterson dot com. You can attend these tutorials for free. I'm not selling anything, right. It's all about the extensions that are going to make you safe. Not these 500 identified as making you less safe. You know what, Danny, some of them are even doing Bitcoin mining using your computer and slowing down your computer. They're making your browsing experience horrible because it's so slow. Things are happening in the background that you don't know are being done. They're using your electricity. We have some of the highest electric rates in the nation here in the northeast. And it's all for their benefit and gain and nothing for you. I'm glad you brought it up. Danny, don't install an extension unless you have to. It's kind of like the app thing.

    Danny
    Yeah, we try to keep yourself as safe as possible. But something you have to do is make sure it's something that isn't going to come and backfire on you ultimately. Because we are talking with our tech expert Craig Peterson. Craig, we only have a few minutes left. But the one story I did want to get into here, the mobile voting app. Who would have thought this is ever a good idea?

    Craig
    heard off and on about what's going to happen Saturday in Nevada with their caucuses. They paid I think it was $60,000 to the same company that completely messed up the Iowa caucuses and they're saying yeah, we're going to do it. No, we're not going to do it. You're going to do it with the latest I heard yesterday was there not going to do it again. But there is an app called a vote to VOA t z. And this is something that supposedly allows you to vote from home vote from overseas. They've been trying to sell this to the military, for our military personnel stationed overseas. And this is crazy. The election is promoting its use of blockchain technology, which is like a vast buzzword nowadays. And people associate blockchain technology with absolutely safe, nothing could go wrong. They ignore the man behind the curtain. It is not secure. There are four states right now that are still planning on using this votes app that is being used in West Virginia. And it has some of the most basic security flaws in it. It allows other people to Steve votes intercept votes change votes, as they're being transmitted from the mobile phones to the company's voting server. If you can This is absolutely crazy. MIT put together a research paper that was released last Thursday. We're not there yet. Don't use these things. You know, the only thing that's really safe is a pencil or maybe a felt tip pen. Because you can't hack, a felt tip pen and a piece of paper. Right, much harder to do, obviously, this imbalance studying before, but you can do it on a wholesale basis like you can with some of these voting apps.

    Danny
    Yeah, what's this one right here? Just say someone to be able just to change votes like that. It seems as though the security and some of the features and noted have a voting type app. They have far away from Craig.

    Craig
    Oh, yeah, end up partner of Homeland Security's warning against it New York Times, even covered on it. They were the first ones to report this research out of MIT. We're going to see a lot of problems of voting over the next few cycles, maybe ten plus years, frankly, as you know, You know, the idiocy tends to tie down in the money, right? Who owns the company, for instance, with the backhoe debacle that happened overnight Iowa, the disaster that was going to happen this weekend in Nevada and still may have been that company that made that software to tally the votes was owned and operated by Hillary Clinton staffers. Okay. So, yeah, accurately. And now the democratic Democratic Party says, Oh, it's great. We know you, Hey, buddy. Yeah, we're going to do it for you, right? Until we can get rid of this phony crony capitalism stuff, which exists all over the place, and we make real decisions. This voting stuff just isn't going to work. Right. And you know, Danny, I hold a zero trust. The government's going to be able to get this right. But you know, another five to 10 years, I think, maybe we will have a reasonably smooth roll road ahead of us. There's a $10 million funding project that came out of the Department of Defense to make an unhackable voting system. So I got my fingers crossed because I know these guys are on the right track.

    Danny
    Well, I'm sure when they come up with something, you'll have a forest Craig Craig is always some great stuff, unfortunately, to get to everything. If somebody wants to hear more, how do they do so?

    Craig
    Well, you can go to Craig Peterson, dot com or they can text Danny, to me at 855-385-5553. That's 855-385-5553.

    Danny
    As always, data rates do apply. Craig, thank you so much for the time. We'll talk to you next week.

    Craig
    Take care, Danny, bye-bye.

    Danny
    It's Craig, always with some great stuff can be scary. But Craig gets us through it. As he said, watch out for your extensions. Watch out for the app to clean up the apps, and yeah, what's the make you think that Hillary Clinton can get a voting app? Right? But yeah, our servers were secured in New York. Yeah, okay. Everyone believes that one. Anyways, I'll take one last time out. Well.

    Craig 
    We've been working on this now for six weeks, eight weeks, we've got some fantastic free tutorials coming up. Frankly, these are going to improve your security posture. By what at least 90%. I'm serious about that when you are online, so it's going to help with security transformation plus a course and everything else. So free stuff, and some paid material, but you are going to love it all. I guarantee it. I've never been so excited about something before. Anyhow, keep an eye out. Make sure you're signed up. Craig Peterson, dot com slash subscribe. We'll be back tomorrow. Bye-bye.

    Transcribed by https://otter.ai

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    15 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Apps, tracking, selling info and election security

    Welcome!

    Good morning, everybody. I was on with Mr. Jim Polito this morning and as you know today is Primary Day in New Hampshire it is the Big Day for our State Sport - Politics.  That means it is the day to address voter manipulation, voter fraud, low tech solutions and why apps are not the answer. So, here we go with Mr. Polito.

    For more tech tips, news, and updates visit - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig
    You've got this free little cute little game, isn't this fun to play? Well, that game is tracking you everywhere you're going. They sell that information to Marketers. Now the Department of Homeland Security is even buying that data of where you are which apps you're using. Just because you have these apps installed on your phone.

    Craig
    Good morning, Craig Peterson, here. That's me with Danny, and it was pretty much all about voting technologies, the new stuff that's coming out the problems we have right now. And my predictions for not just this election, but frankly for the next two or three presidential cycles.

    Danny
    Yes, it is Tuesday. 840 You know what time that is? It is time for tech talk guru Craig Peterson. Hi Craig.

    Craig
    Hey, good morning, Danny.

    Craig
    I've got a little clarification about info from one of your former guests this morning. An earlier guest, I should say this morning. He was talking quite rightly by the about all of these apps and what's been in the news, in fact, just this week about apps and how dangerous they can be how they've been tracking, Google just removed a whole bunch of extensions from the Google Chrome Store. I want to go into slightly more detail if you want it to be secure. Don't download an app you don't need.
    Another thing I've said forever, Danny, is that you should go through your phone, at least every month, and delete apps you're not using. You know, most of us have a lot of apps. I think the last stat I SAW said that about 95% of the apps that we've downloaded only get used once. It's like we're never using them. Delete them off of your phone, off of your tablet, whatever it is you have. I want to add one more thing from a safety standpoint. Even if you are using an app fairly regularly, go ahead and delete it anyway, and then reinstall it. When you reinstall it now, it's going to ask for permission. You're going to be able to have a closer look at that app that again. It may be one you use every day like Google Maps. Believe that when you reinstall it and pay close attention to the permissions that it wants to access. By the way, just because it doesn't ask for permission to share some of your information doesn't mean it's not going to, all right. But as a general rule, those permissions are correct. It's more confusing on Android than it is iOS. Android kind of pushes you on to you the decision about whether or not you should be installing that app. On the iOS side, it's a lot more straightforward than Apple's a little bit better about it. He had some super points. But I go one step further. Just delete the silly things, mainly if you're not using them, as you mentioned, bringing up the app and permitting it.

    Danny
    So what kind of permission should people be looking for Craig to allow it not to?

    Craig
    Yeah, there you go. Well, let's have a look at the most costly divorce in history, which we talked about a couple of weeks ago. Right. So you have Bezos. Yeah, exactly. Billions of dollars in a divorce settlement. How did that all start? Well, that started because he was using WhatsApp, which is an app that is now part of Facebook's family. What WhatsApp had done here is accepted a video, and Jeff Bezos had allowed WhatsApp access to his photos and his videos. Even though you might think, oh, what's the harm and giving it access to my pictures or videos, maybe you're not going to get the virus the Jeff Besos got, but the app has access to your photos, your videos or other things. If there's a bug in the app, if there's something malicious going on, you're going to lose that data. What should you give an app permission to do? That? I think one of the worse things you can do is to permit access to know your location. That data is used and sold. You know, you've got this free little cute little game. Isn't this fun to play? And that game is tracking you everywhere you're going it's been sold to Marketers. Now the Department of Homeland Security is even buying that data of where you are which apps you're using, just because you have these apps installed on your phone. In answer directly to your question, do not give them access to your location unless you absolutely want to. I'm even reluctant to give Google Maps access to my location. Right? But slightly paranoid on that front. As far as photos and videos and things, again, just don't give them access. I think we're at the point now, where the bottom line is, you should only have a half a dozen apps on your phone on your tablet. And they should be apps from the big guys. You know Apple's apps, Microsoft apps, Google's apps, they are moderately trustworthy. And pretty much everything else. I think you shouldn't say bye-bye to them. ya know,

    Danny
    Ya know, that's kind of it sounds like a good plan. We are talking with Tech Talk Guru Craig Peterson, all about apps, and the security behind apps and then allowing permissions and them using your data to sell, and basically, you become the client. Correct. So these free apps not necessarily free, buddy.

    Craig
    No, they're not. And here's another trick, right? If you want to use something, and the app is available, most of the time, there's a website you can go to instead. So, for instance, you might download The let's use Iheart as an example. All right, so IHeart Radio has an app. I use it all the time, right? I'm, I listened to it to listen to my favorite radio shows listen to the gym in the morning. Iheart also has a website that you can visit. Okay, so rather than having the app, just use the browser that comes with your phone, use Safari, which is a good browser on iOS, use one of the Firefox browsers from Mozilla, those are all very good. If someone's twisting your arm with a gun to your head, use Google Chrome. Use the browser to get the data you want to you can stream music from your browser, you can listen to it hard from your browser, you can do all of the reading of news that you might want to do from your browser and avoid the cute apps. Aren't they wonderful? Aren't they fun? But you know what? There are so many Very few apps that can be classified as safe, that it's just not worth it.

    Danny
    Speaking of Google Chrome, speaking of extensions, speaking of people, basically using your uploading your private information, the Google Chrome extension, Craig. There were some issues there aren't there.

    Craig
    Yeah, absolutely. Now I've got some tutorials coming out starting next week, and about some extensions that you might want to use, and they will improve your browsing experience will improve your security, etc. What I think they're talking about here is a problem, Danny, where 500 Chrome extensions, Google Chrome extensions, were identified as secretly uploading people's data, millions of times. These things get downloaded. It's incredible what's happened, more than 1.7 million installations. So again, I still know people who are downloading browser bar extensions for Google Chrome for all of their different browsers, right. And it's a little browser bar extension that gives you a feature to search quickly or watch the stock market, etc. Those are the evilest things and prone to guys. Don't install, never install these little browser extensions that are just going to show you one or two things, because so many of them are sketchy. Many are fraudulent. Some of them are advertising as a service. Some of them will automatically, just from your browser, be clicking on ads on other websites you are not even visiting. Yes, they can click on an advertisement on a site you're not visiting just to increase their revenue. The estimate is that 40 to 60% of all paid advertising Non the internet pay per click advertising 20 60% of that is fraudulent. It's these. Yeah, these extensions, Danny, that we're installing that is supposedly giving us some sort of advantage or some neat little thing. Don't install those. Make sure if you're on my email list, you'll find out about this next week. But make sure you are on that list, which is just a Craig Peterson dot com. You can attend these tutorials for free. I'm not selling anything, right. It's all about the extensions that are going to make you safe. Not these 500 identified as making you less safe. You know what, Danny, some of them are even doing Bitcoin mining using your computer and slowing down your computer. They're making your browsing experience horrible because it's so slow. Things are happening in the background that you don't know are being done. They're using your electricity. We have some of the highest electric rates in the nation here in the northeast. And it's all for their benefit and gain and nothing for you. I'm glad you brought it up. Danny, don't install an extension unless you have to. It's kind of like the app thing.

    Danny
    Yeah, we try to keep yourself as safe as possible. But something you have to do is make sure it's something that isn't going to come and backfire on you ultimately. Because we are talking with our tech expert Craig Peterson. Craig, we only have a few minutes left. But the one story I did want to get into here, the mobile voting app. Who would have thought this is ever a good idea?

    Craig
    heard off and on about what's going to happen Saturday in Nevada with their caucuses. They paid I think it was $60,000 to the same company that completely messed up the Iowa caucuses and they're saying yeah, we're going to do it. No, we're not going to do it. You're going to do it with the latest I heard yesterday was there not going to do it again. But there is an app called a vote to VOA t z. And this is something that supposedly allows you to vote from home vote from overseas. They've been trying to sell this to the military, for our military personnel stationed overseas. And this is crazy. The election is promoting its use of blockchain technology, which is like a vast buzzword nowadays. And people associate blockchain technology with absolutely safe, nothing could go wrong. They ignore the man behind the curtain. It is not secure. There are four states right now that are still planning on using this votes app that is being used in West Virginia. And it has some of the most basic security flaws in it. It allows other people to Steve votes intercept votes change votes, as they're being transmitted from the mobile phones to the company's voting server. If you can This is absolutely crazy. MIT put together a research paper that was released last Thursday. We're not there yet. Don't use these things. You know, the only thing that's really safe is a pencil or maybe a felt tip pen. Because you can't hack, a felt tip pen and a piece of paper. Right, much harder to do, obviously, this imbalance studying before, but you can do it on a wholesale basis like you can with some of these voting apps.

    Danny
    Yeah, what's this one right here? Just say someone to be able just to change votes like that. It seems as though the security and some of the features and noted have a voting type app. They have far away from Craig.

    Craig
    Oh, yeah, end up partner of Homeland Security's warning against it New York Times, even covered on it. They were the first ones to report this research out of MIT. We're going to see a lot of problems of voting over the next few cycles, maybe ten plus years, frankly, as you know, You know, the idiocy tends to tie down in the money, right? Who owns the company, for instance, with the backhoe debacle that happened overnight Iowa, the disaster that was going to happen this weekend in Nevada and still may have been that company that made that software to tally the votes was owned and operated by Hillary Clinton staffers. Okay. So, yeah, accurately. And now the democratic Democratic Party says, Oh, it's great. We know you, Hey, buddy. Yeah, we're going to do it for you, right? Until we can get rid of this phony crony capitalism stuff, which exists all over the place, and we make real decisions. This voting stuff just isn't going to work. Right. And you know, Danny, I hold a zero trust. The government's going to be able to get this right. But you know, another five to 10 years, I think, maybe we will have a reasonably smooth roll road ahead of us. There's a $10 million funding project that came out of the Department of Defense to make an unhackable voting system. So I got my fingers crossed because I know these guys are on the right track.

    Danny
    Well, I'm sure when they come up with something, you'll have a forest Craig Craig is always some great stuff, unfortunately, to get to everything. If somebody wants to hear more, how do they do so?

    Craig
    Well, you can go to Craig Peterson, dot com or they can text Danny, to me at 855-385-5553. That's 855-385-5553.

    Danny
    As always, data rates do apply. Craig, thank you so much for the time. We'll talk to you next week.

    Craig
    Take care, Danny, bye-bye.

    Danny
    It's Craig, always with some great stuff can be scary. But Craig gets us through it. As he said, watch out for your extensions. Watch out for the app to clean up the apps, and yeah, what's the make you think that Hillary Clinton can get a voting app? Right? But yeah, our servers were secured in New York. Yeah, okay. Everyone believes that one. Anyways, I'll take one last time out. Well.

    Craig 
    We've been working on this now for six weeks, eight weeks, we've got some fantastic free tutorials coming up. Frankly, these are going to improve your security posture. By what at least 90%. I'm serious about that when you are online, so it's going to help with security transformation plus a course and everything else. So free stuff, and some paid material, but you are going to love it all. I guarantee it. I've never been so excited about something before. Anyhow, keep an eye out. Make sure you're signed up. Craig Peterson, dot com slash subscribe. We'll be back tomorrow. Bye-bye.

    Transcribed by https://otter.ai

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    15 min
  • Welcome! Rampant Intellectual Property Theft by China, Scams - Airbnb, VRBO and CoronaVirus Phishing, ACLU and DHS and more on Tech Talk with Craig Peterson on WGAN

    Welcome!  

    Today there is a ton of stuff going on in the world of Technology and we are going to hit a number of topics today. There are some scams that are getting more and more prevalent with Airbnb and VRBO that we will talk about. Also, phishing scams using the Coronavirus as a way to trick you into clicking.  The ACLU is filing suit against DHS. China is stealing our Intellectual Property.  Shadow IT becoming more and more of a problem and even more on Tech Talk With Craig Peterson today on WGAN.  It is a busy show -- so stay tuned.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Related Articles:

    Is it possible to secure our Elections using Technology

    The security mistakes made by the Iowa Democratic Party in creating their App

    Coronavirus bringing out opportunistic Hackers  

    Extensive US Intellectual Property theft by Chinese being investigated by FBI 

    Scammers have found a fertile field in Airbnb

    DHS wants to track illegal aliens using available cell-phone location data. ACLU says Whoa! 

    Shadow-IT: Employees putting Business at Risk

    Ransomware rings adapt to business declarations by Revealing Stolen Data

    ---

    Machine Automated Transcript:

    Hey everybody, welcome, welcome. Craig Peterson here on WGIR, you can also hear me every Monday morning at 737 with Jack Heath, where we discuss some of the latest topics in technology. Of course, nowadays, you can't talk about technology without security, which is what I've been doing in my business now for about 30 years. I was coerced into it. Maybe one of these days, I'll share that whole story with you. It can get to be kind of a long one. But today we are going through some of the problems that I've seen out there lately. I have on my podcast this week that you can get at Craig peterson.com slash Iheart, Craig peterson.com slash Iheart. I spent quite a bit of time talking about recent problems people have been finding with Airbnb with VRBO, and I go through some of the problems I recently have had with both of those services. And I think it's well worth listening to because I've gotten to the point right now where I will not use either Airbnb or VRBO, I don't think ever again. My experiences with them have just been so overwhelmingly negative, anyhow you'll find that online, and you can subscribe there as well at Craig peterson.com slash I heart. That like is going to take you to the I heart app. You might be listening to me right now, in fact, on Iheart streaming on these AM and FM stations. If you are, kudos to you, but you can also get all of my content by going and subscribing, Craig peterson.com slash I heart, and I'm also on every other major podcast streaming platform that's out there. But first, I just want to make mention of this other article that came out last month in January. It's talking about computer literate millennials and Generation Z. These are the people that grew up with the internet. They've had the internet pretty much their whole lives. They've found meaning the Federal Trade Commission found that people ages 39 and under are more likely to report fraud than the 40 plus crowd. Now, here's the thinking here. It isn't that the younger kids millennials and Generation Z, it isn't as though they are less afraid to report that money stolen from them. It appears that they are more likely to fall victim to fraud. 25% more likely. Now the millennials are less likely to fall for a scam over the phone and people over 40, but 77% More likely, Millennials are 77% more likely to get duped by email scams and 90% more likely to lose money on a fake check scam. Now, the thinking behind this is that those of us who are a little bit older, we hold the whole internet thing with a little bit more skepticism than our children and grandchildren do. Because we know that there are scammers out there and we've heard all the horror stories, whereas the younger kids are looking at it as well. It's the internet, and they just give their stuff away. We already know that there are studies that show that the millennials will give their email address or weigh in trade for a single donut. Okay. They don't value a lot of this stuff. And, you know, to me, well, it's a little bit concerning, and it should be to you. But let's get into the latest scam that's out there right now. It isn't the Airbnb scam, which has been out there for a few years now. As I said, hey, I've been burned, what, four or five times by this overall personally. I am jaded, and I just don't use it anymore period. It's a real shame because there are some good people out there. But this has to do with what's been happening with the Coronavirus. It is a huge deal. We had one day this week, where 15,000 new cases were reported. The Chinese changed how they tracked and diagnosed cases. So they're saying hey, listen, it's you know, it's Change. Don't expect this to indicate that more viruses are spreading out there. And frankly, I look at it and say, Well, maybe there are there aren't. But what we're seeing are some rather sophisticated phishing scams going on. Phishing, of course, this is the one spelled with a Ph. It is where an attacker tricks you into doing something. It might be
    clicking a link. It might be responding to an email. It might also be a phishing scam over the phone or, you know, SMS a text one which is called smishing. A whole new type of phishing this going on right now. Well, last week, IBM and Kaspersky now Kaspersky is an anti-virus company. They are also trying to stop the general spread of malware. They are a Russian firm, and the State Department and FBI have warned us about using their software, but they do have good information. When I see Kaspersky combined with IBM, a company I do respect, then that does kind of make my ears stand up, if you will. IBM and Kaspersky caught hackers in Japan, trying to spread malware through emails. And the emails had links about the coronavirus outbreak that started Of course and won China last month in January. And now adding cell phones to the list. Of course, Cisco, to the list, they have found phishing emails from cybercriminals, purporting to be from the Center for Disease Control, as well as the World Health Organization and what they're trying to do the bad guys his deal your email credentials and other information. The emails are coming from several domains, including CDC dash gov.org, which, of course, is not the real CDC website. So be very careful if you are trying to find out information about the CDC, or about the spread of Coronavirus about flu in general. For instance, in my home state of New Hampshire, we have I think it's seven deaths so far this year reported g attributed to the flu in general, not the Coronavirus. Every year about 12 to 16,000 people in the United States die from the flu. So far we've only got 14 cases reported of Coronavirus So, at this stage everybody, this is nothing to get all freaky worried about. Okay, so calm down. If you want more, go to CDC.gov. CDC Centers for Disease Control cdc.gov. And it tells you what to do now this Coronavirus has an official name now it's called Covin-19, co vi d dash 19 because there are multiple versions of Coronaviruses and viruses. And we have had a report in the past about Coronaviruses, and they have killed people previously. So you'll see right at the top of the CDC, gov website, information about the Coronavirus and it spread. It is a respiratory disease. It is potentially fatal. It doesn't seem to be any more fatal than some of the other viruses that we've had. So let's put all of this in context. And when you get an email from someone saying hey, Look at this, click on this link, it's going to get you information about the Coronavirus, it's going to let you track the spread of, etc. don't respond. And you, if you get a text message, don't respond. I got one because I'm a member of the Great and Powerful media, right. I got one last week that was sent out to members of the media saying, Hey, we got this new tracking site. You just can't be cautious enough when it comes to this. So if you go to CDC Gov at the top, you'll see the description here about the Covin-19. And you can click on that, and it'll show you a global map about where it has been reported what is happening. I'm looking at one. It's about one day behind it looks like right now for Covin-19. But you can see all of the countries that have been reporting it and then you can also So look at the hard statistics. People under investigation in the United States exactly how many 14 positives you'll see that there. Of course, it changes daily. How many negative how many pending? The people are under investigation. Remember, the airplane full of workers from the State Department that came back from China. They have now been under quarantine for more than 14 days. They released them all from quarantine because it turns out that nobody had that virus, so just because you have the flow doesn't mean it's Coronavirus. More cases over on the left coast and the Midwest, which is kind of surprising to me than there are on the East Coast or the Mid Atlantic, etc., etc. So have a look there. Do not respond to emails or texts or phone calls. Okay. Just be very, very careful. Hackers are imitating this sort of thing. Then the other side of this is they are sending out messages, seeking donations, and they're asking for Bitcoin donations to the World Health Organization. I can tell you right now, the World Health Organization, the CDC, they are not taking Bitcoin donations, okay? Don't go and donate, right. Again the CDC gov.org is the bad guys cdc.gov is the good guys. The scam page is elementary. it might have taken the scammers just a few minutes to put together. It's very effective. It looks legit. And the FBI and, of course, also Homeland Security are taking down these pages as soon as they can, but they can't always get rid of them right away. And companies we got to be proud. We've got a chain, train our employees not to follow up on these scams. So again, that's part of why I publish my newsletters. I report on the biggest scams that are going on. I try and keep it down to just a few a week. You can share them with your employees, share them with your family, but you have to get them to share them. Go to Craig peterson.com slash subscribe. Now, we're going to talk a little bit about this whole thing with the ACLU and their current fight. I spoke about something similar to this a couple of years ago, man, maybe actually the first time was probably about ten years ago. There are companies out there, and they gather information about us. They're called Data brokers. And I have visited some of these data brokers sites themselves. I mean physical site, where the company operates where they have their data collections, to help them with security problems that they have. And to help prevent problems from occurring, right. That's what I do for a living full time. And it was probably ten years ago, the radio show that I talked with some of these companies. But what they do is they take what's called open source information that's used a lot by government or investigations. And you can use open-source information yourself. All you do is go to Google, for instance, and do a search. That's the open-source information. It's anything that anyone can gain access to, without having to be a police officer without having to go and really kind of, you know, get a court order kind of be surreptitious and how you gather that's open source. So the data break brokers will take all of that, and that can include depending on States your living driver's license information. It can include information about the mortgage for your home. It can include you know the ownership of your home, and it can include just all kinds of stuff. And that becomes very, very difficult to control. Because all of your information is out there. It's available for free or for cheap on the internet. So these data brokers, they might buy it from the county, they might get it an open-source. Some of these documents are going to contain like your mortgage is going to contain your signature. The deed to your home is going to contain the signature, the automobiles that you own. There's going to be UCC filings with the Secretary of State's office, detailing what cars you own, who the lien holders are, and how much money is involved, all of this stuff. So it all gets pulled into these days. databases I mentioned on the show a few months ago, a couple of months ago that we were out in Las Vegas at a wedding. And of course, you know, doing work while I'm out there sitting on the couch, doing work for some of our Las Vegas clients when there was a knock at the door. Who's there? Well, it's an insurance investigator investigating an accident that had a fatality. And of course, the insurance company had been asked to payout.
    They came to this home because they had information that the person involved had contact with someone at this address, which indeed she did. It was her sister, and the driver had been responsible for this fake fatal death. The driver listed was one of my sisters in law, who had died six months before the accident. It was all fake. The insurance investigator showed my wife all of this information she had that they had purchased from one of these data brokers. It had listed my deceased sister in law's relatives, everybody every address she had ever had. It had names and contact information for some of my kids as well. Now, it was not all correct or organized. When I've looked at the data brokers' information about me, only about half of it is right, but the other half is entirely incorrect. That's still the case because they had a lot of utterly false information. People that they said were relatives that weren't. People we'd never heard of before, they identified as direct relatives of hers. The insurance company purchased all of this information from a Data Broker, in collections, this is called a skip trace. It's called a skip trace for people who jumped bail, etc. Man, we should talk about this whole bail thing, and the idiocy and New York state that is spreading countrywide dog, the bounty hunter and his wife Beth had been fighting this for a long time because it's making us much, much less safe. But anyhow, that's not a topic for today's show. It's not a political topic, because it's undeniable what's already happening with the increase in the crime rate, New York anyways. What the government is doing now and this is part of what I was warning about a decade ago, is the federal government, the FBI, the NSA, the CIA, of the IRS, you name it. They are limited in how they can collect information, we kind of already knew that, right? They knew that they had to get a search warrant for certain things, right? They can follow you around if you do not expect privacy, etc., etc. So obviously, federal government agencies can use open-source information to see what you're doing online. But how about the closed source stuff? How about this information that the data brokers are collecting? Some of it comes from the people who lent you money. Some of it they're getting from places where you have to pay to get that information. What's happened here now is that the ACLU has filed a suit, according to The Wall Street Journal, against Homeland Security and Homeland Security through its Immigration and Customs Enforcement Agency. As well as Customs and Border Protection, is buying Gilo geolocation data from these data brokers. It's using it to investigate suspects who have allegedly committed immigration violations. So let me boil all that down into plain English.
    You might be using games on your smartphone, and you might be using all kinds of apps on your smartphone. If you have a smartphone, you probably are, frankly, not using 90-95% of those apps that you have downloaded. But many of those apps are tracking you. And that information is being sold to data brokers. So think about that for a minute. Remember that free app and how you've heard me and many others for so many years. Say, hey, you're not the customer. You are the product. But what's happening here now is that the ACLU is saying to the federal government, hey, you cannot, you cannot buy this information that you are not allowed to collect yourself. You cannot buy it from data brokers or these app developers who are selling it. Interesting question, interesting problem, isn't it? What should they do? What should you do? What can you do?
    It is going to play out in court. I suspect it's going to come down on the side of the Department of Homeland Security because this information is generally available to anyone willing to pay for it. So now the government stepped forward, saying we are will pay for it. By the way, it's down to local law enforcement as well, who, in many cases, are also buying information from the data brokers. Have you ever set up a company Amazon account? Have you ever set up an account for a company account for Uber? Maybe it's not a company account. Perhaps it's your account that you're using for Uber or something else? How about using something like Constant Contact to send out emails to your customers? How about salesforce.com, where we've seen a shift over the years from what used to be kind of the glass castle, where you had a central computer room in that computer room was a mainframe. And those mainframes were astounding. They still are. And that mainframe in that glass room was controlled by professional Information Technology people, people that knew what they were doing at least at the time, right? Then we started seeing some changes. You remember the apple two and VisiCalc Visicalc was kind of the killer application. And if you wanted to do numbers, then you bought an apple, you purchased a little apple two. And you then pulled data and people were asking that glass house, they were asking it, Hey, can you give us data because we want to put together some spreadsheet. People put together spreadsheets without really understanding the implications of the numbers they were using without understanding how to audit a spreadsheet to make sure that the figures included were correct. They didn't understand the double journaling. They didn't understand the cross-referencing of the information. They started a bit of a movement away from that glass house from that glass castle from it. They said hey, we could figure this out, why are we going to pay it all of this fake budget money to do something for us and we can do it for ourselves and do it cheaper. Frankly, that's a problem I still face with many organizations, if you can believe it, who think they can do security themselves, which is impossible for almost any organization. In this day and age, any small-medium business must have full-time external professionals who are helping your internal IT people. The internal IT should be doing what they do best, which is helping your business use information technology, to its best use, assisting people to be more efficient, finding new ways of doing things, etc. Instead of that, what most businesses do is they have these various silos, like sales and marketing and accounting. And each one of those silos, those lines company does things their way. So the sales guys, they're out, and they said, Hey, we're going to use Salesforce. And we're going to tie that into Constant Contact. And then you have your accounting people saying, well, we're going to use QuickBooks Online. Or maybe they're going to use one of Oracle's accounting systems. And then the manufacturing people say, Well, we are going to use this particular era p program, which is going to be great for manufacturing. And we've decided that we're going to use Survey Monkey to collect information from our customers from our vendors. You see where I'm going, each one of these lines of business is going out there and making what are in actuality, information technology decisions. They're making decisions about what type of technology to use, which is one level, but then the next Next Level is they're using it. And they're putting the business's information at risk. It is a huge, huge problem. It's something that I'm going to be addressing with some of this training that I have coming up with a couple of these tutorials correctly tackle these problems. And so if you're on my email list at Craig Peterson comm slash subscribe, you're going to find out about these, and I'm going to give you some great cheat sheets and other things. But all of those again, Craig peterson.com slash subscribe.
    All of those different lines of business, all of those different functional responsibilities within an organization larger small, are adding up and adding up hugely. And there is a massive problem behind this. Now you know, that I use one password, and I recommend it, and we typically Use one password in conjunction with Duo to help secure login information. But because one password is used so frequently by companies to keep track of logins, they have kind of a unique view into the risks of all these different accounts. And what we're talking about where these lines of business are making Information Technology decisions that they're not qualified to make, and frankly, in most small-medium companies, there's probably no one in the organization that's fully qualified. Still, at least it has a better idea, but then a marketing person or an accounting person would have. So this is called shadow it and it's absolutely something that we have to be careful of and we have to watch for and if you are one of these people who is using one of these third-party services, and you have not informed your IT person. Do it right now. All right, thanks. Okay, hey, we have a lot more content that you can get online. Just go to Craig Peters on.com. You'll find it right there in my weekly newsletter that you can use to help educate other people inside your company. Maybe family, maybe friends, and indeed, educate yourself and the things that you need to know security-related or just the newest and latest greatest technology. Now I got an email here just while was Facebook a couple of weeks ago a message about a story that I had reported on about Tesla before, and I try and answer those I dig them up I get them for you. But I want to make sure you are subscribed at Craig Peterson comm slash subscribe, so you get all of that. Thanks for being with me here, WGIR, and we'll be back Monday morning with Jack Heath at 737.

    Hey, welcome back Craig Peterson here on WGAN and online Of course, Craig peterson.com. If you want to, you can subscribe to my email list you'll find out about the free tutorials that pop up training, courses, everything that I do to help make you and your business more secure. So again, Craig Peterson, dot com slash subscribe. I got to read this to you right now. I decided to cancel through Airbnb and tell them about what had happened. He went off at me, berated me for not handling in it privately, and told me I was acting in my self-interest, and belittled me. I ended up having to pay the first full month even though I stayed one night. His listing is still up, and a review posted after my state also mentioned the silverfish. Isn't that something? Now, this is from a report that came out from vice. Now you might be familiar with vice.com. There's a lot of decent stuff up there. But I want to tell you a little bit about my own experience I've had with Airbnb and VR Bo now VR Bo is vacation rentals. It's it has been used more, I think, by businesses from what the stuff I've read than it is by individuals. But I have had bad experiences with both of them. Every time I have had an Airbnb, I have had a bad experience. So let me tell you what I mean by a bad experience. For instance, I was out of Vegas at a conference, and we thought, you know what, let's try Airbnb. I'm the tech guy, right? I need to understand this. Why wouldn't I go ahead and use Airbnb in make sense, right? So here the tech guy goes, and we poke around read reviews we read ratings. We found an apartment, not far at all, I mean like half a mile from the convention center. We thought, okay, this is going to be perfect. It says it's right by the strip we could walk over there, hop a cab or, or grab a ride and enjoy The Strip, and then the morning we can just walk over the convention center. We're not going to have any problems parking because it said it is an apartment. Let me start with parking. By the way, parking is another thing in the second Airbnb story. There was no parking. You had to park a half a mile away sometimes because people were just parking in the parking lot of the apartment building. There were no reserved parking slots for the apartment. So there's number one — number two. When we go into the apartment, and it's quite nice. We find out that it has two bedrooms. We had only booked one bedroom because that's all the listing talked about the one-bedroom.
    We get there, and we find, okay, so this is our bedroom over here. Well, the bedroom did not have an ensuite bathroom. The bathroom for the bedroom was across the hall. So there we go, we get in there and okay, fine. So our bathrooms across the hall, and we end up going to bed. We enjoyed it was a nice place relatively clean, quite old. It was probably a 40-50-year-old apartment. In the layout that you would expect there in the southwest where there's kind of a courtyard in the middle, and it's a little two-story thing and, you know, kind of reminded me when I lived in LA back in about 1980 late 70s early 80s. You know it's that part was quite nice. You know brand new shag rug in there, well you know not brand-new but quite new and clean. That part result was good. We go to bed and then we there we hear just tons of commotion because somebody else who didn't speak English very well had come to stay at the apartment as well. We hear them going into our bathroom, using our towels. They are very, very loud talking on the phone, and they get a hold of the owner right of this Airbnb. They got the same impression we did, which is there's one-bedroom in this place. So they had an ensuite bathroom. We did not, but they were using our bathroom the whole time and our towels, there's only one set of towels. It wasn't a great experience at all. They kept us up for quite a while because they were just so loud. Now you know me, I'm not an outgoing guy. You might not believe that, but I'm a little bit of an introvert. And as an introvert, I didn't want to go out and confront these people who were I'm guessing, or you know, from Asia, they were speaking Chinese or Korean or Japanese, I have no idea. I just didn't want to mess with it. So we get up in the morning, we and everything is okay-ish. We go to the conference and then that night, I guess these people only there for one night. That night, we had the whole place to ourselves, which is okay. Knowing that with Airbnb, I rate the place after I stay there, but the owner of the place rates me and so there have been a lot of issues of retaliation when it comes to Airbnb. If you stay at one of these places and you don't give them this glowing five-star review, then you're not going to get reviewed while and other people might not want you to stay at their place. So I gave it a reasonable rating. I can't remember what I gave it, you know, places clean and, and, you know, it was a nice place and there is another bedroom. You know, just kind of hint into anybody reading this. It isn't going to be dedicated to you and maybe your loved one you're staying with and left it at that. That's my first Airbnb story. And then my second Airbnb story, as I mentioned, had a lot to do with parking as well. And in this case, it was in the Toronto area, up in Brampton, and we rented a place on Airbnb, you know, I figured, well, we'll give another chance, see what happens. It was a three-bedroom place, and they said it sleeps like eight or something like that. What you did if you include the fold-out couch, and so we figured, okay, we need some parking. So I had sent them a message saying, hey, it's going to be myself and a couple of my kids and some grandkids. You know, I want to make sure that there's plenty of parking. Is it? Oh, yeah, plenty of parking, buddy parking, no problem. And so we get there, and there is one parking spot. And it's in one of these. I don't know if you know much about Canada and how they build their housing there. But one of the reasons I'm not that fond of it, right. I grew up there. It was these townhouses that are built right on top of each other, you know, the zero property line homes there. Three, four, or five of them attached. The only place you can park is in the little garage place. Well, the garage itself was full of stinking
    trash. Who knows how long it had been there. You couldn't use the garage. It had hared the driveway with the condo next door to you. It had one parking spot. I had my car, my daughter's car for her, her husband, and a couple of her kids. And then one of my other kids also drove up there. We had to find a place to park. Now the good news was that the whole neighborhood was under construction. They were able to park in the mud. in one area where construction wasn't happening right then, of course, the next morning, what shows up big dump trucks, excavators, everything else to work across the street from us. That wasn't fun. Let me tell you that it was not fun. We were quite worried about our cars, with all of this heavy equipment on this little narrow street designed for one car to go down the street when cars park on the street. We have to go right now when we come back, and I'm going to finish what happened with my air mean being being being a story, as well as my VR Bo story. And we got a whole lot more to cover. We're going to get into this Homeland Security thing with the ACLU and more but stick around, listening to Craig Peterson a course on WGAN online at Greg Peterson dot com is where you'll find me. Make sure you subscribe so that you get all of my free tutorials, training courses. Everything, Craig Peterson dot com, stick around.

    Hey, welcome back. Craig Peterson here on WGAN and of course online, at Craig Peterson dot com. I was in the middle of telling you my stories about Airbnb. If you have ever thought about staying at Airbnb, or VRBO, or any of these types of places, right, obviously you're not staying at a website, but you're booking through a website, somebody's home, somebody's rental, whatever it might be then this is for you. I have done it for personal reasons. I have done it for business reasons as well. I told you the beginning of my story in Toronto, and I told you the last segment about my story in Las Vegas. We didn't have the parking, and the kids are all worried, and I was concerned about our cars getting destroyed by the heavy equipment. Were we going to have to move them because they were working on the lots across the street? It's incredible how fast the housing is going up there and how expensive it is to it's, it's just not how pricey it is. We get inside the place. Now, remember, I said that the garage was full of trash which was, and it stunk to high heaven, which it did. Okay, so some of that leaks into the house, which makes the house kind of smell too, which is just plain old, no fun. We get into the house, and I go and sit on this folding couch. And remember, the house is supposed to sleep eight, and it has a fold-out sofa. I sit on the couch. It reeks of BO, body odor. Right? I mean reeks.
    One of the first things I have to do is I want to make sure that they know that this is a problem so that maybe they can take care of it. I call, and I don't get any answer because it's the weekend, right? Nobody's around. We head out to the local grocery store, and we get some odor killer stuff, and we bring it back, and we drench the couch in it. And we're able to get rid of most of the BO you know, and its underarm smell is what it is. Someone with some nasty underarm odor was sitting on that couch. They put their arm up on the back of the sofa and left all of their BO behind them. Then they did the same thing on the couch itself and somebody supposed to sleep there, right?
    Oh, it was just incredible. Then we go upstairs and upstairs that we noticed that the fire alarms had tape all around the sides of them. Now, if you're not familiar with the way firearm alarms work, they have to be able to have air flowing through them to sense that There's smoke in the air or carbon dioxide, carbon monoxide, whatever the type of detector is. And it had been it had tape all around it. Now it looked like it was painters tape right that blue tape that you use as you can pull off that isn't going to leave residue behind. So maybe it was the painters perhaps it was the owners, I don't know, perhaps it was a previous occupant, but I warned them about that as well as saying hey listen, your fire alarms are not going to work because it blocks the airflow on the fire alarms by this tape that's on them. I never got a response on anything there. So what do I do when it's time to leave a review? Well, I said the place was in perfect shape. It's brand new. I had to do a little bit of cleaning. The cleaning crew in because the carpets upstairs all had the markings of a, you know, a vacuum cleaner. You can see the wheel marks on the floor and everything else. So you see it's not as though a rip them a new one like I have seen done before. And you never get to see your ratings by the way from these Airbnb owners. Okay, so there's a second one not neither one of mine were nightmares per se, but they both had significant problems that I was afraid to report on because I know that turnabout is considered fair play and who knows what these owners are going to say.
    Then I tried a VRBO, but they are older. They've been around for something like 30 years, and it's vacation rental type stuff, right? So VRBO, okay, we'll try it out. So we try it. We booked a place, and I wrote to the owners. Hey, there's we're going to have three cars, or two cars can't remember what it was now. Is this going to work for us this okay, I want to make sure this parking is I've had issues before? I never got a response from them. But, you know, they ran my credit card through so I figured, okay, well at least that part is done. I show up with the family in tow. And we're going to have this great time together. I'm going to be working, and they can stay in and just enjoy the place you know, a new city, a new location is going to be great. Guess what? VRBO had canceled my reservation without telling me without informing me, without crediting me. Well, it turned out that they didn't end up crediting me after all the credit card, but here I am waiting for the place that I can't get in. I called up VRBO to say, Listen, I never got a code for the door or anything else. What should I do here?
    Oh, no. Well, I see that reservation was canceled. I never canceled the reservation. Oh, no, sir. It was canceled, like the day after you booked it. I said, wait a minute. I never canceled it. Well, okay. Well, then the owner must have canceled. Why didn't I get notified? Oh, you didn't get notified, sir? Really? It says they sent an email. I went through all my junk mailboxes and everything else and yep. Okay. I got a notice of cancellation. Oh, man, what a pain that one was. Well, we can find another place in the area you're in right now. We'll make sure you get a refund. I said, Listen, I'm here. I don't have A place to stay. What am I supposed to do now? And they just say I'm sorry, sir. You know, I'm sorry, We'll make sure you get credit. That's all they would do. For me, it was absolutely a nightmare. Three experiences personal experiences for me. One of them a nightmare. One of them on the edge of a nightmare. Another one that could well have been a nightmare but was a mere inconvenience. You can probably guess by now what my thinking is about Airbnb and VRBO. That's what got my interest in this article about this poor guy who was scammed, okay. He was trying to stay in Montreal, and the owner asked him to pay for their stay, outside of the Airbnb app. I've seen that happen many, many times. Because that way, the owner does not have to pay the Airbnb fees, okay? But if you do that now you have very little recourse against the owner, then you know, I've done some chargeback. Lately, now my company if someone buys a course from us, and they're not happy, and we will immediately refund their money because we just don't want them to be upset or disappointed. Because again, you know, our whole thing is to nourish you back to health when it comes to security stuff, right, get that transformation done. I have had some nightmares personally trying to do a chargeback for things that were never delivered, or that got charged inappropriately. Or where I canceled the service. In one case, it was like it was over $1,000 a month for the service, and I canceled it. They charged me the 1200 dollars anyways. I went to my credit card company, and they said, well, we'll have to verify it with the vendor first.
    So what? I canceled it. I had to fight with a credit card company, and then when they checked with the vendor, and the vendor said, Okay, well, it's fine. We'll take chargeback. You used to be able to do this at the drop of a hat, and I guess they've abused it, right? I think that's the bottom line on it. But man, oh man, so we'll get a little bit more into this vise story. I guess its turned into an Airbnb, VRBO, what to do if you want a vacation rental or if you want to rent a place while you're on a business trip. And then we'll get into some of the more of the articles here, in the next hour. You're listening to Craig Peterson, of course, on WGAN and online.

    Hi everybody. Craig Peterson back here. I don't know if you guys know what Airbnb's roots were. It started as an air Bed and Breakfast. It was intended for the very young generation to be able to go to concerts and things and just get an air bed in somebody's apartment or home. That's what Airbnb is all about air bed and breakfast. That was the whole idea. And I'm not so sure they've come a long way from those days. I spent the last few segments, in fact, in talking about my horror stories, we've been trying to use Airbnb. There's another one I did not mention in Florida, which was not a horror story quite the disappointment for this house. That I think while I'm quite confident in this house that we rented. It was for a family reunion. So we rented this house that slept like a dozen or something like that. All of the beds were just terrible. You know, the cheapest mattresses that are known to man. You shift your weight at all, and the squeaks loud enough to wake you up. The sheets are the cheapest ones you could imagine. It was an Airbnb as well. It was pretty obvious that the set up for this place was for porn videos. You go into the garage, and the whole garage is one massive shower with I can't remember for six showerheads in it. And then a little bit of workout equipment. I mean a tiny bit of workout equipment. It sounded awful. Okay. And so there you go there, there's all of the Airbnb and VRBO, experiences I can remember. My sister rented the one in Florida for the family, and she did not stay there. She stayed with my mom. It was quite revealing, frankly, so disappointing. I never shared these stories before, but it was because of a story that was in a vice.com, and you'll find this up on my website and Craig peterson.com. They put a little note out saying, Hey, does anybody have any stories about Airbnb, Airbnb scams, and they said, this is Anna Marian, who wrote this that nearly 1000 people sent them emails with their stories. They looked at all of the stories they put together some patterns. A former vice senior staff writer by the name of Alec Conti shared her story about a disastrous vacation to Chicago, and she ran into what she's saying are a bunch of grifters, and frankly a nationwide scam. I no longer use Airbnb at all or VRBO at all. I have been sticking with hotels. If you're interested, I typically use hotwire. I don't use the star ratings of the hotels. I rely on the ratings that are posted by the people who stayed there. I think that's the best feature of hotwire, frankly. I don't care what hotel it is. I just want to stay at a decent hotel. I even used hotwire throughout France and Belgium. It worked great. We found some just wonderful spots that we would never have found if we were just looking to stay at the Marriott or the Hilton or whatever it is, right? So Conti's investigation revealed some serious problems with Airbnb. Now you might have heard about this problem with Airbnb. After all, it hit the news late last year of these party rentals after a death happened. I think it was in San Diego at one of these party rentals. Somebody rented a nice house. Essentially a lot of these places get destroyed by the partiers, right there. There are drugs and heavy drinking, and in this one case, that hit the news. There were gun shootings. Okay, that's a very, very bad, bad thing. So Conti apparently, and again, you can find this article on vice.com traced her scam back to a company that used fake profiles and fake reviews to conceal a whole bunch of wrongdoings. Let's get into this okay because property switches are one of the biggest ones will tell you about what those are the units of sawdust on the floor with holes in the walls, this whole bait and switch game which goes into these properties, switches, and stuff. It's awful. When all else fails, there are these clumsy threatening demands for five-star reviews to hide the evidence of what they've done. Sometimes multiple scams are involved. You know it the hackers aren't just coming after directly our money by trying to hack our businesses by trying to fool us into clicking on links or doing things that we shouldn't be doing, right? These scammers are all over the place. After this story that came out, Airbnb promised to "verify All 7 million listings on this site by December of this year 2020". Frankly, there's no way that they could do this. There's no way you could send investigators to all 7 million listings. He said, Well, we're going to have to take more responsibility for stuff on our platform. Yes, you will. You have to provide a firewall. Not just a firewall of the reviewers, the people who stay there and review can see the reviews that come in from the owners of these properties. That's not going to solve the problem. You need to make it so that there can not be retribution by the bad guys that have given Airbnb a bad name. Now I got to mention that my sister the one that booked that Airbnb for us in Florida, my sister has a house that she rents out in Park City, Utah, on Airbnb, and one of her daughters keeps it clean. I know my sister is not engaged in scams. I know that my niece is somebody who takes responsibility for things. I'm sure she keeps it clean. I don't want to paint the whole Airbnb, a website and people who are renting with a black brush here, I don't want to paint the whole rental market, including the VRBO with a black brush, but I've got to say 100% of the time I have had what I think are scams on both platforms. Now, that's my personal opinion, based on a handful of stays, and I know a handful of stays does not represent every listing on the platforms, right. I understand that. However, its the verification process, we're talking about here. I don't know that he's ever going to do it. How are you going to review and verify all 7 million listings on the Airbnb site within 12 months by December 2020? I don't know how you're going to do it. So let's go through the biggest scams according to vice.com number one, which they say is exceedingly common. It's across hundreds of emails. It's the bait and switch where Airbnb users were promised one apartment and arrived to find something very different. deceptive photos a bore no resemblance to what they found when they got there. My kids found this too. They rented some places in Italy when they did a tour, and you know, black mold everywhere just terrible. Okay? Other times and they were persuaded by those to switch apartments or houses entirely.
    It is a widespread thing where they say, hey, due to unforeseen circumstances, as a pipe broke, I'm going to have to move you to another one of our properties. Now under the rules for Airbnb, the owner does not get penalized if they push you to a property due to quote, unforeseen circumstances unquote, like a pipe break. But it turns out some of these people are using that unforeseen circumstance again and again and again. And they're showing up to their rental defined the new locations filthy, unfurnished on a different part of town. And they're saying that in a surprising number of stories, the original house was full of a weird amount of bear beds laid out and bizarre configurations, kind of sounds like that porn place my sister rented for the family in Florida, doesn't it? So here's one of the quotes I rented a place near Glass beach and a few weeks part of my trip. When I reached out to confirm the booking, the Lister told me she had a septic problem in the unit, and she would see if she'd put me if she could put her up in a more prominent place nearby. It never materialized, but she refused to cancel my booking, saying the first time that her computer wasn't working and the next time weeks later that her father just passed away. I had to complain to Airbnb that she refused to cancel the booking, so they canceled it, but I was unable to write a negative review. According to Vice again, they're saying the plumbing scam seems to rest on the idea Airbnb won't penalize a host if the house is uninhabitable. Okay, that's what I was saying. I've seen this before. So this goes on and on this whole bait and switch thing. Okay, next one, getting the guests to agree to move houses and the plumbing scam is often kind of segway into getting you to agree to move houses. Okay? So they will say, supposed to be this, you know, here's this complaint supposed to be quaint, quiet property in downtown. They get delayed by the homeowner stating that we'd need to change properties the last minute since it was only a quick two-night visit we weren't opposed.
    The new quote larger location was this scummy little apartment complex on the other side of town. Another one - Booking the Airbnb to multiple people at the same time. That's what happened to us in Vegas. When my wife and I showed up at this apartment through Airbnb, perhaps the most socially awkward Bait and switch is this one renting an Airbnb where you believe you booked the whole residence only to arrive and find a whole bunch of strangers there. That happened to us in Vegas. Multiple people told us they came to see other Airbnb guests at the house, or in some cases, people who seem to live there. It just goes on and on. Next one - money scams, paying outside the app. I mentioned this one early. It says it's a straightforward scam. Be careful.
    There's no be careful here, as there is no reason to do that. Fake damages - Man, I've heard about this from multiple people before mine. How can Airbnb police this? Did the guests damage the place? Okay. Oh man scam scams, you'll find more about this online. My advice? Use a hotel you trust us out of the hotel booking site, you believe. And I already told you, I use hotwire because I don't care what the brand is. I just want a good hotel, and I use the ratings from the people who stayed. Stick around. We'll be right back.

    Hey, welcome back, everybody, Craig Peterson here on WGAN and online at Craig peterson.com. Hey, have you thought about how to follow along at home or on the road during the week? The easiest way to do that is to listen to my podcasts. Why not? I put it out there are multiple things, including this weekend show, but many other things that I include during the week, and you can subscribe to that as well on your favorite podcast platform. And it says Craig Peterson dot com slash iTunes. If you are an iTunes type of person or Craig peterson.com, slash tune in or slash I heart. Okay, I am kind of all over the place today. I appreciate everybody who does Listen to me and comments on things during the Week. You'll also find me on LinkedIn and Facebook and YouTube, but it is kind of over the place as I talk about some of the biggest stories of the week. Now we were just talking about scams that seem to be coming from Airbnb and VRBO, of course, but there is a lot of scams going one. We are going to get into one right now tied into the coronavirus. But first I just want to make mention of this other article that came out last month in January. And it's talking about computer literate millennials and Generation Z. These are the people that grew up with the internet. They've had the internet pretty much their whole lives. They found meaning the Federal Trade Commission has found that people ages 39 and under are more likely to report fraud than the 40 plus Crowd now here's the thinking. It isn't that the younger kids and millennials and Generation Z, it isn't as though they are less afraid to report that money has been stolen from them, it appears that they are more likely to fall victim to fraud 25% more likely. Now the millennials are less likely to fall for scams over the phone than people over 40, but 77% More likely, Millennials are 77% more likely to get duped by email scams and 90% more likely to lose money on a fake check scam. Now the thinking behind this is that those of us who are a little bit older, we hold the whole internet thing with a little bit more skepticism than our children and grandchildren do. Because we know that there are scammers out there. And we've heard all of the horror stories, whereas the younger kids are looking at it as well. It's the internet, and they just give their stuff away. We already know that there are studies that show that the millennials will give their email address away in trade for a single donut. Okay, so they don't value a lot of this stuff. You know, to me, well, it's a little bit concerning, and it should be to you. But let's get into the latest scam that's out there right now. It isn't the Airbnb scam, which has been out there for a few years now. As I said, hey, I've been burned what, four or five times by this overall, personally. So I'm just to the point I just don't use it anymore period. It's a real shame because there are some good people out there. But this has to do with what's been happening. Now it is happening with the Coronavirus, and this is a huge deal. We had one day this week, where 15,000 new cases were reported. Supposedly, it was due to a change in the way China was tracking the Coronavirus and diagnosing people. So they're saying, Hey, listen, it's you know is just a change. Don't expect this to indicate that more viruses are spreading out there. And frankly, I look at it and say, Well, maybe there are there aren't. But what we're seeing are some rather sophisticated phishing scams going on. Phishing, of course, this is the one spelled with a Ph. It is where an attacker tricks you into doing something. It might be clicking on a link. It might be responding to an email. It might also be a phishing scam over the phone or, you know, SMS a text one which would be called smishing. A whole new type of phishing this going on right now. Well, last week, IBM and Kaspersky now Kaspersky is a Russian anti-virus company. They are also trying to stop the general spread of malware. The State Department, the FBI, Homeland Security, not to use Kaspersky software, but they do have good information. So when I see Kaspersky, combined with IBM, a company I do respect, then that does kind of make my years and help if you will. Still, IBM and Kaspersky caught hackers in Japan, trying to spread malware through emails, and the emails had links about the Coronavirus outbreak that started, of course, in Wuhan China last month in January. Now adding Sophos and now, of course, Cisco to the list. They have found phishing emails from cybercriminals, purporting to be from the Center for Disease Control, as well as the World Health Organization. And what these bad guys are trying to do is to steal your email credentials and other information. The emails are coming from several domains, including CDC dash gov.org, which, of course, is not the real CDC website. So be very careful if you are trying to find out information about the CDC or the spread of coronavirus about flu in general. For instance, in my home state of New Hampshire, we have I think it's seven deaths so far this year reported g attribute To the flu in general, not the Coronavirus. Every year about 12 to 16,000 people in the United States die from the flu.
    So far, we've only got 14 cases reported of Coronavirus. At this stage everybody, this is nothing to get all freaky worried about. Okay, so calm down. If you want more, go to cdc.gov. CDC Centers for Disease Control - cdc.gov, tells you what to do now. The current Coronavirus has an official name now. It's called covin-19 co vi n dash 19. There are multiple versions of Coronaviruses, which is why they identify each with a number. We have had a report in the past about Coronaviruses, and they have killed people previously. So you'll see Right at the top of the cdc.gov website, information about the Coronavirus and its spread. It is a respiratory disease and potentially fatal. It doesn't seem to be increasingly more fatal than some of the other viruses that we've had. Let's put all this in context. And when you get an email from someone saying, hey, look at this, you click on this link, to get information about the Coronavirus. It's going to let you track the spread of etc. don't respond. If you get a text message, don't respond. I got one because I'm a member of the Great and Powerful media, right. I got one last week that was sent out to members of the press saying, Hey, we got this new tracking site. You just can to be cautious enough when it comes to this. So if you go to CDC Gov at the top, You'll see the description here about the covin-19. You can click on that, and it'll show you a global map about the location of reported cases and what is happening. So, I'm looking at one, and it's about one day behind. It looks like right now for covan-19. But you can see all of the countries that have been reporting it. Then you can also look at the hard statistics. People under investigation in the United States, exactly how many 14 positives, you'll see that there. Of course, it changes daily. You can see how many tested negative and how many pending, the people are under investigation. Remember, the airplane full of workers from the State Department that came back from China. They have now been under quarantine for more than 14 days. They release them all from quarantine because it turns out, nobody had that virus. So just because you have the flow doesn't mean it's Coronavirus. More cases over on the left coast and the Midwest, which is kind of surprising to me than there are on the East Coast or the Mid Atlantic, etc., etc. So have a look there. Do not respond to emails or texts or phone calls. Okay? Just be very, very careful because the hackers are imitating this sort of thing. The other side of this is they are sending out messages seeking donations. They are asking for Bitcoin donations to the World Health Organization can tell you right now, the World Health Organization, the CDC, they are not taking Bitcoin donations, okay. So don't go and donate. Right And again, the CDC gov.org is the band guys CD see.gov is the good guys. The scam page is straightforward. It, you know, took the scammers, maybe just a few minutes to put together. It's handy, and it looks legit. And the FBI and, of course, also Homeland Security are taking down these pages as soon as they can, but they can't always get rid of them right away. And companies, we've got to be proactive. We've got to chain train our employees, not to follow up on these scams. So again, that's part of the reason for my newsletters. I report on the biggest scams that are going on. I try and keep it down to just a few a week. You can share them with your employees, share them with your family, but you have to get them to share them. Go to Craig peterson.com slash subscribe, and you'll get those as well stick around. We'll be right back on WGAN.

    Hey, welcome back, everybody. Craig Peterson here on WGAN, and thanks for joining us today. Hopefully, you picked up a lot of good information. We're just talking about the CDC some of the scams that are out there right now from the Coronavirus, including one involving Bitcoin, which kind of surprised me. We talked a lot in the first hour about the major scams on Airbnb, where you can rent apartments or homes for a day or a week or a month, almost anywhere. It's really quite neat. But the major scams have been going on there and how I've seen them personally and why I will never use it ever again. If you want to listen to that, just go to Craig Peterson comm slash tune in, you can subscribe right there. Listen to me, live by the way on tune in when I'm on the radio. He And when I'm on with canon Matt, the morning drive every Wednesday at 737, every Wednesday morning, as well. And those are all on tune in. Now, we're going to talk a little bit about this whole thing with the ACLU and their current fight. I spoke about something similar to this a couple of years ago, man, maybe actually the first time was probably about ten years ago. There are companies out there, and they gather information about us. They're called Data brokers. I have visited some of these data brokers sites themselves, I mean, physical sites, where the company operates where they have their data collections, to help them with security problems that they have, and to help prevent problems from occurring, right. That's what I do for living full time. It was probably ten years ago, the radio show that I talked with some of these companies. What they do is they collect open-source information that's used a lot by the government for any number of things from financial transactions to investigations. And you can use open-source information yourself. All you do is go to Google, for instance, and do a search. That's the open-source information. It's anything that anyone can gain access to, without having to be a police officer without having to go and really kind of, you know, get a court order kind of be surreptitious and how you gather that's open source. So the data break, brokers will take all of that, and that can include depending on the state you're living, driver's license information, it can include information about the mortgage for your home. It can include you know the ownership of your home, and it can include just all kinds of stuff. That becomes very, very difficult to control. Because all of your information is out there. It's available for free or for cheap on the internet. So these data brokers, they might buy it from the county, they might get it an open-source. Some of this information will contain data from your mortgage, will contain your signature, the deed to your home is going to contain the signature, the automobiles that you own. There's going to be UCC filings with the Secretary of State's office, detailing what cars you own, who the lien holders are, and how much money is involved all of this stuff. So it all gets pulled into these databases. I mentioned on the show a few months ago, a couple of months ago that we were out in Las Vegas at a wedding and of course, you know, doing work while I'm out there and I'm sitting They're on the couch doing work for some of our Las Vegas clients. And there's a knock at the door. And who's there? Well, it's an insurance investigator investigating an accident that it was a fatal accident. And of course, the insurance company had been asked to payout. So they came to this home because they had information that it that the person involved I had a contact with someone at this address, which indeed she did. It was her sister, and apparently, the driver had been responsible for this fatal death. The driver listed one of my sisters in law. She had died about six months before the accident. So obviously, it was all fate. The insurance investigator showed my wife all of this information she had from one of these data brokers. It listed my deceased sister in law's relatives, everybody, every address she had ever had. There were names and contact information for some of my kids. However, it had a lot of incorrect information, including supposed current addresses and voting information for relatives deceased for over two decades. When I've looked at the data brokers' information about me, about half of it's correct, but the other half is completely incorrect. And that's still the case because they had a lot of completely incorrect information. People that they said were relatives that weren't people we'd never heard of before. They said these were direct relatives of hers. At any rate, they had purchased all of this information from a Data Broker. In collections, this is called a skip trace. It's called a skip trace for people who jumped bail, etc. Man, we should talk to about this whole bail thing, and the idiocy in New York state that is spreading country-wide dog, the bounty hunter and his wife, Beth had been fighting this for a long time because it's making us much, much less safe. But anyhow, that's not a topic for today's show. It's not a political topic, because it's undeniable what's already happening with the increase in the crime rate in New York anyways. What the government is doing now is what I was warning about a decade ago. That is that the federal government, the FBI, the NSA, the CIA, of the IRS, you name it, they are limited in how they can collect information, we kind of already knew that right? You know that they had to get a search warrant for certain things right. They can follow you around, without any expectation of privacy, etc., etc. So So obviously, federal government agencies can use open-source information to see what you're doing online. But how about the closed source stuff? How about this stuff that the data brokers are collecting? Some of it they're getting from the people who lent you money, some of it they're getting from places where you have to pay to get that information. So, what's happened here is that the ACLU has filed a suit, according to The Wall Street Journal, against Homeland Security. Homeland Security, through its Immigration and Customs Enforcement Agency, as well as Customs and Border Protection, is buying geolocation data from these data brokers and choosing to investigate suspects who have allegedly committed immigration violations. So let me boil all that down into plain English. You might be using games on your smartphone, and you might be using all kinds of apps on your smartphone. If you have a smartphone, frankly, you're probably not using 90 95% of those apps that you have downloaded. But many of those apps are tracking you. And that information is being sold to data brokers. So think about that for a minute. Remember that free app and how you've heard me and many others for so many years say, hey, you're not the customer. You are the product. Well, what's happening here now is that the ACLU is saying to the federal government, hey, you cannot buy the information that by law your organization cannot collect. You cannot buy it from data brokers or these app developers who are selling it. Interesting question, interesting problem, isn't it? What should they do? What should you do? What can you do? It is going to play out in court, and I suspect it's going to come down on the side of the Department of Homeland Security because this information is generally available to anyone willing to pay for it. So now the government stepped forward, saying we are will pay for it. By the way, this goes down to local law enforcement as well. In many cases, they are also buying this information from the data brokers. So let's stick around when we come back. We're going to talk about shadow IT. If you don't know what it is, it's a problem if you're in business.

    Hey, welcome back, everybody Craig Peterson here on WGAN. Thanks for joining me and for spending part of your Saturday with me. If you're listening to this on a podcast at Craig Peterson dot com slash tune in, thanks for joining me, some listen to me while they're driving to and from work and find the various segments of my show, which are about ten-ish minutes long, really work well into their day. So if you're doing that, thank you if you're not, please do consider it. I try and keep everybody up to date with the information that you need to know. And that leads us to what we got right now. Which is shadow IT. Now I bet there is not a company out there. Well, maybe there's one right because you just can't put always say or you know everyone that I say almost every company out there has a shadow IT problem. So let's start by kind of defining what's going on. Have you ever set up a company Amazon account? Have you ever set up an account for a company account for Uber? Maybe it's not a company account. Perhaps it's a personal account that you're using for Uber or something else? How about using something like Constant Contact to send out emails to your customers? How about salesforce.com? We've seen a shift over the years from what used to be kind of the glass castle where there was a central computer room in housed a mainframe. Those mainframes were truly astounding. They still are. That mainframe, in that glass room, was controlled by professional Information Technology people. People that knew what they were doing, at least at the time, right?
    Then we started seeing some changes. Do you remember the AppleII and Visicalc? Visicalc was the killer application if you wanted to do numbers. You bought an Apple, you purchased a little Apple II, and you then pull data. People were asking the professionals in the glasshouse, "can you give us data because we want to put together some spreadsheets." People put together spreadsheets without really understanding the implications and use of the numbers. Without understanding how to audit a spreadsheet and to make sure that the numbers used got correctly used. They didn't understand the double journaling. They didn't understand the cross-referencing of the information. That started a bit of a movement away from that glass house and the hassle from it. They said, Hey, we can figure this out. Why are we going to pay it all of this fake budget money to do something for us, and we can do it for ourselves and do it cheaper. Frankly, that's a problem I still face with many organizations, if you can believe it. Many think they can do security themselves, which by the way, is near impossible for almost any organization. In this day and age, any small-medium business must have full-time external professionals who are helping your internal IT people. Your internal IT should be doing what they do best, which is helping your business best use information technology, assisting people to be more efficient, finding new ways of doing things, etc. Instead of that, most businesses set up these various silos, like sales and marketing or accounting, and each one of those silos, those lines of business do things their way.
    The sales guys, they're out, and they said, Hey, we're going to use Salesforce. We're going to tie that into Constant Contact. Then you have your accounting people saying we're going to use QuickBooks Online or maybe one of Oracle's accounting systems. The manufacturing people say, Well, we are going to use this particular ERP program, which is going to be great for manufacturing. We've decided that we're going to use Survey Monkey to collect information from our customers from our vendors. Do you see where I'm going? Each one of these lines of business is going out and making what are in actuality Information Technology decisions. They're making decisions about what type of technology to use. Which is one level, but then the next level is they're using it. They're putting the business's information at risk
    It is a huge, huge problem. And it's something that I'll be addressing with some of this training that I have coming up, and a couple of these tutorials specifically tackle these problems. And so if you're on my email list at Craig Peterson comm slash subscribe, you're going to find out about these, and I'm going to give you some great cheat sheets and other things. But all of those again, Craig peterson.com slash subscribe. All of those different lines of business, all of those different functional responsibilities within an organization larger small, are adding up and adding up massively. There is an enormous problem behind this. Now you know that I use one password, I recommend it. And we typically use one password in conjunction with do to help secure login information. But because one password is used so frequently by companies to keep track of logins, they have kind of a unique view into the risks of all these different accounts. And what we're talking about where these lines of business are making Information Technology decisions that they're not qualified to make, and frankly, in most small, medium businesses, there's probably no one in the organization that's fully qualified. Still, at least it has a better idea, but then, a marketing person or an accounting person would have. So this is called shadow IT, and new one password research is showing the risks behind it. And they surveyed 2100 us adults working In an office that has an IT department, now, almost everybody uses a computer for work, right. And so these 2100 that they looked at all use computers at work. And they found that two-thirds of the respondents have created at least one account in the past 12 months, that their IT department doesn't audit. But it's worse than that. It's not only that the IT department hasn't looked at the account. They have not vetted the company behind it to make sure that they conform to the regulatory security standards required for the company. In fact, in two-thirds of the cases, the IT department doesn't even know that user accounts were created and are in use accessing company information. So one of the things when we go in, remember I mentioned earlier that we kind of try and nurse a company back to health. Getting their security, health, and IT on track. What we'll do when we go in is we will start auditing the shadow IT accounts. What are people using? Whether it's a Dropbox account or you know, a photo-sharing site, whatever it is, what are they using? There are some fascinating statistics here that are coming out of one password. Only two and a half percent of the people surveyed. Two and a half percent of the respondents said that they use a unique password every time! Even the most basic of security precautions are not in use by people who are creating accounts on third-party websites. Isn't that amazing? And They're putting company information up on some of those websites. I'm going to make a note of this right now because frankly, it is scary to me to think about this. Maybe we'll try and do a Facebook Live, or try and do a YouTube Live and let you guys ask questions live there. Let me see I want to put that in here so that I'm less likely to forget about it. Alright, noted. So stick around. We're going to do a wrap up when we get back. Couple more stories from this week all of that right here. Thanks for being with us. I am Craig Peterson, and we'll be right back on WGAN. And of course, online as always 24 seven, hopefully at Craig Peterson dot com stick around, because we'll be right back.

    Hi guys, Craig Peterson, here back on WGAN Thanks for joining me. If you're listening to one of my podcasts, thank you very much as well. We've got a lot going on. I have not been producing as much content or shown up as much on Facebook Lives, or YouTube lives, lately, because I've just been so busy with my team here putting together some great tutorials. You are going to love these also we are working on some course materials. You can only get that if you are on my email list. Craig Peterson, dot com slash subscribe. I'm not one of those guys who is sending you emails every day — trying to get you to buy something. I want you to understand what's going on. And if I am in the process of releasing free tutorials, or even paid courses you might get well, you will get more emails from me because I don't want you to miss those things. But this isn't one of those things. We're going to get a constant stream of emails from me. I'm not going to overload you. But again, Craig Peterson, dot com slash subscribe, so that you don't miss out because you will miss some critical stuff. And some training you won't get anywhere else guaranteed. So earlier in the show today, in fact, the first hour I spent talking about these scams from Airbnb, they are horrific. And I told you about some of my own stories, all of them bad, some of them quite literally horror stories. And I really would love it if you would listen to them so that you can find out what I do to book and now when I'm going somewhere, and I need a place to stay.
    I also talked about the ACLU it's fighting against the Department of Homeland Security's new effort here to try and track people through their smartphones using information that any company out there can get about you. Okay. So I'm not sure that this is good or bad, because I don't think anybody should be tracking us. But that's an entirely separate issue, right? How shadow it could put your organization at risk is what we were just talking about a huge deal. I went through some scams that are going on right now surrounding the coronavirus and how they're getting money from people and hacking people through them. And I want to talk right now about the FBI investigations that are going on. I know over the last couple of weeks, I've helped the FBI open a couple of investigations, because of some real hacking that's been going on from Iran, from China, from Russia against small businesses. These are companies that have said to me before, literally, no, I'm too small - Why would anybody care? Well, they do care because it's a foothold. They care because you have intellectual property, they want to steal. US intellectual property that might help them if they're ever in a kinetic war with us, or even if they're just in a cyberwar with us, right. What they want to do is hurt our economy. What they want to do is shut us down. And what are the best ways to do that? Well, let me tell you a China does know they are indeed experts at some of this stuff. So the FBI is in the process right now. And according to the future, really cyber warfare and the future of technology. According to ZDnet, there can now be millions, maybe even billions of dollars at risk by not properly handling information security. And to me, this is a horrifying thing, because I see it every day.
    I know, there are some people out there that are saying, Craig, you're not going to talk about it again. Look at what my conversations with Ken and Matt this week. I asked them if they're using password managers, which is, as I mentioned, the last segment, the essential thing you can do with cybersecurity. And you know what their answer was? No. No, well, and the statistic we just saw, where they're not using unique passwords, only two and a half percent using unique passwords on the website, again, an essential thing you can do, and about 98% of those who responded to this poll. We're not doing it.
    So there was a conference last week in Washington on the topic of Chinese adventure. Structural property from us tech firms, as well as the academic sector. And we've spoken about both of those before. Because there have been so many problems, right? Where the academic sector, they are stealing our ideas before they even become businesses, and they're going into businesses. They're working in our universities in conjunction with the Department of Defense. They're just getting so much information. But some of the highest officials from the FBI, the Department of Justice, spend their time about four hours they were given at this conference, raising a sign of alarm, putting the private academic sector on alert about the threats that they are currently facing over ID theft. It's a very, very big deal that deeply concerns me, and it should concern you too. The Feds are worried about China in particular. Now, as I mentioned, we see right now, and we help the FBI open some investigations into actual Iranian hacking going on, which we've never seen before. My company hasn't ever seen it. But we always see Russian and Chinese. That's just ongoing. Right. But according to John DeMars, the Assistant Attorney General for national security, who opened the conference, said the threat from China is real. It's persistent. It's well-orchestrated, it's well resourced, and it's not going away anytime soon. The FBI director said the cases have been filing up since 2018, which is when the Department of Justice launched the China initiative program, where they started to try and counter as well as investigate Beijing's economic espionage. So here's a quote from him. The FBI has about 1000 investigations involving China's attempted theft of US-based technology in all 56 of our field offices, offices, and spanning just about every industry in sector. That's from director Ray. And some of those thousand are through us through your host through me. Because I have seen them trying to get into I mean directly into and succeeding, getting into some of our clients now, they weren't clients, when the Chinese succeeded in getting through. We cleaned up the mess after the fact its part of what we do at mainstream where we are trying to nurse our newer clients back to health, okay, but I've had a part of this thousand, Believe me, I know what I'm talking about here. And that's why I am just focusing on this so much lately. You know, I used to do, my radio show is mostly about commercial or consumer stuff, just Basic, oh, isn't this a cool new gadget and I still do some of that, right? You've heard me talking about that. But now I end up spending a lot of time talking about cybersecurity because I think everybody needs to understand this a little bit better. But this article is up on my website. As I said, Assam Zd net, it just goes through the details here, what they're doing the business partnerships, investigations The FBI is doing in China is rewarding IP theft. They're encouraging it. quote here from Adam Hickey as Deputy Assistant Attorney General, there are certainly a lot of cases where we don't have evidence beyond a reasonable doubt that the Chinese government has procured or sponsored the theft. But we see patterns with theft rewarded after the fact. They've got a whole structure set up to encourage industrial espionage. We know that's been also happening in Russia. We have seen some of the Russian stuff. The entire Skolkovo project that the Clintons were involved in that they got millions of dollars from was aimed at stealing hypersonic missile technology from the United States. The Russians were able to do through the Skolkovo project, and now can shoot down some of our non-hypersonic cruise missiles, thanks to the technology that they stole directly from us through industrial espionage. And with the help of the United States State Department. Now, that's not the current state department. That's when Hillary Clinton was in charge of it. Okay, man, we could go back. We can go back anyways.
    insiders are also playing a big role. That's why you've got to be careful about the hires from the universities. Okay. These Chinese hackers aren't acting alone. anymore. They're using all kinds of insiders, including useful idiots, which is what they call them. Do you remember that in Homeland? The show Homeland, which has, I think there's their last season is out right now. It's just starting over on Showtime, a phenomenal series by the way. I enjoyed it. In one of the episodes, a US senator, who was fighting some of the legislation that the Feds were trying to push through, found a wall with names and pictures. Under his name was the label UI under his name by the bad guys. When he saw it, He asked, "What does this UI under my name mean?" Upon where he was told, it stands for Useful Idiot because he was an idiot. We've seen that so many times with people in Congress and the Senate. Our representatives. don't understand this stuff. We've seen it so many times, with business owners who just don't understand it, how much at risk they are, and then once the They're hacked. their businesses are over. They are gone. How many times do we talk about that anyway? I'm, I guess I'm kind of lecturing now. cross that line. Yeah, I get it. Right. But we've got to be making people aware of what's happening there. Multiple CEO summits meeting with academics across the US. I've been thinking about maybe trying to put together some summits, here, a virtual summit as well as real summit. We're probably going to try and do that this fall, but certainly by the end of this year. Because we have to help CEOs and everybody else understand what's the risk, why is it a risk? What should we be doing about it? Okay. It is all stuff you need to understand. All right. Well, I hope you enjoyed today's show. I hope that you got something out of it more than anything else, or electronic technology we're using for a lecture. I talked about this week, and I was on TV talking about that on the radio talking about that. Hopefully, you caught some of those interviews. You can catch most of it. I don't have it up yet. I got to get it up over on Craig peterson.com. We try and include it as well. In our weekly newsletters, try and keep you up to date. Use it for training in your organization, whether it's a business, whether you're just sharing it with family, but you're going to get all of that from me, just by subscribing to my free newsletter. It is information-packed. Okay, if anything to complain about, it said there might be a little too much information sometimes. But I want to get it into your hands. Subscribe now. Craig Peterson calm slash subscribe. I am not going to be scamming you spam you or anything else. Thanks for joining me today. I'll be back Wednesday morning with cannon Matt at 730. You're listening to Craig Peterson

    Transcription by otter.ai

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 31 min
  • Welcome! Rampant Intellectual Property Theft by China, Scams - Airbnb, VRBO and CoronaVirus Phishing, ACLU and DHS and more on Tech Talk with Craig Peterson on WGAN

    Welcome!  

    Today there is a ton of stuff going on in the world of Technology and we are going to hit a number of topics today. There are some scams that are getting more and more prevalent with Airbnb and VRBO that we will talk about. Also, phishing scams using the Coronavirus as a way to trick you into clicking.  The ACLU is filing suit against DHS. China is stealing our Intellectual Property.  Shadow IT becoming more and more of a problem and even more on Tech Talk With Craig Peterson today on WGAN.  It is a busy show -- so stay tuned.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Related Articles:

    Is it possible to secure our Elections using Technology

    The security mistakes made by the Iowa Democratic Party in creating their App

    Coronavirus bringing out opportunistic Hackers  

    Extensive US Intellectual Property theft by Chinese being investigated by FBI 

    Scammers have found a fertile field in Airbnb

    DHS wants to track illegal aliens using available cell-phone location data. ACLU says Whoa! 

    Shadow-IT: Employees putting Business at Risk

    Ransomware rings adapt to business declarations by Revealing Stolen Data

    ---

    Machine Automated Transcript:

    Hey everybody, welcome, welcome. Craig Peterson here on WGIR, you can also hear me every Monday morning at 737 with Jack Heath, where we discuss some of the latest topics in technology. Of course, nowadays, you can't talk about technology without security, which is what I've been doing in my business now for about 30 years. I was coerced into it. Maybe one of these days, I'll share that whole story with you. It can get to be kind of a long one. But today we are going through some of the problems that I've seen out there lately. I have on my podcast this week that you can get at Craig peterson.com slash Iheart, Craig peterson.com slash Iheart. I spent quite a bit of time talking about recent problems people have been finding with Airbnb with VRBO, and I go through some of the problems I recently have had with both of those services. And I think it's well worth listening to because I've gotten to the point right now where I will not use either Airbnb or VRBO, I don't think ever again. My experiences with them have just been so overwhelmingly negative, anyhow you'll find that online, and you can subscribe there as well at Craig peterson.com slash I heart. That like is going to take you to the I heart app. You might be listening to me right now, in fact, on Iheart streaming on these AM and FM stations. If you are, kudos to you, but you can also get all of my content by going and subscribing, Craig peterson.com slash I heart, and I'm also on every other major podcast streaming platform that's out there. But first, I just want to make mention of this other article that came out last month in January. It's talking about computer literate millennials and Generation Z. These are the people that grew up with the internet. They've had the internet pretty much their whole lives. They've found meaning the Federal Trade Commission found that people ages 39 and under are more likely to report fraud than the 40 plus crowd. Now, here's the thinking here. It isn't that the younger kids millennials and Generation Z, it isn't as though they are less afraid to report that money stolen from them. It appears that they are more likely to fall victim to fraud. 25% more likely. Now the millennials are less likely to fall for a scam over the phone and people over 40, but 77% More likely, Millennials are 77% more likely to get duped by email scams and 90% more likely to lose money on a fake check scam. Now, the thinking behind this is that those of us who are a little bit older, we hold the whole internet thing with a little bit more skepticism than our children and grandchildren do. Because we know that there are scammers out there and we've heard all the horror stories, whereas the younger kids are looking at it as well. It's the internet, and they just give their stuff away. We already know that there are studies that show that the millennials will give their email address or weigh in trade for a single donut. Okay. They don't value a lot of this stuff. And, you know, to me, well, it's a little bit concerning, and it should be to you. But let's get into the latest scam that's out there right now. It isn't the Airbnb scam, which has been out there for a few years now. As I said, hey, I've been burned, what, four or five times by this overall personally. I am jaded, and I just don't use it anymore period. It's a real shame because there are some good people out there. But this has to do with what's been happening with the Coronavirus. It is a huge deal. We had one day this week, where 15,000 new cases were reported. The Chinese changed how they tracked and diagnosed cases. So they're saying hey, listen, it's you know, it's Change. Don't expect this to indicate that more viruses are spreading out there. And frankly, I look at it and say, Well, maybe there are there aren't. But what we're seeing are some rather sophisticated phishing scams going on. Phishing, of course, this is the one spelled with a Ph. It is where an attacker tricks you into doing something. It might be
    clicking a link. It might be responding to an email. It might also be a phishing scam over the phone or, you know, SMS a text one which is called smishing. A whole new type of phishing this going on right now. Well, last week, IBM and Kaspersky now Kaspersky is an anti-virus company. They are also trying to stop the general spread of malware. They are a Russian firm, and the State Department and FBI have warned us about using their software, but they do have good information. When I see Kaspersky combined with IBM, a company I do respect, then that does kind of make my ears stand up, if you will. IBM and Kaspersky caught hackers in Japan, trying to spread malware through emails. And the emails had links about the coronavirus outbreak that started Of course and won China last month in January. And now adding cell phones to the list. Of course, Cisco, to the list, they have found phishing emails from cybercriminals, purporting to be from the Center for Disease Control, as well as the World Health Organization and what they're trying to do the bad guys his deal your email credentials and other information. The emails are coming from several domains, including CDC dash gov.org, which, of course, is not the real CDC website. So be very careful if you are trying to find out information about the CDC, or about the spread of Coronavirus about flu in general. For instance, in my home state of New Hampshire, we have I think it's seven deaths so far this year reported g attributed to the flu in general, not the Coronavirus. Every year about 12 to 16,000 people in the United States die from the flu. So far we've only got 14 cases reported of Coronavirus So, at this stage everybody, this is nothing to get all freaky worried about. Okay, so calm down. If you want more, go to CDC.gov. CDC Centers for Disease Control cdc.gov. And it tells you what to do now this Coronavirus has an official name now it's called Covin-19, co vi d dash 19 because there are multiple versions of Coronaviruses and viruses. And we have had a report in the past about Coronaviruses, and they have killed people previously. So you'll see right at the top of the CDC, gov website, information about the Coronavirus and it spread. It is a respiratory disease. It is potentially fatal. It doesn't seem to be any more fatal than some of the other viruses that we've had. So let's put all of this in context. And when you get an email from someone saying hey, Look at this, click on this link, it's going to get you information about the Coronavirus, it's going to let you track the spread of, etc. don't respond. And you, if you get a text message, don't respond. I got one because I'm a member of the Great and Powerful media, right. I got one last week that was sent out to members of the media saying, Hey, we got this new tracking site. You just can't be cautious enough when it comes to this. So if you go to CDC Gov at the top, you'll see the description here about the Covin-19. And you can click on that, and it'll show you a global map about where it has been reported what is happening. I'm looking at one. It's about one day behind it looks like right now for Covin-19. But you can see all of the countries that have been reporting it and then you can also So look at the hard statistics. People under investigation in the United States exactly how many 14 positives you'll see that there. Of course, it changes daily. How many negative how many pending? The people are under investigation. Remember, the airplane full of workers from the State Department that came back from China. They have now been under quarantine for more than 14 days. They released them all from quarantine because it turns out that nobody had that virus, so just because you have the flow doesn't mean it's Coronavirus. More cases over on the left coast and the Midwest, which is kind of surprising to me than there are on the East Coast or the Mid Atlantic, etc., etc. So have a look there. Do not respond to emails or texts or phone calls. Okay. Just be very, very careful. Hackers are imitating this sort of thing. Then the other side of this is they are sending out messages, seeking donations, and they're asking for Bitcoin donations to the World Health Organization. I can tell you right now, the World Health Organization, the CDC, they are not taking Bitcoin donations, okay? Don't go and donate, right. Again the CDC gov.org is the bad guys cdc.gov is the good guys. The scam page is elementary. it might have taken the scammers just a few minutes to put together. It's very effective. It looks legit. And the FBI and, of course, also Homeland Security are taking down these pages as soon as they can, but they can't always get rid of them right away. And companies we got to be proud. We've got a chain, train our employees not to follow up on these scams. So again, that's part of why I publish my newsletters. I report on the biggest scams that are going on. I try and keep it down to just a few a week. You can share them with your employees, share them with your family, but you have to get them to share them. Go to Craig peterson.com slash subscribe. Now, we're going to talk a little bit about this whole thing with the ACLU and their current fight. I spoke about something similar to this a couple of years ago, man, maybe actually the first time was probably about ten years ago. There are companies out there, and they gather information about us. They're called Data brokers. And I have visited some of these data brokers sites themselves. I mean physical site, where the company operates where they have their data collections, to help them with security problems that they have. And to help prevent problems from occurring, right. That's what I do for a living full time. And it was probably ten years ago, the radio show that I talked with some of these companies. But what they do is they take what's called open source information that's used a lot by government or investigations. And you can use open-source information yourself. All you do is go to Google, for instance, and do a search. That's the open-source information. It's anything that anyone can gain access to, without having to be a police officer without having to go and really kind of, you know, get a court order kind of be surreptitious and how you gather that's open source. So the data break brokers will take all of that, and that can include depending on States your living driver's license information. It can include information about the mortgage for your home. It can include you know the ownership of your home, and it can include just all kinds of stuff. And that becomes very, very difficult to control. Because all of your information is out there. It's available for free or for cheap on the internet. So these data brokers, they might buy it from the county, they might get it an open-source. Some of these documents are going to contain like your mortgage is going to contain your signature. The deed to your home is going to contain the signature, the automobiles that you own. There's going to be UCC filings with the Secretary of State's office, detailing what cars you own, who the lien holders are, and how much money is involved, all of this stuff. So it all gets pulled into these days. databases I mentioned on the show a few months ago, a couple of months ago that we were out in Las Vegas at a wedding. And of course, you know, doing work while I'm out there sitting on the couch, doing work for some of our Las Vegas clients when there was a knock at the door. Who's there? Well, it's an insurance investigator investigating an accident that had a fatality. And of course, the insurance company had been asked to payout.
    They came to this home because they had information that the person involved had contact with someone at this address, which indeed she did. It was her sister, and the driver had been responsible for this fake fatal death. The driver listed was one of my sisters in law, who had died six months before the accident. It was all fake. The insurance investigator showed my wife all of this information she had that they had purchased from one of these data brokers. It had listed my deceased sister in law's relatives, everybody every address she had ever had. It had names and contact information for some of my kids as well. Now, it was not all correct or organized. When I've looked at the data brokers' information about me, only about half of it is right, but the other half is entirely incorrect. That's still the case because they had a lot of utterly false information. People that they said were relatives that weren't. People we'd never heard of before, they identified as direct relatives of hers. The insurance company purchased all of this information from a Data Broker, in collections, this is called a skip trace. It's called a skip trace for people who jumped bail, etc. Man, we should talk about this whole bail thing, and the idiocy and New York state that is spreading countrywide dog, the bounty hunter and his wife Beth had been fighting this for a long time because it's making us much, much less safe. But anyhow, that's not a topic for today's show. It's not a political topic, because it's undeniable what's already happening with the increase in the crime rate, New York anyways. What the government is doing now and this is part of what I was warning about a decade ago, is the federal government, the FBI, the NSA, the CIA, of the IRS, you name it. They are limited in how they can collect information, we kind of already knew that, right? They knew that they had to get a search warrant for certain things, right? They can follow you around if you do not expect privacy, etc., etc. So obviously, federal government agencies can use open-source information to see what you're doing online. But how about the closed source stuff? How about this information that the data brokers are collecting? Some of it comes from the people who lent you money. Some of it they're getting from places where you have to pay to get that information. What's happened here now is that the ACLU has filed a suit, according to The Wall Street Journal, against Homeland Security and Homeland Security through its Immigration and Customs Enforcement Agency. As well as Customs and Border Protection, is buying Gilo geolocation data from these data brokers. It's using it to investigate suspects who have allegedly committed immigration violations. So let me boil all that down into plain English.
    You might be using games on your smartphone, and you might be using all kinds of apps on your smartphone. If you have a smartphone, you probably are, frankly, not using 90-95% of those apps that you have downloaded. But many of those apps are tracking you. And that information is being sold to data brokers. So think about that for a minute. Remember that free app and how you've heard me and many others for so many years. Say, hey, you're not the customer. You are the product. But what's happening here now is that the ACLU is saying to the federal government, hey, you cannot, you cannot buy this information that you are not allowed to collect yourself. You cannot buy it from data brokers or these app developers who are selling it. Interesting question, interesting problem, isn't it? What should they do? What should you do? What can you do?
    It is going to play out in court. I suspect it's going to come down on the side of the Department of Homeland Security because this information is generally available to anyone willing to pay for it. So now the government stepped forward, saying we are will pay for it. By the way, it's down to local law enforcement as well, who, in many cases, are also buying information from the data brokers. Have you ever set up a company Amazon account? Have you ever set up an account for a company account for Uber? Maybe it's not a company account. Perhaps it's your account that you're using for Uber or something else? How about using something like Constant Contact to send out emails to your customers? How about salesforce.com, where we've seen a shift over the years from what used to be kind of the glass castle, where you had a central computer room in that computer room was a mainframe. And those mainframes were astounding. They still are. And that mainframe in that glass room was controlled by professional Information Technology people, people that knew what they were doing at least at the time, right? Then we started seeing some changes. You remember the apple two and VisiCalc Visicalc was kind of the killer application. And if you wanted to do numbers, then you bought an apple, you purchased a little apple two. And you then pulled data and people were asking that glass house, they were asking it, Hey, can you give us data because we want to put together some spreadsheet. People put together spreadsheets without really understanding the implications of the numbers they were using without understanding how to audit a spreadsheet to make sure that the figures included were correct. They didn't understand the double journaling. They didn't understand the cross-referencing of the information. They started a bit of a movement away from that glass house from that glass castle from it. They said hey, we could figure this out, why are we going to pay it all of this fake budget money to do something for us and we can do it for ourselves and do it cheaper. Frankly, that's a problem I still face with many organizations, if you can believe it, who think they can do security themselves, which is impossible for almost any organization. In this day and age, any small-medium business must have full-time external professionals who are helping your internal IT people. The internal IT should be doing what they do best, which is helping your business use information technology, to its best use, assisting people to be more efficient, finding new ways of doing things, etc. Instead of that, what most businesses do is they have these various silos, like sales and marketing and accounting. And each one of those silos, those lines company does things their way. So the sales guys, they're out, and they said, Hey, we're going to use Salesforce. And we're going to tie that into Constant Contact. And then you have your accounting people saying, well, we're going to use QuickBooks Online. Or maybe they're going to use one of Oracle's accounting systems. And then the manufacturing people say, Well, we are going to use this particular era p program, which is going to be great for manufacturing. And we've decided that we're going to use Survey Monkey to collect information from our customers from our vendors. You see where I'm going, each one of these lines of business is going out there and making what are in actuality, information technology decisions. They're making decisions about what type of technology to use, which is one level, but then the next Next Level is they're using it. And they're putting the business's information at risk. It is a huge, huge problem. It's something that I'm going to be addressing with some of this training that I have coming up with a couple of these tutorials correctly tackle these problems. And so if you're on my email list at Craig Peterson comm slash subscribe, you're going to find out about these, and I'm going to give you some great cheat sheets and other things. But all of those again, Craig peterson.com slash subscribe.
    All of those different lines of business, all of those different functional responsibilities within an organization larger small, are adding up and adding up hugely. And there is a massive problem behind this. Now you know, that I use one password, and I recommend it, and we typically Use one password in conjunction with Duo to help secure login information. But because one password is used so frequently by companies to keep track of logins, they have kind of a unique view into the risks of all these different accounts. And what we're talking about where these lines of business are making Information Technology decisions that they're not qualified to make, and frankly, in most small-medium companies, there's probably no one in the organization that's fully qualified. Still, at least it has a better idea, but then a marketing person or an accounting person would have. So this is called shadow it and it's absolutely something that we have to be careful of and we have to watch for and if you are one of these people who is using one of these third-party services, and you have not informed your IT person. Do it right now. All right, thanks. Okay, hey, we have a lot more content that you can get online. Just go to Craig Peters on.com. You'll find it right there in my weekly newsletter that you can use to help educate other people inside your company. Maybe family, maybe friends, and indeed, educate yourself and the things that you need to know security-related or just the newest and latest greatest technology. Now I got an email here just while was Facebook a couple of weeks ago a message about a story that I had reported on about Tesla before, and I try and answer those I dig them up I get them for you. But I want to make sure you are subscribed at Craig Peterson comm slash subscribe, so you get all of that. Thanks for being with me here, WGIR, and we'll be back Monday morning with Jack Heath at 737.

    Hey, welcome back Craig Peterson here on WGAN and online Of course, Craig peterson.com. If you want to, you can subscribe to my email list you'll find out about the free tutorials that pop up training, courses, everything that I do to help make you and your business more secure. So again, Craig Peterson, dot com slash subscribe. I got to read this to you right now. I decided to cancel through Airbnb and tell them about what had happened. He went off at me, berated me for not handling in it privately, and told me I was acting in my self-interest, and belittled me. I ended up having to pay the first full month even though I stayed one night. His listing is still up, and a review posted after my state also mentioned the silverfish. Isn't that something? Now, this is from a report that came out from vice. Now you might be familiar with vice.com. There's a lot of decent stuff up there. But I want to tell you a little bit about my own experience I've had with Airbnb and VR Bo now VR Bo is vacation rentals. It's it has been used more, I think, by businesses from what the stuff I've read than it is by individuals. But I have had bad experiences with both of them. Every time I have had an Airbnb, I have had a bad experience. So let me tell you what I mean by a bad experience. For instance, I was out of Vegas at a conference, and we thought, you know what, let's try Airbnb. I'm the tech guy, right? I need to understand this. Why wouldn't I go ahead and use Airbnb in make sense, right? So here the tech guy goes, and we poke around read reviews we read ratings. We found an apartment, not far at all, I mean like half a mile from the convention center. We thought, okay, this is going to be perfect. It says it's right by the strip we could walk over there, hop a cab or, or grab a ride and enjoy The Strip, and then the morning we can just walk over the convention center. We're not going to have any problems parking because it said it is an apartment. Let me start with parking. By the way, parking is another thing in the second Airbnb story. There was no parking. You had to park a half a mile away sometimes because people were just parking in the parking lot of the apartment building. There were no reserved parking slots for the apartment. So there's number one — number two. When we go into the apartment, and it's quite nice. We find out that it has two bedrooms. We had only booked one bedroom because that's all the listing talked about the one-bedroom.
    We get there, and we find, okay, so this is our bedroom over here. Well, the bedroom did not have an ensuite bathroom. The bathroom for the bedroom was across the hall. So there we go, we get in there and okay, fine. So our bathrooms across the hall, and we end up going to bed. We enjoyed it was a nice place relatively clean, quite old. It was probably a 40-50-year-old apartment. In the layout that you would expect there in the southwest where there's kind of a courtyard in the middle, and it's a little two-story thing and, you know, kind of reminded me when I lived in LA back in about 1980 late 70s early 80s. You know it's that part was quite nice. You know brand new shag rug in there, well you know not brand-new but quite new and clean. That part result was good. We go to bed and then we there we hear just tons of commotion because somebody else who didn't speak English very well had come to stay at the apartment as well. We hear them going into our bathroom, using our towels. They are very, very loud talking on the phone, and they get a hold of the owner right of this Airbnb. They got the same impression we did, which is there's one-bedroom in this place. So they had an ensuite bathroom. We did not, but they were using our bathroom the whole time and our towels, there's only one set of towels. It wasn't a great experience at all. They kept us up for quite a while because they were just so loud. Now you know me, I'm not an outgoing guy. You might not believe that, but I'm a little bit of an introvert. And as an introvert, I didn't want to go out and confront these people who were I'm guessing, or you know, from Asia, they were speaking Chinese or Korean or Japanese, I have no idea. I just didn't want to mess with it. So we get up in the morning, we and everything is okay-ish. We go to the conference and then that night, I guess these people only there for one night. That night, we had the whole place to ourselves, which is okay. Knowing that with Airbnb, I rate the place after I stay there, but the owner of the place rates me and so there have been a lot of issues of retaliation when it comes to Airbnb. If you stay at one of these places and you don't give them this glowing five-star review, then you're not going to get reviewed while and other people might not want you to stay at their place. So I gave it a reasonable rating. I can't remember what I gave it, you know, places clean and, and, you know, it was a nice place and there is another bedroom. You know, just kind of hint into anybody reading this. It isn't going to be dedicated to you and maybe your loved one you're staying with and left it at that. That's my first Airbnb story. And then my second Airbnb story, as I mentioned, had a lot to do with parking as well. And in this case, it was in the Toronto area, up in Brampton, and we rented a place on Airbnb, you know, I figured, well, we'll give another chance, see what happens. It was a three-bedroom place, and they said it sleeps like eight or something like that. What you did if you include the fold-out couch, and so we figured, okay, we need some parking. So I had sent them a message saying, hey, it's going to be myself and a couple of my kids and some grandkids. You know, I want to make sure that there's plenty of parking. Is it? Oh, yeah, plenty of parking, buddy parking, no problem. And so we get there, and there is one parking spot. And it's in one of these. I don't know if you know much about Canada and how they build their housing there. But one of the reasons I'm not that fond of it, right. I grew up there. It was these townhouses that are built right on top of each other, you know, the zero property line homes there. Three, four, or five of them attached. The only place you can park is in the little garage place. Well, the garage itself was full of stinking
    trash. Who knows how long it had been there. You couldn't use the garage. It had hared the driveway with the condo next door to you. It had one parking spot. I had my car, my daughter's car for her, her husband, and a couple of her kids. And then one of my other kids also drove up there. We had to find a place to park. Now the good news was that the whole neighborhood was under construction. They were able to park in the mud. in one area where construction wasn't happening right then, of course, the next morning, what shows up big dump trucks, excavators, everything else to work across the street from us. That wasn't fun. Let me tell you that it was not fun. We were quite worried about our cars, with all of this heavy equipment on this little narrow street designed for one car to go down the street when cars park on the street. We have to go right now when we come back, and I'm going to finish what happened with my air mean being being being a story, as well as my VR Bo story. And we got a whole lot more to cover. We're going to get into this Homeland Security thing with the ACLU and more but stick around, listening to Craig Peterson a course on WGAN online at Greg Peterson dot com is where you'll find me. Make sure you subscribe so that you get all of my free tutorials, training courses. Everything, Craig Peterson dot com, stick around.

    Hey, welcome back. Craig Peterson here on WGAN and of course online, at Craig Peterson dot com. I was in the middle of telling you my stories about Airbnb. If you have ever thought about staying at Airbnb, or VRBO, or any of these types of places, right, obviously you're not staying at a website, but you're booking through a website, somebody's home, somebody's rental, whatever it might be then this is for you. I have done it for personal reasons. I have done it for business reasons as well. I told you the beginning of my story in Toronto, and I told you the last segment about my story in Las Vegas. We didn't have the parking, and the kids are all worried, and I was concerned about our cars getting destroyed by the heavy equipment. Were we going to have to move them because they were working on the lots across the street? It's incredible how fast the housing is going up there and how expensive it is to it's, it's just not how pricey it is. We get inside the place. Now, remember, I said that the garage was full of trash which was, and it stunk to high heaven, which it did. Okay, so some of that leaks into the house, which makes the house kind of smell too, which is just plain old, no fun. We get into the house, and I go and sit on this folding couch. And remember, the house is supposed to sleep eight, and it has a fold-out sofa. I sit on the couch. It reeks of BO, body odor. Right? I mean reeks.
    One of the first things I have to do is I want to make sure that they know that this is a problem so that maybe they can take care of it. I call, and I don't get any answer because it's the weekend, right? Nobody's around. We head out to the local grocery store, and we get some odor killer stuff, and we bring it back, and we drench the couch in it. And we're able to get rid of most of the BO you know, and its underarm smell is what it is. Someone with some nasty underarm odor was sitting on that couch. They put their arm up on the back of the sofa and left all of their BO behind them. Then they did the same thing on the couch itself and somebody supposed to sleep there, right?
    Oh, it was just incredible. Then we go upstairs and upstairs that we noticed that the fire alarms had tape all around the sides of them. Now, if you're not familiar with the way firearm alarms work, they have to be able to have air flowing through them to sense that There's smoke in the air or carbon dioxide, carbon monoxide, whatever the type of detector is. And it had been it had tape all around it. Now it looked like it was painters tape right that blue tape that you use as you can pull off that isn't going to leave residue behind. So maybe it was the painters perhaps it was the owners, I don't know, perhaps it was a previous occupant, but I warned them about that as well as saying hey listen, your fire alarms are not going to work because it blocks the airflow on the fire alarms by this tape that's on them. I never got a response on anything there. So what do I do when it's time to leave a review? Well, I said the place was in perfect shape. It's brand new. I had to do a little bit of cleaning. The cleaning crew in because the carpets upstairs all had the markings of a, you know, a vacuum cleaner. You can see the wheel marks on the floor and everything else. So you see it's not as though a rip them a new one like I have seen done before. And you never get to see your ratings by the way from these Airbnb owners. Okay, so there's a second one not neither one of mine were nightmares per se, but they both had significant problems that I was afraid to report on because I know that turnabout is considered fair play and who knows what these owners are going to say.
    Then I tried a VRBO, but they are older. They've been around for something like 30 years, and it's vacation rental type stuff, right? So VRBO, okay, we'll try it out. So we try it. We booked a place, and I wrote to the owners. Hey, there's we're going to have three cars, or two cars can't remember what it was now. Is this going to work for us this okay, I want to make sure this parking is I've had issues before? I never got a response from them. But, you know, they ran my credit card through so I figured, okay, well at least that part is done. I show up with the family in tow. And we're going to have this great time together. I'm going to be working, and they can stay in and just enjoy the place you know, a new city, a new location is going to be great. Guess what? VRBO had canceled my reservation without telling me without informing me, without crediting me. Well, it turned out that they didn't end up crediting me after all the credit card, but here I am waiting for the place that I can't get in. I called up VRBO to say, Listen, I never got a code for the door or anything else. What should I do here?
    Oh, no. Well, I see that reservation was canceled. I never canceled the reservation. Oh, no, sir. It was canceled, like the day after you booked it. I said, wait a minute. I never canceled it. Well, okay. Well, then the owner must have canceled. Why didn't I get notified? Oh, you didn't get notified, sir? Really? It says they sent an email. I went through all my junk mailboxes and everything else and yep. Okay. I got a notice of cancellation. Oh, man, what a pain that one was. Well, we can find another place in the area you're in right now. We'll make sure you get a refund. I said, Listen, I'm here. I don't have A place to stay. What am I supposed to do now? And they just say I'm sorry, sir. You know, I'm sorry, We'll make sure you get credit. That's all they would do. For me, it was absolutely a nightmare. Three experiences personal experiences for me. One of them a nightmare. One of them on the edge of a nightmare. Another one that could well have been a nightmare but was a mere inconvenience. You can probably guess by now what my thinking is about Airbnb and VRBO. That's what got my interest in this article about this poor guy who was scammed, okay. He was trying to stay in Montreal, and the owner asked him to pay for their stay, outside of the Airbnb app. I've seen that happen many, many times. Because that way, the owner does not have to pay the Airbnb fees, okay? But if you do that now you have very little recourse against the owner, then you know, I've done some chargeback. Lately, now my company if someone buys a course from us, and they're not happy, and we will immediately refund their money because we just don't want them to be upset or disappointed. Because again, you know, our whole thing is to nourish you back to health when it comes to security stuff, right, get that transformation done. I have had some nightmares personally trying to do a chargeback for things that were never delivered, or that got charged inappropriately. Or where I canceled the service. In one case, it was like it was over $1,000 a month for the service, and I canceled it. They charged me the 1200 dollars anyways. I went to my credit card company, and they said, well, we'll have to verify it with the vendor first.
    So what? I canceled it. I had to fight with a credit card company, and then when they checked with the vendor, and the vendor said, Okay, well, it's fine. We'll take chargeback. You used to be able to do this at the drop of a hat, and I guess they've abused it, right? I think that's the bottom line on it. But man, oh man, so we'll get a little bit more into this vise story. I guess its turned into an Airbnb, VRBO, what to do if you want a vacation rental or if you want to rent a place while you're on a business trip. And then we'll get into some of the more of the articles here, in the next hour. You're listening to Craig Peterson, of course, on WGAN and online.

    Hi everybody. Craig Peterson back here. I don't know if you guys know what Airbnb's roots were. It started as an air Bed and Breakfast. It was intended for the very young generation to be able to go to concerts and things and just get an air bed in somebody's apartment or home. That's what Airbnb is all about air bed and breakfast. That was the whole idea. And I'm not so sure they've come a long way from those days. I spent the last few segments, in fact, in talking about my horror stories, we've been trying to use Airbnb. There's another one I did not mention in Florida, which was not a horror story quite the disappointment for this house. That I think while I'm quite confident in this house that we rented. It was for a family reunion. So we rented this house that slept like a dozen or something like that. All of the beds were just terrible. You know, the cheapest mattresses that are known to man. You shift your weight at all, and the squeaks loud enough to wake you up. The sheets are the cheapest ones you could imagine. It was an Airbnb as well. It was pretty obvious that the set up for this place was for porn videos. You go into the garage, and the whole garage is one massive shower with I can't remember for six showerheads in it. And then a little bit of workout equipment. I mean a tiny bit of workout equipment. It sounded awful. Okay. And so there you go there, there's all of the Airbnb and VRBO, experiences I can remember. My sister rented the one in Florida for the family, and she did not stay there. She stayed with my mom. It was quite revealing, frankly, so disappointing. I never shared these stories before, but it was because of a story that was in a vice.com, and you'll find this up on my website and Craig peterson.com. They put a little note out saying, Hey, does anybody have any stories about Airbnb, Airbnb scams, and they said, this is Anna Marian, who wrote this that nearly 1000 people sent them emails with their stories. They looked at all of the stories they put together some patterns. A former vice senior staff writer by the name of Alec Conti shared her story about a disastrous vacation to Chicago, and she ran into what she's saying are a bunch of grifters, and frankly a nationwide scam. I no longer use Airbnb at all or VRBO at all. I have been sticking with hotels. If you're interested, I typically use hotwire. I don't use the star ratings of the hotels. I rely on the ratings that are posted by the people who stayed there. I think that's the best feature of hotwire, frankly. I don't care what hotel it is. I just want to stay at a decent hotel. I even used hotwire throughout France and Belgium. It worked great. We found some just wonderful spots that we would never have found if we were just looking to stay at the Marriott or the Hilton or whatever it is, right? So Conti's investigation revealed some serious problems with Airbnb. Now you might have heard about this problem with Airbnb. After all, it hit the news late last year of these party rentals after a death happened. I think it was in San Diego at one of these party rentals. Somebody rented a nice house. Essentially a lot of these places get destroyed by the partiers, right there. There are drugs and heavy drinking, and in this one case, that hit the news. There were gun shootings. Okay, that's a very, very bad, bad thing. So Conti apparently, and again, you can find this article on vice.com traced her scam back to a company that used fake profiles and fake reviews to conceal a whole bunch of wrongdoings. Let's get into this okay because property switches are one of the biggest ones will tell you about what those are the units of sawdust on the floor with holes in the walls, this whole bait and switch game which goes into these properties, switches, and stuff. It's awful. When all else fails, there are these clumsy threatening demands for five-star reviews to hide the evidence of what they've done. Sometimes multiple scams are involved. You know it the hackers aren't just coming after directly our money by trying to hack our businesses by trying to fool us into clicking on links or doing things that we shouldn't be doing, right? These scammers are all over the place. After this story that came out, Airbnb promised to "verify All 7 million listings on this site by December of this year 2020". Frankly, there's no way that they could do this. There's no way you could send investigators to all 7 million listings. He said, Well, we're going to have to take more responsibility for stuff on our platform. Yes, you will. You have to provide a firewall. Not just a firewall of the reviewers, the people who stay there and review can see the reviews that come in from the owners of these properties. That's not going to solve the problem. You need to make it so that there can not be retribution by the bad guys that have given Airbnb a bad name. Now I got to mention that my sister the one that booked that Airbnb for us in Florida, my sister has a house that she rents out in Park City, Utah, on Airbnb, and one of her daughters keeps it clean. I know my sister is not engaged in scams. I know that my niece is somebody who takes responsibility for things. I'm sure she keeps it clean. I don't want to paint the whole Airbnb, a website and people who are renting with a black brush here, I don't want to paint the whole rental market, including the VRBO with a black brush, but I've got to say 100% of the time I have had what I think are scams on both platforms. Now, that's my personal opinion, based on a handful of stays, and I know a handful of stays does not represent every listing on the platforms, right. I understand that. However, its the verification process, we're talking about here. I don't know that he's ever going to do it. How are you going to review and verify all 7 million listings on the Airbnb site within 12 months by December 2020? I don't know how you're going to do it. So let's go through the biggest scams according to vice.com number one, which they say is exceedingly common. It's across hundreds of emails. It's the bait and switch where Airbnb users were promised one apartment and arrived to find something very different. deceptive photos a bore no resemblance to what they found when they got there. My kids found this too. They rented some places in Italy when they did a tour, and you know, black mold everywhere just terrible. Okay? Other times and they were persuaded by those to switch apartments or houses entirely.
    It is a widespread thing where they say, hey, due to unforeseen circumstances, as a pipe broke, I'm going to have to move you to another one of our properties. Now under the rules for Airbnb, the owner does not get penalized if they push you to a property due to quote, unforeseen circumstances unquote, like a pipe break. But it turns out some of these people are using that unforeseen circumstance again and again and again. And they're showing up to their rental defined the new locations filthy, unfurnished on a different part of town. And they're saying that in a surprising number of stories, the original house was full of a weird amount of bear beds laid out and bizarre configurations, kind of sounds like that porn place my sister rented for the family in Florida, doesn't it? So here's one of the quotes I rented a place near Glass beach and a few weeks part of my trip. When I reached out to confirm the booking, the Lister told me she had a septic problem in the unit, and she would see if she'd put me if she could put her up in a more prominent place nearby. It never materialized, but she refused to cancel my booking, saying the first time that her computer wasn't working and the next time weeks later that her father just passed away. I had to complain to Airbnb that she refused to cancel the booking, so they canceled it, but I was unable to write a negative review. According to Vice again, they're saying the plumbing scam seems to rest on the idea Airbnb won't penalize a host if the house is uninhabitable. Okay, that's what I was saying. I've seen this before. So this goes on and on this whole bait and switch thing. Okay, next one, getting the guests to agree to move houses and the plumbing scam is often kind of segway into getting you to agree to move houses. Okay? So they will say, supposed to be this, you know, here's this complaint supposed to be quaint, quiet property in downtown. They get delayed by the homeowner stating that we'd need to change properties the last minute since it was only a quick two-night visit we weren't opposed.
    The new quote larger location was this scummy little apartment complex on the other side of town. Another one - Booking the Airbnb to multiple people at the same time. That's what happened to us in Vegas. When my wife and I showed up at this apartment through Airbnb, perhaps the most socially awkward Bait and switch is this one renting an Airbnb where you believe you booked the whole residence only to arrive and find a whole bunch of strangers there. That happened to us in Vegas. Multiple people told us they came to see other Airbnb guests at the house, or in some cases, people who seem to live there. It just goes on and on. Next one - money scams, paying outside the app. I mentioned this one early. It says it's a straightforward scam. Be careful.
    There's no be careful here, as there is no reason to do that. Fake damages - Man, I've heard about this from multiple people before mine. How can Airbnb police this? Did the guests damage the place? Okay. Oh man scam scams, you'll find more about this online. My advice? Use a hotel you trust us out of the hotel booking site, you believe. And I already told you, I use hotwire because I don't care what the brand is. I just want a good hotel, and I use the ratings from the people who stayed. Stick around. We'll be right back.

    Hey, welcome back, everybody, Craig Peterson here on WGAN and online at Craig peterson.com. Hey, have you thought about how to follow along at home or on the road during the week? The easiest way to do that is to listen to my podcasts. Why not? I put it out there are multiple things, including this weekend show, but many other things that I include during the week, and you can subscribe to that as well on your favorite podcast platform. And it says Craig Peterson dot com slash iTunes. If you are an iTunes type of person or Craig peterson.com, slash tune in or slash I heart. Okay, I am kind of all over the place today. I appreciate everybody who does Listen to me and comments on things during the Week. You'll also find me on LinkedIn and Facebook and YouTube, but it is kind of over the place as I talk about some of the biggest stories of the week. Now we were just talking about scams that seem to be coming from Airbnb and VRBO, of course, but there is a lot of scams going one. We are going to get into one right now tied into the coronavirus. But first I just want to make mention of this other article that came out last month in January. And it's talking about computer literate millennials and Generation Z. These are the people that grew up with the internet. They've had the internet pretty much their whole lives. They found meaning the Federal Trade Commission has found that people ages 39 and under are more likely to report fraud than the 40 plus Crowd now here's the thinking. It isn't that the younger kids and millennials and Generation Z, it isn't as though they are less afraid to report that money has been stolen from them, it appears that they are more likely to fall victim to fraud 25% more likely. Now the millennials are less likely to fall for scams over the phone than people over 40, but 77% More likely, Millennials are 77% more likely to get duped by email scams and 90% more likely to lose money on a fake check scam. Now the thinking behind this is that those of us who are a little bit older, we hold the whole internet thing with a little bit more skepticism than our children and grandchildren do. Because we know that there are scammers out there. And we've heard all of the horror stories, whereas the younger kids are looking at it as well. It's the internet, and they just give their stuff away. We already know that there are studies that show that the millennials will give their email address away in trade for a single donut. Okay, so they don't value a lot of this stuff. You know, to me, well, it's a little bit concerning, and it should be to you. But let's get into the latest scam that's out there right now. It isn't the Airbnb scam, which has been out there for a few years now. As I said, hey, I've been burned what, four or five times by this overall, personally. So I'm just to the point I just don't use it anymore period. It's a real shame because there are some good people out there. But this has to do with what's been happening. Now it is happening with the Coronavirus, and this is a huge deal. We had one day this week, where 15,000 new cases were reported. Supposedly, it was due to a change in the way China was tracking the Coronavirus and diagnosing people. So they're saying, Hey, listen, it's you know is just a change. Don't expect this to indicate that more viruses are spreading out there. And frankly, I look at it and say, Well, maybe there are there aren't. But what we're seeing are some rather sophisticated phishing scams going on. Phishing, of course, this is the one spelled with a Ph. It is where an attacker tricks you into doing something. It might be clicking on a link. It might be responding to an email. It might also be a phishing scam over the phone or, you know, SMS a text one which would be called smishing. A whole new type of phishing this going on right now. Well, last week, IBM and Kaspersky now Kaspersky is a Russian anti-virus company. They are also trying to stop the general spread of malware. The State Department, the FBI, Homeland Security, not to use Kaspersky software, but they do have good information. So when I see Kaspersky, combined with IBM, a company I do respect, then that does kind of make my years and help if you will. Still, IBM and Kaspersky caught hackers in Japan, trying to spread malware through emails, and the emails had links about the Coronavirus outbreak that started, of course, in Wuhan China last month in January. Now adding Sophos and now, of course, Cisco to the list. They have found phishing emails from cybercriminals, purporting to be from the Center for Disease Control, as well as the World Health Organization. And what these bad guys are trying to do is to steal your email credentials and other information. The emails are coming from several domains, including CDC dash gov.org, which, of course, is not the real CDC website. So be very careful if you are trying to find out information about the CDC or the spread of coronavirus about flu in general. For instance, in my home state of New Hampshire, we have I think it's seven deaths so far this year reported g attribute To the flu in general, not the Coronavirus. Every year about 12 to 16,000 people in the United States die from the flu.
    So far, we've only got 14 cases reported of Coronavirus. At this stage everybody, this is nothing to get all freaky worried about. Okay, so calm down. If you want more, go to cdc.gov. CDC Centers for Disease Control - cdc.gov, tells you what to do now. The current Coronavirus has an official name now. It's called covin-19 co vi n dash 19. There are multiple versions of Coronaviruses, which is why they identify each with a number. We have had a report in the past about Coronaviruses, and they have killed people previously. So you'll see Right at the top of the cdc.gov website, information about the Coronavirus and its spread. It is a respiratory disease and potentially fatal. It doesn't seem to be increasingly more fatal than some of the other viruses that we've had. Let's put all this in context. And when you get an email from someone saying, hey, look at this, you click on this link, to get information about the Coronavirus. It's going to let you track the spread of etc. don't respond. If you get a text message, don't respond. I got one because I'm a member of the Great and Powerful media, right. I got one last week that was sent out to members of the press saying, Hey, we got this new tracking site. You just can to be cautious enough when it comes to this. So if you go to CDC Gov at the top, You'll see the description here about the covin-19. You can click on that, and it'll show you a global map about the location of reported cases and what is happening. So, I'm looking at one, and it's about one day behind. It looks like right now for covan-19. But you can see all of the countries that have been reporting it. Then you can also look at the hard statistics. People under investigation in the United States, exactly how many 14 positives, you'll see that there. Of course, it changes daily. You can see how many tested negative and how many pending, the people are under investigation. Remember, the airplane full of workers from the State Department that came back from China. They have now been under quarantine for more than 14 days. They release them all from quarantine because it turns out, nobody had that virus. So just because you have the flow doesn't mean it's Coronavirus. More cases over on the left coast and the Midwest, which is kind of surprising to me than there are on the East Coast or the Mid Atlantic, etc., etc. So have a look there. Do not respond to emails or texts or phone calls. Okay? Just be very, very careful because the hackers are imitating this sort of thing. The other side of this is they are sending out messages seeking donations. They are asking for Bitcoin donations to the World Health Organization can tell you right now, the World Health Organization, the CDC, they are not taking Bitcoin donations, okay. So don't go and donate. Right And again, the CDC gov.org is the band guys CD see.gov is the good guys. The scam page is straightforward. It, you know, took the scammers, maybe just a few minutes to put together. It's handy, and it looks legit. And the FBI and, of course, also Homeland Security are taking down these pages as soon as they can, but they can't always get rid of them right away. And companies, we've got to be proactive. We've got to chain train our employees, not to follow up on these scams. So again, that's part of the reason for my newsletters. I report on the biggest scams that are going on. I try and keep it down to just a few a week. You can share them with your employees, share them with your family, but you have to get them to share them. Go to Craig peterson.com slash subscribe, and you'll get those as well stick around. We'll be right back on WGAN.

    Hey, welcome back, everybody. Craig Peterson here on WGAN, and thanks for joining us today. Hopefully, you picked up a lot of good information. We're just talking about the CDC some of the scams that are out there right now from the Coronavirus, including one involving Bitcoin, which kind of surprised me. We talked a lot in the first hour about the major scams on Airbnb, where you can rent apartments or homes for a day or a week or a month, almost anywhere. It's really quite neat. But the major scams have been going on there and how I've seen them personally and why I will never use it ever again. If you want to listen to that, just go to Craig Peterson comm slash tune in, you can subscribe right there. Listen to me, live by the way on tune in when I'm on the radio. He And when I'm on with canon Matt, the morning drive every Wednesday at 737, every Wednesday morning, as well. And those are all on tune in. Now, we're going to talk a little bit about this whole thing with the ACLU and their current fight. I spoke about something similar to this a couple of years ago, man, maybe actually the first time was probably about ten years ago. There are companies out there, and they gather information about us. They're called Data brokers. I have visited some of these data brokers sites themselves, I mean, physical sites, where the company operates where they have their data collections, to help them with security problems that they have, and to help prevent problems from occurring, right. That's what I do for living full time. It was probably ten years ago, the radio show that I talked with some of these companies. What they do is they collect open-source information that's used a lot by the government for any number of things from financial transactions to investigations. And you can use open-source information yourself. All you do is go to Google, for instance, and do a search. That's the open-source information. It's anything that anyone can gain access to, without having to be a police officer without having to go and really kind of, you know, get a court order kind of be surreptitious and how you gather that's open source. So the data break, brokers will take all of that, and that can include depending on the state you're living, driver's license information, it can include information about the mortgage for your home. It can include you know the ownership of your home, and it can include just all kinds of stuff. That becomes very, very difficult to control. Because all of your information is out there. It's available for free or for cheap on the internet. So these data brokers, they might buy it from the county, they might get it an open-source. Some of this information will contain data from your mortgage, will contain your signature, the deed to your home is going to contain the signature, the automobiles that you own. There's going to be UCC filings with the Secretary of State's office, detailing what cars you own, who the lien holders are, and how much money is involved all of this stuff. So it all gets pulled into these databases. I mentioned on the show a few months ago, a couple of months ago that we were out in Las Vegas at a wedding and of course, you know, doing work while I'm out there and I'm sitting They're on the couch doing work for some of our Las Vegas clients. And there's a knock at the door. And who's there? Well, it's an insurance investigator investigating an accident that it was a fatal accident. And of course, the insurance company had been asked to payout. So they came to this home because they had information that it that the person involved I had a contact with someone at this address, which indeed she did. It was her sister, and apparently, the driver had been responsible for this fatal death. The driver listed one of my sisters in law. She had died about six months before the accident. So obviously, it was all fate. The insurance investigator showed my wife all of this information she had from one of these data brokers. It listed my deceased sister in law's relatives, everybody, every address she had ever had. There were names and contact information for some of my kids. However, it had a lot of incorrect information, including supposed current addresses and voting information for relatives deceased for over two decades. When I've looked at the data brokers' information about me, about half of it's correct, but the other half is completely incorrect. And that's still the case because they had a lot of completely incorrect information. People that they said were relatives that weren't people we'd never heard of before. They said these were direct relatives of hers. At any rate, they had purchased all of this information from a Data Broker. In collections, this is called a skip trace. It's called a skip trace for people who jumped bail, etc. Man, we should talk to about this whole bail thing, and the idiocy in New York state that is spreading country-wide dog, the bounty hunter and his wife, Beth had been fighting this for a long time because it's making us much, much less safe. But anyhow, that's not a topic for today's show. It's not a political topic, because it's undeniable what's already happening with the increase in the crime rate in New York anyways. What the government is doing now is what I was warning about a decade ago. That is that the federal government, the FBI, the NSA, the CIA, of the IRS, you name it, they are limited in how they can collect information, we kind of already knew that right? You know that they had to get a search warrant for certain things right. They can follow you around, without any expectation of privacy, etc., etc. So So obviously, federal government agencies can use open-source information to see what you're doing online. But how about the closed source stuff? How about this stuff that the data brokers are collecting? Some of it they're getting from the people who lent you money, some of it they're getting from places where you have to pay to get that information. So, what's happened here is that the ACLU has filed a suit, according to The Wall Street Journal, against Homeland Security. Homeland Security, through its Immigration and Customs Enforcement Agency, as well as Customs and Border Protection, is buying geolocation data from these data brokers and choosing to investigate suspects who have allegedly committed immigration violations. So let me boil all that down into plain English. You might be using games on your smartphone, and you might be using all kinds of apps on your smartphone. If you have a smartphone, frankly, you're probably not using 90 95% of those apps that you have downloaded. But many of those apps are tracking you. And that information is being sold to data brokers. So think about that for a minute. Remember that free app and how you've heard me and many others for so many years say, hey, you're not the customer. You are the product. Well, what's happening here now is that the ACLU is saying to the federal government, hey, you cannot buy the information that by law your organization cannot collect. You cannot buy it from data brokers or these app developers who are selling it. Interesting question, interesting problem, isn't it? What should they do? What should you do? What can you do? It is going to play out in court, and I suspect it's going to come down on the side of the Department of Homeland Security because this information is generally available to anyone willing to pay for it. So now the government stepped forward, saying we are will pay for it. By the way, this goes down to local law enforcement as well. In many cases, they are also buying this information from the data brokers. So let's stick around when we come back. We're going to talk about shadow IT. If you don't know what it is, it's a problem if you're in business.

    Hey, welcome back, everybody Craig Peterson here on WGAN. Thanks for joining me and for spending part of your Saturday with me. If you're listening to this on a podcast at Craig Peterson dot com slash tune in, thanks for joining me, some listen to me while they're driving to and from work and find the various segments of my show, which are about ten-ish minutes long, really work well into their day. So if you're doing that, thank you if you're not, please do consider it. I try and keep everybody up to date with the information that you need to know. And that leads us to what we got right now. Which is shadow IT. Now I bet there is not a company out there. Well, maybe there's one right because you just can't put always say or you know everyone that I say almost every company out there has a shadow IT problem. So let's start by kind of defining what's going on. Have you ever set up a company Amazon account? Have you ever set up an account for a company account for Uber? Maybe it's not a company account. Perhaps it's a personal account that you're using for Uber or something else? How about using something like Constant Contact to send out emails to your customers? How about salesforce.com? We've seen a shift over the years from what used to be kind of the glass castle where there was a central computer room in housed a mainframe. Those mainframes were truly astounding. They still are. That mainframe, in that glass room, was controlled by professional Information Technology people. People that knew what they were doing, at least at the time, right?
    Then we started seeing some changes. Do you remember the AppleII and Visicalc? Visicalc was the killer application if you wanted to do numbers. You bought an Apple, you purchased a little Apple II, and you then pull data. People were asking the professionals in the glasshouse, "can you give us data because we want to put together some spreadsheets." People put together spreadsheets without really understanding the implications and use of the numbers. Without understanding how to audit a spreadsheet and to make sure that the numbers used got correctly used. They didn't understand the double journaling. They didn't understand the cross-referencing of the information. That started a bit of a movement away from that glass house and the hassle from it. They said, Hey, we can figure this out. Why are we going to pay it all of this fake budget money to do something for us, and we can do it for ourselves and do it cheaper. Frankly, that's a problem I still face with many organizations, if you can believe it. Many think they can do security themselves, which by the way, is near impossible for almost any organization. In this day and age, any small-medium business must have full-time external professionals who are helping your internal IT people. Your internal IT should be doing what they do best, which is helping your business best use information technology, assisting people to be more efficient, finding new ways of doing things, etc. Instead of that, most businesses set up these various silos, like sales and marketing or accounting, and each one of those silos, those lines of business do things their way.
    The sales guys, they're out, and they said, Hey, we're going to use Salesforce. We're going to tie that into Constant Contact. Then you have your accounting people saying we're going to use QuickBooks Online or maybe one of Oracle's accounting systems. The manufacturing people say, Well, we are going to use this particular ERP program, which is going to be great for manufacturing. We've decided that we're going to use Survey Monkey to collect information from our customers from our vendors. Do you see where I'm going? Each one of these lines of business is going out and making what are in actuality Information Technology decisions. They're making decisions about what type of technology to use. Which is one level, but then the next level is they're using it. They're putting the business's information at risk
    It is a huge, huge problem. And it's something that I'll be addressing with some of this training that I have coming up, and a couple of these tutorials specifically tackle these problems. And so if you're on my email list at Craig Peterson comm slash subscribe, you're going to find out about these, and I'm going to give you some great cheat sheets and other things. But all of those again, Craig peterson.com slash subscribe. All of those different lines of business, all of those different functional responsibilities within an organization larger small, are adding up and adding up massively. There is an enormous problem behind this. Now you know that I use one password, I recommend it. And we typically use one password in conjunction with do to help secure login information. But because one password is used so frequently by companies to keep track of logins, they have kind of a unique view into the risks of all these different accounts. And what we're talking about where these lines of business are making Information Technology decisions that they're not qualified to make, and frankly, in most small, medium businesses, there's probably no one in the organization that's fully qualified. Still, at least it has a better idea, but then, a marketing person or an accounting person would have. So this is called shadow IT, and new one password research is showing the risks behind it. And they surveyed 2100 us adults working In an office that has an IT department, now, almost everybody uses a computer for work, right. And so these 2100 that they looked at all use computers at work. And they found that two-thirds of the respondents have created at least one account in the past 12 months, that their IT department doesn't audit. But it's worse than that. It's not only that the IT department hasn't looked at the account. They have not vetted the company behind it to make sure that they conform to the regulatory security standards required for the company. In fact, in two-thirds of the cases, the IT department doesn't even know that user accounts were created and are in use accessing company information. So one of the things when we go in, remember I mentioned earlier that we kind of try and nurse a company back to health. Getting their security, health, and IT on track. What we'll do when we go in is we will start auditing the shadow IT accounts. What are people using? Whether it's a Dropbox account or you know, a photo-sharing site, whatever it is, what are they using? There are some fascinating statistics here that are coming out of one password. Only two and a half percent of the people surveyed. Two and a half percent of the respondents said that they use a unique password every time! Even the most basic of security precautions are not in use by people who are creating accounts on third-party websites. Isn't that amazing? And They're putting company information up on some of those websites. I'm going to make a note of this right now because frankly, it is scary to me to think about this. Maybe we'll try and do a Facebook Live, or try and do a YouTube Live and let you guys ask questions live there. Let me see I want to put that in here so that I'm less likely to forget about it. Alright, noted. So stick around. We're going to do a wrap up when we get back. Couple more stories from this week all of that right here. Thanks for being with us. I am Craig Peterson, and we'll be right back on WGAN. And of course, online as always 24 seven, hopefully at Craig Peterson dot com stick around, because we'll be right back.

    Hi guys, Craig Peterson, here back on WGAN Thanks for joining me. If you're listening to one of my podcasts, thank you very much as well. We've got a lot going on. I have not been producing as much content or shown up as much on Facebook Lives, or YouTube lives, lately, because I've just been so busy with my team here putting together some great tutorials. You are going to love these also we are working on some course materials. You can only get that if you are on my email list. Craig Peterson, dot com slash subscribe. I'm not one of those guys who is sending you emails every day — trying to get you to buy something. I want you to understand what's going on. And if I am in the process of releasing free tutorials, or even paid courses you might get well, you will get more emails from me because I don't want you to miss those things. But this isn't one of those things. We're going to get a constant stream of emails from me. I'm not going to overload you. But again, Craig Peterson, dot com slash subscribe, so that you don't miss out because you will miss some critical stuff. And some training you won't get anywhere else guaranteed. So earlier in the show today, in fact, the first hour I spent talking about these scams from Airbnb, they are horrific. And I told you about some of my own stories, all of them bad, some of them quite literally horror stories. And I really would love it if you would listen to them so that you can find out what I do to book and now when I'm going somewhere, and I need a place to stay.
    I also talked about the ACLU it's fighting against the Department of Homeland Security's new effort here to try and track people through their smartphones using information that any company out there can get about you. Okay. So I'm not sure that this is good or bad, because I don't think anybody should be tracking us. But that's an entirely separate issue, right? How shadow it could put your organization at risk is what we were just talking about a huge deal. I went through some scams that are going on right now surrounding the coronavirus and how they're getting money from people and hacking people through them. And I want to talk right now about the FBI investigations that are going on. I know over the last couple of weeks, I've helped the FBI open a couple of investigations, because of some real hacking that's been going on from Iran, from China, from Russia against small businesses. These are companies that have said to me before, literally, no, I'm too small - Why would anybody care? Well, they do care because it's a foothold. They care because you have intellectual property, they want to steal. US intellectual property that might help them if they're ever in a kinetic war with us, or even if they're just in a cyberwar with us, right. What they want to do is hurt our economy. What they want to do is shut us down. And what are the best ways to do that? Well, let me tell you a China does know they are indeed experts at some of this stuff. So the FBI is in the process right now. And according to the future, really cyber warfare and the future of technology. According to ZDnet, there can now be millions, maybe even billions of dollars at risk by not properly handling information security. And to me, this is a horrifying thing, because I see it every day.
    I know, there are some people out there that are saying, Craig, you're not going to talk about it again. Look at what my conversations with Ken and Matt this week. I asked them if they're using password managers, which is, as I mentioned, the last segment, the essential thing you can do with cybersecurity. And you know what their answer was? No. No, well, and the statistic we just saw, where they're not using unique passwords, only two and a half percent using unique passwords on the website, again, an essential thing you can do, and about 98% of those who responded to this poll. We're not doing it.
    So there was a conference last week in Washington on the topic of Chinese adventure. Structural property from us tech firms, as well as the academic sector. And we've spoken about both of those before. Because there have been so many problems, right? Where the academic sector, they are stealing our ideas before they even become businesses, and they're going into businesses. They're working in our universities in conjunction with the Department of Defense. They're just getting so much information. But some of the highest officials from the FBI, the Department of Justice, spend their time about four hours they were given at this conference, raising a sign of alarm, putting the private academic sector on alert about the threats that they are currently facing over ID theft. It's a very, very big deal that deeply concerns me, and it should concern you too. The Feds are worried about China in particular. Now, as I mentioned, we see right now, and we help the FBI open some investigations into actual Iranian hacking going on, which we've never seen before. My company hasn't ever seen it. But we always see Russian and Chinese. That's just ongoing. Right. But according to John DeMars, the Assistant Attorney General for national security, who opened the conference, said the threat from China is real. It's persistent. It's well-orchestrated, it's well resourced, and it's not going away anytime soon. The FBI director said the cases have been filing up since 2018, which is when the Department of Justice launched the China initiative program, where they started to try and counter as well as investigate Beijing's economic espionage. So here's a quote from him. The FBI has about 1000 investigations involving China's attempted theft of US-based technology in all 56 of our field offices, offices, and spanning just about every industry in sector. That's from director Ray. And some of those thousand are through us through your host through me. Because I have seen them trying to get into I mean directly into and succeeding, getting into some of our clients now, they weren't clients, when the Chinese succeeded in getting through. We cleaned up the mess after the fact its part of what we do at mainstream where we are trying to nurse our newer clients back to health, okay, but I've had a part of this thousand, Believe me, I know what I'm talking about here. And that's why I am just focusing on this so much lately. You know, I used to do, my radio show is mostly about commercial or consumer stuff, just Basic, oh, isn't this a cool new gadget and I still do some of that, right? You've heard me talking about that. But now I end up spending a lot of time talking about cybersecurity because I think everybody needs to understand this a little bit better. But this article is up on my website. As I said, Assam Zd net, it just goes through the details here, what they're doing the business partnerships, investigations The FBI is doing in China is rewarding IP theft. They're encouraging it. quote here from Adam Hickey as Deputy Assistant Attorney General, there are certainly a lot of cases where we don't have evidence beyond a reasonable doubt that the Chinese government has procured or sponsored the theft. But we see patterns with theft rewarded after the fact. They've got a whole structure set up to encourage industrial espionage. We know that's been also happening in Russia. We have seen some of the Russian stuff. The entire Skolkovo project that the Clintons were involved in that they got millions of dollars from was aimed at stealing hypersonic missile technology from the United States. The Russians were able to do through the Skolkovo project, and now can shoot down some of our non-hypersonic cruise missiles, thanks to the technology that they stole directly from us through industrial espionage. And with the help of the United States State Department. Now, that's not the current state department. That's when Hillary Clinton was in charge of it. Okay, man, we could go back. We can go back anyways.
    insiders are also playing a big role. That's why you've got to be careful about the hires from the universities. Okay. These Chinese hackers aren't acting alone. anymore. They're using all kinds of insiders, including useful idiots, which is what they call them. Do you remember that in Homeland? The show Homeland, which has, I think there's their last season is out right now. It's just starting over on Showtime, a phenomenal series by the way. I enjoyed it. In one of the episodes, a US senator, who was fighting some of the legislation that the Feds were trying to push through, found a wall with names and pictures. Under his name was the label UI under his name by the bad guys. When he saw it, He asked, "What does this UI under my name mean?" Upon where he was told, it stands for Useful Idiot because he was an idiot. We've seen that so many times with people in Congress and the Senate. Our representatives. don't understand this stuff. We've seen it so many times, with business owners who just don't understand it, how much at risk they are, and then once the They're hacked. their businesses are over. They are gone. How many times do we talk about that anyway? I'm, I guess I'm kind of lecturing now. cross that line. Yeah, I get it. Right. But we've got to be making people aware of what's happening there. Multiple CEO summits meeting with academics across the US. I've been thinking about maybe trying to put together some summits, here, a virtual summit as well as real summit. We're probably going to try and do that this fall, but certainly by the end of this year. Because we have to help CEOs and everybody else understand what's the risk, why is it a risk? What should we be doing about it? Okay. It is all stuff you need to understand. All right. Well, I hope you enjoyed today's show. I hope that you got something out of it more than anything else, or electronic technology we're using for a lecture. I talked about this week, and I was on TV talking about that on the radio talking about that. Hopefully, you caught some of those interviews. You can catch most of it. I don't have it up yet. I got to get it up over on Craig peterson.com. We try and include it as well. In our weekly newsletters, try and keep you up to date. Use it for training in your organization, whether it's a business, whether you're just sharing it with family, but you're going to get all of that from me, just by subscribing to my free newsletter. It is information-packed. Okay, if anything to complain about, it said there might be a little too much information sometimes. But I want to get it into your hands. Subscribe now. Craig Peterson calm slash subscribe. I am not going to be scamming you spam you or anything else. Thanks for joining me today. I'll be back Wednesday morning with cannon Matt at 730. You're listening to Craig Peterson

    Transcription by otter.ai

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 31 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…