Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Using Punchlists to Stop Ransomware

    Using Punchlists to Stop Ransomware

    I really appreciate all of the emails I get from you guys. And it is driving me to do something I've never done before now. I've always provided all kinds of free information. If you're on my email list, you get great stuff. But now we're talking about cyber punch lists.

    [Automated transcript follows]

    [00:00:16] Of course, there are a number of stories here that they'll come out in the newsletter or they did, excuse me, go in the newsletters should have got on Tuesday morning.

    [00:00:26] And that's my insider show notes, which is all of the information that I put together for my radio appearances radio shows. And. Also, of course, I sent it off to the hosts that these various radio stations. So they know what taught because, oh, who really tracks technology, not too many people. And I get a little off-put by some of these other radio hosts, they call themselves tech people, and they're actually marketing people, but.

    [00:00:57] That's me. And that's why, if you are on my list, you've probably noticed I'm not hammering you trying to sell you stuff all the time. It's good. Valuable content. And I'm starting something brand new. Never done this before, but this is for you guys. Okay. You know that I do cybersecurity. As a business and I've been doing it now for more than three decades.

    [00:01:22] I dunno if I should admit that right there. Say never say more than 17 years. Okay. So I've been doing it for more than 17 years and I've been on the internet now for. Oh, 40 years now. Okay. Back before it was even called the internet, I helped to develop the silly thing. So over the years, we've come up with a number of different strategies.

    [00:01:43] We have these things that are called plan of action and milestones, and we have all kinds of other lists of things that we do and that need to be done. So what we're doing right now is we're setting up. So that you can just email me M [email protected]. And I will go ahead and send you one of these punch lists.

    [00:02:09] Now the punch lists are around one specific topic. We've got these massive. Punch lists with hundreds and hundreds of things on them. And those are what we use when we go in to help clean up the cybersecurity and accompany. So we'll go in, we'll do scans. We will do red team blue team, or we're attacking.

    [00:02:30] We do all kinds of different types of scans using different software, trying to break in. We use the same tools that the hackers use in order to see if we can. Into your systems and if the systems are properly secured, so we do all of this stuff and then it goes into all of the paperwork that needs to be done to comply with whatever might be, it might be, they accept payment cards. It might be that they have. But information, which is healthcare information. And it might be also that they're a government contractor. So there are hundreds and hundreds of things that they have to comply with. Most of them are procedural. So we have all of this stuff.

    [00:03:13] We do all of this stuff. And I was talking with my wife here this last week about it and said, yes, That's so much of this could be used by small companies that can't afford to hire my team to come in and clean things up. And I don't want them to suffer. So here's what we're doing. We're starting this next week.

    [00:03:36] We have a punch list for you on email. So what are the things you can do should do for email? Just very narrow on email so that you can recognize a Fisher. Email, what you might want to do to lock down your outlook, if you're on windows or your Mac mail. So we're taking these massive spreadsheets that we have and we're breaking them up.

    [00:04:03] So the first one that's available to you guys, absolutely. A hundred percent free. Is the one on email. So just send me an email. Me M [email protected]. Now, remember I am, my business is a business to business, but almost everything in these various. Punch lists applies to individuals as well.

    [00:04:27] So I got an email this last week from a guy saying, Hey, I'm 80 years old and retired and I don't know much about computers. And that's what got us thinking about. No, we need to be able to help him. We need to be able to help you out. Okay. And if you're a small business and we've dealt with a lot of them over the years, and as a small business, you just don't have the funds to bring in an expert, whether it's me or somebody else, although yeah.

    [00:04:56] You want the best anyways. It it is going to allow you to do it yourself. Okay. So absolutely free. All of these punch lists on all of these topics. We're probably going to end up with more than a hundred of these punch lists. And all you do is email me M [email protected]. Just let me know in there what you're interested in.

    [00:05:19] So even if we haven't got that punch list broken down for you yet, we will go ahead and put that on the. To do right. We need the priorities. What kind of a priority should we have as we're putting these things together for free for people. And the only way we know is if you ask, so the first one's on email, you can certainly ask for email.

    [00:05:39] We've got, as I said, more than a hundred others, that we think we're going to be able to pull out of the exact. Plan of action worksheets that we use so that you can go through this yourself, whether you're a home user or you are a small business or even a big business, we were talking with a gentleman who's probably listening right now, who has a business.

    [00:06:06] They have three offices, they have some requirement because of the military contracts for high level. Cybersecurity. And they would work for him too. All right. So they, this is all of the punch list stuff. He probably know what a punch list is. It's used in the construction industry a lot, but in our case, it's indeed to do this.

    [00:06:27] You need to do this, you need to do this. Okay. So that's what that's all about. So enough rambling on that. It's going to take us some time to get them all together. I'm also. And then her do more video stuff again, training. So just like on the radio show where we're talking about what's in the news, we're going to talk about watch what's in the news.

    [00:06:49] When it comes to small businesses, what you should be paying attention to with of course, an emphasis on cyber security and. Putting those up on my [email protected]. In fact, we've already got some up there already, and then we are going to also be putting them on YouTube and rumble. So if you don't like YouTube and Google, then you can certainly go to rumble.

    [00:07:14] You'll see them there. But if you're on the email list, Starting to put links in the bottom of the emails. So you can go and watch those videos. If you're a video type person that you know, more visual. So it's, I think all good. And it's good news for everybody. And this is what happens, I think, as you get more mature, In the business.

    [00:07:36] As I said, I've been on the internet for more than 40 years, helped develop some of that software that some of it's still in use today and now it's time to do more give back. And I really am trying to give back, okay, there's this isn't. This isn't a joke. No joke. So go ahead. Email me at Craig Peterson.

    [00:07:57] Tell me which punch list that you would like. And I can also put you on my email list so that you get my insider show notes, and you can just do that yourself by going to Craig Peterson. Calm. You'll see right up at the top of the page. If you scroll down a little bit, it'll pop up. It's a big red bar that goes across the top.

    [00:08:17] I try not to be too intrusive and you can sign up there for the newsletter. So you'll get some of these trainings automatically. You'll get my insider show notes, all of this stuff. It's absolutely free. Okay. This is my give back to help you out. It really is. Okay. As I mentioned at the very beginning.

    [00:08:37] Peeve by some of these people that represent themselves as tech experts. And in fact, all they are marketers. We've got a client that decided that I was too expensive. My team. So they went out and shopped around, tried to find the cheapest company they could. And so now the company that they're bringing in is saying, you're saying Hey so how does this work?

    [00:08:59] How do you do zero trust? Why do you have a firewall here? Why do you bother to have a direct fiber link between the offices? All this stuff? Because they need it. Okay. I get it. You use. Barracuda spam firewalls and Barracuda firewall holes it, yeah, this is a different league. Okay. So you're going to be getting these punch lists from me that are really going to help you understand and secure your systems.

    [00:09:29] This isn't your average run of the mill, managed security services provider or managed services or break fix shop. You're getting it from the guy that the FBI. InfraGuard program went to, to do their trainings. That was me. Okay. So for two years I set up the program. I ran it. And if we ever sitting down and having a coffee or a beer, sometimes I'll tell you why I left.

    [00:09:53] Okay. But think about FBI and I think you might have a clue as to why I decided not to do that anymore. I trained thousands of businesses, government agencies, state local. Federal, you name it. So you're getting what you really need, which is another problem. I keep hearing from people, you do a search for something on YouTube or Google and you get what a million, 5 million pages, as supposedly that it says are available and they give you, okay, then here's the top one. But what you need is an integrated, single. To do things where everything works together. And that's what I'm trying to do for you guys, because there's so many little products, different products that just don't work so well together.

    [00:10:46] So we'll be covering that as well in these, but you gotta be on that email list. Craig peterson.com. Craig Peterson, S O n.com/subscribe. We'll take you right to the subscription page and I'll keep you up to date. This is not my paid newsletter. All right, stick around. We'll be right back. And I promise I'll get to Russia.

    [00:11:12] Some of the high-tech companies and others pulled out of Russia after the Ukraine invasion, but one stayed Google. What is going on with Google? And now they're in big trouble with the Russian government. Wow

    [00:11:28] here's the list of companies according to seeing that, that have. Out of Russia because you remember Russia invaded !Ukraine, February 24, we had Adobe, these are the guys that make Photoshop, Adobe reader. Airbnb has an interesting story too in Ukraine because a number of quite a number of Airbnb customers went ahead and rented rooms and homes from Ukrainians, even though they had no intention of going and they told the Ukrainians, Hey.

    [00:11:59] The I'm not going to show up, just take this money. I'm sure you need it. Can you imagine that? But that's fantastic. Good for them, Amazon. They suspended shipments of all retail products at customers in Russia and Bella ruse and also suspended prime video for users. Apple stopped selling its product in rushes.

    [00:12:21] It's halting online transactions, including limiting apple pay. It's also disabled. Some apple map features in Ukraine in order to protect civilians, Amazon web services. They don't have data centers or offices in Russia, but it stopped allowing new signups for the service in Russia. BMW for GM, huh? I have all scaled back their operations or stopped them.

    [00:12:49] Ford suspended its operations in Russia effective immediately until further notice. GM is suspending business in Russia. Honda has a suspended exports to Russia, Disney halted, all theatrical releases in Russia, including the new Pixar film, turning red, also pause content DJI. The drone company that has gotten in trouble here in the U S for some of its practices of sending GPS information to China while they're not doing it over there.

    [00:13:20] Electronic arts. They make a bunch of very popular games, epic games, and other one Erickson, FIFA body band Russia from this year's world cup formula one canceled its plan planned Russian grump, pre Fujitsu, Goldman Sachs. Now Google that's where I want to go. We'll stop at Google here for a minute.

    [00:13:44] Google. Suspended their ad network in Russia. And the idea was okay. We're not sure how payments are going to work because Russia of course has had this kind of this lockdown by foreign countries on their banking system. We're not sure we can get the money out. That's what they're apparently doing now.

    [00:14:08] They're still there. Google's YouTube it search engine on and on still running in Russia. Now that is really disturbing. If you ask me, why did they not pull out? It doesn't make sense. So Google did stop accepting new customers for Google cloud in March. YouTube said is removing videos at denier trivial trivialize, the Russian invasion, but what finally got.

    [00:14:42] Out of Russia, Russia seized their bank accounts. They froze them. They transferred their money out of the main bank account in Russia. We're talking about a $2 billion per year business, Google Russia, that really upsets me. So I did a little more research online about all of this, and I was really surprised to see that you crane now has given the Ukraine peace prize to Google.

    [00:15:12] And it says, quote, on the behalf of Ukrainian people with gratitude for the support during this pivotal moment in our nation's history. So what is it? I'm not sure. So they're one of their foreign ministers, and Karen. I think I said, thank you. From the beginning of the war, Google has sought to help power.

    [00:15:35] However we can through humanitarian support of our tools, we'll continue to do as long as needed. So I dug in a little more and tried to figure out what's up. Russia or Google left its Russian search engine online and YouTube online and was using it in Russia in order to. Control the narrative in Russia.

    [00:15:59] Now, unlike what they've done here in the U S where Google hasn't been caught, many times controlling the narrative in various elections and taking certain ads and not taking others and taking certain business and not taking others, apparently in Russia, it has been. Blocking a lot of the stuff that Russia itself has been putting out.

    [00:16:23] So the federal government there in Russia. Interesting. Hey, so they also have helped you crane out by providing them with mapping GPS and rumor has it satellite services. Yeah, interest in it to track Russian troop movements. All also Ukraine saying the Google news component has also been tremendously valuable.

    [00:16:51] Google's also helping to raise money for the cause of Ukraine. Like many companies are doing right now to help people displace due to the war and Poland. Wow. They've been doing yeoman's work and bringing. People in, by the millions, into Poland from Ukraine or reminds me when I lived in Calgary, Alberta, my Cub, one of the Cub masters Cub troop leaders was a woman who came from Poland many years ago.

    [00:17:18] This was back during Soviet occupation. Poland. And I remember talking to her about what was happening over there. Why did she leave? And it was just so impressive. The polls have done so much impressive stuff over the years. So they're also saying that Google has done a lot of other things in order to.

    [00:17:39] Help protect Ukraine, including Google's blocked domains. They've prevented phishing attacks against Ukraine. They warned targeted individuals that they are being targeted. It's really something what they've done. So my first knee jerk was why is Google? Still doing business in Russia while now it's become clear because they have a special page for Russians that gives correct information, at least, Google is claiming it's correct.

    [00:18:13] I don't know which fact-check teachers checkers they're using. That gives Russians real information about the war what's going on in Ukraine. What's happening with the Russian soldiers. Did you see this? Just this last week, the apparently Russia removed the age limit for volunteers for the military.

    [00:18:35] It used to be, I think it was 40 years old. If you were a Russian citizen and 30 years old, if you are a foreign national, now the Russian military will take any. At any age from anywhere. In other words, Russia has really getting hard up if they want people like me to fight their wars.

    [00:18:54] I'm sure they don't really want, I don't know. Maybe they do want me, that every war needs cannon fodder. So it is fascinating to see good job Google. I am quite impressed. I did not expect them to be doing that. They've also. Provided over $45 million in donations and grants to various groups.

    [00:19:18] They've done pro bono work for various organizations over there. So this is really cool. So that's it. That's what's happening over there? Yeah. Crane and Googled, you can of course, find out a lot more. Get my insider show notes. So you had all of this on Tuesday morning. You could have digested it all and be ahead of everybody else out there.

    [00:19:43] And then also don't forget about my new offer here. Free, absolutely free for anyone. Asks by emailing [email protected]. I'll go ahead and send them to you, which is I think a pretty cool thing now. What am I going to send you? You got to ask first, right? You got to ask. And what we're going to be doing is taking what I have been using for years to help secure my customer.

    [00:20:14] And we're making available for free my cyber punch lists. Craig peterson.com/subscribe.

    [00:20:22] Bit of a hub-bub here. Biden's infrastructure bill $1.2 trillion. And it's in there is this thing that Bob Barr's calling an automobile kill switch. I did some more research and we'll tell you the facts right now.

    [00:20:39] What are you supposed to do? If you are trying to pass a bill to stop drunk driving deaths, and you've got all of the money in the world, Joe I guess 1.2 trillion, isn't all of the money in the world. What are you going to put in there? I did a search on this and I'm chuckling because this is craziness.

    [00:20:59] This is the AP associated press. And they've got this article claiming. President and Joe Biden signed a bill that will give law enforcement access to a kill switch that will be attached to all new cars in 2026 APS assessment false. Okay. So we've got fact checkers here while the bipartisan infrastructure bill Biden signed last year requires advanced drunk and impaired driving technology to become standard equipment in cars.

    [00:21:31] Experts say. Technology doesn't amount to a kill switch. Let me see. So I can't start the car. If the car's computer thinks I might be drunk or impaired in some other way, but that's not a kill switch. What is that? Then if I can't start the car, because I have a disagreement with the computer. How about these people that I don't know, maybe their eyes can't open all of the weight.

    [00:21:59] Maybe they have problems with eyes on nystagmus though. Eyes jittering back and forth. And then now what are they going to argue with the computer? That's a kill switch. I can't believe these crazy people that are like AP here, coming up with fact checking on things. So yeah, I'm sure there some distortions in some articles out there, but they contradicted themselves and to bear graphs, I guess they figure people are just going to see false.

    [00:22:30] Okay. I'm done. And they're not going to bother reading the rest of the article. Ah, Kind of crazy, isn't it? So according to an article written by member, former us representative Bob BARR in the infrastructure bill, is this kill switch. Now the big question is what is the kill switch? How far does it.

    [00:22:55] So I decided let's look up something I remember from years ago and that is GM has the OnStar system it's yet another reason I won't buy GM, there are a number of reasons, but this doesn't, it. OnStar system, they've got an advisors and that grade, and if your car is in a car accident, a crash that advisor can hop on and ask if you're okay.

    [00:23:22] And if you want emergency services coming, they'll come OnStar. We'll call them. And if you are just fine, they won't bother calling. If there's no answer at all, they'll call emergency services and let them know where the vehicle is because the vehicle has with OnStar built-in GPS. One of the features of OnStar is that it can send a signal to disable cars, engines, and gradually slow the vehicle to an idle speed to assist police in recovering the vehicle.

    [00:23:58] Now they will only do that at least right now for vehicles that have been reported stolen and have been confirmed by the police. So in reality, that's cool, right? It slows down. Hopefully the bad guy, if he's on the highway, makes it over to the side of the road and while the car slows down and eventually stops.

    [00:24:22] So all of this stuff sounds good. This kill switch. Sounds good. Doesn't it? Because we're going to keep drunk drivers off the road. Now in reality, of course, they're not going to be able to keep drunk drivers or other impaired drivers off the road. I really don't care what kind of technology they put in.

    [00:24:44] And they're not talking about putting in one of these blow in the tube, things that checks your blood alcohol level. They're talking about having a camera facing you as the driver and probably other occupants of the vehicles and that internally facing camera. Is going to evaluate you. It's going to look at you.

    [00:25:07] It's going to look at your face. If something droopy, or are you slow to respond? It might have a little test to that. It has you take right there. The law is very loosey goosey on any details. There really aren't any, so it's going to be up to the manufacturer. So they put this in the car step.

    [00:25:28] Just like OnStar, step one, put it in the car and they'll tell you when to turn you remember how cool that was the GPS with OnStar. And you tell ya, I want to go to this address. And then the assistant goes ahead and sends programming to your car. And now you can go. And if you lock your keys in the car, they can unlock the car for you.

    [00:25:51] All kinds of cool stuff. And then next up what happened. But they can stop the vehicle. So there's another technology story related to OnStar. And this is from 2009 from Kelly blue book, OnStar stolen vehicle slowed down Fort it's first carjacking. So again, doesn't that sound fantastic. And this was a Tahoe OnStar.

    [00:26:18] And the driver and his passenger forced out of the vehicle robbed by a shotgun wielding perp who then drove off in the SUV. And the OnStar dispatcher was able to locate the vehicle using GPS advice please, of exact location. And as soon as the police establish visual contact, the stolen vehicle slowdown system is activated available on a number of GM cars and trucks.

    [00:26:43] So this was over a decade. That this happened, but the technology's evolved. Yeah. So we initially have all of these car companies trying to decide, okay, so we've got this kill switch law, which AP says is not a kill switch law because they talk to experts just the, what was it? 52 people heads of intelligence.

    [00:27:08] Committees and agencies said that this wasn't a collusion hope, right? So they talked to experts who said no, this isn't a kill switch, but that's today you can argue, it's not a kill switch. I would completely disagree with you. Day one. It's a kill switch. Cause you can't start your car. It's a kill switch.

    [00:27:25] I kill switch is often something you hide somewhere on the car so you can kill the engine. So it can't be stolen. It's a kill switch. Come on. People fact checkers aside, but this could potentially allow law enforcement again, to shut down your car. Remotely track the cars, metrics, location, maybe the passenger load, because remember now cars are tracking all of this.

    [00:27:51] They've already been. Tickets issued by police. The did not see anyone speeding. The car was not caught on a traffic camera, but they hook up a device to your cars port that talks to its computer. And the computer says, yeah, he was doing 80 miles an hour, five minutes. And all of a sudden you got a ticket, right?

    [00:28:12] Massachusetts wants to go ahead now and say, ah yeah. Let's charge by the mile that you drive in mass. Because of course you're not getting enough revenue from gasoline because of the electric cars, electric cars are not paying their fair share when it comes to road taxes. So let's do it that way.

    [00:28:32] So how are they going to collect the information while. And they're going to hook up to your car's computer. The next thing coming down the road in it's already in most cars is wireless data connectivity, or you might've found already. If you have a Nissan, a Honda, many other cars. You have to get a major, upgrade it very 600 bucks up to a few grand for an expensive car, but the two G data network.

    [00:29:02] And we talked about this on the show already is being completely shut down by the end of the year. So they've got to replace it and switch you over. To the L G E data network, which of course eventually will go away as well, or at least three G what happens once it's all hooked up? The next easy step is just feed all of that information straight to the government.

    [00:29:26] Craig peterson.com.

    [00:29:30] If you've been afraid of ransomware before, I've got a good example for you where a whole country now has been ransomed. Absolutely crazy. So we'll talk about that. What is the state of ransomware? And the NSA is asking us to trust them again.

    [00:29:47] Of course staying up to date means that you get my insider newsletter pretty much every Tuesday morning.

    [00:29:54] And the only way to get that is to go to Craig Peterson.com/subscribe. And I will keep you up to date. You'll get even more insight information. The Costa Rican government has declared a state of national emergency. And to the best of my knowledge, this is the first time a government has done this because agencies of the Costa Rican government have been hit so badly by the Conti rants.

    [00:30:24] That the new incoming president immediately declared a state of emergency. So now the country has expanded law enforcement powers and they are trying to go after the Conti ransomware group. No between you and me. Good luck on that one. They are based in Russia. There's a number of different articles out this week.

    [00:30:47] This one from ADV Intel at tech target. But according to their research, the Conti ransomware groups attack on Costa Rican government was part of a rebranding effort. So this ransomware gang has seen a lot of their payments, just dry up. Because it's harder to get the money in. And what are you going to do with cryptocurrency?

    [00:31:11] If you're the Conti group, can you turn it into anything useful? It depends on the country you're in, but for most people, no. Okay. Absolutely. No. So we were able to knock the Conti ransomware groups website. Offline. And we talked about that before here. The U S government did that, but now this is marking a new chapter for the cybercrime landscape.

    [00:31:38] Interesting. Isn't it? So there are some investigations that have been going on. They've been trying to figure out what happened. What was the cause of the downfall of the Conti ransomware group? Are they really gone? Why did they pull their website offline and. They declared publicly support for Russia in its invasion of Ukraine.

    [00:32:02] And so now the Conti ransomware group got hacked and held ransom. They suffered major league. As a consequence. So other hackers went after Conti, which is a hacking group and they showed here from internal documents that were stolen, that the Conti ransomware gangs primary Bitcoin address, which was found in the leak, showed that they had taken in over $2 billion in cryptocurrency over the last five.

    [00:32:35] Isn't that just amazing and anonymous leaker has published more of the gangs communications, that can help the mass for sure. But you think with that much money, they'd be able to protect themselves right now on top of it, because of the hack of Costa Rica and the major damages, because the U S government has offered a couple of bounties here.

    [00:33:00] Against the Conti ransomware group. So there's $10 million available. If you can provide the feds with information about the leaders of the Conti ransomware group and $5 million that you can get leading to the arrest of anyone involved with a Conti ransomware attack. Isn't that something. So ransomware has been really out of control for years.

    [00:33:25] There's no signs that things are actually slowing down. Definitely been enhanced law enforcement efforts to track them down. But I'll ultimately here, the core members of these groups have been escaping these law enforcement activities. They've been using mules like 2000 mules. Have you seen that movie?

    [00:33:46] But the idea is they get people primarily in the U S because that's where most of the money comes from. They do rent. Of people and businesses information here. In fact, last year, it's estimated that 60%, six, 0% of small businesses were hacked, which is just crazy. No wonder has got $2 billion. Okay.

    [00:34:07] What are we supposed to do? What are they doing to really come after us? They're doing many of the same things. These mules will be hired saying, Hey, I just need to use your PayPal account. And all you have to do is transfer some money. 5%, 10% of the money I put in there. And they've always got these excuses, think that I, Jerry, an email scams from years past, and frankly still go around a little bit here, but large bounties are really becoming a part of the toolbox, a law enforcement's been using in the us and abroad to try and track them down.

    [00:34:44] And that's really what they're hoping for down in Costa Rica, because what are they going to do? Frankly, really what are they going to do? I don't know. And they obviously are relying on the United States to help them out with this. And the internal structure of the Conti group has been highly organized.

    [00:35:03] They've got the same type of structure of legitimate corporation would have it takes it to work that needs to be done. They hire contractors that may not even know who they're actually working for to write small pieces of a code here that gets tied. So it's not too surprising that a Conti affiliate is going to go far enough to cause a national emergency to be declared.

    [00:35:30] One of the things that Conti has done and some of these other ransomware companies have done companies gangs. They have ransomware as a service. So there's all of these people that are affiliated with Conti and all you have to do is get the Conti ransomware onto someone's computer and ta-da, they will pay you.

    [00:35:54] It's really that simple. They've got tech support for the people that are ran through there. They got ransomed to help them supposedly pay, right? How do I buy Bitcoin? And they'll walk you through. And then they will help you with restoring your files. Hopefully they can be restored. They are, they can't always be restorative.

    [00:36:15] I think right now the latest number I saw. How about 60% of people who have their data encrypted and ransomed are in fact able to get that data, but there's 60% of the data back. So that's not too big a deal, but Conti operates on affiliate. And this affiliate that went ahead and grandson and our friends in Costa Rica is called UNC 1 7 5 6, uncles, 7 56.

    [00:36:51] They're also suspected in other attacks on government servers, including a theft of intelligence materials. Peru. And this attacker has already leaked information stolen from Costa Rica and it's on the Conti ransomware dark web portal, which is online. And after the former president of the country refused to pay a $10 million ransom demand, they started leaking the data.

    [00:37:17] So in this case, focus has been on the national government agencies. They are potentially looking at what might you might call espionage, but these Conti ransomware affiliates have become famous for really quickly exploiting new vulnerabilities as they're published and being indiscriminate in who they attack, because $2 billion.

    [00:37:39] And then the other part that I think is really interesting here. W we're talking about money, we're talking about real money, obviously, Conti deals almost exclusively in Bitcoin, which can be hard to turn into hard currencies, but that our friends in Costa Rica have said, no we're not going to.

    [00:37:59] Knowing what has been stolen and what they no longer have access to. In fact, the president said that the company, the country Costa Rica is effectively at war. Now, they got a foothold Conti did in 27 agencies at different levels of the. And the yeah. Okay. So Conti is say, I'm looking at an article in the register here.

    [00:38:26] Conti is apparently has made more than 150 million from a thousand plus victims while we know it's actually 2 billion, but it depends on the timeframe that they're talking about. And the Conti says that they are determined to overthrow the government by means of a cyber attack. We've already shown you all the strength and power.

    [00:38:45] You have introduced an emergency. It's really quite something. Now I mentioned earlier today that I am. Taking all of the cyber security stuff that we have been using here over the years. Things like our plan of action and milestones documents and all of this stuff we use to run our projects for our customers.

    [00:39:11] It's the real stuff, people. And remember, I've been doing the cyber securities. Since the early nineties, so we know what we're doing, I know what I'm doing and I'm making it available for free. Okay, guys, you just have to send me an email [email protected]. So the first cyber punch list that we have that available, and all you have to do is ask for it again.

    [00:39:37] Me, M [email protected] is the. Email punch list. So with this punch list, I go through the things that you need to do. In order to secure your email and be more or less secure in your email. Now, I don't know about you. I do not like these long diatribes. I have a book behind me that is hardening windows 10 and it is in a four inch binder.

    [00:40:14] Cited. There are thousands of recommendations in there from Microsoft. There's a lot that needs to be done. So what I've done is boiled it down to the most important things. And as I said, it's available for absolutely. Free for you. It really is. If you're a listener, just email me M [email protected].

    [00:40:38] You can ask me to add you to my insider show notes and my little three minute trainings that we do every week. You can also ask for a cyber punch list that you might need. So it's just, okay, we need to do this. You need to do that. You need to do this. You need to do that. So it makes it very straightforward.

    [00:40:57] I'm trying to. To be, to see about any of this, but we have had amazing feedback on this from companies over the years, and now it's available to you for $0. Okay. So make sure you check it out. Craig peterson.com and you can always email me M [email protected] as well. Thanks for taking a little time with me today and look for me online.

    [00:41:24] Look for my emails and if you would please. Thumbs up on your favorite podcasting platform, YouTube or rumble or subscribe. Thanks.

    [00:41:37] We're going to talk about the Senate bill that has big tech scared, really scared. I'll talk about a new job site problem for a number of different industries because of hackers and cloud, the cost and reliability.

    [00:41:53] This tech bill. It has the Senate really scared.

    [00:41:57] He is frankly, quite a big deal for those of you who are watching over on of course, rumble or YouTube. I'm pulling this up on this screen. This is an article. ARS Technica and they got it originally from wired it's it was out in wired earlier in the month. And it's pointing out a real big problem that this isn't just a problem.

    [00:42:23] This is a problem for both the legislature. In this case, we're going to talk about the Senate and a problem for our friend. In big tech. So let us define the first problem as the big tech problem. You're Amazon. You are Google. Those are the two big targets here of this particular bill. We're going to talk about, or maybe your Facebook or one of these other Facebook properties, et cetera.

    [00:42:50] If you are a small company that wants to compete with any of these big guys, What can you do? Obviously you can do what everyone's been telling us. Oh, you don't like the censorship, just make your own platform. And there've been a lot of places and people that are put a lot of money into trying to make their own platform.

    [00:43:12] And some of them have had some mild successes. So for instance, I'm on. You can watch my videos there. And there have been some successes that rumble has had and making it into kind of the competition to YouTube. But YouTube is still the 800 pound gorilla. Everybody wants to be where the cool kids are.

    [00:43:32] So for most people. That YouTube. They look at YouTube as being the popular place. Thus, we should be, we are obviously saw the whole thing with Elon Musk and Twitter, and the goings on there. And Twitter really is the public square, although it's died down a lot because of this censorship on Twitter.

    [00:43:52] Interesting. So as time goes forward, these various big companies are worried about potential competition. So how do they deal with that? This is where the real problems start coming in because we saw Amazon, for instance, in support of an internet sales tax. You remember that whole big deal. The internet had been set aside saying, Hey, no states can tax the internet and that's going to keep the internet open.

    [00:44:21] That's going to help keep it free. And people can start buying online. And that worked out fairly well. A lot of people are out there, why would Amazon support a sales tax on the internet? They are the biggest merchant on the internet, probably the biggest merchant period when it comes to not just consumer goods, but a lot of goods, like a staples might carry for business.

    [00:44:45] So they'd have to deal with what they're 9,000 different tax jurisdictions in the United States. And then of course all these other countries, we're not going to talk about them right now, but the United States 9,000 tax jurisdictions. So why would Amazon support an internet sales tax when there's 5,000 tax jurisdictions?

    [00:45:10] The reason is it makes life easier for them when it comes to competition. So if you are a little. And do you want to sell your widgets or your service? Whatever it might be online. You now have to deal with 9,000 tax jurisdictions. It's bad enough in the Northeast. If you are in New Hampshire, if you live in New Hampshire and you spend more than, I think it's 15% of your time south of the border and mass, then mass wants you to pay income tax for that 15% that you are spending your time there.

    [00:45:48] Now they do that with the. Baseball teams with football teams, hockey, you name it, right? So the big football team comes into town. The Patriots are paying the New York jets or whatever it might be. The Patriots have to pay New York state taxes, income tax now because they stepped foot in New York heaven forbid that they try and do business there and help New York state out.

    [00:46:12] And they now have to pay income tax. Now they only have to pay income tax for, or for the amount of time. They're more New York. Various states have various weirdnesses, but if you're only playing 1, 2, 3 dozen games a year, It isn't like your normal work here, which is 2080 hours. We're talking about their plane to New York and they're only spending maybe 10 hours working in New York, but that represents what percentage, 10, 20, 30% of their income, depending on how many games they play and how they're paying.

    [00:46:45] And so they got to keep track of all that and figure it out. Okay. We played in New York, we played in New Jersey. We're in mass. We were they weren't in New Hampshire, certainly the Patriots plane, but they got to figure it all out. Guess what? Those big pay. Football players, hockey, baseball.

    [00:47:03] They can afford to have a tax accountant, figure it all out and then battle with them. I had a booth one time at a trade show down in Connecticut. Didn't say. Thing it was terrible trade shows, man. They aren't what they used to be. And they haven't been for a long time. This is probably a decade plus ago, maybe even 20 years ago.

    [00:47:26] So I had a little booth, we were selling our services for cybersecurity and of course, nobody wanted to bother pain for cybersecurity who needs it. I haven't been hacked yet. Although there's an interesting article. We'll talk about next week based on a study that shows. Small businesses are going out of business at a huge rate because of the hacks because of ransomware.

    [00:47:49] And if you're worried about ransomware, I've got a really great little guide that you can get. Just email me, [email protected]. I'll send it off to you, right? It's a free thing. Real information, not this cruddy stuff that you get from so many marketers, cause I'm an engineer. They'll go out of business.

    [00:48:10] So they figured I haven't got a business yet, not a big deal. And so no body. There's big trade show. And I was so disappointed with the number of people that even showed up for this silly thing. So what happens next while I get back to the office and about a month to two months later, I get this notice from the state of Connecticut they're tax people saying that I haven't paid my Connecticut taxes yet.

    [00:48:37] And because I was in connected. I should be paying my income tax for that day that I spent and wasted in Connecticut. Oh. And plus every company in Connecticut that I'm doing business with now, I need to collect their taxes and pay them the taxes that I'm collecting for those Connecticut businesses are resident.

    [00:48:59] I didn't sell a thing. You know what it took almost, I think it was three or maybe four years to get the state of Connecticut to finally stop sending me all of these threatening notices because I didn't get a dime from anybody in Connecticut. So I'd love the internet from that standpoint saying you don't have to collect taxes in certain cases, certain states, et cetera, unless you have a legal nexus or a legal presence there in the state. So back to Amazon, Amazon loves the idea of having everything on the internet packs. They love the fact that there's 9,000 plus tax jurisdictions. When you get right down to city, state county Lilian, either local taxes, or you look at those poor residents of New York state, or they're poor residents out in Washington state that have to worry about that, right?

    [00:49:52] There's county taxes, state sales tax. City sales tax, and income taxes are much the same, the, all of these crazy cities and states around the country. Yeah. The ones that are in serious trouble right now, they are those same ones. Those particular jurisdictions are hard to deal with. So from Amazon standpoint is just like the Patriots football players.

    [00:50:17] We've got plenty of money. We've got teams of lawyers. We have all kinds of accountant. We can handle this and you know why Amazon really loves it because it provides another obstacle for any competitors who want to enter the business. That's the real reason, so many big businesses don't go ahead and charge you serious money so that they can use that money against you.

    [00:50:48] Okay. You see where I'm going with this? Because if you want to start a business that competes with Amazon, if you want to have a doilies, you're making doilies. My grandmother used to make them all the time and she had them on the toilet paper in the bathroom, little doily holders. Doilies everywhere.

    [00:51:06] And then of course, the seashells shells on top of the toilet paper holders. If you want to do that and sell it, how are you going to deal online with 9,000 tax jurisdictions? All what you're going to do is you're going to go to Etsy, or you may be going to go to Amazon marketplace and sell your product there.

    [00:51:25] An Amazon marketplace. So Amazon is taking its cut out of it at is taking it's cut off. And you still ultimately have some of that tax liable. Amazon loves it. It's the same reason you see these groups forums, right? Barbers saying, oh, we've got to be regulated. Really you need to have a regulation in place for barbers.

    [00:51:49] You need to have licensing for barbers. Why do they do that? They do that. Not just barbers, right? It's all of these licensures and various states. They do that really to keep people. To keep their prices high. That's why they do it because someone can't just put up a sign and say, Hey, I am now a barber.

    [00:52:10] Come get a haircut. And if you don't like the barber, if they do a lousy job, you go elsewhere. We don't need all of the bureaucracy on top of this to enforce licensure. Anyways, when we get back, let's talk about that Senate. It's a big deal. And I am coming down in the middle of this thing. Hey, visit me online.

    [00:52:30] Sign up right now. Craig peterson.com and get my special report on passwords.

    [00:52:38] We just talked about why big business loves regulation. It helps protect them from up and coming small business, frankly, let's look at this bill, the Klobuchar and Grassley just introduced in the Senate.

    [00:52:54] I am coming down in the middle of this bill. And let me tell you why we really do have a problem with some of these big businesses.

    [00:53:04] For those of you who were watching here on rumble or YouTube, I'm going to pull this up. This is an article that was originally in wired and is in ARS Technica, great website. They got lots of good information and the title of the bill is a Senate bill that has big texts. So the question is why now are ours technical?

    [00:53:27] I'm going to scroll this down so you can see what they are saying. They're claiming that this is really apocalyptic that frankly the people who are pushing against this bill are obviously the wrong people and everything else. But I love this point here. This is from a senior VP of policy at Yelp.

    [00:53:50] You can see this on my screen. Luther Lowe. And he's talking about this bill. Actually one of two. Antitrust bills is what they're called in the us. There's voted out of committee by a very strong bi-partisan vote. And the other bill is to regulate app stores and there's issues with that too, that we won't really be talking about today, but they have to do with protecting you the consumer.

    [00:54:19] If you can load any app you want from any app store on the internet, on your iPhone, is your iPhone still? Versus having to get it from apple. We're not talking about that one right now. This is Congress's shot here to stop big tech companies from abusing what they're calling a gatekeeper status.

    [00:54:42] So we're going to talk about that. What is this gig key keeper status? What does that mean? So Luther low back to him, VP of policy at Yelp long time ago. Antagonist says it, the ball game. That's how these guys stay big and relevant. If they can't put their hand on the scale that it makes them vulnerable to small and medium-sized companies eating their market share.

    [00:55:11] Isn't that what I was. Protecting themselves, protecting themselves against the small startups. And if you've got government regulation on your side, you can just hammer them with the fact that, Hey, you guys aren't compliant, right? If you've got some major government regulation to just look at what happened with Elon Musk, when he said I'm going to buy Twitter, all of a sudden his.

    [00:55:40] And he, his Twitter account has problem. All of a sudden what w what his money has prompted. All of a sudden when Elon Musk's that I'm going to buy Twitter, the government started investigating Tesla. It's amazing. How these people work and how they think. It's just, it's absolutely amazing.

    [00:56:00] So they use these big companies, use government to beat other people over there. It's like my example of the barbers, right? Do we really need licensing for barbers? Do we really need to have a barber board that oversees barbers? If someone harms you, there are laws against that. No. When I was, for 10 years, I was in EMS.

    [00:56:26] I was a volunteer EMT. You guys know that emergency medical technician and my wife was. And if we were to cut someone's hair without their consent, that would be considered assault, even battery in some cases. So there's laws on the book to protect your hair. Okay. Need laws about barbers? We don't need laws about so many things.

    [00:56:52] The government sticks its fingers in. And so what is it? Stick his fingers in here. What are they trying to do? Let me pull that up on this screen for you. Senators Amy Klobuchar and Chuck Grassley, CR grassy, I should say, who were our, excuse me. So are the top Democrat and Republicans on the Senate judiciary committee are saying, Hey, we need to regulate how Amazon, how Google and these others can use their position in order to.

    [00:57:30] Keep their fingers off the scale. So bottom line, that, that sounds like a pretty good idea to me. And that's the thing that fits on the bumpers bumper stickers, stop Google from putting their thumb on the scale. Stop Amazon from putting the thumb on the scale because we have.

    [00:57:47] Actual problems with this. We have seen where people who are using Amazon marketplace to sell their stuff. Why would they do that? Obviously they've got to pay a percentage to Amazon plus depending on how your business operates, you have to pay Amazon to warehouse. You're good. Just for you. You have to pay Amazon for all the logistic services for shipping, for moving around between Amazon warehouses and then for selling it, it can get pretty darn expensive.

    [00:58:20] Okay. Amazon charges, that seems pretty fair to me, right? The libertarian mindset. Where's the problem. I don't see the problem, Craig. The problem is that Amazon has. Own products that they want to sell more than half of what's on the Amazon store is actually sold by third parties. And we've talked about that before.

    [00:58:42] We talked about problems with that before, but that means that what almost half of it is sold by Amazon. So Amazon has a number of brands. Last I checked, it was a few dozen brands that don't look like they're Amazon. There's a home services brand. There's a place that sells couches or Chesterfields depending on where you're from.

    [00:59:06] There's a whole bunch of different businesses, clothing, businesses, et cetera, that are actually Amazon who might've bought a company or they saw. That accompany was doing really well in their marketplace by selling item X. So what do they do? They go ahead and say, okay we're going to start making an item X, see where the problem comes in.

    [00:59:29] So Amazon is using these small businesses that put everything on the line, right? They might have their house leveraged to the max. They might have sold their house and living with somebody else, apartments are too expensive. The cash to get their business going. They scraped the money together.

    [00:59:46] Maybe they had to pay $5,000 to have a mold made injection mold, and then they have the stuff made in the U S or in China, or there they're trying to print it on a 3d printer for the. Concept. And they'd go through a number of different iterations of trying to make that product work and consumers to like it.

    [01:00:07] And consumers give them feedback saying, what, if this was a quarter in smaller or moved over there on the product, that would just be so much more useful. So they add that they had the engineering time, they've invested quarter million dollars. Easily to get the product off the floor to get it out there and people start buying it.

    [01:00:29] Where are they selling it? They got to really sell it on Amazon marketplace because who else are you going to go to for logistics, sales, support, everything else. And not to mention the tax jurisdictions that want to collect money from you. And then Amazon comes out with a competing. Is that enough to drive you crazy.

    [01:00:51] Now we've seen this forever in the software industry. Microsoft has done this for years. Apple does it to I'm looking at a screen right here in front of me. I hooked up to an apple mini. Some of the side card functions and stuff. They were developed by a third party that spent their blood, sweat, tears, and money on developing it.

    [01:01:16] And then along comes a big guy and you're out of business. We've got to finish this up. We will do that. When we get back, what's a Senate doing actually here. And what does it mean to you and me? Hey, visit me online. Craig peterson.com. Get my insider information for free.

    [01:01:38] We just talked about how big business uses its advantages to crush potential competition. Crush them. And it's a shame and it's happened to me and many people I know, and now the Senate's getting involved and making things worse.

    [01:01:55] This happened to me a number of years ago, and I will never forget it.

    [01:02:00] It was a really big lesson for me. I had designed and written a computer system that would take the code that it was written for a much older system. And run it for much less money. So bottom line here, this was a system called Cade computer assisted data entry that was made by Sperry way back in the day.

    [01:02:25] Yeah. I've been in there for that long and they had little programs, so they would not punch cards, but punch right on two tapes, those big nine track tapes and that information would then be used for processing later on then. People, big businesses grocery stores, you name it. We're using that Sperry system.

    [01:02:48] And I designed a system that would take their COBOL is what it was. It was a form of COBOL code from this cage system. And you could use my code to compile it and run it on a Unix system. So the cost involved here was that it would be cheaper to buy a whole new Unix computer and buy new terminals and do some slight training changes.

    [01:03:18] But the key punch operators would be exactly the same keystrokes as they were already used to. Okay. So you know how fast they were, so it wouldn't slow than none at all. And their cost would be. Then just the maintenance contract on the old Sperry cage. Very cool stuff. And I worked really well.

    [01:03:38] Then I worked with a couple of sales guys at spirit because Barry had a Unix tower system. It was a mini computer that was Unix space. And I had one, I had saved up my money. We bought this thing. It was a lot of money nowadays. It'd be about a hundred thousand dollars I spent on that system and it was really great.

    [01:04:00] Cool. So some grocery stores started using it. They used it to build the space shuttle to design it and send it into space. RCA, Astro space used it, my system, which is all really cool. So Sperry was interested in it saying, okay let's do this. Now. I had flown myself across the country too, because I was in California at the time to do some of this work for.

    [01:04:25] The for RCA Astro space for the space program and help make sure it was working and get it installed, help them configure it and everything else. So I had a lot of time, a lot of money, a lot of effort into this. It was a big venture. So Sperry invited me down to their headquarters down in blue bell, Pennsylvania to talk about this.

    [01:04:50] And I was so excited because their sales guys wanted to sell it. They gave me some free space in a booth in Las Vegas. So I was in the Sperry booth with them and, say, yeah, you can buy this. And you're using the Sperry, the new Sperry hardware. And I went down there and talked with them.

    [01:05:10] They never did anything with me, or, here's a huge investment young guy. And all of this stuff just worked and they had proof of concept. They had a couple of customers already using the system and it never materialized. And then about a year and a half later, I found out Sperry had tried to duplicate my system and had messed it up terribly.

    [01:05:35] It wasn't keystroke compatible. So anyone using the new Sperry system, they had to learn. Okay. So I got to hit this and I got to go over here and I got to click on this. Are you kidding me using a mouse? Aren't you not? These are data entry operators. They just go all day long, just typing and.

    [01:05:52] They had stolen my ideas. They messed it up. They didn't do as good a job as I did, which turns out it's pretty common. And they had stolen it. They stolen years of my life. So I've seen that before with me. I've seen Microsoft do that with friends of mine, and I've seen apple do it with various products that they've decided to release.

    [01:06:17] They all do it. Why do you think these businesses can not spend money on research and development, and yet at the same time, stay in business as technology's continuing to move forward? Why? The reason is. They don't have to do, or why would we do T wait a minute. Now, all we have to do is either buy the company or steal the product just re-engineer.

    [01:06:44] Oh. And if we want to buy the company, we can do what Microsoft has been accused of doing again and again, which is. We'll just Microsoft. Let's see here. I like that database is pretty darn cool. So here's what we're going to do. So Microsoft announces, Hey, we're going to have a competitor to that in coming out soon.

    [01:07:03] And then they sit there and they wait and they say, okay, how many people are going to ask about, oh wow. A lot of people asking for it. In the meantime, that company that had that great little database soft. Trying to sell it. And people are saying, wait, Microsoft is going to come up with a version of this.

    [01:07:18] I'm just, I'm going to wait. We can wait a few months. Let's see what Microsoft. So that poor company is now seriously struggling because this big company came out and made the announcement that they're going to do something like this. And then that small company gets a knock on the door. Hey, we're Microsoft or company X.

    [01:07:41] And we like your product. Wow. Okay. So we're going to do a buyout. We're going to we're just, oh, this is going to be fantastic. I might have to sign what a two year contract non-compete and help them manage it. Okay. We can deal with this. And then they find out that company X says Your company is not worth that much anymore.

    [01:08:02] Your sales look at their sales here, man. They've gone way down. Okay. So let me see let's do a nickel on every dollar evaluation you had a year ago. This happens every day, worldwide in America, it should never happen to anyone. And as you can tell, it upsets me. So what are Klobuchar and Grassley doing here?

    [01:08:30] Amy, when she was running for president, she made this big deal. I'm going to pull us up on my screen. Those of you who are watching on rumble or YouTube. And you can find all of that in my website, Craig peterson.com can see here. So they are trying to protect the American consumer, right? Yeah.

    [01:08:49] Yeah. That's it. They're gonna protect us. And so what they're doing is saying that. Would a rule ruin Google search results because that's what Google says. Is it going to bar apple from offering new features, useful ones on the iPhone? How about Facebook? Will it stop them from moderating content? So the legislation's core idea is we will just.

    [01:09:17] The marketplace take care of things. We're not going to let Amazon put their products in the product listings before third parties, but how are you possibly going to be able to regulate that stuff you can't, you can regulate it talking about a bureaucracy. You'd probably need one about as big as the federal government is right now.

    [01:09:41] And the federal government needs to be cut back in a major way. There's this two months. How about the 150 million Americans? This article brings that up to that are currently using Amazon prime, even though the price one hump. And they have it free to prime members. It's this is a big deal.

    [01:10:00] The bill doesn't mention prime. Doesn't mention Google by name, Amazon. But this is going to be a nightmare to enforce the bill is not specific enough. It should be voted down. And between you and me, I don't know what can be done about this other than to have additional marketplaces show up online. And you know what the conservative social media sites are starting to win.

    [01:10:29] So maybe there's hope.

    [01:10:32] We've got two things we're going to talk about right now. One of them is tech jobs. And man, is there a lot of scamming going on there as you might expect in the second is cloud, are you looking at cloud services? Hey, a home or business.

    [01:10:48] You can see this. I'm going to pull this up on my screen for those watching on rumble or on YouTube, but this is a big problem.

    [01:10:58] And we've seen this again and again right now, they're going after certain workers in the chemical. The sector, but it isn't just the chemical sector. What we've seen is the bad guys going after anyone that's applying for a job. So let me give you a few tips here. First of all, you should not be pain to apply for a job.

    [01:11:25] We see that all of the time when it comes to the head hunting firms, what. Is, they will charge the business who is looking to hire someone that makes sense to you. They'll hire they'll charge the business. So oftentimes it's a percentage of the annual salary committee where from usually 20% up to a hundred percent or more, depending on the position.

    [01:11:49] And boy can, they make a lot of money, but they don't necessarily place. People, but you know how it is right now, there, there can be quite a few. So people have been applying for jobs to make a lot of money and not realizing that fee that supposedly they have to pay is illegitimate. So remember that.

    [01:12:10] Okay. The second thing has to do with this particular scam, because what they're trying to do is. Into some of these companies. So they will send a thing out saying, Hey, on my head hunter, I'm here for you. We're going to get you this job you need to apply. Are you interested in a new job now? I've seen some stats online saying that somewhere around 30 plus percent of people are looking or at least open to.

    [01:12:45] Take getting a new job, which means a lot more are looking for jobs. Now I have to add to that, that the people who have jumped ship over the lockdown period really are not happy. The majority of them wish they had stayed where they were at. So keep that in mind too. But what they'll do is they'll say, Hey, listen.

    [01:13:07] Oh, there's this new feature on LinkedIn. By the way, you can say y'all are, I'm interested in looking for a job. I forget exactly what it says, but it goes around your picture and I have it up there because I'm a contractor, I go to businesses and I'm. To harden their cybersecurity. And we usually start slowly, especially with some of these startups we're doing work with right now where they won't, they go from a completely flat network and it's all engineers and I don't want anything hindering anything.

    [01:13:39] And so you got to work with them and it's just, we had a time sort of a thing. Okay. I just had this one thing this week. And then move on to one thing next week as well. So that's what I do for a living. And a lot of people are looking on LinkedIn and other places to find people who can be a chief information security officer.

    [01:14:01] So I'm what you call a fractional chief information security officer. I do this under contract and I've been doing contracts and contract work for. I don't know if I shouldn't be on the air, but my gosh it's been now I guess it's 40 years right now. So I've been doing this for a long time.

    [01:14:22] So I'm familiar with some of these scams, so they didn't take my word on some of this stuff. So what they do is they say, Hey, we've got a potential job opening. Are you in interested now? When we talk about 30 plus percent of people polled say that they're looking interested in a new job, the numbers are probably a little higher. Not that everyone's going to jump ship. Some people will, but there are a lot of people that if they get this email, they're going to open it up. And so what'll happen now is this group out of North Korea called the Lazarus group? And we've talked about them before.

    [01:15:00] We'll go ahead and say yeah, the here's, what's going to happen here. Let's just send you this thing. You can open it up. You can look at it and see if it's really a fit for you. I love this graphic that they have. This is from dark reading. I have it up on the screen again. Rumble and YouTube.

    [01:15:19] What should we do now? Should I open this up? Should I not open it up? It turns out that what's happening is that Symantec and Broadcom, both have noticed this and stated in an advisory a couple of weeks ago. Be very careful because what it's going to do is install a Trojan horse on your computer.

    [01:15:40] So let's think about this. You're talking about the chemicals. You have a lot of people who are very technical. And if a company wants to get some new technology, we talked about this earlier in the show, what did they do? Do they just go and say, oh, okay, let's get some R and D going here. Let me research and development.

    [01:15:59] Let's hire some scientists and do some pure science here, which are almost never happens anymore. No, what they do is they either buy a company, they steal a company's idea. If you are like the communist, you try and steal the technology directly. And that's exactly what these guys are doing. They put a Trojan on your machine because you open that file and that Trojan then gives you.

    [01:16:28] Oh, excuse me, gives them access to your machine. Now this particular Trobe Trojan is a malicious web file. Disguises. This job offer and your machine gets comparable. They attempt to compromise it, right? It's not always successful. They're not as many zero days out there for these lower level actors like North Korea, but they've been able.

    [01:16:52] Now, they're not just going after chemical sectors, they're going after it service providers. So companies like mine that provide managed security services for businesses, they are being attacked. So that's a problem too, isn't it? Because if you can compromise. A nine company and we've seen this all the time.

    [01:17:14] It's getting reported like crazy. You now have access to all of their customers because the it service company has passwords, et cetera. And they're probably using. Industry is number one or number two products for managing the customer's computers, neither of which are secure. And that's the biggest problem that we've had.

    [01:17:38] We use some of these things before, I'm not going to name them right now because it wouldn't mean anything to you anyways, but we had to get. We worked with our, it people inside the software companies that make the software that are used by the managed services providers. And we'd talked with their developers and said, Hey, listen, this is a serious problem.

    [01:17:57] That's a serious problem. You've got to change this. You got to change that. And what ended up happening? We left them because they weren't doing what they were supposed to be doing a very big deal. So they're targeting defense, contractors, engineering firms of any sort. They want to steal IP, intellectual property, pharmaceutical companies.

    [01:18:18] Yeah. Very big deal. These third hunting teams, including Cisco's, which are the guys that we use. Tallow sets again, an example of a big company buying a smaller company called telos that does threat intelligence and it looks at stuff. They're all reporting to this. So high level jobs in an industry or what you have to watch out.

    [01:18:40] It'd be very careful. Now, earlier this year, Lazarus group, again, North Korea went after some of these jobs people 250 that were identified working in the news media, software vendors, internet infrastructure providers, using job offers that appeared to come from. Disney, Google Oracle by the way, that was according to Google who tracked the campaign.

    [01:19:06] They know what their employees are doing, where they're going, what emails coming in. It's crazy. We're looking a lot of stuff. Okay. So I want to move on to the next topic here. Last one, this hour, but I'm gonna pull this up right now on my screen. You can have a look at it there. Of course, if you are at home.

    [01:19:27] You can or you really can't on the road. You can see this on rumble and also see this on the YouTube site. At least for the time being until I get kicked off right. Kicked off again. That seems to be the word of the hour, but cost reliability are raising concerns in. Again, this is a dark reading article, came out a couple of weeks back here, but the biggest concerns about cloud computing to what is cloud computing.

    [01:19:58] Let's talk about that first for a minute. Cloud computing is going online using something like salesforce.com. People don't think of that as cloud computing. But you have in Salesforce, all the communications with all of your customers, et cetera, that's an example of a platform as a service, basically. So they're providing you with everything and it's up in the cloud, nothing to worry about here, folks, but of course you have the same potential problems.

    [01:20:28] You do outs where people use what's it called now? Microsoft 365. Which Microsoft disclaimed any liability for any problems they cause for anything customers it's really crazy, but again, what are the problems there? Reliability slash performance, 50% of the people, 50% applaud on the screen.

    [01:20:51] Again here worried about reliability and performance, because if your business is relying on cloud computing, What, how is the security any good? That you could use something, as I mentioned Salesforce, and just picking them out of a hat and not, they haven't been like a terrible provider by any stretch.

    [01:21:13] But how about if you're going to Azure and you're using a workstation news here? How about if you're going to some other place, right? It could be Amazon web services. Google also has data processing services. Security's huge issue. Cost is a huge issue, reliability, performance, all of those. We're issues with more than 50% of the it professionals.

    [01:21:37] I'm surprised that this next one, which is our staff skillset on dealing with cog computing 26%. The reason I'm surprised by that is hardly anybody knows enough about cloud computing. Do we really confident about it? I'm serious about that. There's some companies right now, we're talking with a company called Wiz and they audit Azure configuration.

    [01:22:05] So be very careful if you're using. Particularly if you're a business, it may not work out well for you. Hey, make sure you go online right now. Craig peterson.com/subscribe. Sign up. You'll get my newsletters. You'll get all kinds of great information. Absolutely free Craig peterson.com including my special report on passwords.

    [01:22:29] Now, if you have any questions, just email me [email protected].

    1 hr 23 min
  • Do You Know How Crypto's Nose-dive Will Even Hurt Your 401K?

    Do You Know How Crypto's Nose-dive Will Even Hurt Your 401K?

    Hey, it looks like if you did not invest in "Crypto," you were making a smart move! Wow. We got a lot to talk about here. Crypto has dived big time. It's incredible. What's happened? We get into that and more.

    [Following is an automated transcript]

    Hi everybody. Craig Peterson here. Appreciate your joining me today. Spend a little bit of time with me. It's always a fun thing to do thanks for coming in. And Thanks for sticking around.

    [00:00:29] Crypto currencies. It's a term for all kinds of these basically non-government sanctioned currencies.

    [00:00:39] And the idea behind it was I should be able to trade with you and you should be able to trade with me. We should be able to verify the transactions and it's nobody's business as to what's happening behind the scenes. And yet in reality, Everybody's business because all of those transactions are recorded in a very public way.

    [00:01:03] So crypto in this case does not mean secret or cryptography. It's actually referring to the way the ledgers work and your wallet. And in fact, the actual coins themselves, a lot of people have bought. I was talking with my friend, Matt earlier this week and Matt was saying, Hey, listen I made a lot of money off a crypto.

    [00:01:29] He's basically a day trader. He watches it. And is it going up? Is it going down? Which coin is doge coin? The way to go? Because Elon Musk just mentioned it. Is it something else? What should I do? And he buys and sells and has made money off of it. However, a lot of people have. And held on to various cryptocurrencies.

    [00:01:51] Of course, the most popular one. The one everybody knows about is Bitcoin and Bitcoin is pretty good stuff, bottom line, but 40% right now of Bitcoin investors are underway. Isn't that incredible because of the major drop-off from the November peak. And this was all started by a problem that was over at something called Terra Luna, which is another cryptocurrency now.

    [00:02:22] Already that there is a ton of vulnerable vol a ton of changes in price in various cryptocurrencies, Bitcoin being of course a real big one where, we've seen 5,000, $10,000 per Bitcoin drops. It really is an amazingly fluid if you will coin. So there's a number of different people that have come out with some plans.

    [00:02:47] How about if we do like what the us dollar used to do, which is it's tied to a specific amount of gold or tied to a specific amount of silver. And of course, it's been a while since that was the case. President Nixon is the one that got us off of those standards. Having a gold, for instance, back in your currency means that there is going to be far less fluctuation and your currency means something.

    [00:03:16] See, the whole idea behind currency markets for government is yeah, you do print money and you do continue to increase the amount of money you print every year. Because what you're trying to do is create money for the. Good product services that are created as well. So if we created another million dollars worth of services in the economy, there should be another million dollars in circulation that's the basic theory.

    [00:03:46] Monetary theory, really boiling. Down now of course, already our government is printed way more than it. Maybe should have. It is certainly causing inflation. There's no doubt about that one. So they're looking at these various cryptocurrencies and say what can we do? How can we have a gold standard where the us dollar was the currency the world used and its value was known.

    [00:04:10] Having a stable currency is incredibly important for consumers and businesses. The business needs to know, Hey, listen, like we signed a three-year contract with our vendors and with our customers. And so we need a stable price. So we know what's our cost going to be, what can we charge our customer here?

    [00:04:30] Can the customer bear the price increases, et cetera. The answer to most of those questions of course is no, they really can't is particularly in this day and age. So having a. Fixed currency. We know how much it's worth. I know in two years from now, I'm not going to be completely upside down with this customer because I'm having to eat some major increases in prices.

    [00:04:55] And as a consumer, you want to look at it and say, wow, I've got a variable rate interest rate on my mortgage. And man, I remember friends of mine back in the eighties, early eighties, late seventies, who just got nailed by those. They had variable rate interest loan on their home because that's all they could get.

    [00:05:14] That's all they could afford. So the variable rate just kept going up. It was higher than credit cards are nowadays. I remember a friend of mine complaining. They had 25% interest and that's when they lost the house because 25% interest means if you have a hundred thousand dollar loan, you got $25,000 in interest that year, let alone principal payments.

    [00:05:36] So it, it was a really. I think it was really hard for people to, to deal with. And I can understand that. So the cryptocurrency guys. I said, okay, let's tie it to something else. So the value has a value and part of what they were trying to tie it to is the us dollar. That's some currencies decided to do that.

    [00:06:00] And there were others that tried to tie it to actual. Assets. So it wasn't just tied to the dollar. It was okay. We have X dollars in this bank account and that's, what's backing the value of our currency, which is quite amazing, to think about that. Some of them are backed by gold or other precious metals.

    [00:06:24] Nowadays that includes a lot of different metals. This one coin called Terra Luna dropped almost a hundred percent last year. Isn't that amazing. And it had a sister token called Tara USD, which Tara Luna was tied to. Now, this is all called stable coin. The idea is the prices will be staying.

    [00:06:46] And in the case of Tara and Tara USD, the stability was provided by a computer program. So there's nothing really behind it, other than it can be backed by the community currencies themselves. So th that's something like inter coin, for instance, this is another one of the, there are hundreds of them out there of these cryptocurrencies.

    [00:07:13] Yeah. The community backs it. So goods and services that you can get in some of these communities is what gives value to inter coin money system. Now that makes sense too, right? Because the dollar is only worth something to you. If it's worth something to someone else, if you were the only person in the world that had us dollars, who would want.

    [00:07:36] Obviously the economy is working without us dollars. So why would they try and trade with you? If you had something called a us dollar that nobody else had, or you came up with something, you made something up out of thin air and said, okay, this is now worth this much. Or it's backed by that.

    [00:07:56] Because if again, if he can't spend it, it's not worth anything. Anyhow, this is a very big deal because on top of these various cryptocurrencies losing incredible amounts of money over the last couple of weeks, We have another problem with cryptocurrencies. If you own cryptocurrencies, you have, what's called a wallet and that wallet has a transaction number that's used for you to track and others to track the money that you have in the cryptocurrencies.

    [00:08:29] And it's pretty good. Function or feature it's hard for a lot of people to do so they have these kinds of crypto banks. So if you have one of these currencies, you can just have your currency on deposit at this bank because there's a whole bunch of reasons, but one of the reasons is that.

    [00:08:50] There is a run on a bank, or if there's a run on a cryptocurrency, currencies have built into them incredibly expensive penalties. If you try and liquidate that cryptocurrency quickly. And also if there are a lot of people trying to liquidate it. So you had a double whammy and people were paying more than three.

    [00:09:13] Coin in order to sell Bitcoin. And so think about that and think about much a Bitcoin's worth, which is tens of thousands of dollars. So it's overall, this is a problem. It's been a very big problem. So people put it into a bank. So Coinbase is one of the big one called Coinbase, had its first quarter earnings report.

    [00:09:37] Now, this is the U S is largest cryptocurrency exchange and they had a quarterly loss for the first quarter of 2022 of $430 million. That's their loss. And they had an almost 20% drop in monthly users of coins. So th that's something right. And they put it in their statement. Their quarterly statement here is to, WhatsApp.

    [00:10:07] Here's the real scary part Coinbase said in its earnings report. Last Tuesday that it holds. $256 billion in both Fiat currencies and cryptocurrencies on behalf of its customer. So Fiat currencies are things like the federal reserve notes are U S dollar, okay. Quarter of a trillion dollars that it's holding for other people think of it like a bank.

    [00:10:36] However, they said in the event, Coinbase we ever declare bankruptcy, quote, the crypto assets. We hold in custody on behalf of our customers could be subject to bankruptcy proceedings. Coinbase users would become general unsecured creditors, meaning they have no right to claim any specific property from the exchange in proceedings people's funds would become in accessible.

    [00:11:06] A very big deal. Very scary for a very good reasons. Hey, when we come back a website, no, you go, you type stuff in my email address, do you know? You don't even have to hit submit. In most cases, they're stealing it.

    [00:11:23] I'm sure you've heard of JavaScript into your browser. This is a programming language that actually runs programs right there in your web browser, whether you like it or not. And we just had a study on this. A hundred thousand websites are collecting. Information upfront.

    [00:11:40] Hi, I'm Craig Peterson, your chief information security officer. This is not a surprising thing to me. I have in my web browser, I have JavaScript turned off for most websites that I go to now, Java script is a programming language and then lets them do some pretty cool things on a webpage.

    [00:12:02] In fact, that's the whole idea behind Java. Just like cookies on a web browser, where they have a great use, which is to help keep track of what you're doing on the website, where you're going, pulling up other information that you care about, right? Part of your navigation can be done with cookies. They go on and on in their usefulness.

    [00:12:23] Part of the problem is that people are using them to track you online. So like Facebook and many others will go ahead and have their cookies on the other websites. So they know where you're going, what you're doing, even when you're not on Facebook, that's by the way, part of. The Firefox browsers been trying to overcome here.

    [00:12:48] They have a special fenced in mode that happens automatically when you're using Firefox on Facebook. Pretty good. Pretty cool. The apple iOS device. Use a different mechanism. And in fact, they're already saying that Facebook and some of these others who sell advertiser in from advertisers information about you have really had some major losses in revenue because apple is blocking their access to certain information about you back to Jarvis.

    [00:13:24] It's a programming language that they can use to do almost anything on your web browser. Bad guys have figured out that if they can get you to go to a website or if they can insert an ad onto a page that you're visiting, they can then use. Your web browser, because it's basically just a computer to do what while to mine, Bitcoin or other cryptocurrencies.

    [00:13:51] So you're paying for the electricity for them as your computer is sitting there crunching on these algorithms that they need to use to figure out the, how to find the next Bitcoin or whatever. And you are only noticing that your device is slowing down. For instance, our friends over on the Android platform have found before that sometimes their phones are getting extremely hot, even when they're not using them.

    [00:14:18] And we found that yeah, many times that's just. Bitcoin miner who has taken over partial control of your phone just enough to mind Bitcoin. And they did that through your web browser and JavaScript. So you can now see some of the reasons that I go ahead and disable JavaScript on most websites I go to now, some websites aren't going to work.

    [00:14:40] I want to warn you up front. If you go into your browser settings and turn off JavaScript, you are going. Break a number of websites, in fact many of the websites that are out there. So you got to figure out which sites do you want it on? Which sites don't you want it on? But there's another problem that we have found just this week.

    [00:15:00] And it is based on a study that was done as reported in ARS Technica, but they found. A hundred thousand top websites, a hundred thousand top websites. These include signing up for a newsletter or making a hotel reservation, checking out online. You probably take for granted that you nothing happens until you hit submit, right?

    [00:15:25] That used to be the case in web one dot O day. It isn't anymore. Now I want to point out we, I have thousands of people who are on my email list. So every week they get my insider show notes. So these are the top articles of the week. They are, usually six to 10 articles, usually eight of them that are talking about cybersecurity, things of importance.

    [00:15:51] The whole radio show and podcasts are based on those insider show notes that I also share with the host of all of the different radio shows and television shows that I appear on. It's pretty, pretty cool. So they get that, but I do not use this type of technology. Yeah. There's some Java script.

    [00:16:11] That'll make a little signup thing come up at the top of the screen, but I am not using technology that is in your face or doing. What these people are doing, right? So you start filling out a form. You haven't hit cement. And have you noticed all of a sudden you're getting emails from. It's happened to me before.

    [00:16:31] Your assumption about hitting submit, isn't always the case. Some researchers from KU Leuven university and university of Lu sane, crawled and analyze the top 100,000 websites. So crawling means they have a little robot that goes to visit the web page, downloads all of the code that's on the page.

    [00:16:55] And then. Analyzed it all so what they found was that a user visiting a site, if the user is in the European union is treated differently than someone who visits the site from the United States. Now there's a good reason for it. We've helped companies with complying with the GDPR, which are these protection rules that are in place in the European union.

    [00:17:21] And that's why you're seeing so many websites. Mine included that say, Hey, listen, we do collect some information on you. You can click here to find out more and there's some websites let you say no. I don't want you to have any information about me where you collect information, just so that you can navigate the site properly.

    [00:17:39] Okay. Very basic, but that's why European union users are treated differently than those coming from the United States. So this new research found that over 1800 websites gathered an EU users' email address without their consent. So it's almost 2000 websites out of the top 100,000. If you're in the EU and they found.

    [00:18:07] About well, 3000 website logged a U S users' email in some form. Now that's, before you hit submit. So you start typing in your email, you type in your name and you don't hit cement. Many of the sites are apparently grabbing that information, putting it into the database and maybe even started using it before you gave them explicit permission to do.

    [00:18:36] Isn't that a fascinating and the 1800 sites that gathered information on European news union users without their consent are breaking the law. That's why so many us companies decided they had to comply with the GDPR because it's a real big problem. So these guys also crawled websites for password leaks and made 2021, and they found 52 websites where third parties, including Yandex, Yandex is.

    [00:19:11] Big Russian search engine and more we're collecting password data before submission. So since then the group went ahead and let the websites know what was happening, what they found because it's not necessarily intentional by the website itself. It might be a third party, but third-party piece of software.

    [00:19:33] That's doing it. They w they informed those sites. Hey, listen, you're collecting user data before there's been explicit consent to collect it. In other words, you, before you hit the submit button and they thought, wow, this is very surprising. They thought they might find a few hundred website. In the course of a year now they've found that there were over 3000 websites really that were doing this stuff.

    [00:20:01] So they presented their findings that use neck. Oh, actually they haven't presented them yet because it's going to be a useful. In August and these are what the cold leaky forum. So yet another reason to turn off JavaScript when you can. But I also got to add a lot of the forums do not work if JavaScript's not enabled.

    [00:20:23] So we got to do something about it. Maybe complain, make sure they aren't collecting your. Maybe I should do a little course on that once you can figure out are they doing it before I even give them permission? Anyhow, this is Greg Peterson. Visit me online, Craig Peter, som.com and sign up for that. No obligation insider show notes.

    [00:20:44] We are shipping all kinds of military equipment over to Ukraine. And right now they're talking about another $30 billion worth of equipment being shipped to what was the world's number one arms dealer.

    [00:21:00] I'm looking right now at an article that was in the Washington post. And some of their stuff is good.

    [00:21:07] Some of their stuff is bad, I guess like pretty much any media outlet, but they're raising some really good points here. One of them is that we are shipping some pretty advanced equipment and some not so advanced equipment to you. To help them fight in this war to protect themselves from Russia.

    [00:21:31] Now, all of that's pretty common. Ultimately looking back in history, there have been a lot of people who've made a lot of money off of wars. Many of the big banks financing, both sides of wars. Going way, way back and coming all the way up through the 20th century. And part of the way people make money in war time is obviously making the equipment and supplies and stuff that the armies need.

    [00:22:03] The other way that they do it is by trading in arms. So not just the supplies. The bullets all the way through the advanced missile systems. Now there's been some concerns because of what we have been seen online. We've talked about telegram here before, not the safest webs, app to use or to keep in touch.

    [00:22:28] It's really an app for your phone. And it's being used by. Ukraine to really coordinate some of their hacker activities against Russia. They've also been using it in Russia to have telegram that is in order to communicate with each other. Ukraine has posted pictures of some of the killed soldiers from Russia and people have been reaching out to their mothers in Russia.

    [00:22:57] They've done a lot of stuff with telegram. It's interesting. And hopefully eventually we'll find out what the real truth is, right? Because all of a sudden hides in the military, he uses a lot of propaganda, right? The first casualty in war is the truth. It always has been. So we're selling to a comm country, Ukraine that has made a lot of money off of selling.

    [00:23:22] Then systems being an intimate intermediary. So you're not buying the system from Russia? No. You're buying it from Ukraine and it has been of course, just as deadly, but now we are sending. Equipment military grade equipment to Ukraine. We could talk about just that a lot. I mentioned the whole Lend-Lease program many months ago now teams to be in the news.

    [00:23:50] Now it takes a while for the mainstream media to catch up with us. I'm usually about six to 12 weeks ahead of what they're talking about. And it's so when we're talking about Lynn Lee sent me. We're not giving it to them. We're not selling it to them. We're just lending them the equipment or perhaps leasing it just like we did for the United Kingdom back in world war two, not a bad idea.

    [00:24:16] If you want to get weapons into the hands of an adversary and not really, or not an adversary, but an ally or potential ally against an adversary that you have, and they have. But part of the problem is we're talking about Ukraine here. Ukraine was not invited in Donato because it was so corrupt. You might remember.

    [00:24:39] They elected a new president over there that president started investigating, hired a prosecutor to go after the corruption in Ukraine. And then you heard president Joe Biden, vice president at the time bragging about how he got this guy shut down. Yeah, he got the prosecutor shut down the prosecutor that had his sights on, of course hunter Biden as well as other people.

    [00:25:03] So it's a real problem, but. Let's set that aside for now, we're talking about Ukraine and the weapon systems who we've been sending over there. There have been rumors out there. I haven't seen hard evidence, but I have seen things in various papers worldwide talking about telegram, saying. The Ukrainians have somehow gotten their hands on these weapons and are selling them on telegram.

    [00:25:32] Imagine that a effectively kind of a dark web thing, so we're saying the byte administration okay. There, that none of this is going to happen. Why? Because we went ahead and we put into the contracts that they could not sell or share or give any of this equipment away without the explicit permission of the United States, governor.

    [00:25:57] Okay. That kind of sounds like it's not a bad idea. I would certainly put it into any contract like this, no question, but what could, what happened here? If this equipment falls into the hands of our adversaries or our other Western countries, NATO countries, how do you keep track of them? It's very hard to do.

    [00:26:18] How do you know who's actually using. Very hard to do so in forcing these types of contracts is very difficult, which makes the contract pretty weak, frankly. And then let's look at Washington DC, the United States, according to the Washington post in mid April, gave Ukraine a fleet of M 17 helicopter. Now, these are my 17 helicopters are Russian, originally Soviet designs.

    [00:26:51] Okay. And they were bought by the United States. About 10 years ago, we bought them for Afghans government, which of course now has been deposed, but we still have our hands on some of these helicopters. And when we bought them from Russia, We signed a contract. The United States signed a contract promising not to transfer the helicopters to any third country quote without the approval of the Russian Federation.

    [00:27:23] Now that's according to a copy of the certificate that's posted on the website of Russia's federal service on military technical cooperation. Russia has come out and said that our transfer, those helicopters has grossly violated the foundations of international law. And you know what they think it has, right?

    [00:27:43] Arms experts are saying the Russia's aggression Ukraine more than justifies you. I support, but the violations of the weapons contracts, man, that really hurts our credibility and our we're not honoring these contracts. How can we expect you crane to honor those contracts? That's where the problem really comes in.

    [00:28:07] And it's ultimately a very big problem. So this emergency spending bill that it, the $30 billion. Makes you crane, the world's single largest recipient of us security assistance ever. They've received more in 2022 than United States ever provided to Afghanistan, Iraq, or Israel in a single.

    [00:28:33] So they're adding to the stockpiles of weapons that we've already committed. We've got 1400 stinger and the aircraft systems, 5,500 anti-tank missiles, 700 switch blade drones, nine 90. Excuse me, long range Howard. There's that's our Chellora 7,000 small arms. 50 million rounds of ammunition and other minds, explosives and laser guided rocket systems, according to the Washington post.

    [00:29:03] So it's fascinating to look. It's a real problem. And now that we've got the bad guys who are using the dark web, remember the dark web system that we set up, the onion network. Yeah. That one they can take these, they can sell them, they can move them around. It is a real problem. A very big problem. What are we going to do when all of those weapons systems come back aimed at us this time?

    [00:29:32] It's one thing to leave billions of dollars worth of helicopters, et cetera, back in Afghanistan is the Biden administration did with her crazy withdrawal tactic. But at least those will wear out the bullets, missile systems, Howard, a different deal.

    [00:29:51] It seems like the government calls a war on everything, the war against drugs or against poverty. Now we are looking at a war against end-to-end encryption by governments worldwide, including our own.

    [00:30:07] The European union is following in America's footsteps steps again, only a few years behind this time.

    [00:30:16] But it's not a good thing. In this case, you might remember a few have been following cybersecurity. Like I have back in the Clinton administration, there was a very heavy push for something called the clipper chip. And I think that your whole clipper chip. Actually started with the Bush administration and it was a bad thing because what they were trying to do is force all businesses to use this encryption chip set that was developed and promoted by the national security agency.

    [00:30:52] And it was supposed to be an encryption device that is used to secure voice and data messages. And it had a built-in. Back door that allowed federal state, local law enforcement, anybody that had the key, the ability to decode any intercepted voice or data transmissions. It was introduced in 93 and was thank goodness.

    [00:31:19] Defunct by 1996. So it used something called skipjack, man. I remember that a lot and use it to transfer Dilley or defi, excuse me, Hellman key exchange. I've worked with that maybe for crypto keys that used it. Use the Dez algorithm, the data encryption standard, which is still used today. And the Clinton administration argued that the clipper chip was.

    [00:31:46] Absolutely essential for law enforcement to keep up with a constantly progressing technology in the United States. And a lot of people believe that using this would act as frankly, an additional way for terrorists to receive information and to break into encrypted information. And the Clinton administration argued that it would increase national security because terrorists would have to use it to communicate with outsiders, bank, suppliers, contacts, and the government could listen in on those calls, are we supposed to in the United States have a right to be secure in our papers and other things, right? That the federal government has no right to come into any of that stuff unless they get a court order. So they were saying we would take this key. We'll make sure that it's in a lock box, just like Al gore social security money.

    [00:32:41] And no one would be able to get their hands on it, except anyone that wanted to, unless there was a court order and you know how this stuff goes. And it just continues to progress. A lot worse. There was a lot of backlash by it. The electronic privacy information center, electronic frontier foundation boast, both pushed back saying that it would be.

    [00:33:05] Only have the effect of have not, excuse me, have the effect of, this is a quote, not only subjecting citizens to increased impossibly illegal government surveillance, but that the strength of the clipper Chip's encryption could not be evaluated by the public as it's designed. It was classified secret and that therefore individuals and businesses might be hobbled with an insecure communication system, which is absolutely true.

    [00:33:33] And the NSA went on to do some things like pollute, random number generators and other things to make it so that it was almost impossible to have end-to-end encrypted data. So we were able to kill. Many years ago. Now what about 30 years ago? When they introduced this thing? It took a few years to get rid of it, but now the EU is out there saying they want to stop and end encryption.

    [00:34:00] The United States has already said that the new director of Homeland security has, and as well as Trump's again Homeland security people said we need to be able to break the. And we've talked about some of those stories, real world stories of things that have happened because of the encryption.

    [00:34:20] So the EU is now got our proposal forward. That would force tech companies to scan private messages for child sexual abuse material called CSM and evidence of grooming. Even when those messages are supposed to be protected by indenting. So we know how this goes, right? It starts at something that everybody can agree on, right?

    [00:34:48] This child, sexual abuse material abductions of children, there's still a lot of slavery going on in the world. All of that stuff needs to be stopped. And so we say, yeah. Okay. That makes a whole lot of sense, but where does it end? Online services that receive detection orders. This is from ARS Technica under the pending European union legislation would have obligations concerning the detection, the reporting, the removal, and blocking of known and.

    [00:35:20] Child sexual abuse material, as well as the solicitation of children. So what we're starting to see here in the us is some apps, some companies that make smartphones, for instance, looking at pictures that are sent and shared to see if it looks like it might be pornographic in. Because again, we're seeing the younger kids who are sending pictures of each other naked or body parts and they get to others.

    [00:35:46] If you can believe that. Absolutely incredible. But what happens when you send them using an end-to-end encrypted app? Now, my advice for people who want to keep information private, you're a business person you're working on a deal. You don't go to Twitter like Elon Musk and put it out there for the world.

    [00:36:08] Although, I'm sure he's got some ulterior motives in doing that. You use an app called signal. That's certainly the best one that's out there right now. It provides a whole lot of encryption and privacy, and even has some stuff built in to break the software. That's often used to break into the end to end encryption systems.

    [00:36:29] So they're trying to get this in place here. They're calling it an important security tool. But it's ordering companies to break that end to end encryption by whatever technological means necessary. It's going to be hard because it's, frankly, it's going to be impossible for them to enforce this because you can take encrypted data and make it look like.

    [00:36:53] Anything, and man has that happened for a long time? Think of the microdots way back when, certainly in rural world war two and on, they were very popular there's techniques to encrypt data and embedded in a photograph and make it almost impossible to detect. So again they're not going to get to do what they're hoping to do.

    [00:37:18] And I think that's an important thing for everybody. Please pay close attention to, so they do want to get rid of end-to-end there's WhatsApp out there, which I don't really trust because it's owned by Facebook, but that's supposedly end to end. There's end to end encryption on apple. I message. Although.

    [00:37:38] Apparently, there are some ways to get into that. I think apple is now maintaining a secondary key that they can use to decrypt, but the back doors that the us has called for and other people have called for. I have been pushed back by companies like apple CEO, Tim cook, oppose the government mandated back doors.

    [00:38:01] Of course, apple got a major backlash from security experts when in veiled, a plan to how I phones and other devices, scan user photos for child sexual abuse images. That's what I was referring to earlier. And apple put that plan on hold and promised to make changes. But this is apple all over again. And it's hard to say what's the least privacy intrusive way, because if the ISP can read them all, if the company that's providing new with the app that you're using to send the message.

    [00:38:34] I can read them all, how much privacy is there and if they can read it, who else can read it and what can be done with it? Blackmail has happened many times in the past because someone got their hands on something. So what happens when a Congressman or the military or someone in the military uses that's another problem.

    [00:38:54] Because if we don't know the way the encryption is being used or is made just like, was true with a clipper chip. And then we move on to the next step, which is okay. So what do we do now with this data that we're storing? Are they going to keep that data confidential? Can they keep it out of the hands of the criminals.

    [00:39:17] We've certainly found that they just haven't been able to. And if you're talking about grooming, which is what the European union wants. In other words, someone that's trying to get a child to the point where they're doing something that would be important. You've got two. Look at all of the messages, you have to have them analyze by some sort of an AI artificial intelligence, and then ultimately analyzed by people.

    [00:39:42] It's just going to get worse and worse. This is the most sophisticated mass surveillance machinery. That has ever been deployed outside of China in the USSR. It's absolutely incredible when you look at it from a crypto graphic standpoint. And again, we understand protecting the children. We all want to do that, but how far will this end up going?

    [00:40:06] I also want to point out that. Nu insider show notes that I've been sending out over the last few weeks have had some amazing responses from people. I've had people saying that this is what they look for in their mailbox. It's the first piece of email they read that it's the most relevant news. But you can only get it one way and that's by going to Craig peterson.com, you can sign up there.

    [00:40:33] It's easy enough to do. There's no obligation on your part, right? This is not my paid newsletter. This is absolutely free. And it's incredibly valuable. Plus I'll also be sending you once a week. Ish, a small training, just, it takes you a few minutes to read. I just last week went through the firewall in your windows machine, the firewall.

    [00:40:56] And gave you step-by-step instructions. Is it turned on? What is it doing? What should it do? How do you turn it on and how do you use it? So you can only get that one way and that's, if you are on my email list, so it's important to be there. And if you have any questions, you can hit reply. Any of those emails where there's a training, or if it's the insider show notes, just hit reply.

    [00:41:22] And I'll go ahead and answer your question. You might have to wait a few days cause I can get pretty busy sometimes, but always answer. So me M [email protected]. Anybody can send me email and you can also text me at 6 1 7 503 2 2 1 6 1 7 5. 3, 2, 2, 1 with any questions? That's it for right now, there is so much more.

    [00:41:51] Make sure you sign up right now. And of course there's more coming right up. So stick around. .

    [00:42:04] Jam packed today. We're going to start with non fungible tokens. If you don't know what those are, this is a very big deal because so many people are investing in them right now. Are they really investments? I've got a bit of a blow back here. Most people think that Bitcoin is anonymous. We're going to talk about how it absolutely is not.

    [00:42:24] We're going to talk about anonymous. In fact, the Russians, Microsoft, what they're doing against the Russians and this little comedic thing about cars.

    [00:42:32] NFTs or very big deal.

    [00:42:34] I'm going to pull up here on my screen right now. This is a picture of Mr. Jack Dorsey. We'll go full screen, an article from a website called CoinDesk. CoinDesk is one of these sites that really tries to track what's happening out there in the Bitcoin community. Of course, nowadays it's much more than Bitcoin.

    [00:42:57] Isn't it? We're talking about all kinds of. Different currencies that have a blockchain backend. They're called cryptocurrencies basically. But the big one was of course, Bitcoin. And there is a whole concept. Now, when we're talking about things like cryptocurrencies and these non fungible tokens. People have been investing them in them.

    [00:43:23] Like crazy people are making millions of dollars every week. Now, remember, I am not an investment advisor and particularly I'm not your investment advisor. So take all the. To your investment advisor. I'm not telling you to buy them. I am telling you to be cautious here though, because these non fungible tokens are designed to give you the ability to be able to just, own something in the digital world.

    [00:43:52] What might you own in the digital world? We've had a lot of different stuff. We've seen some just crazy monkey things. Have you seen those, these little pictures of monkeys there? Graphic designed and it's all animated. If you will. It's like cartoons and people pay money for them. One of the things that people paid money for was the rights to the first tweet ever on Twitter.

    [00:44:20] So that's what you're getting. When we're talking about an NFT on a non fungible transaction, it is now yours. So this particular NFT we're talking about was of our friend here, Jack Dorsey. We'll pull it up again, this article, and he had a tweet that was sold last year for $48 million. That is a lot of money.

    [00:44:47] So people look at this as an investment, but it's not the same as hanging art on the wall. You've got a Picasso that has some intrinsic value. It's a painting. It has all the oil paint on that, it was designed by and painted by a crazy man years ago. And you can take that Picasso and you can.

    [00:45:11] Turn it around and sell it. It has some real value. If you own the rights to something, let's say it's one of these monkey pictures. It reminds me of a postage stamp and you paid real money for it. Some of these things are going, as I said, for over a million dollars and this Jack Dorsey first tweet went for $48 million.

    [00:45:31] So let's say that's what you did, right? You bought this thing for $48 million. Really? What do you have? Because anybody can go online and look at that tweet. Anybody can print it up and stick it on a wall. Anybody can go out and get that picture of the monkeys right there. The guy drew, and you can look at it.

    [00:45:54] In fact, I can pull it up right now, if you want to do. But people paid real money for that. So they've got what really? What do they have? You can't take it off the wall, like you're Picasso and salad, right? Or Banksy, if you're into the more modern art, it's just not. What is doable? How do you make this work?

    [00:46:15] Only the NFT only gives you bragging rights in reality. That's what it does. You have bragging rights because you could take that digital picture and make a hundred quadrillion copies. Yeah, you'd still own the NFT you would still have in the blockchain for whatever NFT company you're using the rights to it.

    [00:46:41] They would say this, you owned it. So let's talk about the blockchain behind it. There are a lot of companies that are trying to give you that. Okay. All right. I get it. Yeah, I get to to own it. But who's running the blockchain behind it. Who's validating that you own it with Bitcoin and many of these other blockchain currencies that are out there.

    [00:47:08] There are various. Companies and individuals who are registered, who have all of the paperwork, if you will saying who owns, how much of what, and who paid, who and everything. And that by the way, is why it takes so long for some of these Bitcoin and other transactions to occur. But how about the NFT? There are tons of companies out there that say they will certify the NFT.

    [00:47:38] So it gets to be real problem. And when we get into this Jack Dorsey tweet and this article about it, which are let me pull it up again here for you guys. This guy Sina bought the very first tweet ever from Twitter founder, Jack Dorsey for $2.9 million last year. And he decided that he wanted to sell it.

    [00:48:07] So he listed it for sale again at $48 million last week. Real. He put it up for open bid and this article and CoinDesk is talking about that. And you can see that if you're watching me on rumble or YouTube, I'm showing you my screen here right now. But this Iranian born crypto entrepreneur named of again.

    [00:48:32] As TAVI purchased it for $2.9 million in March, 2021. Last Thursday, he announced on Twitter where out, that he wanted to sell this and Ft. And he said, Hey, listen, I'm going to put 50% of the proceeds to charity while the auction closed. This was an open auction. People could go and bid on it and head auction closed.

    [00:49:00] With a, an offer of basically $288, $277 at current prices when this article was written $277 and the lowest bid was $6. And as I recall, this is not in this article, but there were only. I handful of bids. Like when I say handful, I mean a half a dozen beds. Crazy. This is a real problem because the deadline is over.

    [00:49:31] He paid how much for it, right? How much did he pay? Pull that up again. $2.9 million last year. And his highest bid was in the neighborhood of $280. Isn't that crazy. So did he get money on this? Did he win money on this? I don't know. I'm looking at those saying is it worth it to buy something like that?

    [00:49:59] That you might think, oh, the very first apple computer, an apple. While that's going to be worth some serious money. Yeah, it is. It's something, you can grab onto, you can hold onto it, it's something and you can sell it. You can trade it. You can take a picture of it. You can't make digital copies of it.

    [00:50:20] You, you, it's a physical thing. That's worth something. Same thing with that Picasso on the wall, it's really worth something that has some basic intrinsic. Jack's true tweet. The very first tweet. How much is that thing worth? It basically nothing. So the tweet is showing he'll pull it up on the screen again that he's selling ad Jack 2000 6 0 3 21 at eight 50 14:00 PM.

    [00:50:50] Just setting up my Twitter. So there you go. There's Jack is very first to. And it's absolutely amazing. Is it worth it? Let me pull up some other stuff here for you guys. I'm going to pull this up here is Coinbase launching an NFT marketplace in hopes of appealing to crypto on mainstream users. So here's some examples from a man and FTEs.

    [00:51:16] I'm going to zoom in on this for those of you guys watching on rumble or on Twitter. All right. Mean. Yeah actually you can see it on Twitter too, but YouTube, here you go. Here's some NFTs it's artwork and it's a creature. So you can buy creature number 7, 8 0 6 right now for six Eve. So let me see.

    [00:51:39] Value of six. Ethereum is what ether, M two us dollars. So for 3000. And $84. As of right now, you can get a crappy picture that even I could have draw okay. Of this guy and look at all of the work this artist has put in. There's how many of these up here? 1, 2, 3, 4, or five, 10 of them. And it's the same head.

    [00:52:08] Each time it looks like this almost the same eyes. He changes colors and he's got different background. It's absolutely not. So that's what they're trying to do right now, trying to sell these NFT. So who's going to buy that. Who's going to pay $3,000 for artwork that hunter Biden could have done with a straw.

    [00:52:30] Anchored around. Here's another one. This is from ledger insights. NBA's launching dynamic NFTs for fans, baseball cards for the NBA that are basically just worthless. They're NF. Non fungible tokens. It has taken the crypto world by storm and people are losing millions as you look, but it really is changing the e-commerce world.

    [00:52:58] Stick around. We'll be right back.

    [00:53:02] Bitcoin blockchain. All of the rage, a lot of people are talking about it, but I got to say most people who are talking. I don't know much about it. And when it comes to anonymity, Bitcoin is probably the worst thing you could possibly do. It's amazing.

    [00:53:20] There are a lot of misconceptions out there when it comes to technology, you have almost any kind of technology and blockchain and Bitcoin are examples of a very misunderstood technology.

    [00:53:35] Now I'm not talking about how does it work? How are these ledgers maintained? How does this whole mining thing work? Why has Chan. Bandit. Why are a lot of countries going away from it, one country. Now the dictator said, yeah, we're going to use Bitcoin as our we're official currency. In addition to the U S dollar what's going on.

    [00:53:57] It is complicated behind the scenes. It's complicated to use. Although there are some entrepreneurs that have made some great strides there. I saw a documentary on what has been happening in that one country. I mentioned. They are able to pay in us dollars using Bitcoin. So they'll go up to a vendor on the street.

    [00:54:22] Quite literally they'll have their smartphone with them. The vendor has their smartphone. They type in 15 cents for the taco and a hit send. It goes to the other person and they have 15 cents worth of Bitcoin. By the way, these types of micro-transactions with the way Bitcoin is structured behind the scenes, make things even less manageable in the Bitcoin world than they have been in the past.

    [00:54:50] And that's why in case you didn't know, Bitcoin is making some major changes here fairly soon. They've got to change the way all of this ledger stuff works because it takes too long. To record and authorized transactions. And these ledgers just get way too long when it comes to all of these kinds of microtransaction.

    [00:55:14] So there's stuff going on, Bitcoin, there, there are many of these types of currencies out there. Theories comes one. You've heard about doge coin because of course that's Elon Musk has been talking about and many others and they're all different somewhat, but the main concepts are the. One of the big concepts, I'm going to pull an article up here on the screen for those watching on YouTube or also on rumble.

    [00:55:39] But this is an article from our friends at wired magazine. And now you have subscribed to wired for many years. This particular one is about what wired is calling the crypto. Trap now that's a very big deal. It is a trap and it's a trap and a lot of different ways. And that's what we're going to talk about right now.

    [00:56:05] Crypto is not what its name implies. A lot of people look at it and say, oh, crypto that's cryptography. That's like the German enigma machine in world war two and all of this new, great crypto that we have nowadays. And there are some pretty amazing new cryptographic technologies that we've been using, but no, that's not.

    [00:56:26] What's really going on. You see the basic premise behind all of these technologies is the concept of having a. And this wallet has a unique identifier. It has a number assigned to it. So if I'm sending money to you, I'm going to have your wallet, ID, your wallet number, and I'm going to now send you some amount of fraction, most likely of a cryptocurrency.

    [00:56:55] It's certainly if it's Bitcoin, it's almost certainly a fraction. And so I'm going to send you $100 worth of, let's say. What ends up happening now is these ledgers, which are public, are all going to record the Craig's sent you a hundred dollars worth of Bitcoin. Of course, it's going to be in a fraction of a Bitcoin.

    [00:57:16] So sometimes there's rounding errors is not going to be really exactly a hundred dollars. Plus there's the amazing amount of. Tivoli volatility in the cyber currencies. So even though I meant just hitting a hundred dollars, mine ended up being 110 of it goes up. It might be 90. If it goes down you get that.

    [00:57:34] You don't understand how that works. So the problem now is I have sent you a hundred dollars. And public ledgers that anyone can gain access to now say wallet number 1, 2, 3, 4 cent, a hundred dollars, two wallet, number 5, 6, 7, 8. Obviously the wallet numbers bruises a lot longer than that. So then it's fine.

    [00:57:58] And there's a degree of anonymity there it's really called pseudo anonymity because in reality, it's not completely anonymous because people know the transaction occurred and they know the wallet numbers. Correct. It's like a bank account, and if I'm putting money into your bank account, that bank account number knows that the money came from a check that I wrote.

    [00:58:21] Can you imagine that someone writing a check and that check I had a number on it, a bank account number, right? So it can all be tracked while much. The same thing is true when it comes to cryptocurrencies, these cryptocurrencies are in public ledgers and those public ledgers can be used with a little bit of work to figure out.

    [00:58:42] Who you are. So this article here from our friends at wired gets really hairy. And it might be of interest to you to read, but this is talking about a take-down that happened, and this is a massive take down. This take down was of a whole group of people who were involved in some really nasty stuff.

    [00:59:09] In this particular case, what it was kitty. Just a terrible thing and the abuse surrounding it. So this logical goes into not a lot of detail. I'm not going to read it because here on the air, because I don't want to upset too many people. Cause it's some of the details of this evening to think about them are incredible.

    [00:59:29] But. This the police broke into this middle-class suburb home in the outskirts of Atlanta. And he there was Homeland security. It was a guy from the IRS and they came in, they took all of their electronic devices. They separated the family, putting the father who is an assistant principal at the local high school assistant printers.

    [00:59:57] And he was the target of this investigation. So they had him in one room, they had his wife and another room and they put the two kids into a third room and they started questioning him. Now, this is part of a takedown of a, as I said, a whole ring of these people, including this assistant. Principal at a school.

    [01:00:20] Can you believe that? So this IRS guy had flown in from Washington DC to have a look over what was going on, but this agent from the IRS and his partner whose name is let's see, his name was Jenn S Scouts. I probably got that wrong. And Tigran GAM bar Yan, Cambodian, and they had a small group of investigators and they were at a whole bunch of different federal agencies, not just the IRS.

    [01:00:48] What once seemed to be. Untraceable was no longer traceable. Now I've talked on this show before about a lecture I went to by the secret service about how they had tracked down and shut down the world's largest website that was being used to sell illegal materials online. And it's fascinating what they did.

    [01:01:12] But frankly, they're calling this particular boss to proof of concept and that's why they are IRS was in on this as well, but it was huge. Here's a quote from the IRS agent in this wired magazine article. He's saying he remembers how the gravity of this whole thing. Let me pull this up on the screen too.

    [01:01:32] So you can read along here, but this was a high school administrator, a husband, and a father of two, whether he was guilty or innocent. The accusations, this team of law enforcement agents were leveling against him. There are mere presence in the home would almost certainly ruin his life. And he, as well as these other people were counting on anonymity from Bitcoin.

    [01:01:59] Now, obviously I'm glad they got taken down, but listen, folks, if you think that it's safe, that it's anonymous, it ain't Bitcoin just ain't there. Craig peterson.com stick around.

    [01:02:15] I've been blamed for really complaining about people not updating their software. And that includes things like firewalls. The FBI has stepped in and they are going ahead and doing updates for you.

    [01:02:30] So once you get into this, because this is, I think something that should concern all of us, what should we be doing as a country?

    [01:02:40] People are. Updating their software. They're not updating their hardware. And particularly our hardware take a look at what's been happening with the firewalls and the firewall concerns. Everybody has some sort of firewall will almost everybody, but enough people that we can say, everybody has a firewall, you get your internet from you, name it.

    [01:03:05] And because of the fact they're using something called Nat network address translation, they've got some sort of firewall in front of you. So for instance, You've got your phone, right? You're using your phone and it's got internet on it. You're going through whoever your carrier is. And that carrier is giving you internet access, right?

    [01:03:28] They don't have enough IP addresses, particularly IPV four, in order for you to get your very own unique little address out on the. No they do. When it comes to V6 things a little bit different, but your device is not completely exposed on the internet. Windows comes to the fire. And by default, the windows firewall is turned on.

    [01:03:50] Now this gets more than a little concerning because that firewall that's turned on. Isn't really doing anything because I've got a firewall turned on and yet every service is accessible from outside, which is defeating the purpose of the firewall. Again, it's a complaint I've had about Microsoft now for.

    [01:04:10] Decades, which is they have features that are just check boxes. Yes. Yes. It's got a firewall. Yeah, it's turned on, but the features don't work. So having a firewall and having everything open defeats the purpose of a firewall max do not have a firewall turned on by default, but they do have their services disabled.

    [01:04:33] Which is just as effective if not more effective. So one of the things we advise people to do is go into your windows system, into the firewalls and your security settings, and turn off any services that you're not using. If you're not sharing file systems, then turn that off. In other words, You're mounting the G drive or whatever you might call it from another computer, then you don't need it.

    [01:04:59] If you're not as server for what's called SMB, then you don't need to share it. So turn off everything that you don't need. That's going to happen is one of your programs isn't going to work, right? And the, what you did last year, you're going to turn it back on and you can do a lot of research online to find out what they are.

    [01:05:18] We have over 200 settings that we change in windows. When we get a customer. Now on the Mac side, you can turn it on. I liked turning it on. I liked turning off the ability to see my machine. So in other words, the ability to be able to. So I turned it on and I enable specific services. And again, you can do some research on that.

    [01:05:44] I've got an improving windows security course that people have taken, and we should probably do that again, if not just have some free webinars on how to do this. So you guys can learn how to do it, but not that hard to do. Anyhow, bottom line is. People aren't updating their computers, even the Macs and windows.

    [01:06:06] We have a client that would just started a new client and we're tightening things up and we've been finding Mac computers that are major multiple major revisions behind. And that to me is shocking. Apple Macs are just so easy to update. It is extremely rare that an apple update will make your computer break unlike in the windows world, where it's pretty common.

    [01:06:32] So windows guys, I can understand, but your even more exposed, your bigger target, you need to keep up to date. So how about all of the other equipment that we. I've had warnings again and again, with you guys about what's happening with our smart devices that are out there, right? Our security cameras we have up in the corner, right?

    [01:06:56] We have these smart thermostats, people are using the list goes on and on of all of this equipment that we're using that is exposing us because when was the last time you have. How about the firmware in your router or your wifi, right? Some of the devices that I recommend to people, and if you have any questions, just email me M [email protected].

    [01:07:19] I can give you recommendations, even if you're a home user. Although my business obviously is working with businesses on what kind of wifi to buy, what you should get, what you should do. I don't charge for any of that stuff. Okay. You get it. But you have to ask. [email protected]. So you get this information and you go ahead and you buy whatever it is, but you don't keep it up to date, which is why I tend to only recommend stuff that automatically updates.

    [01:07:48] But that also means every few years you're going to have to replace it because unless you're using the good Cisco equipment where you can get a seven year life out of it you're not gonna find that in consumer grid. So what's happened here. I'm going to pull this up on my screen for people watching this on YouTube or on rumble.

    [01:08:07] But here is a thing that came straight out of our friends here from the FBI. This is from CSO. This is a a magazine that I do follow. But they're talking about what they call psych clock. Blink. So the article says for the second time in a year, the FBI has used search and seizure warrant to clean malware from devices owned by private businesses and users without their explicit approval.

    [01:08:40] The FBI used this approach to disrupt a botnet, believed to be the creation of right. Government hackers. So the calling this SYEP clock cycle clubs, blink malware discovered earlier this year. So here's the problem. What do you do if you're the federal government, how do you try and keep your country safe?

    [01:09:05] Now we know. We've got these military contractors. They make missiles that take out missiles, right? The provide defensive systems. You've heard of iron dome from years ago, all the way through all of the current stuff. That's what they do, but what do they do? What can they do when there's a botnet? A botnet is where there are multiple computers in this case, probably tens of thousands of computers located in the United States that are acting like sleeper.

    [01:09:36] They sit there and they wait for commands as to what they should do. Should they try and attack a machine? Should they try and spread more? Malware, what should they be doing? And the, these things are vicious. They are absolutely nasty. And in this case, we're looking at Russian malware. So Russia effectively like the Americans.

    [01:09:59] You might remember that TV show. It was great show, but that. Computers that are owned by you and me and our businesses and government agencies that are under the control of the Russians. Now you don't even know it. You're using your computer or you're playing games. You're going to Facebook, whatever it is you do on your computer.

    [01:10:20] Your computer is under command and control of the Russians. So the FBI goes to a court and says, Hey, we've got to go ahead and shut this down. We need a warrant. They get the warrant and the search and seizure warrant lets them now. Get on to these machines that are part of the bot net or the controlling machines for the bot net, and either remove the malware or go ahead and take control of the botnet themselves.

    [01:10:49] So it can't be used. And by the way, our friends at Microsoft they've gotten involved in this too, which is really frankly, cool in shutting down some of these botnets, Hey, I want to encourage everyone. Take a couple of minutes, go to Craig peterson.com/subscribe. That's Craig Peterson. CREI G P T R S O N.

    [01:11:12] And subscribe, and I'll be sending you a special report on passwords. Plus two more. I send out the most popular special reports that anybody has ever asked for.

    [01:11:25] Hey, I've got a little bit more to discuss on what's happening with Russia and Microsoft and more, but I'm also going to talk about QR codes. There is a great explanation. That's in your newsletter from Monday about why you shouldn't trust him.

    [01:11:41] Let's finish up this Russian thing. And then we're going to get into why you cannot trust QR codes and a brand new way.

    [01:11:51] The bad guys are using QR codes to really mess with us. Now, if you're watching over on either YouTube or on rumble, you'll see this. Let me pull up my screen for you. But here we go. Okay. This is very interesting. Then the last segment, we talked a little bit about what our friends over at the FBI had been doing, which is they have been removing malware from people's computers because people haven't been keeping their computers up-to-date right.

    [01:12:26] Part of the botnets. So we explained. At the FBI, isn't the only one out there trying to stop these Russians and the hackers anonymous has been very big at it. In fact, let me pull up this other article. This is from security affairs. And here we go. And it's talking about this whole army of these anonymous hackers.

    [01:12:50] Now none of us have been a nightmare for many businesses that they didn't like. I had an anonymous we'll go ahead and they'll do usually pretty basic stuff. They'll do denial of service attacks and some other things, so they don't like you because of. The don't say gay bill in Florida, and, without bothering to do any research, they'll just start attacking organizations that support it, or organizations that don't support it depending on how they want to do it. So this is an interesting article here, because it's talking about these various. Websites that they've hacked. Now, some of them are government site and some of them are private industries. Now, one of the cool things, bad things about hacking private industry and releasing the emails is now the competitors to these businesses know what they're doing.

    [01:13:46] And in some cases there's proprietary technology that's being released. Now, when it comes to Russian proprietary technology. The Western world doesn't care a whole lot about some of it, but here's some examples of what these hacktivists of GoDaddy. This is a company called forest 37,000 emails stolen from the company, Russian logging and wood manufacturing firm.

    [01:14:09] Again, it would give a little bit of an idea into the whole Russian, what are they doing? In the forest industry. This one, I think is a little more concerning for the Russians Aero gap. This is an engineering company that focuses in the oil and gas industry. Their clients include a whole bunch of Russian companies.

    [01:14:30] They've leaked approximately 100,000 emails from Aero gas. That is a huge deal because so much of the country's revenue, the number one industry in Russia is oil and gas. Petro Fort one of the largest office space and business centers in St. Petersburg, the hackers have leaked approximately 300,000 emails from Petro fork.

    [01:14:56] Again, you can use that to find out what's happening in your economy. What. Doing how are businesses doing? Are they going to go under so you can see some tweets here. I've got them up on my screen on YouTube and rumble anonymous. What they're saying that they've done and you can follow anonymous directly on Twitter.

    [01:15:14] Particularly fond of them. They've done a lot of things that I disagree with. This is really telling us about a whole new approach to warfare, right back in the day, you and I couldn't get involved, we could potentially take up arms and go and fight right there and think about the Spanish American war.

    [01:15:33] Think about what's happening now in Ukraine, where Americans have just gone over there. Taken up firearms in order to help them defend Ukraine. People who are maybe of Ukrainian descent, maybe not right. We have never seen this type of involvement by average citizens because anonymous is not like some big fancy company or government agency anonymous is a bunch of people who are trying to be anonymous and do something.

    [01:16:05] So they stole 145 gigabytes. Look at this. It's just crazy. So here. The anonymous Twitter thread itself, right? Talking about what. It's absolutely incredible. Incredible. So that's what anonymous is up to. They are hacking Russia and they're hacking Russia in a big way. Now, next stop. We have our friends at Microsoft.

    [01:16:30] Microsoft has been seizing Russian domains that they are accusing of having been linked to these Russian hackers that have been going after think tanks and government agencies in the U S and the. He knew, I shouldn't say which I'm sure includes the UK cause UK has gotten involved. So this article from the verge is talking about how Microsoft has seized seven domains, belonging to fancy bear apt 28, which is we've seen them active in a number of companies here, right in the Northeast United States.

    [01:17:13] These companies who are. Trying to provide materials, software, hardware for government contracts, right? So they're not even direct government contractors for the feds. They are just a sub contractors. And then we've seen fancy bear in there. We've seen the Chinese in these companies. It's incredible.

    [01:17:34] They have no. DIA that all of their intellectual property is being stolen, which is why the federal government has started cracking down on contractors and subcontractors. And there's this whole paragraph 70 12 thing. We're getting geeky here, but companies that have to protect even unclassified information, confidential, classified, and they haven't been so Microsoft.

    [01:18:01] Obtained a court order. You can see this on my screen, over at YouTube and at rumble to take control of each domain on April six, that then started redirecting them to a sinkhole. So what they do is they take control of the DNS for the domain. So the root name servers, now, point to a Microsoft name server, and then send them to a sinkhole.

    [01:18:24] A sinkhole is basically nowhere you go there. There's nothing on the site, right? Or in this case also servers used by cybersecurity experts to capture and analyze malicious connections. And they'll do this. Oftentimes, when we're talking about these botnets, like we talked about a little earlier today, so apparently they're trying to establish long-term access to the system.

    [01:18:48] So the targets, what did we just talk about? Long-term acts. But net, right? That's what button that saw. So Microsoft has gotten involved. They've been doing this now for a little while. It's obviously not their normal business model, but it is something that they've been doing. They were also, by the way, the fancy bear link to these cyber attacks on the DNC in 2016.

    [01:19:12] And they also targeted the UFC election in 2020, which is why, part of the reason why anyways, don't use electronic equipment for our elections, have paper ballot, have people count those ballots yet it takes longer. You can't have the instant thing on TV, which is why all of these new services, they all don't do that.

    [01:19:34] That's ridiculous. But it's the only thing we can guarantee that these guys, like I got it up on the screen again. Fancy bear the Chinese et cetera. It's the only way they can get in. And if we were doing paper ballots and we had bipartisan people counting the ballots and independence, counting the ballots, observing this, we wouldn't have all of these problems that we had with the last election where people were saying it was stolen.

    [01:20:03] It was hacked. How do we know it was stolen? How do we know it? Wasn't stolen? How, go back to paper ballots, get rid of the scanning machines and particularly get rid of these electronic voting machines where you touch the screen to cast your vote. Those things are ridiculous. What if there's a software bug in it?

    [01:20:21] How can you go back and change the vote? People that complained about it again, and wait a minute. I voted for this guy and you had to record my vote for the other guy. It's ridiculous. Anyways. Back to QR codes. Okay. I'm going to pull this up on this screen because I think this is a cool article here.

    [01:20:40] This is from a, actually a site over in India. It's called scroll.in, and they're talking in here about how hazardous it can be. To use QR codes. Now they're not saying don't use QR codes, we've all had to use them. I've got up on my screen, this picture of being at a table. And you scan the QR code in order to get the menu.

    [01:21:03] In order to order, I did that. I was in Vermont and we were riding motorcycles or buddy, and I go into the little tiny. Restaurant, small restaurant and I had a half a dozen tables and they didn't have menus. You scanned it, the QR code that was there on the table and you placed your order. And off it goes a lot of places they've been doing that with menus.

    [01:21:27] You've seen that more and more saves them money as well and lets them change their prices more frequently. Yeah. Thanks for that inflation guys. Why shouldn't you use these QR codes? Why should you be extra careful? Here's the answer. QR codes are the URL of a webpage. That's the bottom line. Would you click a random URL that came in an email?

    [01:21:53] Would you click on a random URL in an ad or on a web page? We certainly know better than to cook URLs in our email. But that's exactly what the QR code is. And on top of it, the URL in a QR code tends to be what we call a shortened URL. So it might be Bitly, so might be bit.ally/and then some random characters.

    [01:22:19] How do you know where it's going to take? You don't all you know, is it's going to take you to Bitly, but that Bitly URL could be sending you to a malicious site. And now your phone could be hacked. It could be using your phone for Bitcoin mining for who knows what. So be very careful and the bad guys are using these in a different way that you might not have seen before, which is they are embedding QR code graphics.

    [01:22:50] Into emails. And they're thinking that people are going to hold up their phone to the email and what are they going to do? They're going to scan the QR code that was in their email. And now they're in trouble. Yeah, that's simple. Hey, visit me online. Craig peterson.com. Make sure you sign up for my newsletter.

    [01:23:08] Craig peterson.com/subscribe course, Craig Peterson, S O n.com. And I'm going to send you. Top three special reports, absolutely free. We got to take care of these bad guys.

    1 hr 24 min
  • Facebook Has No Idea Where Your Data Is and What They Do With It?!

    Facebook Has No Idea Where Your Data Is and What They Do With It?!

    Facebook's about 18 years old coming on 20 Facebook has a lot of data. How much stuff have you given Facebook? Did you fall victim for that? Hey, upload your contacts. We'll find your friends. They don't know where your data is.

    [Following is an automated transcript]

    [00:00:15] This whole thing with Facebook has exploded here lately.

    [00:00:20] There is an article that had appeared on a line from our friends over at, I think it was, yeah. Let me see here. Yeah. Yeah. Motherboard. I was right. And motherboards reporting that Facebook doesn't know what it does with your data or. It goes, no, there's always a lot of rumors about different companies and particularly when they're big company and the news headlines are grabbing your attention and certainly Facebook can be one of those companies.

    [00:00:57] So where did motherboard get this opinion about Facebook? Just being completely clueless about your personal. It tamed from a leaked document. Yeah, exactly. So we find out a lot of stuff like that. I used to follow a website about companies that were going to go under and they posted internal memos.

    [00:01:23] It basically got sued out of existence, but there's no way that Facebook is going to be able to Sue this one out of existence because they are describing this as. Internally as a tsunami of privacy regulations all over the world. So Gores, if you're older, we used to call those tidal waves, but think of what the implication there is of a tsunami coming in and just overwhelming everything.

    [00:01:53] So Facebook, internally, their engineers are trying to figure out, okay. So how do we deal with. People's personal data. It's not categorized in ways that regulators want to control it. Now there's a huge problem right there. You've got third party data. You've got first party data. You've got sensitive categories, data.

    [00:02:16] They might know what religion you are, what your persuasions are in various different ways. There's a lot of things they might know about you. How were they all cat categorize now we've got the European union. With their general data protection regulation. The GDPR we talked about when it came into effect back in 2018, and I've helped a few companies to comply with that.

    [00:02:41] That's not my specialty. My specialty is the cybersecurity. But in article five this year, peon law mandates that personal data must be collected for specified explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. So what that means is that every piece of data, like where you are using Facebook or your religious orientation, Can only be collected in use for a specific purpose and not reused for another purpose.

    [00:03:19] As an example here, that vice has given in past Facebook, took the phone number that users provided to protect their accounts with two factor authentication and fed it to its people, feature as well as. Advertisers. Yeah. Interesting. Hey, so Gizmodo with the help of academic researchers caught Facebook doing this, and eventually the company had to stop the practice because, and this goes back to the earlier days where Facebook would say, Hey, find out if your friends are on Facebook, upload your contacts right now.

    [00:03:54] And most people. What did you know back then about trying to keep your data private, to try and stop the proliferation of information about you online then nothing. I think I probably even uploaded it back then thinking it'd be nice to see if I got friends here. We can start chatting, et cetera.

    [00:04:12] According to legal experts that were interviewed by motherboard who wrote this article and has a copy of the internal memo this year, PN regulation specifically prohibits that kind of repurposing of your phone number of trying to put together the social graph and the leaked document shows that Facebook may not even have the ability to live.

    [00:04:37] How it handles user's data. Now I was on a number of radio stations this week, talking about this. And the example I gave is just look at an average business from the time it start, Facebook started how right? Wildly scraping pictures of young women off of Harvard university. Main catalog, contact page, and then asking people what do you think of this? This person, that person. And off they go, trying to rate them. Yeah. Yeah. All that matters to a woman, at least to Courtney, to mark Zuckerberg girl, all the matters about a woman is how she looks. Do I think she's pretty or not?

    [00:05:15] It's ridiculous. What he was doing. It just, oh, that's zackerburg who he is not a great guy anyways. So you go from stealing pictures of young ladies asking people to rate them, putting together some class information and stuff there at Harvard, and then moving on to other universities and then open it up even wider and wider.

    [00:05:42] And of course, that also created demand because you can't get on. If you're not at one of the universities that we have set it up for. And then you continue to grow. You're adding these universities, certainly starting to collect data and you are making more money than God. So what do you do? You don't have to worry about any efficiencies.

    [00:06:02] I'll tell you that. Right? One thing you don't have to do is worry about gee. We've got a lot of redundant work going on here. We've got a lot of teams working on basically the same thing. No, you've got more money than you can possibly shake a stick at. So now you go ahead and send that money to this group or that group.

    [00:06:24] And they put together all of the basic information, that they want. Pulling it out of this database and that database in there doing some correlation, writing some really cool CQL queries with mem credible joins and everything else. And now that becomes part of the main code for Facebook.

    [00:06:45] And then Facebook goes on to the next little project and they do the same thing. Then the next project, then the next project. And then someone comes along and says, Hey, we. This feature, that feature for advertisers and then in that goes, and then along comes candidate Obama. And they, one of the groups inside Facebook says, yeah here we go.

    [00:07:09] Here's all of the information we have about everybody and it's free. Don't worry about it. And then when Trump actually bought it and hired a company to try and process some of that information he got in trouble. No but the. The whole campaign could get access to anything they wanted to, again, because the data wasn't controlled, they had no idea who was doing what with the data.

    [00:07:34] And according to this internal memo, they still don't know. They don't even know if they can possibly comply with these regulations, not just in Europe, but we have regulations in pretty much all of the 50 states in the U S Canada of course, has their own Australia and New Zealand think about all the places.

    [00:07:57] Facebook makes a lot of. So here's a quote from that we build systems with open borders. The result of these open systems and open culture is well-described with an analogy. Imagine you hold a bottle of ink in your hand, the bottle of ink is a mixture of all kinds of user data. You pour that ink into a lake of water and K and it flows every year.

    [00:08:22] The document read. So how do you put that ink back in the bottle? I, in the right bottle, how do you organize it again? So that it only flows to the allowed places in the lake? They're totally right about that. Where did they collect it from? Apparently they don't even know where they got some of this information.

    [00:08:43] This data from reminds me of the no fly list. You don't know you're on it and you can't get yourself off of it. It's crazy. So this document that we're talking about, it was written last year by. Privacy engineers on the ad and business product team, whose mission is to make meaningful connections between people and businesses and which quote sits at the center of our monetization strategy.

    [00:09:06] And is the engine that powers Facebook's growth. Interesting. Interesting problems. And I see this being a problem well into the future for more and more of these companies, look at Twitter as an example that we've all heard about a lot lately. And then I've talked about as well along comes Elon Musk and he says wait a minute.

    [00:09:29] I can make Twitter way more profitable. We're going to get rid of however many people over a thousand, and then we are going to hire more people. We're going to start charging. We're going to be more efficient. You can bet all of these redundancies that are in Facebook are also there. And Twitter also has to comply with all of these regulations that Facebook is freaking out about it for a really a very good reason.

    [00:10:00] So this document is available to anybody who wants to look at it. I'm looking at it right now, talking about regulatory landscape and the fundamental problems Facebook's data lake. And this is a problem that most companies have not. As bad as Facebook does the button. Most companies you write, you grow. I have yet to walk into a business that needs help with cybersecurity and find everything in place as it should be because it grew organically.

    [00:10:32] Do you started out with a little consumer firewall router, wifi, and then you added to it and you put a switch here and you added another switch behind that and move things around. This is normal. This is not total incompetence on the part of the management, but my gosh, I don't know. Maybe they need an Elon Musk.

    [00:10:52] Just straighten them out as well. Hey, stick around. I'll be right back and sign up [email protected].

    [00:11:02] Apparently looting is one of the benefits of being a Russian soldier. And according to the reports coming out of Ukraine, they've been doing it a lot, but there's a tech angle on here that is really turning the tables on these Russian Looters.

    [00:11:19] We know in wars, there are people that loot and typically the various militaries try and make sure, at least recently that looting is kept to an absolute minimum.

    [00:11:32] Certainly the Americans, the British, even the Nazis during world war II the the socialists they're in. Germany they tried to stop some of the looting that was going on. I think that's probably a very good thing, because what you end up with is just all of these locals that are just totally upset with you.

    [00:11:57] I found a great article on the guardian and there's a village. I hadn't been occupied for about a month by Russian troops and the people came back. They are just shocked to see what happened in there. Giving a few examples of different towns. They found that the alcohol was stolen and they left empty bottles behind food wrappers, cigarette butts, thrown all over the place in apartments in the home.

    [00:12:26] Piles of feces blocking the toilets, family photographs torn, thrown around the house. They took away all of the closes as a code from one of the people, literally everything, male and female coats, boots, shirts, jackets, even my dresses and laundry. This is really something. The Sylvia's didn't do this, but now Russia.

    [00:12:49] The military apparently does. So over the past couple of weeks, there have been reporting from numerous places where Russian troops had occupied Ukrainian territory and the guardian, which is this UK newspaper collected evidence to suggest looting by Russian forces was not merely a case of a few way, word soldiers, but a systematic part of Russian military behavior across multiple towns.

    [00:13:17] And villages. That's absolutely amazing. Another quote here, people saw the Russian soldiers loading everything onto your old trucks. Everything they could get their hands on a dozen houses on the villages. Main street had been looted as well as the shops. Other villagers reported losing washing machines, food laptops, even as sofa, air conditioner.

    [00:13:41] Being shipped back, just you might use ups here or they have their equivalent over there. A lady here who was the head teacher in the school, she came back in, of course, found her home looted and in the head teacher's office. She found an open pair of scissors that had been jammed into a plasma screen that was left behind because if they can't steal it, they're going to destroy it.

    [00:14:07] They don't wanna leave anything behind. They found the Russian to take in most of the computers, the projectors and other electronic equipment. It's incredible. So let's talk about the turnaround here. You might've heard stories about some of these bad guys that have smashed and grabbed their way into apple stores.

    [00:14:27] So they get into the apple store. They grab laptops on iPads, no longer iPods, because they don't make those anymore. And I phone. And they take them and they run with them. Nowadays there's not a whole lot of use for those. Now what they have been doing, some of these bad guys is they'd take some parts and use them in stolen equipment.

    [00:14:52] They sell them on the used market, et cetera. But when you're talking about something specific, like an iPhone that needs specific activation. Completely different problem arises for these guys because that iPhone needs to have a SIM card in order to get onto the cell network. And it also has built in serial numbers.

    [00:15:15] So what happens in those cases while apple goes ahead and disables them. So as soon as they connect to the internet, they didn't say they put them on wifi. They don't get a SIM card. They don't. Service from T-Mobile or Verizon or whoever it might be. So now they just connect to the wifi and it calls home.

    [00:15:33] Cause it's going to get updates and download stuff from the app store and they find that it's been bricked. Now you can do that with a lot of mobile device managers that are available for. All kinds of equipment nowadays, but certainly apple equipment where if a phone is lost or stolen or a laptop or other pieces of equipment, you can get on the MDM and disable it, have it remotely erase, et cetera.

    [00:16:00] Now, please have had some interesting problems with that. Because a bad guy might go ahead and erase a smartphone. That's in the evidence locker at the police station. So they're doing things like putting them into Faraday cages or static bags or other things to try and stop that. So I think we've established here that the higher tech equipment is pretty well protected.

    [00:16:25] You steal it. It's not going to do you much. Good. So one of the things the Russian stole when they were in a it's called a, I think you pronounced. Melad Mellott DePaul which is again, a Ukrainian city is they stole all of the equipment from a farm equipment dealership and shipped it to check. Now that's according to a source in a businessman in the area that CNN is reporting on.

    [00:16:56] So they shipped this equipment. We're talking about combine harvesters were 300 grand a piece. They shipped it 700 miles. And the thieves were ultimately unable to use the equipment because it had been locked remotely. So think about agriculture equipment that John Deere, in this case, these pieces of equipment, they, they drive themselves.

    [00:17:23] It's atonomous it goes up and down the field. Goes to any pattern that you want to it'll bring itself within a foot or an inch of your boundaries, of your property being very efficient the whole time, whether it's planting or harvesting, et cetera. And that's just a phenomenal thing because it saves so much time for the farmer makes it easier to do the companies like John Deere.

    [00:17:49] Want to sell as many pieces of this equipment as they possibly can. And farming is known to be a what not terribly profitable business. And certainly isn't like Facebook. So how can they get this expensive equipment into the hands of a lot of farmers? What they do is they use. So you can lease the equipment through leasing company or maybe directly from the manufacturer and now you're off and running.

    [00:18:16] But what happens if the lease isn't paid now? It's one thing. If you don't pay your lease on a $2,000 laptop, right? They're probably not going to come hunting for you, but when you're talking about a $300,000 harvester, they're more interested. So the leasing company. Has titled to the equipment and the leasing company can shut it off remotely.

    [00:18:41] You see where I'm going with this so that they can get their equipment in the hands of more farmers because the farmers can lease it. It costs them less. They don't have to have a big cash payment. You see how this all works. So when the Russian forces stole this equipment, that's valued, total value here is about $5 million.

    [00:19:02] They were able to shut it all off. And th the, obviously if you can't start the engine, because it's all shut off and it's all run by computers nowadays, and there's pros and cons to that. I think there's a lot of cons, but what are you going to do? How's that going to work for? Isn't going to work for you.

    [00:19:22] And they were able to track it and had GPS trackers find out exactly where it was. That's how they know it was Tara taken to Chechnya and could be controlled remotely. And in this case, how did they control it? They completely. Shut it off, even if they sell the harvesters for spare parts to learn some money, but they sure aren't gonna be able to sell them for the 300 grand that they were actually worth.

    [00:19:48] Hey, stick around. We'll be right back and visit me [email protected]. If you sign up there, you'll be able to get my insider show notes. And every week I have a quick. Training right there. New emails, Craig Peterson.com.

    [00:20:05] If you've been worried about ransomware, you are right to worry. It's up. It's costly. And we're going to talk about that right now. What are the stats? What can you do? What happens if you do get hacked? Interesting world!

    [00:20:20] Ransomware has been a very long running problem. I remember a client of ours, a car dealership who we had gone in.

    [00:20:31] We had improved all of their systems and their security, and one of them. People who was actually a senior manager, ended up downloading a piece of ransomware, one of these encrypted ones and opened it up and his machine all of a sudden, guess what it had ransomware on it. One of those big. Green's that say, pay up and send us this much Bitcoin, and here's our address.

    [00:21:00] All of that sort of stuff. And he called us up and said, what's going on here? What happened? First of all, don't bring your own machine into the office. Secondly, don't open up as particularly encrypted files using a password that they gave. And thirdly, we stopped it automatically. It did not spread.

    [00:21:20] We were able to completely restore his computer. Now let's consider here the consequences of what happened. So he obviously was scared. And within a matter of a couple of hours, we actually had him back to where he was and it didn't spread. So the consequences there, they weren't that bad. But how about if it had gotten worse?

    [00:21:47] How about if the ransomware. Also before it started holding his computer ransom, went out and found all of the data about their customers. What do you think an auto dealership would love to hear that all of their customer data was stolen and released all of the personal data of all of their customers?

    [00:22:08] Obviously not. So there's a potential cost there. And then how long do you think it would take a normal company? That thinks they have backups to get back online. All I can tell you it'll take quite a while because the biggest problem is most backups don't work. We have yet to go into a business that was actually doing backups that would work to help restore them.

    [00:22:35] And if you're interested, I can send you, I've got something I wrote up. Be glad to email it back to you. Obviously as usual, no charge. And you'll be able to go into that and figure out what you should do. Cause I, I break it down into the different types of backups and why you might want to use them or why you might not want to use them, but ransomware.

    [00:22:58] Is a kind of a pernicious nasty little thing, particularly nowadays, because it's to two factor, first is they've encrypted your data. You can't get to it. And then the second side of that is okay I can't get to my data and now they're threatening to hold my data ransom or they'll release. So they'll put it out there.

    [00:23:22] And of course, if you're in a regulated industry, which actually car dealers are because they deal with financial transactions, leases, loans, that sort of thing you can lose your license for your business. You can, you lose your ability to go ahead and frankly make loans and work with financial companies and financial instruments.

    [00:23:45] It could be a very big. So there are a lot of potential things that can happen all the way from losing your reputation as a business or an individual losing all of the money in your operating account. And again, we've got a client that we picked up afterwards. That yes, indeed. That lost all of the money in their operating account.

    [00:24:09] And then how do you make payroll? How do you do things? There's a new study that came out from checkpoint. Checkpoint is one of the original firewall companies and they had a look at ransomware. What are the costs of ransomware? Now bottom line, I'm looking at some stats here on a couple of different sites.

    [00:24:29] One is by the way, Conti, which is a big ransomware gang that also got hacked after they said we are going to attack anyone. That doesn't defend Plaid's invasion of Ukraine, and then they got hacked and their information was released, but here's ransomware statistics. This is from cloud words. First of all, the largest ransom demand is $50 million.

    [00:24:55] And that was in 2021 to Acer big computer company. 37% of businesses were hit by ransomware. In 2021. This is amazing. They're expecting by 2031. So in about a decade, ransomware is going to be costing about $265 billion a year. Now on average. Ransomware costs businesses. 1.8, $5 million to recover from an attack.

    [00:25:25] Now that's obviously not a one or two person place, but think of the car dealer again, how much money are they going to make over the year or over the life of the business? If you're a car dealer, you have a license to print money, right? You're selling car model or cars from manufacturers. And now you have the right to do that and they can remove that.

    [00:25:48] How many tens, hundreds of millions of dollars might that end up costing you? Yeah. Big deal. Total cost of ransomware last year, $20 billion. Now these are the interesting statistics here right now. So pay closer attention to this 32% of ransomware victims paid a ransom. So about a third Peter ransom demand.

    [00:26:12] Lastly. It's actually down because my recollection is it used to be about 50% would pay a ransom. Now on average that one third of victims that paid a ransom only recovered 65% of their data. Now that differs from a number I've been using from the FBI. That's a little bit older that was saying it ends it a little better than 50%, but 65% of pain victims recovered their.

    [00:26:41] Now isn't that absolutely amazing. Now 57% of companies were able to recover their data, using a cloud backup. Now think about the different types of backup cloud backup is something that can work pretty well if you're a home user, but how long did it take for your system to get back? Probably took weeks, right?

    [00:27:05] For a regular computer over a regular internet line. Now restoring from backups is going to be faster because your downlink is usually faster than your uplink. That's not true for businesses that have real internet service like ours. It's the same bandwidth up as it is down. But it can take again, days or weeks to try and recover your machine.

    [00:27:28] So it's very expensive. And I wish I had more time to go into this, but looking at the costs here and the fact that insurance companies are no longer paying out for a lot of these ransomware attacks, it could be credibly expensive for you incredibly. The number one business types by industry for ransomware attacks, retail.

    [00:27:59] That makes sense. Doesn't it. Real estate. Electrical contractors, law firms and wholesale building materials. Isn't that interesting? And that's probably because none of these people are really aware or conscious of doing what a, of keeping their data secure of having a good it team, a good it department.

    [00:28:24] So there's your bottom line. Those are the guys that are getting hit. The most, the numbers are increasing dramatically and your costs are not just in the money. You might pay as a ransom. And as it turns out in pretty much every case prevention. Is less expensive and much better than the cure of trying to pay ransom or trying to restore from backups.

    [00:28:52] Hey, you're listening to Craig Peterson. You can get my weekly show notes by just going to craig peterson.com.

    [00:29:00] You and I have talked about passwords before the way to generate them and how important they are. We'll go over that again a little bit in just a second, but there's a new standard out there that will eliminate the need for passwords.

    [00:29:16] Passwords are a necessary evil, at least they have been forever. I remember, I think the only system I've ever really used that did not require passwords was the IBM 360.

    [00:29:31] Yeah, 360, you punch up the cards, all of the JCL you feed the card deck in and off it goes. And does this little thing that was a different day, a different era. When I started in college in university, we. We had a remote systems, timeshare systems that we could log into. And there weren't much in the line of password requirements.

    [00:29:58] And, but you had a username, you had a simple password. And I remember one of our instructors, his name was Robert, Andrew Lang, and his password was always some sort of a combination of RA Lang. So it was always easy to guess what his password was. Today. It has gotten a lot worse today. We have devices with us all the time.

    [00:30:22] You might be wearing a smart watch. That requires a password. You course probably have a smartphone that also maybe requiring a password. Certainly after it boots nowadays they use fingerprints or facial recognition, which is handy, but it has its own drawbacks. But how about the websites? You're going to the systems you're using in you're at work and logging in.

    [00:30:49] They all require password. And usernames of some sort or another well, apple, Google, and Microsoft have all committed to expanding their support for a standard. That's actually been out there for a few years. It's called the Fido standard. And the idea behind this is that you don't have to have a password in order to.

    [00:31:15] Now that's really an interesting thing, right? Just looking at it because we're so used to have in this password only authenticate. And of course the thing to do there is to make sure you have for your password, multiple words in the password, it should really be a pass phrase. And between the words put in special characters or numbers, maybe.

    [00:31:41] Upper lower case a little bit. In those words, those are the best passwords, 20 characters, 30 characters long. And then if you have to have a pin, I typically use a 12 digit pin. And how do I remember all of these? Cause I use a completely different password for every website and right now, Let me pull it up.

    [00:32:03] I'm using one password dot coms, password manager. And my main password for that is about 25 characters long. And I have thirty one hundred and thirty five. And trees here in my password manager, 3,100, that is a whole lot of passwords, right? As well as software licenses and a few other things in there.

    [00:32:30] That's how we remember them is using a password manager. One password.com is my favorite. Now, obviously I don't make any money by referring you there. I really do like that. Some others that I've liked in the past include last pass, but they really meant. With some of their cybersecurity last year and I lost my faith in it.

    [00:32:51] So now what they're trying to do is make these websites that we go to as well as some apps to have a consistent, secure, and passwordless. And they're going to make it available to consumers across all kinds of devices and platforms. That's why you've got apple, Google, and Microsoft all committing to it.

    [00:33:15] And you can bet everybody else is going to follow along because there's hundreds of other companies that have decided they're going to work with the Fido Alliance and they're going to create this passwordless future. Which I like this idea. So how does this work? Basically you need to have a smartphone.

    [00:33:33] This is, I'm just going to go with the most standard way that this is going to work here in the future, and you can then have. Passkey, this is like a multi-factor authentication or two factor authentication. So for instance, right now, when I sign into a website online, I'm giving a username, given a password, and then it comes up and it asks me for a code.

    [00:33:57] So I enter in a six digit code and that code changes every 30 seconds. And again, I use my password manager from one password. In order to generate that code. So that's how I log into Microsoft site and Google sites and all kinds of sites out there. So it's a similar thing here now for the sites for my company, because we do cyber security for businesses, including regulated businesses.

    [00:34:24] We have biometrics tied in as. So to log into our systems, I have to have a username. I have to have a password. I then am sent to a single sign-on page where I have to have a message sent to my smart device. That then has a special app that uses biometrics either a face ID or a fingerprint to verify who I am.

    [00:34:49] Yeah, there's a lot there, but I have to protect my customers. Something that very few it's crazy. Actual managed security services providers do, but it's important, right? By the way, if you want my password. Special report, just go to Craig peterson.com. Sign up for my email list. I'll send that to you.

    [00:35:13] That's what we're sending out right now for anyone who signs up [email protected]. And if you'd like a copy of it in you're already on the list, just go ahead and email me. At Craig peterson.com and ask for the password special report where I go through a lot of this sort of thing. So what will happen with this is you go to a website and I might come up with a QR code.

    [00:35:37] So you then scan that QR code with your phone and verify it, authorize it on your phone. You might again to have it set up so that your phone requires a facial recognition or perhaps it'll require a fingerprint. And now you are. Which is very cool. They fix some security problems in Fido over the last few years, which is great over the coming year.

    [00:36:02] You're going to see this available on apple devices, Google Microsoft platforms, and it really is simple, stronger authentication. That's sort of Fido calls it. But it is going to make your life a lot easy, easier. It is a standard and the passwordless future makes a whole lot of sense for all of us. Now, I want to talk about another thing here that just bothered me for a long time.

    [00:36:30] I have a sister. Who is in the medical field and gives prescriptions, doctor thing. And I think she's not quite a doctor. I can't remember what she has. She's an LPN or something. And anyhow, so she. We'll get on a zoom call with someone and they'll go through medical history and what's happening right now and she'll make prescriptions.

    [00:36:57] And so I warned her about that saying, it is very bad to be using zoom because zoom is not secure. Never has been, probably never will be right. If you want secure. To go and pay for it from one of these providers like WebEx, that's what we use. We have a version of WebEx that is set up to be secure.

    [00:37:20] So I talked to her about that and said, Hey, listen, you can't do this. You've really got to go another way here. And so she started using one of these mental or. Medical health apps. What I want to talk about right now specifically are some checks that were just performed some audits on mental health apps.

    [00:37:45] That's why I messed up a second ago, but what they looked at is that things are a serious problem there. And then fact, the threat post, just calling it a. Frankly, just plain old creepy. So they've got some good intentions. They want to help with mental health. You've probably seen these or at least heard them advertise.

    [00:38:06] So you can get on the horn with a mental health professional, a doctor or otherwise in order to help you here with your psychological or spiritual wellness. And people are sharing their personal and sensitive data with third parties and have 32 mental health and prayer mobile apps that were investigated by the open source organization.

    [00:38:32] 28, 28 of the 32 were found to be inherently insecure and were given a privacy not included label, including others here. So this is a report. That was released here by the open source organization, tied into Mozilla. Those are the Firefox people. They have what they call their minimum security standards.

    [00:38:56] So things like requiring strong passwords, managing security, updates, and vulnerabilities, et cetera. 25 of the 32 failed to meet. Even those minimum security standards. So these apps are dealing with some of the most sensitive mental health and wellness issues people can possibly have, right? Depression, anxieties, suicidal fonts, domestic violence, eating disorders.

    [00:39:23] And they are being just terrible with your security Mozilla researchers spent 255 hours or about eight hours per product pairing under the hood of the security, watching the data that was going back and forth, right between all of these mental health and prayer apps. It was just crazy. So for example, eight of the apps reviewed, allowed weak passwords, that range.

    [00:39:52] One digit one as the password to 1, 1, 1, 1, while a mental health app called a mood fit only required one letter or digit as a password. Now that is very concerning for an app that collects mood and symptom data. So be very careful. Two of the apps better help a popular app that connects users with therapists and better stop suicide, which is a course of suicide prevention app have vague and messy, according to Mozilla privacy policies that have little or no effect on actual.

    [00:40:30] User data protection. So be very careful. And if you're a mental health, professional or medical professional, don't just go and use these open video calls, et cetera, et cetera, find something good. And there are some standards out there. Again. Visit me online, get my insider show notes every week. Get my little mini trends.

    [00:40:56] And they come up most weeks. Just go to Craig peterson.com. And I'll send you my special report on passwords and more.

    [00:41:06] We know the Russians have been attacking us. I've talked a lot about it on the radio station, all kinds of stations. In fact, here over the last couple of weeks, and I am doing something special, we are going through the things you can do to keep safe.

    [00:41:23] Last week we started doing something I promise we would continue.

    [00:41:27] And that is how can you protect yourself when it comes to the Russians, right? When it comes to the bad guys, because the Russians are definitely the bad guys. There's a few things you can do. And there's a few things, frankly, you shouldn't be doing. And that's exactly what we're going to talk about right now.

    [00:41:45] So last week he went over some steps, some things that you can look at that you should look at that are going to help protect you. And we are going to go into this a whole lot more today. And so I want you to stick around and if you miss anything, you can go online. You can go to Craig peterson.com, make sure you sign up there for my email.

    [00:42:08] And what I'm going to do for you is. Send you a few different documents now where we can chat back and forth about it, but I can send you this. Now I'm recording this on video as well as on audio. So you can follow along if you're watching either on YouTube or. Over on rumble and you can find it also on my website.

    [00:42:32] I've been trying to post it up there too, but right now let's talk about what we call passive backend protections. So you've got the front end and the front end of course, is. Stuff coming at you, maybe to the firewall I've mentioned last week about customers of mine. I was just looking at a few customers this week, just so I could have an idea of their firewalls.

    [00:42:59] And they were getting about 10 attacks per minute. Yeah. And these were customers who have requirements from the department of defense because they are defense sub subcontractors. So again, Potential bad guys. So I looked up their IP addresses and where the attacks were coming from. Now, remember that doesn't mean where they originated because the bad guys can hop through multiple machines and then get onto your machine.

    [00:43:28] What it means is that all, ultimately they ended up. Coming from one machine, right? So there's an IP address of that machine. That's attacking my clients or are attacking my machines. That just happens all the time. A lot of scans, but some definite attacks where they're trying to log in using SSH.

    [00:43:48] And what I found is these were coming from Slovakia, Russia, and Iran. Kind of what you were expecting, right? The Iranians, they just haven't given up yet. They keep trying to attack, particularly our military in our industry. One of the things we found out this week from, again, this was an FBI notice is that the Russians have been going after our industrial base.

    [00:44:15] And that includes, in fact, it's more specifically our automobile manufacturers we've already got problems, right? Try buying a new car, try buying parts. I was with my friend, just this. I helped them because he had his car right. Need to get picked up. So I took him over to pick up his car and we chatted a little bit with this small independent automotive repair shop.

    [00:44:40] And they were telling us that they're getting sometimes six, eight week delays on getting parts and some parts. They just can't. So they're going to everything from junkyards on out, and the worst parts are the parts, the official parts from the car manufacturers. So what's been happening is Russia apparently has been hacking into these various automobile manufacturers and automobile parts manufacturers.

    [00:45:10] And once they're inside, they've been putting in. A remote control button net. And those botnets now have the ability to wake up when they want them to wake up. And then once they've woken up, what do they do? Who knows? They've been busy erasing machines causing nothing, but having they've been doing all kinds of stuff in the past today, they're sitting there.

    [00:45:31] Which makes you think they're waiting, it's accumulate as much as you possibly can. And then once you've got it all accumulated go ahead and attack. So they could control thousands of machines, but they're not just in the U S it's automobile manufacturers in Japan. That we found out about.

    [00:45:50] So that's what they're doing right now. So you've got the kind of that front end and back end protections. So we're going to talk a little bit about the back end. What does that mean? When a cybersecurity guy talks about the backend and the protections. I got it up on my green right now, but here's the things you can do.

    [00:46:10] Okay. Remember, small businesses are just getting nailed from these guys, because again, they're fairly easy targets. One change your passwords, right? How many times do we have to say that? And yet about 70% of businesses out there are not using a good password methodology. If you want more information on passwords, two factor authentication, you name it.

    [00:46:37] Just email me M [email protected]. I want to get the information out now. You got to make sure that all of the passwords on your systems are encrypted are stored in some sort of a good password vault as you really should be looking at 256 bit encryption or better. I have a vendor of. That I use. So if you get my emails every week, when them, there's the little training.

    [00:47:06] And so I'll give you a five minute training. It's written usually it's in bullet point for, I'm just trying to help you understand things. That provider of mine has a big database and there's another provider that I use that is for. So the training guys use the database of my provider.

    [00:47:27] In using that database, they're storing the passwords and the training providers putting passwords in the clinics. Into the database, which is absolutely crazy. So again, if you're a business, if you're storing any sort of personal information, particularly passwords, make sure that you're using good encryption and your S what's called salting the hash, which means.

    [00:47:53] You're not really storing the password, just joining assaulted hash. I can send you more on this. If you are a business and you're developing software that's, this is long tail stuff here. Configure all of the security password settings so that if someone's trying to log in and is failing that, and you block it, many of us that let's say you're a small business.

    [00:48:15] I see this all of the time. Okay. You're not to blame. You, but you have a firewall that came from the cable company. Maybe you bought it at a big box retailer. Maybe you bought it online over at Amazon, as hurricane really great for you. Has it got settings on there that lets you say. There's 20 attempts to log in.

    [00:48:38] Maybe we should stop them. Now, what we do personally for our customers is typically we'll block them at somewhere around three or four failed attempts and then their passwords block. Now you can configure that sort of thing. If you're using. Email. And that's an important thing to do. Let me tell you, because we've had some huge breaches due to email, like Microsoft email and passwords and people logging in and stealing stuff.

    [00:49:06] It was just a total nightmare for the entire industry last year, but limit the number of login retries as well as you're in there. These excessive login attempts or whatever you want to define it as needs to lock the account. And what that means is even if they have the right password, they can't get in and you have to use an administrative password in order to get in.

    [00:49:31] You also want to, what's called throttle, the rate of repeated logins. Now you might've gotten caught on this, right? You went to your bank, you went to E-bay, you went to any of these places and all of a sudden. And denied you write it blocked you. That can happen when your account is on these hackers lists.

    [00:49:51] You remember last week we talked about password spraying while that's a very big deal and hackers are doing the sprain trick all of the time, and that is causing you to get locked out of your own account. So if you do get locked out, remember it might be because someone's trying to break. Obviously you have to enforce the policies.

    [00:50:16] The capture is a very good thing. Again, this is more for software developer. We always recommend that you use multifactor or two factor authentication. Okay. Do not use your SMS, your text messages for that, where they'll send you a text message to verify who you are. If you can avoid that, you're much better off.

    [00:50:36] Cause there's some easy ways to get around that for hackers that are determined. Okay. A multi-factor again, installed an intrusion. system. We put right at the network edge and between workstations and servers, even inside the network, we put detection systems that look for intrusion attempts and block intrusion attempts.

    [00:51:02] A very important use denied lists to block known attackers. We build them automatically. We use some of the higher end Cisco gates. Cisco is a big network provider. They have some of the best hardware and software out there, and you have to subscribe to a lot of people complain. I ain't going to just go buy a firewall for 200 bucks on Amazon.

    [00:51:24] Why would I pay that much a month just to to have a Cisco firewall? And it's like praying pain for the brand. I've got by logo chert on here. Oh, I wouldn't pay for that. No, it's because they are automatically providing block lists that are updated by the minute sometimes. And then make sure you've got an incident response plan in place.

    [00:51:50] What are you going to do when they come for you? What are you going to do?

    [00:51:55] Now we're going to talk about prevention. What can you do an order to stop some of these attacks that are coming from Russia and from other countries, it is huge. People. Believe me, this is a very big problem. And I'm here to help.

    [00:52:12] We've reviewed a number of things that are important when it comes to your cyber security and your protection.

    [00:52:20] We talked about the front end. We talked about the backend. Now we're going to talk about pure prevention and if you're watching. Online. You'll be able to see my slides as they come up, as we talk about some of this stuff and you'll find me on YouTube and you'll also find me on rumble, a fairly new platform out there platform that doesn't censor you for the things you say.

    [00:52:44] Okay. So here we go. First of all, enabling your active directory password protection is going to. Four's password protection all the way through your business. Now I've had some discussions with people over the months, over the years about this whole thing and what should be done, what can be done, what cannot be done.

    [00:53:09] Hey, it's a very big deal when it comes to password protection and actor directory, believe it or not, even though it's a Microsoft product is pretty darn good at a few things. One of them is. Controlling all the machines and the devices. One of the things we do is we use an MDM or what used to be a mobile device manager called mass 360.

    [00:53:34] It's available from IBM. We have a special version of that allows us as a managed security services provider to be able to control everything on people's machines. Active directory is something you should seriously consider. If you are a Mac based shop. Like I am. In fact, I'm sitting right now in front of two max that I'm using right now, you'll find that active directory is a little bit iffy.

    [00:54:04] Sometimes for max, there are some work around and it's gotten better mastery. 60 is absolutely the way to go, but make sure you've got really good. Passwords and the types of passwords that are most prone to sprain the attacks are the ones you should be banning specifically. Remember the website? Have I been poned?

    [00:54:28] Yeah. It's something that you should go to pretty frequently. And again, if you miss anything today, just email me M [email protected]. Believe me, I am not going to harass you at all. Okay. Now, the next thing that you should be doing is what's called red team blue team. Now the red team is a group of people, usually outside of your organization.

    [00:54:54] If you're a big company they're probably inside, but the red team is the team that attacks you. They're white hat hackers, who are attacking you, looking for vulnerabilities, looking for things that you should or shouldn't be doing. And then the blue team is the side that's trying to defend. So think of, like war games.

    [00:55:12] Remember that movie with Matthew Broderick all of those decades ago and how the, he was trying to defend that computer was trying to defend that it moved into an attack mode, right? Red team's attack, blue team is defend. So you want. To conduct simulated attacks. Now w conducting these attacks include saying, oh my let's now put in place and execute our plan here for what are we going to do once we have a.

    [00:55:44] And you darn well better have a breach plan in place. So that's one of the things that we help as a fractional chief information security officer for companies, right? You've got to get that in place and you have to conduct these simulated attacks and you have to do penetration testing, including password spraying attacks.

    [00:56:04] There's so many things you can do. The one of the things that we like to do and that you might want to do, whether you're a home user, retiree or a business is go and look online, you can just use Google. I use far more advanced tools, but you can use Google and look for your email address right there.

    [00:56:23] Look for the names of people inside your organization. And then say wait a minute, does that data actually need to be there? Or am I really exposing the company exposing people's information that shouldn't be out there because you remember the hackers. One of the things they do is they fish you fish as in pH.

    [00:56:47] So they'll send you an email that looks like. Hey let me see. I know that Mary is the CFO, and I know that Joe's going to be out of town for two weeks in The Bahamas, not a touch. So while he's got. I'm going to send an email to Mary, to get her to do something, to transfer the company's funds to me.

    [00:57:06] Okay. So that's what that's all about. You've got to make sure, where is our information? And if you go to my company's page, mainstream.net, you'll see on there that I don't list any of the officers or any of the people that are in the company, because that again is a security problem.

    [00:57:24] We're letting them know. I go to some of these sites, like professional sites lawyers, doctors, countenance, and I find right there all, are there people right there top people or sometimes all of them. And then we'll say, yeah, I went to McGill university, went to Harvard, whatever my B. It's all there. So now they've got great information to fish you, to fish that company, because all they have to do is send an email to say, Hey, you remember me?

    [00:57:56] We're in Harvard when this class together. And did you have as a professor to see how that works? Okay. You also want to make. That you implement, what's called a passwordless user agent, and this is just so solely effective. If they cannot get into your count, what's going to, what could possibly go wrong, but one of the ways to not allow them into the count is to use.

    [00:58:24] Biometrics. We use something called duo and we have that tied into the single sign-on and the duo single sign-on works great because what it does now is I put in, I go to a site, I put it into my username and. Pulls up a special splash page that is running on one of our servers. That again asks me for my duo username.

    [00:58:48] So I've got my username for the site then to my dual username and my duo password single sign on. And then it sends me. To an app on my smart device, a request saying, Hey, are you trying to log into Microsoft? And w whatever it might be at Microsoft, and you can say yes or no, and it uses biometric.

    [00:59:11] So those biometrics now are great because it says, oh, okay, I need a face ID or I need a thumb print, whatever it might be that allows a generalized, a password, less access. Okay. Password less. Meaning no pass. So those are some of the top things you can do when it comes to prevention. And if you use those, they're never going to be able to get at your data because it's something you have along with something, it works great.

    [00:59:45] And we like to do this. Some customers. I don't like to go through those hoops of the single sign-on and using duo and making that all work right where we're fine with it. We've got to keep ourselves, at least as secure as the DOD regulations require unlike almost anybody else in industry, I'm not going to brag about it.

    [01:00:09] But some of our clients don't like to meet the tightest of controls. And so sometimes they don't. I hate to say that, but they just don't and it's a fine line between. Getting your work done and being secure, but I think there's some compromises it can be readily made. We're going to talk next about saving your data from ransomware and the newest ransomware.

    [01:00:36] We're going to talk about the third generation. That's out there right now. Ransomware, it's getting crazy. Let me tell ya and what it's doing to us and what you can do. What is a good backup that has changed over the last 12 months? It's changed a lot. I used to preach 3, 2, 1. There's a new sheriff in town.

    [01:00:58] Stick around Craig peterson.com.

    [01:01:02] 3, 2, 1 that used to be the standard, the gold standard for backing up. It is no longer the case with now the third generation of ransomware. You should be doing something even better. And we'll talk about it now.

    [01:01:19] We're doing this as a simulcast here. It's on YouTube. It is also on rumble.

    [01:01:27] It's on my [email protected] because we're going through the things that you can do, particularly if you're a business. To stop the Russian invasion because as we've been warned again and again, the Russians are after us and our data. So if you missed part of what we're talking about today, or.

    [01:01:50] Last week show, make sure you send me an email. [email protected]. This is the information you need. If you are responsible in any way for computers, that means in your home, right? Certainly in businesses, because what I'm trying to do is help and save those small businesses that just can't afford to have full-time.

    [01:02:15] True cyber security personnel on site. So that's what the whole fractional chief information security officer thing is about. Because you just, you can't possibly afford it. And believe me, that guy that comes in to fix your computers is no cyber security expert. These people that are attacking our full time cybersecurity experts in the coming from every country in the world, including the coming from the us.

    [01:02:44] We just had more arrests last week. So let's talk about ransomware correctly. Ransomware, very big problem. Been around a long time. The first version of ransomware was software got onto your computer through some mechanism, and then you had that red screen. We've all seen that red screen and it says, Hey, pay up buddy.

    [01:03:07] It says here you need to send so many Bitcoin or a fraction of a Bitcoin or so many dollars worth of Bitcoin. To this Bitcoin wallet. And if you need any help, you can send email here or do a live chat. They're very sophisticated. We should talk about it some more. At some point that was one generation.

    [01:03:29] One generation two was not everybody was paying the ransoms. So what did they do at that point? They said let me see if they, we can ransom the data by encrypting it and having them pay us to get it back. 50% of the time issue got all your data back. Okay. Not very often. Not often enough that's for sure.

    [01:03:49] Or what we could do is let's steal some of their intellectual property. Let's steal some of their data, their social security number, their bank, account numbers, et cetera. They're in a, in an Excel spreadsheet on their company. And then we'll, if they don't pay that first ransom, we'll tell them if they don't pay up, we'll release their information.

    [01:04:10] Sometimes you'll pay that first ransom and then they will hold you ransom a second time, pretending to be a different group of cyber terrorists. Okay. Number three, round three is what we're seeing right now. And this is what's coming from Russia, nears, everything we can tell. And that is. They are erasing our machines.

    [01:04:31] Totally erasing them are pretty sophisticated ways of erasing it as well, so that it sinks in really, it's impossible to recover. It's sophisticated in that it, it doesn't delete some key registry entries until right at the very end and then reboots and computer. And of course, there's. Computer left to reboot, right?

    [01:04:55] It's lost everything off of that hard drive or SSD, whatever your boot devices. So let's talk about the best ways here to do some of this backup and saving your data from ransomware. Now you need to use offsite disconnected. Backups, no question about it. So let's talk about what's been happening.

    [01:05:17] Hospitals, businesses, police departments, schools, they've all been hit, right? And these ransomware attacks are usually started by a person. I'll link in an email. Now this is a poison link. Most of the time, it used to be a little bit more where it was a word document, an Excel document that had something nasty inside Microsoft, as I've said, many times has truly pulled up their socks.

    [01:05:45] Okay. So it doesn't happen as much as it used to. Plus with malware defender turned on in your windows operating system. You're going to be a little bit safer next step. A program tries to run. Okay. And it effectively denies access to all of that data. Because it's encrypted it. And then usually what it does so that your computer still works.

    [01:06:09] Is it encrypts all of you, like your word docs, your Excel docs, your databases, right? Oh, the stuff that matters. And once they've got all of that encrypted, you can't really access it. Yeah. The files there, but it looks like trash now. There's new disturbing trends. It has really developed over the last few months.

    [01:06:31] So in addition to encrypting your PC, it can now encrypt an entire network and all mounted drives, even drives that are marrying cloud services. Remember this, everybody, this is really a big deal because what will happen here is if you have let's say you've got an old driver G drive or some drive mounted off of your network.

    [01:06:57] You have access to it from your computer, right? Yeah. You click on that drive. And now you're in there and in the windows side Unix and max are a little different, but the same general idea you have access to you have right. Access to it. So what they'll do is any mounted drive, like those network drives is going to get encrypted, but the same thing is true.

    [01:07:20] If you are attaching a U S B drive to your company, So that USB drive, now that has your backup on it gets encrypted. So if your network is being used to back up, and if you have a thumb drive a USB drive, it's not really a thumb drive, right? There's external drive, but countered by USP hooked up.

    [01:07:45] And that's where your backup lives. Your. Because you have lost it. And there have been some pieces of software that have done that for awhile. Yeah. When they can encrypt your network drive, it is really going after all whole bunch of people, because everyone that's using that network drive is now effective, and it is absolutely.

    [01:08:10] Devastating. So the best way to do this is you. Obviously you do a bit of a local backup. We will usually put a server at the client's site that is used as a backup destiny. Okay. So that servers, the destination, all of the stuff gets backed up there. It's encrypted. It's not on the network per se. It's using a special encrypted protocol between each machine and the backup server. And then that backup servers data gets pushed off site. Some of our clients, we even go so far as to push it. To a tape drive, which is really important too, because now you have something physical that is by the way, encrypted that cannot be accessed by the attacker.

    [01:09:03] It's offsite. So we have our own data center. The, we run the, we manage the no one else has access to it is ours. And we push all of those backups offsite to our data center, which gives us another advantage. If a machine crashes badly, right? The hard disk fails heaven forbid they get ransomware. We've never had that happen to one of our clients.

    [01:09:29] Just we've had it happen prior to them becoming clients, is that we can now restore. That machine either virtually in the cloud, or we can restore it right onto a piece of hardware and have them up and running in four hours. It can really be that fast, but it's obviously more expensive than in some.

    [01:09:51] Are looking to pay. All right, stick around. We've got more to talk about when we come back and what are the Russians doing? How can you protect your small business? If you're a one, man, one woman operation, believe it. You've got to do this as well. Or you could lose everything. In fact, I think our small guys have even more to lose Craig peterson.com.

    [01:10:16] Backups are important. And we're going to talk about the different types of backups right now, what you should be doing, whether you're a one person, little business, or you are a, multi-national obviously a scale matters.

    [01:10:32] Protecting your data is one of the most important things you can possibly do.

    [01:10:36] I have clients who had their entire operating account emptied out, completely emptied. It's just amazing. I've had people pay. A lot of money to hackers to try and get data back. And I go back to this one lady over in Eastern Europe who built a company out of $45 million. By herself. And of course you probably heard about the shark tank people, right?

    [01:11:07] Barbara Cochran, how she almost lost $400,000 to a hacker. In fact, the money was on its way when she noticed what was going on and was able to stop it. So thank goodness she was able to stop it. But she was aware of these problems was looking for the potential and was able to catch it. How many of us are paying that much attention?

    [01:11:34] And now one of the things you can do that will usually kind of protect you from some of the worst outcomes. And when it comes to ransomware is to backup. And I know everybody says, yeah, I'm backing up. It's really rare. When we go in and we find a company has been backing up properly, it even happens to us sometimes.

    [01:11:59] We put them back up regimen in place and things seem to be going well, but then when you need the backup, oh my gosh, we just had this happen a couple of weeks ago. Actually this last week, this is what happened. We have. Something called an FMC, which is a controller from Cisco that actually controls firewalls in our customer's locations.

    [01:12:26] This is a big machine. It monitors stuff. It's tied into this ice server, which is. Looking for nastiness and we're bad guys trying to break in, right? It's intrusion detection and prevention and tying it into this massive network of a billion data points a day that Cisco manages. Okay. It's absolutely huge.

    [01:12:48] And we're running it in a virtual machine network. So we. Two big blade. Chassies full of blades and blades are each blade is a computer. So it has multiple CPU's and has a whole bunch of memory. It also has in there storage and we're using something that VMware calls visa. So it's a little virtual storage area network.

    [01:13:15] That's located inside this chassis and there are multiple copies of everything. So if a storage unit fails, you're still, okay. Everything stays up, it keeps running. And we have it set up so that there's redundancy on pond redundancy. One of the redundancies was to back it up to a file server that we have that's running ZFS, which is phenomenal.

    [01:13:40] Let me tell you, it is the best file system out there I've never ever had a problem with it. It's just crazy. I can send you more information. If you ever interested, just email [email protected]. Anytime. Be glad to send you the open source information, whatever you need. But what had happened is.

    [01:13:57] Somehow the boot disk of that FMC, that, that firewall controller had been corrupted. So we thought, oh, okay, no problem. Let's look at our backups. Yeah, hadn't backed up since October, 2019. Yeah, and we didn't know it had been silently failing. Obviously we're putting stuff in place to stop that from ever happening again.

    [01:14:27] So we are monitoring the backups, the, that network. Of desks that was making up that storage area network that had the redundancy failed because the machine itself, somehow corrupted its file system, ext four file system right then are supposed to be corruptible, but the journal was messed up and it was man, what a headache.

    [01:14:51] And so they thought, okay, you're going to have to re-install. And we were sitting there saying, oh, you're kidding me. Reinstalling this FMC controller means we've got to configure our clients, firewalls that are being controlled from this FMC, all of their networks, all of their devices. We had to put it out.

    [01:15:07] This is going to take a couple of weeks. So because I've been doing this for so long. I was able to boot up an optics desk and Mount the file system and go in manually underneath the whole FMC, this whole firewall controller and make repairs to it. Got it repaired, and then got it back online. So thank goodness for that.

    [01:15:33] It happens to the best of us, but I have to say I have never had a new client where they had good backups. Ever. Okay. That, and now that should tell you something. So if you are a business, a small business, whatever it might be, check your backups, double check them. Now, when we're running backups, we do a couple of things.

    [01:15:57] We go ahead and make sure the backup is good. So remember I mentioned that we have. Backup server that sits onsite. Usually it depends on the size of the client. But sits onsite at the client's site. So it will perform the backup and then tries to actual restore of that backup to make sure it's good.

    [01:16:18] And we can even. Client, depending on what they want. So a higher level, if a machine goes down, let's say it catches fire, or disk explodes in it, or completely fails. We can actually bring that machine online inside our backup server or the customer. Yeah, how's that for fancy and bring it back online in just a matter of minutes instead of days or weeks.

    [01:16:48] So that's true too. If that machine had been a ransom had this data, you raised whatever might've happened to it. We can restore it now. We've never had to knock on wood, except when there was a physical problem with the machine and as. Starting from scratching it, that machine, the new machine online in four hours or less.

    [01:17:12] And it's really cool the way it works. If you like this stuff, man, it is great. Okay. Protecting your data. I'm rambling a little bit here. You need an archival service there's companies out there like iron mountain, you can at your local bank, depending on the bank. It ain't like it used to be, get a box, right?

    [01:17:33] A special box in the vault that you. The tapes and other things in nowadays there's cloud options, virtual tape backup options, which is a lot of what we use and we do. Okay. We also use straight cloud at the very bottom end again. It's not located on the network. It's up in the cloud. It's double encrypted.

    [01:17:57] It's absolutely the way to do now if you're going to have a backup and if that backup, you want to be secure, it must not be accessible. To the attacker, you've got to put some literal air space between your backups and the cyber criminals. It's called an air gap. So there's no way for them to get to it.

    [01:18:21] Okay. Now I want you to consider seriously using tape these a LTO. These linear tape drives. They've been around for a long time, but their cartridges you can pull in and out. And they're huge. They they're physically small, but they can hold terabytes worth of data. They're absolutely amazing. There's some great disk based backup systems as what we do.

    [01:18:46] Some of them are been around a long time and they can be quite reasonably. Price. All right. So it's something for you to consider, but you've got to have at least that air gap in order to make sure that you're going to be protected. What should you be looking for in a backup system? This is called 3, 2, 2 1, which means maintain at least three copies of your data store the backups on two different meters.

    [01:19:15] Store at least one of the copies at an offsite location store, at least one of the copies offline, and be sure to have verified backups without air. Okay. Does that sound a little complicated? 3, 2, 1, 1 0 is what it's called. Just to be 3, 2, 1. Now it's 3, 2, 1, 1 0. I can send you Karen put together a special report on this based on our research.

    [01:19:41] And I can share that with you. Absolutely free. Hey guys, if you want it, you got it. But you got to ask me, just email me M [email protected]. This is absolutely essential. If you're a small business, a tiny business to do it this way. Let me tell you, okay, this is just huge. Physical backups should be stored off site.

    [01:20:02] I mentioned the bank fault. A lot of people just go ahead and take them home with. That might be a desk. It might be a tape. It can be a little bit complicated to do. And I've picked up customers that thought they were backing up. They were using a USB drive. They were putting it in due to flee every Monday.

    [01:20:24] And then every Wednesday, what happened? Every Wednesday they bring in Wednesdays desk and then they bring that disc home and then Thursday, they bring in the Thursday disc. And none of them had been working. Okay. So be very careful. All of your backups should be encrypted. We encrypted at the customer site and then we reencrypt it when we bring it over to us.

    [01:20:50] Okay. Keys are essential. Particularly if you're using a cloud-based backup, don't use the same keys across multiple backups. Very important there. You should have some good procedures that are well-documented test, test your restores because very frequently. We find they don't work. In fact, that's the number one problem, right?

    [01:21:14] If they had just tried to restore, even once from their backup, they would've known they had problems. And get those backups scheduled on a regular schedule. Okay. So there's a lot more offline backups and more that we can talk about another time, but this is important. If you want any help, send me an email, just put backups in the subject line.

    [01:21:39] I'll send you some stuff. Email me, M [email protected]. Now I am more than glad to help. Pretty much anybody out there. I'm not going to help. What about blah, blah, Amir Putin. But anybody else I'll help, but you got to reach out. Okay. You listen here. And I know some of this stuff is over some of our heads, some of your heads, you're the best and brightest.

    [01:22:04] That's why you're listening and I'll help you out. I'll send you some information. That's going to get you on the right track. Me [email protected]. That's Craig Peterson, S O N have a great day.

    1 hr 23 min
  • Did You Hear How the FBI, NSA, and CIA Got Tracked Because of Their Smartphones? How About You?

    Did You Hear How the FBI, NSA, and CIA Got Tracked Because of Their Smartphones? How About You?

    You're worried about surveillance. Hey, I'm worried about surveillance. And it turns out that there's a secretive company out there that to prove their mustard tracked the CIA, and NSA yeah. Fun thing.

    [Following is an automated transcript.]

    [00:00:16] This is a company that is scary. We've talked before about a couple of these scary guys.

    [00:00:22] There's this Israeli company called NSO group. And this it is, so group is absolutely incredible. What they've been doing, who they'll sell to these. Guys are a company that sells cell phones, smart phone exploits to its customers. And there are alleged to have sold their software to a variety of human rights abusers.

    [00:00:53] We're talking about NSO group coming up with what we would term a zero day hack against I-phones against Android phones against pretty much anything out. So in other words, I hacked that no one ever seen before and then use that in order to get into the phone and find information, they views things like the, I think it was what's app and video that was sent and usually.

    [00:01:22] To hack Saudi Arabian phones. You might remember Chris Shogi this journalist. I guess he was who apparently was murdered by them. Big problem. So this Israeli group. Yeah. Yeah. They sell to anybody that's willing to pay. At least that's what the allegations are. I've never tried to buy their stuff, but yeah, they're assisting government with hacks with.

    [00:01:48] Ultimate in surveillance. Another one clear view. We've talked about them on the show before this is a company that has done all kinds of illegal stuff. Now some of it's technically not illegal. They're against the terms of usage, what Clearview has done. And now they've gotten involved in this Russian Ukrainian.

    [00:02:12] War that's been going on here and they've gotten involved with a number of legal cases in the us. What they did is they said, okay great. Let's do something. You remember Facebook, right guys. So you've heard of that before. And how Facebook got started. Mike Zuckerberg. MK went ahead and stole the pictures of the women that were in Harvard's cattle.

    [00:02:41] And I will, when I'm, when I say catalog, okay, this isn't like a catalog of women, order one mail order type thing. We're talking about their index, their contacts, there is a catalog of all of the students that are there in the school. So Zuckerberg goes and grabs those against policy.

    [00:03:00] Okay. Maybe it wasn't strictly against policy at the time. And then he puts up some. Called the Facebook where people can look at a picture of a girl and decide whether or not she should get a five or a 10 or a one. Yeah. That sort of stuff, abusing people that really is abuse. I can't imagine.

    [00:03:19] The way people felt, I had seen their ratings by people that didn't know them, that somehow their Def definition of beauty really defined who they are. It's crazy what the stuff he did. So he started his business by stealing stuff. Microsoft started his business by. By going ahead and misrepresenting, some would say lying to IBM about what he had as far as an operative system goes right, again and again, we're seeing dishonest people getting involved, doing dishonest things to get their companies off of the ground.

    [00:03:54] And I have a friend who's an attorney who says, and Craig, that's why you will never be wealthy because you just wouldn't do any of that. So Clearview is another example of these types of companies. In this case, clear view, went to Facebook and crawled any page. It could get its little grubby crawlers on.

    [00:04:18] So it found your public fake Facebook page. It went. Over the internet. There's a number of websites. Some are out of business now, but the, you upload your pictures to you. People can rate them, can share them. You can share them. Hey, you got your own photo gallery here that you can share with friends and a million other people.

    [00:04:39] I'm right. That's what ended up happening. That's how those guys made the money. They're selling you on, Hey, you can look at how convenient this. And you can have your own little photo gathered at gallery and you can take that full load photo gallery and share it with your friends. And then if you read the fine print at T and we'll make money off of showing your pictures and showing ads well, Ah, Clearview went and scanned every website.

    [00:05:08] It could get its grubby little scanners on crawled through the mall, downloaded pictures of any face that it could find. And then went ahead and digitized information about people's faces. So it spent years scraping and then it put together its technology, facial recognition technology, and went to the next level, which is, Hey, please department, get my app so you can get the clear view.

    [00:05:41] And do you encounter someone? You can take a picture of them and upload it, which now gives them another face. Doesn't it. And then once it's uploaded, it'll compare it. It'll say, okay. Found the guy here. So with the Russia Ukrainian war, what they were doing is taking pictures of dead and injured, Russian soldiers, running them through this database online of all of these spaces, found out who they were and went so far as to use.

    [00:06:14] Stolen data online. Now this is war, right? The whole thing is crazy, but the stolen database online find out who their mothers were, the phone numbers for the mothers, and to have people all over the world, sending text messages to mom about their dads. Yeah. Okay. So Clearview sells it to police departments.

    [00:06:38] They sell it to pretty much the highest bidder they say, Hey, listen, we don't do that. Come on right now. There's other data brokers. And I've had a few on my show in the past who are using harvested information from phone apps to provide location data. To law enforcement so that they can then circumvent.

    [00:07:03] What you have a right to privacy. Don't you it's codified right in the bill of rights. I was first 10 amendments to the U S constitution and it was all defined by the Supreme court's carpenter decision. So we have protections in the constitution, natural, right? That were confirmed by the Supreme court that say, Hey, the federal government, you cannot track all of the citizens.

    [00:07:31] You can't track what they're doing. You can't harvest their information. And yet at the same time, They go to the data brokers that have put together all of these face pictures, figured out who your friends are, you sign up for Facebook and it says, Hey, you want me to find your friends?

    [00:07:49] See if they're already on Facebook. Just hit. Yes. Here, not blowed your contact list. So I'll go. Facebook says, oh, look at all your friends. Or we found isn't this exciting. And in the meantime, in the background, Facebook is looking at all of this data and saying, we now know who your friends are. And so many people have wondered I wait a minute.

    [00:08:10] I didn't talk about. I didn't do a search for product X online, and yet I'm getting ads for product X. Well, did you mention it to a friend who might've done a search for it? Because these search engines, these companies like Facebook know who your friends are, what they're interested in, and they'll sell ads to people who are going to promote to you the same items they're promoting to your friends.

    [00:08:35] It's absolutely crazy. So this company. It's called and they're very quiet, very low key. The website doesn't say anything at all, but they took their software. That's pulling all of this data together and compiling it. Yeah. And ASX pointed all of this technology towards the national security agency and the C I a and Jews, their own cell phones against them.

    [00:09:08] Now, why did they do this? They didn't do it to prove something about how, you shouldn't allow this sort of thing to happen and they didn't do it to prove that man, we've got to have tighter controls because look at what we can do. If we can do it, other people can do it. No. According to audio, visual presentations and recordings of an ACX presentation reviewed by the intercept and tech inquiry.

    [00:09:36] claimed that it can track roughly 3 billion devices in real time. That's equivalent to a fifth of the world population. You're not going to find anything out about Asics it's called anomaly six. Good luck online. If you find it, let me know [email protected]. I'd love to know more about these guys. The only thing on a website for them as an email address and a six anomalies six in that presentation showed the nation spooks.

    [00:10:13] Exactly what knew about. All right. Apparently is also ignoring questions from journalists and will only respond to emails from people in upper levels of federal agencies, which means, and maybe this is a supposition from our friends over at tech dirt. I don't know. But then what that means is they're looking to sell your information in real time.

    [00:10:43] To the feds to get around the carpenter decision and the constitution just absolutely amazing. Hey, go online right now. Craig peterson.com. I'll send you my special report on passwords and my two other most popular Craig peterson.com. Stick around.

    [00:11:06] Have you ever wondered about search engines? Which one should you be using? You're not alone. It's probably the number one question I get from people. What should I use? Google is falling behind, but we're going to talk about the top engines and the why.

    [00:11:23] Google has been an amazing company moving up. Of course, we're just talking about the cheats.

    [00:11:31] So many companies have taken over the years and Google has certainly had its share of cheat. I haven't seen anything about them just doing completely underhanded things to get started. I think. They were pretty straightforward. They had a great idea back in the beginning, where they were just looking at links, how many sites linked into this one particular site?

    [00:11:57] And that gave this concept of a page rank. Very simple, very easy to do. Of course, are problems with. Because you would end up with pages that are older, having more links to them, et cetera. And they have over the years really improved themselves, but we also have some other problems right now with Google.

    [00:12:22] If you do searches on Google for a number of different. And you'll see that really Google search quality has deteriorated in recent years. We've talked before here about some of the problems with Google and elections and how they have obviously gone out of their way to influence the election.

    [00:12:43] There is study down in, done in orange county, California, or at least about orange county, California, and an election down there showed that Google had a major influence on that election and also tilted it a certain way on purpose. Absolutely amazing. So that's one way Google has fallen behind, but you can.

    [00:13:06] At all kinds of searches and hope you're going to get a great response. And you don't have you noticed that it's gotten worse and then on top of it, you're starting to see more ads squeezed in it is not great. I have used. Of course for programming in years past, before that I liked alter Vista, which was a digital equipment corporation product out there.

    [00:13:32] Vista was pretty darn good. And you could use Boolean logic with it. Google says you can use Boolean with us, but it's not the same as Google's is very simple. But at any rate they have not made any. Leaps here going forward. It's been absolutely amazing. So let's go through the search engines.

    [00:13:53] I'm going to give you right now, the pros and cons to some of these search engines out there. So we started with. It is 800 pound gorilla. And in case you didn't know the number two overall search engine is YouTube. Okay. But let's stick with straight searches, not video searches. So what is great about Google?

    [00:14:19] One of the big things is they like fresh content. So if you're looking to do search engine optimization for your business, you are best off having some Keystone pages. So having these pages that are. Kept up to date. So you might have a page on whatever it might be hacking VPNs, right? And you make sure you update it because Google does favor the fresh content.

    [00:14:45] They rank blogs and. Services, which is really nice and they're accessible in any device. They have apps that work well on a browser. And I'm right now, I'm [email protected] on the best search engine. So you'll see some of this information there. They don't like about it is the same thing you don't.

    [00:15:09] Right? Which is, it collects all kinds of data on you. They also have hidden content that, that might damage your ranking as a business or someone who has a website and the search delivers. Too many results, millions of results. Yeah, there probably are millions of results for a single search, but what I want are the really relevant ones and Google learns over time.

    [00:15:38] What kind of results that you want, which is kudos to them, but they are tone deaf sometimes, frankly as well. Okay. Our number two on our list of topics. Is duck go. Now I've been talking about them for quite a while and some people have been disparaging talk, talk, go lately. And the reason is they say, what.

    [00:16:03] And those search results maybe are a little wrong, right? They are maybe student little sensory, not as much as Google does, but some, at first duck go.com is where you'll find them online named after that kids game. Is a privacy search engine. So it is not tracking or storing any information about you.

    [00:16:29] That's a very big one. There are searches are very fast, but they're backed. The actual backend search engine is. Which is Microsoft. We're going to get to that in a couple of minutes here. That means that if Microsoft is deciding to do some weighting on search results, based on their political views, then that's going to show up in duck go, but it's nowhere near as bad.

    [00:16:54] And I've talked about it on the show before we'd done some examples. So it is also now giving you the option to restrict your searches to the last month worth of results, which is really nice. That keeps a little more up to date. They also aren't great at image searches, no personalized results, and it is free, which is nice.

    [00:17:17] You might also want to look at quant Q w a N T. If you look at. A private or privacy browser. Quanta's a French company, but it does leave English as well. Okay. English results. They like the older and well-established web pages, they rank home pages. They do not rank blogs. They crawl all kinds of hidden content and non hidden, equally, unlike Google, which is really great being as not great at forums.

    [00:17:50] As I mentioned, blogs, they're not as fast as Google. And they have some seriously heavy search results screened. Dogpile they've been around for quite a while. You might want to check them out. They have something called fetches and favorite fetches. So you can have a home screen when you go to dog pile and you'll see right there.

    [00:18:14] Your favorite searches and they're right there for you. You can just keep going to them. They use multiple databases so they can get broad results, multiple backend search engines, and there's no home screen personalization available. And lots of sponsored results, which isn't a real big deal, but you'll find them [email protected], Google scholar search.

    [00:18:38] I've used this a number of times. If you're looking for scholarly articles, it is really good. You can get citations in various styles. If you are working on your master's PhD, whatever. B and they're imposing a style in the document that you're writing. So you can put it into the bibliography and a, they got a lot of great stuff.

    [00:19:02] Google scholar you'll find online at scholar dot, google.com. Wearable PDs, sir. It focuses on technical terms and applications, which is good, friendly to non-tech users. And it is only searching the web well, PD is 10,000 word and phrase database. So that's pretty. To to understand to Yahoo search, they have a home screen, has news trending topics.

    [00:19:33] I've used y'all who? Of course it's not what it used to be, but it does have everything right there. Even your horoscope. And the ads are not marked out clearly. And then there's the internet archive search. This is actually a site that I fund. I donate money to them every month and you'll find [email protected], but it is really cool.

    [00:19:58] You can search based on timeframes again, if you are doing papers, if you're a journalist. You can find what was the internet like? Or was this webpage? What was it like around a hurricane Katrina in 2005, right there. We will find it [email protected]. Hey, stick around. We'll be right back.

    [00:20:23] You already know that hackers are coming after you we've talked about how they are out there, scraping web pages, putting together stuff. I want to bring up again, the Ukraine, Russian war and Russia leaking data like a sieve .

    [00:20:39] It is, of course in the news again, it seems like it has been in the news for how long now, six years, maybe longer in this case, we're going to talk about what the hackers are doing because they're not just doing it to Russia.

    [00:20:56] They're doing. Us. And it's a problem. We're going to explain why you've heard of doxing before D O X I N G two docs, someone which is basically to find documentation about people and to release it. That's really a part of it. So you've seen some political operatives who have gone online and doxed people.

    [00:21:22] For instance one of them is libs of tick talk. You might've heard of that one, and this is where they take all of these crazy things that crazy people on tick talk, go ahead and publish and just put excerpts of them together. They don't cut it up to make them look crazy. No. They let them be crazy.

    [00:21:42] All by themselves and put it online. So some libs decided, Hey, we don't like this. And journalists who had been complaining about doxing before that shouldn't be done and it's unethical. It should be illegal. Yeah. What does she do? She goes and docks. The lady that was running libs of tick talk.

    [00:22:07] And I, it just blows my mind here. How can these people be so two faced, they really are just crazy to face. So she went ahead and did what she said should never be done. And I'm sure she had some form of justification for it and put it out online. So I went online, comes this lady's home. Address her name.

    [00:22:31] Kinds of stuff and that's available online right now. Now you might want to try and do something that I've done before, which is, if you go to one of these data brokers, ads for these things, right? Do a search for yourself with us. And have a look at how accurate that information is. When I looked last time I looked cause I had a few data brokers on the radio show.

    [00:22:58] I would say less than a third of the information that they claimed was information about me was actually accurate less than a third, frankly. And I don't think that's a particularly, what's the word I'm looking for, but Unique situation. Let me put it that way. I don't think it's unique at all. I think they get a lot of it wrong because remember, they're trying to piece together this piece together that and put it all together.

    [00:23:27] So you can't a hundred percent rely on any of that stuff. And as I said, for me, it wasn't particularly accurate. Now let's move into. Ukraine has claimed to have doxed Russian troops as well as FSB spies. Do you remember them from the Soviet union? They still exist, and hacktivists actually have official scheduled meetings and are leaking private information from various Russian organizations in Russia.

    [00:23:59] So we're talking about things like their names, birth dates, passport numbers, job titles, and the personal information that they have released about these Russian companies. And people goes on for pages here. It looks like frankly, any data breach, you'll find a great article about this that I'm referring to in wired.com, but this particular data.

    [00:24:25] Can change personal information on 1600 Russian troops who served in bootcamp, a Ukrainian city, that's been attacked by Russia. And by the way, you've probably seen these things. There were all kinds of accusations here of multiple potential war crimes. What was going on over there? So this data sets not the only one.

    [00:24:50] There's another one that legislature legislation. Allegedly contains the names and contact details of 620 Russian spies who are registered to work at the Moscow office of the F S B. That is Russia's main security agents. Now this information wasn't released by hackers in North Korea or hackers in the us or Russia, because we already know Russian hackers.

    [00:25:22] Don't attack Russia. They're not stupid. Okay. They don't want boudin coming after them, but this was published by Ukraine's intelligence service. So all of these names, all of these personal details, birth dates, passport numbers, job titles, where they're from all kinds of stuff. I'm freely available online to anyone who cares to look now, Ukrainian officials wrote in a Facebook post as they publish the data that every year peon should know their names.

    [00:25:56] So you got to bet, there are a lot of people freaking out over there. Absolutely freaking out in Russia that is. Since the Russians invaded Ukraine, there have been huge amounts of information about Russia itself, the Russian government activities and companies in Russia. These, all the guards that are over there and it's all been made public.

    [00:26:21] So it's very interesting because these are been closed off private institutions in the us. Yeah, we do some hacking of potential adversaries, but they don't release. All right. Not at all, but there's really two types of data here. First of all, you've got the information that the Russian authorities are publishing.

    [00:26:42] Their allies are publishing, and then you've got the hacktivists, these companies, these groups, I should say. Anonymous hundreds of gigabytes of files and millions of emails have been made public, including some of the largest companies within Russia. The big guys, oil and gas companies or lumber companies, et cetera, et cetera.

    [00:27:08] So there's a former British Colonel in the military intelligence. Wired is quoting here, his name's Phillip Ingram. And he said, both sides in this conflict are very good at information operations. The Russians are quite blatant about the lies that they'll tell we're used to that aren't we, and much of the Russian disinformation has been debunked, but they say.

    [00:27:36] They have to make sure that what they're putting out is credible and they're not caught telling out right. Lies in a way that would embarrass them or embarrass their international partners. So it's really quite interesting. We've started seeing the stuff coming out in March 20, 22. Of course. And it's hard to tell how accurate the data is.

    [00:28:00] Looks probably pretty accurate. It has been scooped up as I mentioned on the show before, but. Some activists, one of whom has put together an app that anyone can download. And that allows you to send texts to the mothers of Russian soldiers, some alive, some dead, and it automatically translated into Russian.

    [00:28:24] I assume it's a crude translation, but whatever. So you can. Harass some bore a babushka over there in Russia, whose grandson is out there fighting. This is just incredible. We've never seen anything like any of this before, but doxing very toxic online behavior. And when it comes to war, the gloves are off.

    [00:28:48] And by the way, these groups that I mentioned, these hacktivists have official meetings, Tuesday mornings on telegram, and they talk about who the next target is. Absolutely amazing. Make sure you visit me online. Craig Peter sawn.com and don't go anywhere because we've got more coming up here about organizations in general, here in the us breaches are up stolen data or.

    [00:29:17] And the number of bankruptcies are up because of it.

    [00:29:23] Hacks or up no, you know that we've known that for awhile, but did you know that is not necessarily the number one reason businesses are suffering breaches. So we're going to talk about that right now. What else you have.

    [00:29:39] We've talked before about some of the websites that I keep an eye on.

    [00:29:44] One of them is called dark reading and they've got a lot of good stuff. Some of the stuff I don't really agree with, who agrees with everybody or another person, just one, even a hundred percent of the time. Like no one. Okay. So in this case, we're talking to. Organization suffering a breach.

    [00:30:03] And the stat that they're quoting here is that more than 66, 0% of organizations have suffered a breach in the last 12 months. That's huge. And the breaches have gotten more expensive. Global average breach cost is $2.4 million. And if you are unprepared to respond to a compromise, that price tag increases to $3 million.

    [00:30:36] Yeah. That's how bad it is. That's what's going on out there right now. But the point that really they're trying to make here, a dark reading in this article by Robert Lim. Is that organizations are focused too narrowly on external attackers when it's insiders third parties and stolen assets that cause many breaches.

    [00:31:02] That's what this new study is showing from Forrester research. Now I had them on the show a few times in the past, you might be familiar with them. They are a research company. The charges a lot for very little information, they've got the research to back it up right there. They're really one of the leading, if not the leading research company out there.

    [00:31:26] So last month they came in. With the 20, 21 state of enterprise breaches report. And they found that the number of breaches in the cost of breaches varied widely, depending on where the organization is based. And. The big one that you have control over is whether they were prepared to respond to breaches.

    [00:31:53] Now, companies in north America had the largest disparity between the haves and have not listened to these numbers. They're bad for businesses, these numbers, and they're worse for individuals. The average organization required 38 days. 38 days over a month on average to find eradicate and recover from a breach, but companies that were not prepared for security challenges took 62 days.

    [00:32:28] Now the good news here is that this is down. It used to take nine months on average, and now we're down to two months, but here's the big question. Can you, or can a company survive 62 days or is it going to be out of business? Do you have enough money to make payroll for the next two months? That's where the problem.

    [00:32:55] Really starts to come in. That's why small businesses that are hacked small businesses that are using things like Norton or some of the other real basic software without having a good firewall and good security practices. And same thing with individuals here. You are going to be out of business.

    [00:33:17] That's of the showing right now. And your insurance policy that you have for cybersecurity insurance will not pay out. I did a presentation for an insurance industry group. This was in Massachusetts and it was a statewide group. And we'd talked about how the. Are not paying out the companies.

    [00:33:41] Aren't right. And why, and if you are not prepared, if you are not doing the right things and I can send you a list of what you need to be doing, if you'd like, just email [email protected]. Be glad to send it to me. M E at Craig Peterson, P E T E R. So when Dr. And just to ask for it and I'll respond to you or we'll get married or someone else to forward it to you because I've already got it.

    [00:34:07] Okay. This isn't a big deal for me. Okay. It's ready to go. But that list is an important list because if you don't meet the standard. That the insurance industry has set forward and you are a hack. They're not going to pay you a dime, even if you Sue them. And we've seen this with very large companies as well, where they're trying to recover tens of millions of dollars from the insurance policy, and they didn't get a dime.

    [00:34:36] They had to also pay who knows how many millions to lawyers to Sue the insurance companies. And they lost. Okay. It's a very big deal. So there's a huge misalignment, according to Forrester, between the expectation and the reality of breaches on a global scale, there's a big disparity of above $600,000 between those.

    [00:34:59] Paired to respond to a breach and those who are not. And we can talk about that as well, because there's things you need to do obviously backup, but backup means you've got to check the backup. You've got to make sure it's valid. You should be spinning up the backups on, in a virtual environment in order to make sure the backups are good.

    [00:35:22] There's a lot of things you should be doing. Okay. And that's just a part of it. Plus, do you have your PR people ready? Are you able to respond to the state requirements? A lot of states. Now, if you are hacked require you to report it to the state, in some cases in as little as 72 hours. So do you have that paperwork ready?

    [00:35:46] Do you have the phone numbers of all of the people that are on the team? Okay. All of these things now, the threats are not just the external hack. Anybody who's trying to protect their data is focused on obviously the external hackers. That's where we tend to focus part one part two is we focus in on the people that are working inside.

    [00:36:13] The company, right? It's a zero trust narrative here. Why is this guy in sales, trying to get into the engineering files? Why are they trying to get into payroll? You understand where I'm going with this, you buy and what I'm selling. You don't want them to have access to stuff that they don't need access.

    [00:36:37] Attacks that Forrester found were spread over external attacks, internal incidents, third party, and supply chain attacks, which is really big nowadays and lost or stolen. Assets globally. Half of companies consider external attacks to be this top threat, but in reality, only a third of the incidents come from external actors.

    [00:37:04] Nearly a quarter of them are traced back to an internal event. 23% consisted of lost or stolen assets and 21% involved with third. Partner. Interesting. Hey, so we've got to keep an eye on this. These external attacks are a very big deal and that's where they have success with what are called zero day attacks.

    [00:37:31] But your internal people can be a problem. Now I have. Put together in 2022, this is something really important. What we call a POA and M it's a plan of action and milestones of what you need to be doing. For your cybersecurity. Okay. This is available absolutely free. You have to email me M [email protected].

    [00:38:00] But the idea behind this is it's a spreadsheet that you can use in numbers on a Mac or Excel on windows. And it has all of the key items. Now we follow what's called the. 801 71 standard. This is the national Institute of standards and technology, and they've laid out all of the different things. That you should be doing now.

    [00:38:26] We've broken them down into eight cybersecurity activators as what we called them. And we have, you should have already gotten an email this week from me. If you're on my email list, just talking about, cause we're starting now getting into those cybersecurity activators. I'm showing you. To do about each one of them.

    [00:38:46] So you can do it yourself. So many of us are stuck with being the CTO or the guy or gal in charge of it just because we like computers or we know more than somebody else. So if you're on my email list, you will be getting these things off. We're going to be going through them in the weeks. I had little quick mini micro trainings, if you will, but you gotta be on the email list in order to get them.

    [00:39:12] These are also appropriate for home users right now. You're going to have to make your decisions as to what you're going to do, but home users have the same exposure, the same basic problems that they have in bigger organizations out. So I follow the national Institute of standards and technologies.

    [00:39:34] They have broken it down into a number of different sections. They actually require it. And if you are compliant with this new standard you are going to be able to recover your money from the insurance company. If you are hacked, I don't know. I was going to say it for a win, but hopefully you won't get hacked because of this.

    [00:39:58] So it's an important thing to follow. So make sure you go to Craig peterson.com/subscribe right now and get subscribed. A lot of stuff for home users. My business is focused on securing businesses. Particularly regulated businesses, right? If you have intellectual property, you don't want to have stolen a few do government contracts where they're requiring you to be compliant with this new standard or some of the others, but it's.

    [00:40:27] Basic stuff that every business should be following. So just email me, M [email protected] with your questions. We've been really good at answering them. We've probably lately been averaging about a dozen a day. Which is quite a few, but so it might take us a little bit to get back to, but we've gotten much better.

    [00:40:48] Mary her number one responsibility right now is making sure that we answer all of your emails. We'll send out this plan of action and milestone spreadsheet for you. So you know what to do. This is updated. This is 2022. Everything you need right there. Me at Craig Peterson dot. Alright, you'll also find my podcast there.

    [00:41:14] Craig peterson.com. And I want to point out that I'm not doing the show on video anymore. Just wasn't getting enough traction with, if it just takes too long. Anyways, Craig peterson.com.

    [00:41:29] This is one of the top topics I've had people ask about lately, and that is protecting yourself and your business against Russian hacker. So I've got a presentation. We're going to run through it. We're going to talk about what you can do.

    [00:41:46] This has been a long time coming. I have been doing a lot over the years of webinars of online meetings, trying to help people understand what's going on, what can be done.

    [00:41:58] And I got a great email this week from one of the listeners. Who's been man on my email list now for years, I'm not even sure how many years. And he was saying, Hey, thanks for giving all of this information for free for small businesses. I can't afford it. And I got to thinking, because there've been a lot of requests lately, for instance, backups how should I be doing them?

    [00:42:22] What should I be doing? And a number of other topics that really all go together into the, how do I protect myself? My business. From ransomware from these Russian hackers. So that's what we're going to be talking about today. We're going to go through a few of these. This is going to be a series.

    [00:42:41] We're going to continue this here and weeks ahead, and I appreciate all your feedback. And if you miss part of it, make sure you email me just M. Craig peterson.com. Let me know, and I'll be glad to send some of it to you. Now I'm recording this on video as well. So it's great when you're driving around and listening in picking up some tidbits.

    [00:43:04] And if you do want to see the recorded version again, dropping them in an email to [email protected] or search for me on YouTube or on one of the other sites that are out there like grumble and you'll. This as I release it. Cause this is going to take a few weeks to really get into the whole thing.

    [00:43:26] So let's get started. I'm going to pull this up here. Full screen. For those watching at home and what this is called today, we're talking about protecting your business and your self from Russian hackers because they have been out there. They have been causing just all kinds of problems, but there's a few things that you can do.

    [00:43:48] And I have them up on the screen here. Let me pull them up, but I want to get into the background first. Russian ransomware group. They're a bunch of bad guys and it's called Conti. Now. Conti has been around for a long time. These are the guys that have been ransoming us. They're the guys who in rants. The businesses they've been rants.

    [00:44:10] Government, you might've heard them. They've got into hospitals. They have been all over the place and they've raised a whole lot of. For the Russians. I'm also going to tell you about a couple of things you can do here. Cause there's a real neat trick when it comes to keeping Russians out of your computers, but Conti decided, Hey, listen, we are all for Russia and president and Putin.

    [00:44:34] So they came out with an official warning, oh, I want to read this to it says if anybody. We'll decide to organize a cyber attack or any war activities against Russia. We are going to use our all possible resources to strike back at the critical infrastructures of an enemy. Yeah, no, not the best English, but much better than my Russian.

    [00:44:55] I got to say that I know two words or so in Russian, but they said that they were announcing full support for president. That's a pretty bad thing. If you asked me, they also have ties to Russian intelligence intelligence, but what are we talking about really? Think of the KGB.

    [00:45:13] The FSB is what they're called nowadays, but directly tie. China and North Korea, Iran, or also now tied in with Russia to varying degrees, but all of them are a little bit concerned about getting into it a little too much, but we're going to talk about their tactics. That's what's important today. What are they doing?

    [00:45:35] Why are they doing it? What can you do about. So the first thing is password sprain. This is big deal. I've got a nice big slide up here. I like that color blue. I don't know about you, but I think it's pretty, but password sprain is something we all need to understand a little bit better. It's a brute force attack that has been really hurting.

    [00:46:00] Many of us. Let me see if I can get this to work. For some reason it has decided it just doesn't want. Let me see here. What is up? Oh, is something isn't it's just, I'm getting a white screen, but it's a brute force attack targets users who have common passwords. Now this is a problem. When we're talking about passwords.

    [00:46:25] If you have a password that has been breached in any of these breaches that have gone on over the last, however long, right? 30 years plus now that password is known to the bad guy. So what they'll do is they'll take that common password and they'll start to try it. So password sprain is where they will go to a bank site or they'll go to Google.

    [00:46:51] The, oftentimes they're trying to get at your email accounts. So if you have Google email or Yahoo or Hotmail, they'll try it. Use passwords that they have found against accounts that they have found on those various sites that ends up being quite a big problem for everybody out there. Okay. I got that screen back here.

    [00:47:12] So I'll put that up for those people who are well. But they will send multiple times attacks using variations of these passwords. And it's known as a low and slow method of password hacking because if they were to go bam, and send all of these passwords and login attempts.

    [00:47:35] They'd get caught. The automated systems would say, Hey, wait a minute. This is not good. We're going to cut you off. In fact, that's what I do for my client. We have remote access using SSH, which is a an encryption session so that we can have a terminal session. And if you try and log in three times, We automatically zap you, right?

    [00:47:58] We shut you down. So they take a very slow approach to this password sprain technique. And they're also going after volume, which makes a whole lot of sense. And there are right now, billions of passwords usernames, email addresses that have been stolen that are sitting out in the dark. So you've got to make sure that you are not reusing passwords.

    [00:48:24] How many times have we talked about that? You've got one common password that you're using over and again, while that's a problem, but they're not going to keep hacking your account. They're going to switch from one account to another because they don't want to get locked out.

    [00:48:39] Just like I lock out somebody who's trying to get in. So if someone's coming from that same. IP address that same internet site. And they're trying to log into that same account multiple times. Bam. They are gone. So with path's word sprain, they're trying to get around the problem of you noticing they're trying to get into a bunch of different accounts and they try and leverage it.

    [00:49:04] So they'll oftentimes use multiple computers that they've stolen access to. We've talked about that before too. It gets to be a real big. Now they're also targeting these single sign-on and cloud-based applications, because once they're on. Using one of these federated authenticated authentication protocols, they can mask the malicious traffic.

    [00:49:30] We've heard some of these hacks lately where they're using a token that they managed to pick up from somebody's email, I account, or they got onto Microsoft and they got into the email account on Microsoft. That happened recently. In a supply chain attack, solar winds. You heard about that 20, 21, right?

    [00:49:52] So they're going after these email applications, including Microsoft or Microsoft has done they're going after routers and internet of things, devices for a very good reason, those IOT devices, which are things like your smart lights, they can be. Controlling the cameras outside, they go on and on there's thousands, millions of them.

    [00:50:14] Now I actually all the way through your microwave, they tend to not be very well protected. So that's a real big target for them. So step. They want to acquire a list of usernames. Step two, they're going to spray the passwords. Where do they get those passwords in those usernames? Or they get them from breaches.

    [00:50:36] So again, if you have an account that's breached at some online shopping site, a big one, a small one, it doesn't really mean. That particular breach is now well known and they can, will and do gain access to your account which is step three, gain access to it. It gets to be a serious problem.

    [00:50:57] Okay. How do you know if you are under attack? Number one? There is a spike in failed. Log-ins this is where having a system and there's technical terms is tough for this. I'm trying to avoid a lot of those terms, but this is where the system is watching logins, noticing that there's a problem and going ahead and stopping it, not just noticing it, but stop. Very important to do. There are a high number of locked accounts, which means what it means that again, someone's been trying to log in. You should make sure that your account, if there are invalid, lock-ins automatic. Locks it out after some number of attempts and five attempts is usually considered to be okay.

    [00:51:44] I know on my phone, for instance, I have a higher number of the neck, cause sometimes the grandkids get at it. But when it comes to your business account, when it comes to your bank account, you probably don't want to have a whole bunch of attempts, and then in known or valid or invalid, I should say use.

    [00:52:04] Attempt again, why are they trying to log in with a username that just doesn't exist? Yeah, it can be a problem. Hey, when we come back. We're going to talk about some steps. Like you can take here to really remediate, maybe even stop a password spraying attack. I've already given you a few ideas here, but what are some act of things that you can do, particularly for a small business to really protect yourself?

    [00:52:33] Hey, stick around. We'll be right back. Craig peterson.com.

    [00:52:39] Russia has, been hacking our computers, Russia's continuing to hack our computers and this is a real problem. So we are going to talk right now about how to stop some of these things. We already talked about password sprain. How do you stop it?

    [00:52:56] There are a lot of things we have to pay attention to, and that's what I'm going to be doing in the weeks ahead.

    [00:53:03] We're going to be going through some of the things you need to do to keep yourself safe. Keep your business safe in this really dangerous online. There are so many things going on. So many people that are losing their retirement businesses, losing their operating accounts. We've seen it before with clients of ours while you know their clients now.

    [00:53:29] And it was just a devastating thing to them. So I don't want that to happen to you now, if you are interested. All of this is recorded and I am doing this as video as well. We've got slides and you can find out more about it. Just email me M [email protected]. It's really that simple. And I didn't let me know.

    [00:53:54] And I'll be glad to send it off to you. Okay. This is available to anybody I'm trying to help. And we've had a lot of emails recently about some of these things. So th this is covering everything from the password spraying we're talking about right now through backups and other things that you need to do.

    [00:54:14] Let's get going on our sprain problem. So w what are the steps that we need to take in order to really remediate against one of these password spraying attacks? And frankly, it is. Oh, a lot to do. It has a lot to do with our users and what we do, if you're a business, if you are an individual, we need to be using longer passwords.

    [00:54:43] Now we're not talking about all of these random characters that we used to have. I remember having to have my password be at least four characters, long APAC, when didn't even have to have a username, it was just all based on the password. And things changed over the years, the latest standards that are out there right now come from this too, which is the national Institute for science and technology.

    [00:55:07] They are the guys that put together, all of the guidelines said federal government and businesses need to follow. And they're telling us that a longer passwords means elaborate pass phrase. So you should use 15 character passwords. I had an article just a couple of weeks ago saying that an eight character password can be cracked almost instantly, certainly within an hour, any eight character password.

    [00:55:39] So if you're still using that, you've got to make a change. And obviously nine characters is a lot more possibilities, takes a lot longer to crack. I don't have those numbers right in front of me, but 15 is the ideal. So use pass phrases instead of single words. So phrases like I don't know secretary of one, the Kentucky.

    [00:56:04] There you go. There's a phrase. So what you would do is put, maybe dashes between each one of the words. Maybe you would go ahead and use a comma, put some numbers in there, put some special characters in upper lowercase, right? So it's basically on uncrackable at that point. And that's what you want.

    [00:56:24] Next one. When we're talking about rules for your passwords, the best passwords are the passwords that you can remember without writing them down and words that don't make sense to anyone else's. I remember taking a memory course a few years back and they had random words and you had to remember them.

    [00:56:49] And the whole idea was okay, visualize this happening. And as I recall, man, it's been a lot of years I won't say decades, but it hasn't been. Since I did this, I still remember a part of it, it was first word was airplane. Next was all envelope. The next one was paper clip. Next one was pencil.

    [00:57:08] So I visualized an airplane flying into an all envelope and that all envelope then goes into a paper clip and a pencil writes on the outside. Like it's addressing it to someone. That is a good little password, actually airplane or envelope, paperclip, a pencil with a mixed case and maybe a number two or special symbol thrown in.

    [00:57:35] Those are the types of rules that we're talking about. The types of rules that really. Next up here. Oops. Wrong keyboard. Stay away from frequently used passwords. We've talked about this many times. If you're using one of the better password managers, like for instance, one password, you will automatically have any passwords that you are there in Shirin or that it creates you'll have them checked via a website out there.

    [00:58:07] It's called. Yeah. Okay. It's called. Have I been poned I, and I hated to say this because how do you spell it? It's all one big, long word. Have I been poned to.com and poned is P w N E d.com. It will tell you if a password that you're trying to use is a known password. If it has been found out in the wild, okay.

    [00:58:32] Use unique passwords for every site you visit, I can't stress this enough. We were talking about password sprain. If you use the same password and email address on multiple sites, you're in. Because all they have to do is try your email address and your password for whichever site it is that they might want to try out.

    [00:58:58] Remember, many of them are trying to get into your email and they have done that successfully. With Microsoft email, if you have their Microsoft 365 service and you might want to read the fine print there very carefully, because Microsoft does not guarantee much of anything. You make sure you back it up yourself.

    [00:59:20] Make sure you do all of these things because Microsoft just plain, isn't doing them for you. Next one here. Next up is our password manager. And I mentioned this before installing and using a password manager is phenomenal. It automates the generation of passwords. If you have. Integrated with your web browser.

    [00:59:45] It now allows your web browser to work with your password manager. So when you go to a site, you can have it pull up your passwords. How could it be much easier than that? It's really rather simple. That way it's keeping track of your logins. And again, One password.com is the one I recommend and people get confused.

    [01:00:06] When I say that, when I'm saying one password, I don't mean only have one password used for everything. One password is a name of a company. Okay. So it Talking about only having a single password, but use a password manager. And I've got all of these up on the screen right now. If you're interested in getting copies of these, you can go ahead and just email me M [email protected].

    [01:00:35] And I'll make sure I send you a copy of the slide deck of this presentation as well. Cause this is just so important, frankly, but having these points is going to be huge for you. Now strange activity. That's another very big deal. And we're going to talk about this when we get back, what is it?

    [01:00:55] What does it mean? But I'm going to hold off the rest of this, I think for another week. But right now, what let's hit this, we're talking about odd log-in attacks. A lot of login attempts, the excessive login attempts trends in unusual activities take any, you need to basically take measures to block it and determine if this activity is legitimate.

    [01:01:20] Is someone just for forgetting their password and spraying themselves or what's going on? Okay. There you go. Simple. Hey, everybody, you can find out a lot more and you'll be getting links to this automatically to these videos, et cetera. If you're on my email list, Craig peterson.com and you can email me M [email protected].

    [01:01:45] We'd be glad to send you this or any other information I might have. All right. Take care. We'll be right back.

    [01:01:54] Putin has been working for a while. In fact, it looks like as early as September in 2021, Putin started going after major us corporation. So we're going to talk about that. And what does it mean?

    [01:02:10] Putin has been going crazy for a while. I'm going to put this up on the screen for those of you who are watching either on rumble or YouTube, but Putin planned this whole invasion apparently quite a while ago.

    [01:02:27] And I got an article from the Washington post up on MSN talking about what Putin did at least a little bit about what he did. And you can see right here if you're following. That Russian agents came to the home of Google's top executive and Moscow. And what they did is gave an ultimatum. They told that Google, a senior executive that they needed.

    [01:02:55] Pull down an app that was in use in Russia. And this app was polling. It was for people to do polls and say, Hey what do you think about Putin's garden performance, et cetera. We do them in the U S all of the time you hear about the polls right left and center. Poland, which is a small country next to another small country called Ukraine next to a large country called Russia.

    [01:03:21] But we're talking about Paul's favoribility polls. What do you think they should be doing? What do you think that the government should be doing and maybe what they should not be. So Putin didn't like this. He didn't like this at all. And so what he did is he sent a couple of guys ex KGB, FSB, the secret police over in Russia by to visit this Google executive.

    [01:03:47] If you're the Google executive, what are you going to do? If you Google. Yeah, you're going to say, oh my gosh, I'm out of here. So I'm not sure if she, if this executive was an American or Russian, this article doesn't seem to be clear about it, but what happened is they said, okay let's go hide.

    [01:04:12] So they rented a hotel room for the. They put her in it and they rented the room under an assumed name. So it wasn't the real name of the executive. It wasn't tied into Google and they thought, okay, now we're pretty safe. Cause you got a hotel security, I guess there are a couple of Google people hanging out with her and they felt pretty safe.

    [01:04:35] What happens next? There is a knock on the door. These same agents, again, that are believed to be Russian secret. Police showed up at her room and told her that the cock was still ticking because they had given her 24 hours for Google to take down the app because Putin, dental. People weren't particularly pleased with Putin.

    [01:05:02] So at that point, of course it was forget about it. And within hours, Google had pulled down the app. Now you might complain, right? A lot of people might complain about it. It's one thing for a company like Google or apple to capitulate, to a government to do maybe some censorship, like the great firewall of China.

    [01:05:25] You might've heard of that where the Chinese citizens can't get certain information. Russia has something pretty similar and us companies have gone ahead and helped build it, provided the technology for it and put it in place. They sold it to them. I don't like that in case you didn't guess, right?

    [01:05:43] I'm all for free speech. I think it's very important for any form of a democracy. No question about it, but these companies apparently don't have a problem with that. However, now this is something, a little different. If you have employees who are being threatened and I mean threatened to serve 15 years in a Russian prison, what are you going?

    [01:06:10] Are you going to say no, I'm going to leave that app up. And then now all of a sudden your executives, or even a coder, somebody a programmer, like the guy that sweeps the floors, whatever are you going to let them be arrested so that you can have this app up on your Google play store or your app store over the apple side?

    [01:06:29] Probably not because frankly, this is something that is not worth it. So what are you. I think the only answer is what we've seen company after company do, and that is get out of Russia completely. And there was an interesting story. I read this recently about McDonald's you might remember back in the Soviet days, McDonald's worked out this deal with the Soviet union to open a McDonald's right there in downtown Moscow.

    [01:07:03] I guess it was pretty prominent. I don't know if it was, I think I might've been even on red square and there were people like. To have an American hamburger and it's been pretty popular the whole time. McDonald's closed that store and pulled out of the country. Starbucks has pulled out, are they going to reopen?

    [01:07:21] Cause I don't think either one of them said, forget about it. We're not coming back, but I know both of them have closed on operations. Automobile manufacturers from the U S have closed on operations. What is their choice? You can't just go ahead and say, okay yeah. Okay. Yeah. You're just going to arrest people or, we'll keep quiet for now and come back later.

    [01:07:42] What are you supposed to do? That's part of the problem with these oligarchies, with these people who are basically all powerful. Now we actually see some of that here in the us, which is just as shame, just a shame because we see these companies going ahead and cutting out free speech saying, oh, you can't say that there was a time where if you said masks work, that you would have been censored. And then there was a time where if you said masks don't work. You cloth mass don't work, you would have been censored. There was a time when you said masks aren't necessary. You would have been censored right now, but the science is settled.

    [01:08:27] It was just crazy. Science has never settled and oh, we could go on with this for hours and hours, but potent is not a good guy. And this article, I'm going to bring it up on the screen here again. But this article talks about. And a single year. And again, this is MSN. Potent had his political nemesis, Aloxi Novolin novel ne yeah, I got it right.

    [01:08:54] He had him in prison after a poisoning attempt, felled to kill him. Do you remember that whole poison in attempt? Where they gave him this really nasty radioactive bride product, as I recall, and potent went ahead and basically shut down. They pushed all of these independent news organizations to the brink of extinction.

    [01:09:17] Look at what happened with Russia today. The entire staff walked off on the. Saying, we're not going to report on any of these lies that are coming out of Moscow. It's happened again and again, Putin orchestrated a Kremlin controlled takeover of Russia's Facebook equivalent, and he's also issued liquidation orders against human rights organizations.

    [01:09:43] And so all this is going on. What are you going to do if you're. If you're a Google, right? I can see the criticism of those countries or companies should say when they're cooperating with the regimes, putting in place, things like facial recognition to, to spy on people, to have a social credit system, these great firewalls in these countries.

    [01:10:05] But when you have something like this happen, I forget about it. There's nothing you can do. And the crackdown is accelerated Facebook and Twitter were knocked offline by the government for millions of Russians news outlets had survived the state harassment for years, shut down in the face of a new law impose.

    [01:10:26] 15 year prison sentences for spreading fake news. It's incredible what has happened. And we've got to be careful here in the U S too, because we see this censorship, there's a lot of complaints about what was happening under Donald Trump president and old Biden, both Obama and Biden.

    [01:10:45] Both of those have done some of these same things to a lesser extent. Stick around. We'll be right back.

    [01:10:53] This whole war with the crane, Ukraine and Russia has brought a few things to light here over the months, and really the more than year that it's been leading up to the beginning of that war even, but we've got clear view in the news again.

    [01:11:09] So you can always follow along at rumble or at YouTube, but there's a great article here.

    [01:11:16] I have up on my screen for you to see. And this is from writer. Para carried over on MSN. And it is an exclusive story talking about Ukraine, using something called clear views. AI facial recognition. This to me is absolutely fascinating because what is happening. Is the technology that Clearview develop and has it been selling to police forces in the United States is being used on the battlefield and.

    [01:11:51] How here's what the technology did. And does Clearview illegally went on websites, major websites all over the world and did what we call scraping. Now, scraping is where they go to the site and they grab the pictures. So they scraped Facebook. They scraped you tube. They scraped. Dan and many more.

    [01:12:18] And then they put it all into a big database that told them where they found it, who that person was. And then they also took that biometric information from that image of the face and came up with some unique codes, a hash basically is what they did. And. Now what Clearview is doing is if you are a police organization, you can get a little app that runs right there on your.

    [01:12:46] And you have an encounter with someone you're a policeman, right? Let's say, and you just hold the camera up and it gets a picture of that person. It now finds the background information on them. And then you can use that tied into the police databases to check and see if there's any record of this person.

    [01:13:06] If they've been doing anything illegal. It's really quite cool. What they're able to do and scary at the same time, we use the same basic technology over in Afghanistan. So literary troops as they're out, and they're having encounters with civilians, people in the street fighters, et cetera. They could hold the device up.

    [01:13:29] It would identify them. It went further than just the face that actually did retinal scans and things, all kinds of cool stuff, but basically recognize the face. And they were able to tell if this was a friend of foe or. So a friend might be someone who worked as a translator who has been known to be helping the us troops in Afghanistan, et cetera.

    [01:13:53] So we built this huge database of hundreds, of thousands of people's biometrics person, very personal information in it. And if they were getting paid even how much they're getting paid, all of that was in the database, in the backend. And then we abruptly. And we left that equipment behind. I hope the database was destroyed.

    [01:14:16] I haven't found anything. Absolutely conclusive on it. That the withdrawal from Afghanistan was frankly unforgivable. It just I can't believe they did what they did at any rate. This is Clearview. This is this company. So now that same technology has moved to Ukraine. What's interesting. About this whole Ukrainian thing to me was okay, great.

    [01:14:42] Now they can identify people. Can they really identify a pretty much everybody? Who are they going to identify? As it turns out clear Clearview also illegally stole photos of people over in Russia and in Ukraine. So the clear view founder said that they had more than 2 billion images from. How's that right from this social media service called V contact a or somebody like that out of a database of 10 billion photos total.

    [01:15:16] So one out of five of the pictures they scraped was Russian, which surprised me. So the Ukrainians have been using it to identify dead Russian. And it's, they're saying it's much easier than matching fingerprints even works. If there's facial damage, it's scary to think about right. Wars, terrible.

    [01:15:38] Who wants to go to war? I can't believe all of the people that want to jump in there. I really feel for these people in Ukraine, what can we do? I'll start proximal interest. Research for the department of energy, found the decomposition, reduce the technology's effectiveness while a paper from 2021 showed some promising results.

    [01:16:01] Now, this again is an example of technology being used in a way it's never been used before. And having that ability to identify dead or living combined combatants on a field like this is just amazing. So this is the most comprehensive data set. There's critics, of course, they're saying that the facial recognition could misidentify people at checkpoints, obviously.

    [01:16:29] Could miss identify people in a battle mismatch could lead to civilians. Just like unfair arrests have risen from police use. And that's from Albert Kahn, executive director of surveillance, technology oversight, product project in New York. So as usual, these things can backfire and I think they probably will given a little bit of time and that's a sad.

    [01:16:56] Now I also want to talk about this. This is cool. Another article here, I'm pulling up on the screen right now, and this is about some hackers. Now we know that the Kremlin has been lying. Do we know that if a politician's lips are moving their line, right? Isn't that the old standby, but Russians apparently don't know this.

    [01:17:22] And the average Russian on the street is thinking that, okay, we're rescuing Ukraine. Isn't that just a wonderful thing? There's a couple of ways that the hackers have been getting around it. It's called a squad 3 0 3. They have this tool that's hosted at the domain. 1920 dot I N. There's an Indian domain and it loads a pre-written statement in Russian into your native SMS app.

    [01:17:54] In other words, the app that you use for texting and the idea is they that they've taken, oh, let's see here. Tens of thousands of trying to remember the exact number of stolen phone numbers from Russia. So all of those hacks that we've talked about for all of these years, those hacks have many of them phone numbers in them.

    [01:18:18] And they've been taking those phone numbers from some of those hacks and using them to send out about 6.5. Million text messages. So what happens is you, your phone, your actual phone ends up sending a text in Russia saying something to the effect of dear Russians. Your media is being censored. The Kremlin is lying.

    [01:18:43] Find out the truth about Ukraine on the free internet, and then the telegram app time to overthrow dictator. Yeah, that's not going to cause any problems, is it right? I'll put that up on the screen again for people who might read Russian. Cause it's got it in Cyrillic. Okay. And then you have the option to get an, another set of text and figure it out.

    [01:19:05] So the phone number, you can see there, you can copy it and paste it into your app and off the message goes. It's very cool. And in the daily dog, They're quoting a member of this squad 3 0 3 saying that this is a non-violent communications project. It's bypassing Russia's crackdown on the news.

    [01:19:26] They're sensitive. They're censorship of the news. And by the way, the domain 1920 dot. Refers to Poland's surprise victory against Russian forces just after world war one and the Bolshevik Menshevik revolution. You might remember all that stuff, that you studied all those years ago. So it's interesting.

    [01:19:47] We'll see what happens. But this hacking group also claimed that they were attacked probably again by Russian hackers, the FSB ex. Using a distributed denial of service attack shortly after launch. And they put CloudFlare in front of their domain. Now we use CloudFlare for one of our, something, not one, but some of our customers.

    [01:20:15] What CloudFlare is a website that's designed to basically buffer your website when it's been served. So if all of a sudden you get a ton of legitimate request, your site's going to stay up. It's going to be able to respond to people. The other big advantage to CloudFlare is what's happening here with 1920, Diane CloudFlare goes ahead and will block some of these denial of service attack.

    [01:20:43] So I think that's pretty darn cool. Many texts apparently are met with silence. Some say they've been able to converse with Russian citizens. One user who remained anonymous said they had made. The text messages they'd made using the tool really worked it says, I want the people of Russia to know the truth.

    [01:21:03] The government is doing to the people of Ukraine. This is a quote from the daily dot going to pull this up too. This is a a tweet here on Twitter and. Yeah, it's from anonymous. That hacker group, you've probably heard of them before. Cause they've done a lot of nasty stuff over the years, but he says it's been doing just absolutely amazing things for him.

    [01:21:27] Let's see here. Can we hear this? Here we go. Ah, I got to unmute it. Let's see. Where is my mute? There it is. So this guy's name is Rodney. He is. D Jang, oh my dog. Get to Django my dog. And he's got a really great little testimonial there about that. It works and his tweet has had 4,300 views and it's good.

    [01:21:54] Again, another way around censorship now, Twitter, of course could decide they're going to sensor and that could be a problem too, but that's also why we now have alternatives to Twitter. And some of these other sites that are out there that are doing a whole bunch of blocking really, they don't like you.

    [01:22:15] And by the way, the reference to Telegraph was fascinating because they are using. In order to get around censorship. Again, many people are using it to to send information about what is really, truly happening in Ukraine. So a lot of stuff from the beginning of the war here, visit me online. Craig peterson.com.

    [01:22:38] Get my newsletter and get the free up-to-date trainings.

    1 hr 23 min
  • How Does Big Government Collaboration With Big Tech Raise the Costs of Everything?

    How Does Big Government Collaboration With Big Tech Raise the Costs of Everything?

    We're going to talk about the Senate bill that has big tech scared, really scared. I'll talk about a new job site problem for a number of different industries because of hackers, the cloud, the cost and reliability.

    [Following is an automated transcript]

    This tech bill. It has the Senate really scared.

    He is frankly, quite a big deal for those of you who are watching over on of course, rumble or YouTube. I'm pulling this up on this screen. This is an article. ARS Technica and they got it originally from wired it's it was out in wired earlier in the month. And it's pointing out a real big problem that this isn't just a problem.

    This is a problem for both the legislature. In this case, we're going to talk about the Senate and a problem for our friend. In big tech. So let us define the first problem as the big tech problem. [00:01:00] You're Amazon. You are Google. Those are the two big targets here of this particular bill. We're going to talk about, or maybe your Facebook or one of these other Facebook properties, et cetera.

    If you are a small company that wants to compete with any of these big guys, What can you do? Obviously you can do what everyone's been telling us. Oh, you don't like the censorship, just make your own platform. And there've been a lot of places and people that are put a lot of money into trying to make their own platform.

    And some of them have had some mild successes. So for instance, I'm on. You can watch my videos there. And there have been some successes that rumble has had and making it into kind of the competition to YouTube. But YouTube is still the 800 pound gorilla. Everybody wants to be where the cool kids are.

    So for most people. That YouTube. They look at YouTube as being the [00:02:00] popular place. Thus, we should be, we are obviously saw the whole thing with Elon Musk and Twitter, and the goings on there. And Twitter really is the public square, although it's died down a lot because of this censorship on Twitter.

    Interesting. So as time goes forward, these various big companies are worried about potential competition. So how do they deal with that? This is where the real problems start coming in because we saw Amazon, for instance, in support of an internet sales tax. You remember that whole big deal. The internet had been set aside saying, Hey, no states can tax the internet and that's going to keep the internet open.

    That's going to help keep it free. And people can start buying online. And that worked out fairly well. A lot of people are out there, why would Amazon support a sales tax on the internet? They are the biggest merchant on the internet, probably the biggest [00:03:00] merchant period when it comes to not just consumer goods, but a lot of goods, like a staples might carry for business.

    So they'd have to deal with what they're 9,000 different tax jurisdictions in the United States. And then of course all these other countries, we're not going to talk about them right now, but the United States 9,000 tax jurisdictions. So why would Amazon support an internet sales tax when there's 5,000 tax jurisdictions?

    The reason is it makes life easier for them when it comes to competition. So if you are a little. And do you want to sell your widgets or your service? Whatever it might be online. You now have to deal with 9,000 tax jurisdictions. It's bad enough in the Northeast. If you are in New Hampshire, if you live in New Hampshire and you spend more than, I think [00:04:00] it's 15% of your time south of the border and mass, then mass wants you to pay income tax for that 15% that you are spending your time there.

    Now they do that with the. Baseball teams with football teams, hockey, you name it, right? So the big football team comes into town. The Patriots are paying the New York jets or whatever it might be. The Patriots have to pay New York state taxes, income tax now because they stepped foot in New York heaven forbid that they try and do business there and help New York state out.

    And they now have to pay income tax. Now they only have to pay income tax for, or for the amount of time. They're more New York. Various states have various weirdnesses, but if you're only playing 1, 2, 3 dozen games a year, It isn't like your normal work here, which is 2080 hours. We're talking about their plane to New York and they're only spending maybe 10 hours working in New York, but that [00:05:00] represents what percentage, 10, 20, 30% of their income, depending on how many games they play and how they're paying.

    And so they got to keep track of all that and figure it out. Okay. We played in New York, we played in New Jersey. We're in mass. We were they weren't in New Hampshire, certainly the Patriots plane, but they got to figure it all out. Guess what? Those big pay. Football players, hockey, baseball.

    They can afford to have a tax accountant, figure it all out and then battle with them. I had a booth one time at a trade show down in Connecticut. Didn't say. Thing it was terrible trade shows, man. They aren't what they used to be. And they haven't been for a long time. This is probably a decade plus ago, maybe even 20 years ago.

    So I had a little booth, we were selling our services for cybersecurity and of course, nobody wanted to bother pain for cybersecurity who needs it. I haven't been hacked yet. [00:06:00] Although there's an interesting article. We'll talk about next week based on a study that shows. Small businesses are going out of business at a huge rate because of the hacks because of ransomware.

    And if you're worried about ransomware, I've got a really great little guide that you can get. Just email me, [email protected]. I'll send it off to you, right? It's a free thing. Real information, not this cruddy stuff that you get from so many marketers, cause I'm an engineer. They'll go out of business.

    So they figured I haven't got a business yet, not a big deal. And so no body. There's big trade show. And I was so disappointed with the number of people that even showed up for this silly thing. So what happens next while I get back to the office and about a month to two months later, I get this notice from the state of Connecticut they're tax people saying that I haven't paid my Connecticut taxes yet.

    [00:07:00] And because I was in connected. I should be paying my income tax for that day that I spent and wasted in Connecticut. Oh. And plus every company in Connecticut that I'm doing business with now, I need to collect their taxes and pay them the taxes that I'm collecting for those Connecticut businesses are resident.

    I didn't sell a thing. You know what it took almost, I think it was three or maybe four years to get the state of Connecticut to finally stop sending me all of these threatening notices because I didn't get a dime from anybody in Connecticut. So I'd love the internet from that standpoint saying you don't have to collect taxes in certain cases, certain states, et cetera, unless you have a legal nexus or a legal presence there in the state. So back to Amazon, Amazon loves the idea of having everything on the internet packs. They love the fact that there's 9,000 plus [00:08:00] tax jurisdictions. When you get right down to city, state county Lilian, either local taxes, or you look at those poor residents of New York state, or they're poor residents out in Washington state that have to worry about that, right?

    There's county taxes, state sales tax. City sales tax, and income taxes are much the same, the, all of these crazy cities and states around the country. Yeah. The ones that are in serious trouble right now, they are those same ones. Those particular jurisdictions are hard to deal with. So from Amazon standpoint is just like the Patriots football players.

    We've got plenty of money. We've got teams of lawyers. We have all kinds of accountant. We can handle this and you know why Amazon really loves it because it provides another obstacle for any competitors who want to enter the business. That's the [00:09:00] real reason, so many big businesses don't go ahead and charge you serious money so that they can use that money against you.

    Okay. You see where I'm going with this? Because if you want to start a business that competes with Amazon, if you want to have a doilies, you're making doilies. My grandmother used to make them all the time and she had them on the toilet paper in the bathroom, little doily holders. Doilies everywhere.

    And then of course, the seashells shells on top of the toilet paper holders. If you want to do that and sell it, how are you going to deal online with 9,000 tax jurisdictions? All what you're going to do is you're going to go to Etsy, or you may be going to go to Amazon marketplace and sell your product there.

    An Amazon marketplace. So Amazon is taking its cut out of it at is taking it's cut off. And you still ultimately have some of that tax liable. [00:10:00] Amazon loves it. It's the same reason you see these groups forums, right? Barbers saying, oh, we've got to be regulated. Really you need to have a regulation in place for barbers.

    You need to have licensing for barbers. Why do they do that? They do that. Not just barbers, right? It's all of these licensures and various states. They do that really to keep people. To keep their prices high. That's why they do it because someone can't just put up a sign and say, Hey, I am now a barber.

    Come get a haircut. And if you don't like the barber, if they do a lousy job, you go elsewhere. We don't need all of the bureaucracy on top of this to enforce licensure. Anyways, when we get back, let's talk about that Senate. It's a big deal. And I am coming down in the middle of this thing. Hey, visit me online.

    Sign up right now. Craig peterson.com and get my special report on passwords.[00:11:00]

    We just talked about how big business uses its advantages to crush potential competition. Crush them. And it's a shame and it's happened to me and many people I know, and now the Senate's getting involved and making things worse.

    This is a huge problem. This happened to me a number of years ago, and I will never forget it.

    It was a really big lesson for me. I had designed and written a computer system that would take the code that it was written for a much older system. And run it for much less money. So bottom line here, this was a system called Cade computer assisted data entry that was made by Sperry way back in the day.

    Yeah. I've been in there for that long and they had little programs, so they would not punch cards, but punch right on two tapes, those big [00:12:00] nine track tapes and that information would then be used for processing later on then. People, big businesses grocery stores, you name it. We're using that Sperry system.

    And I designed a system that would take their COBOL is what it was. It was a form of COBOL code from this cage system. And you could use my code to compile it and run it on a Unix system. So the cost involved here was that it would be cheaper to buy a whole new Unix computer and buy new terminals and do some slight training changes.

    But the key punch operators would be exactly the same keystrokes as they were already used to. Okay. So you know how fast they were, so it wouldn't slow than none at all. And their cost would be. Then just the maintenance contract on the old Sperry cage. Very [00:13:00] cool stuff. And I worked really well.

    Then I worked with a couple of sales guys at spirit because Barry had a Unix tower system. It was a mini computer that was Unix space. And I had one, I had saved up my money. We bought this thing. It was a lot of money nowadays. It'd be about a hundred thousand dollars I spent on that system and it was really great.

    Cool. So some grocery stores started using it. They used it to build the space shuttle to design it and send it into space. RCA, Astro space used it, my system, which is all really cool. So Sperry was interested in it saying, okay let's do this. Now. I had flown myself across the country too, because I was in California at the time to do some of this work for.

    The for RCA Astro space for the space program and help make sure it was working and get it installed, help them configure it and everything else. So [00:14:00] I had a lot of time, a lot of money, a lot of effort into this. It was a big venture. So Sperry invited me down to their headquarters down in blue bell, Pennsylvania to talk about this.

    And I was so excited because their sales guys wanted to sell it. They gave me some free space in a booth in Las Vegas. So I was in the Sperry booth with them and, say, yeah, you can buy this. And you're using the Sperry, the new Sperry hardware. And I went down there and talked with them.

    They never did anything with me, or, here's a huge investment young guy. And all of this stuff just worked and they had proof of concept. They had a couple of customers already using the system and it never materialized. And then about a year and a half later, I found out Sperry had tried to duplicate my system and had messed it up terribly.

    It [00:15:00] wasn't keystroke compatible. So anyone using the new Sperry system, they had to learn. Okay. So I got to hit this and I got to go over here and I got to click on this. Are you kidding me using a mouse? Aren't you not? These are data entry operators. They just go all day long, just typing and.

    They had stolen my ideas. They messed it up. They didn't do as good a job as I did, which turns out it's pretty common. And they had stolen it. They stolen years of my life. So I've seen that before with me. I've seen Microsoft do that with friends of mine, and I've seen apple do it with various products that they've decided to release.

    They all do it. Why do you think these businesses can not spend money on research and development, and yet at the same time, stay in business as technology's continuing to move forward? Why? The reason is. They don't have to do, or why [00:16:00] would we do T wait a minute. Now, all we have to do is either buy the company or steal the product just re-engineer.

    Oh. And if we want to buy the company, we can do what Microsoft has been accused of doing again and again, which is. We'll just Microsoft. Let's see here. I like that database is pretty darn cool. So here's what we're going to do. So Microsoft announces, Hey, we're going to have a competitor to that in coming out soon.

    And then they sit there and they wait and they say, okay, how many people are going to ask about, oh wow. A lot of people asking for it. In the meantime, that company that had that great little database soft. Trying to sell it. And people are saying, wait, Microsoft is going to come up with a version of this.

    I'm just, I'm going to wait. We can wait a few months. Let's see what Microsoft. So that poor company is now seriously struggling because this big company came out and made the announcement that they're going to do something like this. And then that small company gets a [00:17:00] knock on the door. Hey, we're Microsoft or company X.

    And we like your product. Wow. Okay. So we're going to do a buyout. We're going to we're just, oh, this is going to be fantastic. I might have to sign what a two year contract non-compete and help them manage it. Okay. We can deal with this. And then they find out that company X says Your company is not worth that much anymore.

    Your sales look at their sales here, man. They've gone way down. Okay. So let me see let's do a nickel on every dollar evaluation you had a year ago. This happens every day, worldwide in America, it should never happen to anyone. And as you can tell, it upsets me. So what are Klobuchar and Grassley doing here?

    Amy, when she was running for president, she made this big deal. I'm going to pull us up on my screen. Those of you who are watching [00:18:00] on rumble or YouTube. And you can find all of that in my website, Craig peterson.com can see here. So they are trying to protect the American consumer, right? Yeah.

    Yeah. That's it. They're gonna protect us. And so what they're doing is saying that. Would a rule ruin Google search results because that's what Google says. Is it going to bar apple from offering new features, useful ones on the iPhone? How about Facebook? Will it stop them from moderating content? So the legislation's core idea is we will just.

    The marketplace take care of things. We're not going to let Amazon put their products in the product listings before third parties, but how are you possibly going to be able to regulate that stuff you can't, you can regulate it [00:19:00] talking about a bureaucracy. You'd probably need one about as big as the federal government is right now.

    And the federal government needs to be cut back in a major way. There's this two months. How about the 150 million Americans? This article brings that up to that are currently using Amazon prime, even though the price one hump. And they have it free to prime members. It's this is a big deal.

    The bill doesn't mention prime. Doesn't mention Google by name, Amazon. But this is going to be a nightmare to enforce the bill is not specific enough. It should be voted down. And between you and me, I don't know what can be done about this other than to have additional marketplaces show up online. And you know what the conservative social media sites are starting to win.

    So maybe there's hope.

    We've got two things we're going to talk about right now. One of them [00:20:00] is tech jobs. And man, is there a lot of scamming going on there as you might expect in the second is cloud, are you looking at cloud services? Hey, a home or business.

    You can see this. I'm going to pull this up on my screen for those watching on rumble or on YouTube, but this is a big problem.

    And we've seen this again and again right now, they're going after certain workers in the chemical. The sector, but it isn't just the chemical sector. What we've seen is the bad guys going after anyone that's applying for a job. So let me give you a few tips here. First of all, you should not be pain to apply for a job.

    We see that all of the time when it comes to the head hunting firms, what. Is, they will charge the business who is looking to hire someone [00:21:00] that makes sense to you. They'll hire they'll charge the business. So oftentimes it's a percentage of the annual salary committee where from usually 20% up to a hundred percent or more, depending on the position.

    And boy can, they make a lot of money, but they don't necessarily place. People, but you know how it is right now, there, there can be quite a few. So people have been applying for jobs to make a lot of money and not realizing that fee that supposedly they have to pay is illegitimate. So remember that.

    Okay. The second thing has to do with this particular scam, because what they're trying to do is. Into some of these companies. So they will send a thing out saying, Hey, on my head hunter, I'm here for you. We're going to get you this job you need to apply. Are you interested in a new job now? I've seen some stats online saying [00:22:00] that somewhere around 30 plus percent of people are looking or at least open to.

    Take getting a new job, which means a lot more are looking for jobs. Now I have to add to that, that the people who have jumped ship over the lockdown period really are not happy. The majority of them wish they had stayed where they were at. So keep that in mind too. But what they'll do is they'll say, Hey, listen.

    Oh, there's this new feature on LinkedIn. By the way, you can say y'all are, I'm interested in looking for a job. I forget exactly what it says, but it goes around your picture and I have it up there because I'm a contractor, I go to businesses and I'm. To harden their cybersecurity. And we usually start slowly, especially with some of these startups we're doing work with right now where they won't, they go from a completely flat network and [00:23:00] it's all engineers and I don't want anything hindering anything.

    And so you got to work with them and it's just, we had a time sort of a thing. Okay. I just had this one thing this week. And then move on to one thing next week as well. So that's what I do for a living. And a lot of people are looking on LinkedIn and other places to find people who can be a chief information security officer.

    So I'm what you call a fractional chief information security officer. I do this under contract and I've been doing contracts and contract work for. I don't know if I shouldn't be on the air, but my gosh it's been now I guess it's 40 years right now. So I've been doing this for a long time.

    So I'm familiar with some of these scams, so they didn't take my word on some of this stuff. So what they do is they say, Hey, we've got a potential job opening. Are you in interested now? When we talk about 30 plus percent of people polled [00:24:00] say that they're looking interested in a new job, the numbers are probably a little higher. Not that everyone's going to jump ship. Some people will, but there are a lot of people that if they get this email, they're going to open it up. And so what'll happen now is this group out of North Korea called the Lazarus group? And we've talked about them before.

    We'll go ahead and say yeah, the here's, what's going to happen here. Let's just send you this thing. You can open it up. You can look at it and see if it's really a fit for you. I love this graphic that they have. This is from dark reading. I have it up on the screen again. Rumble and YouTube.

    What should we do now? Should I open this up? Should I not open it up? It turns out that what's happening is that Symantec and Broadcom, both have noticed this and stated in an advisory a couple of weeks ago. Be very careful [00:25:00] because what it's going to do is install a Trojan horse on your computer.

    So let's think about this. You're talking about the chemicals. You have a lot of people who are very technical. And if a company wants to get some new technology, we talked about this earlier in the show, what did they do? Do they just go and say, oh, okay, let's get some R and D going here. Let me research and development.

    Let's hire some scientists and do some pure science here, which are almost never happens anymore. No, what they do is they either buy a company, they steal a company's idea. If you are like the communist, you try and steal the technology directly. And that's exactly what these guys are doing. They put a Trojan on your machine because you open that file and that Trojan then gives you.

    Oh, excuse me, gives them access to your machine. Now this particular Trobe Trojan is a malicious [00:26:00] web file. Disguises. This job offer and your machine gets comparable. They attempt to compromise it, right? It's not always successful. They're not as many zero days out there for these lower level actors like North Korea, but they've been able.

    Now, they're not just going after chemical sectors, they're going after it service providers. So companies like mine that provide managed security services for businesses, they are being attacked. So that's a problem too, isn't it? Because if you can compromise. A nine company and we've seen this all the time.

    It's getting reported like crazy. You now have access to all of their customers because the it service company has passwords, et cetera. And they're probably using. Industry is number one or number two products for managing the customer's computers, neither of which are secure. [00:27:00] And that's the biggest problem that we've had.

    We use some of these things before, I'm not going to name them right now because it wouldn't mean anything to you anyways, but we had to get. We worked with our, it people inside the software companies that make the software that are used by the managed services providers. And we'd talked with their developers and said, Hey, listen, this is a serious problem.

    That's a serious problem. You've got to change this. You got to change that. And what ended up happening? We left them because they weren't doing what they were supposed to be doing a very big deal. So they're targeting defense, contractors, engineering firms of any sort. They want to steal IP, intellectual property, pharmaceutical companies.

    Yeah. Very big deal. These third hunting teams, including Cisco's, which are the guys that we use. Tallow sets again, an example of a big company buying a smaller company called telos that does threat intelligence and it looks at stuff. They're all reporting to this. [00:28:00] So high level jobs in an industry or what you have to watch out.

    It'd be very careful. Now, earlier this year, Lazarus group, again, North Korea went after some of these jobs people 250 that were identified working in the news media, software vendors, internet infrastructure providers, using job offers that appeared to come from. Disney, Google Oracle by the way, that was according to Google who tracked the campaign.

    They know what their employees are doing, where they're going, what emails coming in. It's crazy. We're looking a lot of stuff. Okay. So I want to move on to the next topic here. Last one, this hour, but I'm gonna pull this up right now on my screen. You can have a look at it there. Of course, if you are at home.

    You can or you really can't on the road. You can see this on rumble and also see this on the YouTube [00:29:00] site. At least for the time being until I get kicked off right. Kicked off again. That seems to be the word of the hour, but cost reliability are raising concerns in. Again, this is a dark reading article, came out a couple of weeks back here, but the biggest concerns about cloud computing to what is cloud computing.

    Let's talk about that first for a minute. Cloud computing is going online using something like salesforce.com. People don't think of that as cloud computing. But you have in Salesforce, all the communications with all of your customers, et cetera, that's an example of a platform as a service, basically. So they're providing you with everything and it's up in the cloud, nothing to worry about here, folks, but of course you have the same potential problems.

    You do outs where people use what's it called now? Microsoft 365. Which Microsoft disclaimed [00:30:00] any liability for any problems they cause for anything customers it's really crazy, but again, what are the problems there? Reliability slash performance, 50% of the people, 50% applaud on the screen.

    Again here worried about reliability and performance, because if your business is relying on cloud computing, What, how is the security any good? That you could use something, as I mentioned Salesforce, and just picking them out of a hat and not, they haven't been like a terrible provider by any stretch.

    But how about if you're going to Azure and you're using a workstation news here? How about if you're going to some other place, right? It could be Amazon web services. Google also has data processing services. Security's huge issue. Cost is a huge issue, reliability, performance, all of those. We're issues with more than 50% of the it [00:31:00] professionals.

    I'm surprised that this next one, which is our staff skillset on dealing with cog computing 26%. The reason I'm surprised by that is hardly anybody knows enough about cloud computing. Do we really confident about it? I'm serious about that. There's some companies right now, we're talking with a company called Wiz and they audit Azure configuration.

    So be very careful if you're using. Particularly if you're a business, it may not work out well for you. Hey, make sure you go online right now. Craig peterson.com/subscribe. Sign up. You'll get my newsletters. You'll get all kinds of great information. Absolutely free Craig peterson.com including my special report on passwords.

    Now, if you have any questions, just email me M [email protected].

    [00:32:00] There is a whole bunch going on when it comes to Russia, of course, invasion of Ukraine. We're going to talk about that. And what is I can, how does this domain system work and why are people calling to have dot R U deleted?

    This is really a big deal. And if you're watching from home, I'm going to go full screen on this article.

    This is an article from ARS Technica, and I've been talking about it all week, which is that I can won't revoke Russian in Jeanette domains, says the effect. Devastating. This is frankly pretty darn fascinating to me because I can, as this international organization, it was put together in order to help make the internet international.

    And I'm not talking about the data international, but control of it. A lot of countries work. Because of [00:33:00] course the internet was created in that states. It was created by us tax payers, money for the DOD. And it was designed to be very resilient, in fact, so resilient that there could be a nuclear blast and that nuclear blast and.

    Causing problems, but yeah. Yeah, the internet is still going to work. And the whole idea behind it was you could have multiple routers. They're all talking to each other nowadays. They're talking BGP four and they can say, how can I get from here? To there. And so the idea behind BGP is they all share this information once the least cost way.

    What's the easiest way to post way. If you will, for me to get from point a to point B and it changes all the time. So you might be on a phone conversation. You might be listening to me right now, online streaming or watching the video you might be doing, who knows what [00:34:00] out there with digital communications.

    But the communications channel that you think you're using, where the data is going from, let's say my microphone, ultimately to your device, your ears, that data path, once it becomes dated. Can be changing multiple times a second. Now it actually changes quite a bit. Initially as these internet backbone routers, send the least cost, routing information back and forth to, and fro a very good thing, frankly, because it helps to speed everything up.

    And there's other tricks that we're using you. Might've seen. For instance, Akamai and some of the URLs before have sites that you've gone to, and that's called a content delivery network and that helps get the content to be closer to you. So if you're on a website in California and you're in New Hampshire, that website video, that website graphic, et cetera, is going to be coming from [00:35:00] a server local to me here in New Hampshire.

    All right. That's how that all is supposed to work. So we have names you guys know about that internet, domain names and those domain names. You already know those are turned into internet addresses, and those addresses are then used by the routers to figure out where to go, how to get the data. The problem that we're having right now, of course, is Russia seems to be substantially abusing the intranet Putin, put a kill switch on to the Russian internet sometime ago.

    And the idea behind the skills, which was, Hey, listen, if we don't want the world to be talking to us, we'll just cut it. Now he's tested it a couple of times, but what he has not done is shut it down and he hasn't shut it down. As part of this Ukraine, more, what they did is they passed laws saying, Hey, if you publish something that [00:36:00] disagrees with what we're saying, you get 15 years.

    And even these people who've been protesting on the streets, they're getting a bound 60 days, 30 to 60 days in jail, just for protesting what's going on. So a lot of people have been saying why don't we just, we turn off the Russian internet now we're not going to use Putin's kill switch in order to shut it all off.

    We're not going to do a well, a few things. She decided not to do, denial of service attacks, et cetera. Although there are hackers doing that and we are going to talk about that today, but they're saying what? Let's just go ahead and let's kill their dot R E. The country domain. And I can, the guy who heads it up said, Hey, listen our mission is just to make sure that the internet works.

    So shutting off the dot R U domain so that no one can go ahead and. We send right. A [00:37:00] request out to the domain name servers and get a resolution to an IP address. So if you try and go to Kremlin dot REU or something, you will get blocked and you will get blocked. Not blocked. No, I like the great firewall of China or of Russia.

    Now they've got one going pretty good. Yeah. Thank you. You ain't using us technology. It's crazy. What we've. But what it does is it says, oh, I hide dot, are you, I don't know. What are you talking about? So there have been a lot of people who have been pushing for it. And you'll see, on my screen here, that Ukraine is requested to cut Russia off from some of these core parts of the internet.

    And I can, which is the internet corporation for assigned names and numbers. I couldn't remember what that was earlier said that I can must remain neutral and their mission they say is not to take punitive actions. It's to make sure the internet works. So are they really taking punitive actions [00:38:00] of the cat Russia off?

    It's really interesting to me because look at what has been going on. You've got companies like Facebook as the great example who has gone ahead and just shut off people. They didn't like what they were saying. My goodness. At one point of you said you should wear a mask during this pandemic.

    You would be cut off from Facebook. And then of course, if you said, no, you don't, you shouldn't don't need you, you shouldn't wear a mask that at that point you would be cut off, because science right. Sciences, we know exactly what we're doing now. It goes on and on. If you said that it came from a lab in China, you would have your account suspended.

    Now of course their whole tune has changed and yeah probably came from a lab in China. It's crazy what these people have been doing. So we have arbiters of truth, who are some contractors sitting in their home or wherever it is the contractors for Facebook [00:39:00] that are going through posts that people are flagging as Incorrect as fake news.

    So what happens is people say fake news and then that goes off to their team that then looks at it and says okay. Yeah, fake news because we disagree with it. It just blows my mind. We have to have free and fair and open discussions. Don't we. You have that line at Facebook and Google does some of the same.

    A lot of these sites do a lot of the same. You get our major media outlets that are all deciding what they want to report on and what they want to label as fake and fake news. I'm just shaking my head because it's hard. It's hard to believe. What about. Russia is putting out fake news, as I've said many times before the first casualty in war, this isn't my quote. The first casualty in war is what, it's the truth. So if [00:40:00] truth is the first casualty, then that means we've got a lot of propaganda going on. We had propaganda coming out of Ukraine. We've caught some of those, like the, what was it? The. Chat goes, fighter, pilot, whatever it was who had killed, what was it?

    Five Soviet or Russian jets, Soviet era using silver deer, techno era technology on the part of the Ukrainian turns out well. Okay, that, that was false news. That was fake news. The whole thing about snake island, where you had that Russian military. I know what it was a frigging but anyways boat sitting there saying we are a Russia.

    Warship, you will surrender or, whatever. Do you remember that snake on just the small place, 13 guys and supposedly they shelled it and they killed all 13 turns out that was probably fake news as well. So that's from the Ukrainian side and on the Russian side they hardly reported I as to how many.[00:41:00]

    The we're in fact, initially for quite a while, they were saying there are no desks. Then at the same time, the Ukrainians are saying they're 2,500 Russians dead. And that number keeps going up, who knows what it is today. It gets really crazy in the time of war. So if Facebook is going to stop someone from saying don't wear masks or do wear masks, depending on what day of the week it is basically right.

    Wednesday. It's okay to say that Thursday is not okay to say that we're back. No it's not. Or then why can't that type of censorship? Move on to the next. I that's a big question I have now. Should we be shutting it off? I'll pull this back up on the screen again. And it, this article from ARS, Technica is saying that experts have warned, whoever they are that shutting down the dot R U domain.

    Is going to cause just incredible problems [00:42:00] for Russians, which man would it ever talking about a major blow to the economy. And it would also cause problems for people who are trying to find out more truth about. Russia cause you couldn't get to their site. Now we've seen some amazing things in Russia.

    We had the Russian, one of the Russian news agencies T, which is broadcasting and here in the U S that their entire staff just walked out saying, forget about it. We're not going to promote this fake news, but this is a little bit different question. Me personally. I don't think anybody should be censoring any.

    For almost anything. Yo, there are some limits, but they're pretty extreme in my book. I'd rather know someone is an idiot because they're allowed to say stupid things, and counter, counter it, counter their arguments. You've got to have discussions anyways, stick around. We'll be [00:43:00] right back.

    Microsoft. Yeah, they've been around a long time. They've been helping us. They've had lots of cybersecurity problems. People use Microsoft software on their desktop. Some people use it for servers, which is crazy, but listen to what they're doing now.

    This is a little concerning. I'm going to pull this article up on the screen.

    For those of you who are watching a long, either on rumble or YouTube ARS, Technica article, they have some really great articles. This particular one is about our friends at Microsoft. This is cool. Microsoft announced today? This was like a week or so ago that Microsoft would be suspending all new sales of Microsoft products and services in Russia.

    Following the countries, unjustified, unprovoked, and unlawful invasion of. Now Microsoft [00:44:00] didn't give any specifics about the products, but it really is likely to be a blanket ban of all of the Microsoft products. This is very cool because Microsoft has taken an approach I've never seen them do before, which is okay.

    When. Gets hacked. You get our friends at apple, putting together patches and getting them out. They get them up pretty quick. Microsoft had been doing much the same. The problem was some months there were patches every day that you had to apply. That's how bad this software is. And they decided that man, let's be like politicians here.

    Let's release some very damning news Friday. At about 4:30 PM before a long weekend. So no one will notice. Yeah. Y'all are friends of politicians do that all the time. What Microsoft decided they do is, Hey, wait a minute. We know we're going to have patches. [00:45:00] It's not going to slow down. And because our code is terrible.

    So what we're going to do, let me see here. How about we just release all of them at once and we'll just call it patch Tuesday, right? Because people were complaining about how much work it was, how much effort was effort. It was to try. They hate them. These machines apply these patches every day. Huge problem for everybody from home users to big companies out there.

    So Microsoft has said, okay let's do that. Let's burry it. So nobody will notice okay that's what Microsoft does. And now we've gotten used to that. Now we have. We remember two guys, right? Bill gates followed by Steve Ballmer. Steve Bohmer was a nut job. Bill gates was a bad man.

    I think he's just been trying extra hard to compensate for all of the evil he did over the years. But what we're looking at now is new management and that he's been in [00:46:00] there now for a few years, doing a great job, cleaning up Microsoft, making it a very competitive company. He has done some amazing things.

    One of the things that he has decided to do, that's been very effective is how about this? How about we go ahead. And we work with various governments to help stop these Russian hackers. And I mentioned this a couple of weeks ago, what was happening and the Microsoft had reached out to the white house and said, Hey, listen.

    What we have been looking at the hacks that have been coming from the Russian hackers, and we've been preparing fixes for some of those hacks. How about we work directly with some of these other countries? This reminds me a whole lot of the lend lease program in world war two. You might remember this thing, but the [00:47:00] us of course, initially was not involved in the war and they decided, okay we've got to help the United Kingdom.

    How are we going to help them? The UK doesn't have the money to buy ships, to have us make weapons, bullets know. What they did is they had people donate the rifles, the guns ammo from home. Plus they made them the government, instead of selling them to the UK, they lent them to the UK because the UK could not afford everything that it needed in order to fight a war against the national socialist in Germany.

    So what did they do? We just shipped the stuff over there and called it a lend slash lease. I think that's a great idea. And what Microsoft is doing is also great idea. They have been decoding, reverse compiling, if you will, and interpreting the code, looking at what some of the ransomware and other malicious code the Russia has [00:48:00] been using against Ukraine, and they have been providing.

    All kinds of insight information to these other countries. Now, this is a great idea for a few reasons, one of the reasons, and I think maybe the biggest reason is that the ransomware, the viruses, all of this malware that they're producing is. Not particularly discriminating. Do you guys remember maybe I dunno, what was it?

    Six months ago, I taught, told you how to avoid getting most of this Russian ransomware. And it was as easy as just installing. Yeah, installing a keyboard on your computer windows or Mac, windows. Those are the machines are always getting attacked quite successfully most of the time, but the windows keyboard.

    Russian language. Now you didn't even have to use it. [00:49:00] You don't have to have a keyboard, right? This isn't a Russian keyboard that I'm holding up here on camera. This is just a regular us keyboard. You can just install a virtual, Russian keyboard. And once that keyboard was installed, you're pretty safe.

    Why? Because Vladimir poop. Dictator for life of Russia decided he would just go ahead and stop anybody that was trying to hack Russian. Companies businesses, government agencies and what's the best way for the hackers to do that. Cause they didn't want to end up in Siberia for the rest of their lives because of a hack.

    Now they went ahead and said, okay if there's a Russian Cyrillic keyboard on the machine, we're not going to activate. So if the software, the malware on your computer, all you need to do is have a Russian keyboard. Yeah, that's it pretty simple. I told you that months ago, now what we're seeing is these indiscriminant [00:50:00] types of software that are being used in Ukraine.

    Why doesn't the keyboard trick work while some of Ukrainians peak Russian, we could go in. To the background on that of the massacre, the starvation purposeful starvation of Ukrainians by the Soviet union over many years ago. And how they then gave their property, their homes to Russians to move into in order to occupy Ukraine.

    So there's people in Ukraine who are Russian speaking of course. Now we're talking two or three generations, four, maybe down the road from when the Soviet union killed all of those millions of people. But there are some fights that to say, there's Russians, Russian speaking people there. Let me put it that way.

    Perfectly. In Southeastern Ukraine anyways I'm going on and on I, this is not an education on war or history. This we're talking about [00:51:00] cyber security. So the, they have, they been, Microsoft found many cases of Russians putting destructive. And disruptive or even more than that data wiping malware onto computers, it spreads indiscriminately.

    So Microsoft looking at what's happening, you crane, trying to get patches together for all of us, letting other countries know about what's going on is going to be. Amazing because this malware, which is wiping computers, primarily, it's not really just straight up ransomware give us money and we'll give you your data back.

    This is just showing your data, that malware is going to leak outside of Ukraine. Yeah. Cause us all kinds of book tension, probably. When we get back, I want to talk about this here. This is our friend Ilan Musk, and we've been following [00:52:00] along with some of the stuff been going on with his new satellite system in Ukraine.

    Stick around.

    The whole concept of these satellites and circling the earth, providing us with internet, just regular guides. It's going to be in our smartphones is changing everything. We're going to talk about Elon Musk and what's happened over in Ukraine.

    Our friend Elon Musk has done a lot of things over the years. He has really helped us for frankly, the Tesla and what's been happening there.

    SpaceX, his main concern being let's get off of a single planet on to multiple planets, right? The movement to Mars, NASA's working on a serious moon base. I reminded him of space 1999. You guys remember that show, but yeah, we're going to have a moon base by then [00:53:00] and it makes a lot of sense. So who's going to go to these well, there's some interesting lotteries people have to apply and everything else, but he's done so much, right?

    He's got the boring company you'd already know about Tesla and boring company in case you didn't know makes underground tunnels. He has also. A few other things has got a huge battery manufacturing facility. They're working on new battery technologies to make all of our lives a little bit better, particularly if we have an electric house or electric car, because this is what good is it to have electricity that you can't use.

    And that's really what they're trying to do is make it so that electricity is available 24 7 for you. And. Those space X, which is what I mentioned as well as what we're going to talk about right now. I'm going to pull this up on my screen. For those of you who are watching over on rumble, or of course, YouTube, this is fascinating.

    He [00:54:00] said there's a high probability of Russian attacks on Starlink in Ukraine. Now that is fascinating because what he's done is he has sent over truckloads. I'm showing a picture of a truck. In fact, with these Starling terminals in it, that's from ARS Technica. Just double-checking it here, but this is very cool.

    This is posted by the vice prime minister over there in Ukraine. And they are talking about these terminals. Now a terminal in this case is something that allows your devices to talk to the Starlink satellites, or there's going to be a huge constellation. They've got 2000 satellites up and they're putting another 12,000.

    These types of satellites are much different than what we've been used to over the years. We were typically, we've had these massive things sitting up in space. [00:55:00] I worked with RCA Astro space many years ago and I saw. They're testing facilities, which are just incredible. They had this huge vacuum chamber that they brought me in to see as we were working on space shuttle software.

    Yeah. I wrote software that they used to put the space shuttle together yeah. Way back in the day. So that was a pretty proud moment. Anyways. It's we're not talking about these huge satellites, like they used to launch, we're talking about very small cell. And they're not just sitting way, way up there.

    These are in basically in low orbit around the earth and they're geostationary. In other words, they stay in one spot. I believe this is the way they've got these things set up. So these satellites then allow because they're so close to the earth, allow them to use less power. And also the other advantage to that is.[00:56:00]

    The delay, right? The delay between having to send it all the way up and back down, because electricity takes time, right? Yeah. Travels at the speed of light. But nowadays you might've noticed it can take your quarter second, half a second. When you're talking to someone, when I'm on the radio with some of these radio stations or the delay can be absolutely incredible.

    Like I half second to a second sometimes. And that's just because they're being cheap. This type of technology where you have these constellations and it isn't just Elon Musk. It isn't just Starling, but constellations with will ultimately we'll have tens of thousands of satellites up there. Not, there's all kinds of other potential problems not getting into that right now.

    But what it does mean is yes. Can communicate and we've never had this sort of thing before we had the us military, the Navy in fact, put together a communication system that [00:57:00] lives on top of the internet and called nowadays. Generically the dark web. And it was set up to allow our military, our state department to be able to communicate with people in countries that are back in the day under Soviet control, all kinds of potential problems.

    So whenever those problems existed, they just went ahead and used this onion network, which is a part of the dark web, et cetera, et cetera. So let's say we had before. Now what happens if you're a country like Ukraine, where 100% of your internet comes from Russia, Russia obviously can sit there and listen in.

    Hopefully your encryptions. Good. A lot of Russians have been using telegram and already get real news about what's happening in their country and other places. And Della Graham is not that secure, frankly. WhatsApp pretty secure signal is the [00:58:00] one you want to pay close. Attention to signal is considered to be the most secure of all of these secure communications apps.

    But there's a level above all of that, because if they can tell that you're communicating, even that is enough to give them some information. So they might not know what was in that transmission, but if the transmission is all of a sudden, a tons of activity coming over, lots of data, lots of messages going back and forth, they can say maybe there's something about to happen.

    That came out. You might remember the old orange book for security way back in the eighties, I think is when it came out. But part of what you had to do was cover up your. Actual real communication. So it's one thing to have the communications encrypted, but you wanted to always have about the same amount of communications going back and forth.

    So people couldn't figure out what you're doing now with these types of devices. That [00:59:00] kind of problem still exists. And this is part of what Elon Musk is warning about here. Pull it up on my screen again, for those people who are watching Elon Musk is urging users of his satellite system to put their Starlink antennas as far as.

    From people as possible. Now, why would he be doing that? Because frankly, that terminal is transmitting to the satellite as well as receiving from the satellite. And it is entirely possible that there could be some evil software that is listening in for the satellite transmissions and sends a little missile your way.

    Also, of course the Russians have satellites in space that can look down on the ground. Now it's something as small as a terminal four Starlink, little hard to see, but Elon Musk is saying, Hey, listen guys, [01:00:00] go ahead and camouflage it. You might want to spray paint. It just don't use metallic paint so that they can't see it and place it as far away from where people are as post.

    So you can still use it and only use it when you need to use it. Don't keep it up and running all the time. But this is the start of something great. Something where you can't easily block people's communication. So Russia has tried to do. And they have been jamming the Starlink satellites. So what did must do?

    He delivered all of his engineers to working on how can we get around the Russian Jack? And according to Elon Musk, they have gotten around it and they now have their satellite systems completely jammed free from the Russians. I think that's fascinating. They're probably using some good spread spectrum technology that was actually known about it and world war II.

    And then we can talk [01:01:00] about that for a long time. Heady, you might remember her anyways, skip that for now. Stick her out. We got more when we. A whole bunch of pandemonium out there because of what Russia's been doing in Ukraine and how it's flowing over to us as well. Hey, this is not great news.

    Pandemonium is the name of the game over there in Russia. And they are being very successful. We're going to talk about what happened in Bella ruse. We'll talk a little bit about what happened in Ukraine with cybersecurity and what's happening right here right now.

    I'd also like to invite you guys to listen to me on all kinds of apps out there, including the tune-in app and many others. Let me get my screen set up because now you can also catch me on. And on YouTube, this is almost [01:02:00] a complete, let me pull this up for you.

    There we go. Complete ARS Technica today. They've got some great articles this week, looking into the Russians. What are they doing? What kind of problems is that causing us? But we are seeing some interesting attacks back on. And back in very big way. Russia has been going after you crane in the cyberspace for a long time, we spoke a few years ago about what Russia had been doing with the tax software for Ukraine.

    We don't do this in the us or in Canada, but my number of European countries do you, where you have to have. The old official tax preparation software put together by the government for your business or for your person, depending on the country you're living in [01:03:00] France is a great example of this. And Ukraine is another one.

    So Ukraine says, Hey guys, you got to go ahead and use our software. That means every business in Ukraine is using their software. To manage their tax payments and their accounts, frankly. And that wonderful little piece of software was hijacked by our friends in Russia. So they grabbed a hold of it. They in.

    Did some code into it that added rent somewhere to the software. So now all of the businesses in Ukraine are pretty much guaranteed to be using this hacked software. We have a client who has offices over in France, and we found a really interesting problem with them because. The French software that was being used for taxes for French businesses had an extra little [01:04:00] problem.

    And that extra problem was, it was insecure as can be whoever wrote this, must've taken a Microsoft programming course and had no idea DIA about the consequences of what they were. So it was very insecure. The, it was using a version of SSL, which is an encryption that's based on another type of increase.

    I don't want to get too wonky here, but that was just one of its many problems and bad keys, et cetera, et cetera. And keys by the way, was using keys that had been revoked, which you should never do. Bottom line. Oh my gosh. Hey, if you want more information on this, just drop me a note.

    me@craigpetersohndotcomandyoucanalsogetmynewsletterwithallkindsofgreatlittletipsmeatcraigpeterson.com. Just let me know. So in this case, we had to help that company in [01:05:00] France. Ignore the security restrictions that were on their systems so they could use the French tax system. So anyways, I told you that, so I could tell you that the same thing happened to Ukraine.

    In a different way, their software was pre infected. So when they downloaded it, ta-da. They got that piece of ransomware that virus had spread. It was just a nightmare. And of course it robbed. If you will, Ukraine, government of funds, that would have been. So we had now a bit of a shift. I'm going to pull this up on the screen again, this article, because what this shift has shown is that the hackers are now operating on the side of you.

    Crazy. Which is just fascinating. So the group called anonymous, you might be familiar with them. Of course, they've been doing a lot of hacking for a [01:06:00] lot of years, releasing private information, government and information. All of that sort of stuff. And they have a mast what they're calling a volunteer.

    It. And this it army has been going and doing what well hacking Russian sites apparently. So this article is just absolutely fascinating and they pulled some of from wired as well, but the Russian space research Institute, their website was hacked, leaked files that were stolen from the Russian space agency, made it all the way on to the.

    The space agency was hacked in their website said, leave Ukraine alone, Alto anonymous. Will you up even more? They also did. What's called a D O S. Which is a distributed denial of service attack. Those can be [01:07:00] very difficult to protect against unless you're set up in advance to help protect yourself.

    And that pretty much destroyed Russia's dot are you top level domain? So we've talked about how domain services work, right? So Doug are, you is like.com except dot R U is for running. And so the domain name servers that handled our, you were knocked off the air because no one could really get to them.

    They used amplifying attacks and stuff without getting into all of the details. So basically they were trying to cut off access and they did for a lot of people to any. That ended in, are you? It's great. These are just some of the latest in this surge of hacktivism. That's been going on one of the ones I mentioned a couple of weeks ago with the Belarusians deciding they were going to hack the Belarus railroad, which was being used.

    To bring Russian [01:08:00] troops, supplies, tanks, et cetera, all on rail, right on down right to the border of Ukraine. So that was hacked so that they couldn't use it in order to go after. Of course Russia was able to get to Ukraine, but there's also been protests around the world. 48 Russian cities raise millions of dollars through cryptocurrency donations.

    Now, I'm not a big cryptocurrency guy and I'm not a big crypto currency guy because while. Cryptocurrency is likely to be outlawed by most, if not all governments. And they certainly could shut it down and it is not anonymous. All right. So using cryptocurrency does not mean it does not equate to completely anonymous.

    They have done a lot of donations. They're big companies including, we [01:09:00] just talked earlier about Microsoft, but also apple shell, BP, a McDonald's Starbucks. And these hacktivists have really joined in. And w we talked about a couple of other things, so this is messy. Because even more than in peace time, these active combat that are really hacking happening right now, rendering, hacktivism, any effectual and largely just distracting because we are now in a hot war right now.

    Maybe we don't have our. Eric planes bombing Russian movements or other things, but there is a kinetic war going on over there. There are bullets, et cetera, mean exchanged. So the hacktivist efforts have been, visible. There's no question about that. But what have they done? See, [01:10:00] that's an advantage to being a country like Russia, or like the Ukraine, or excuse me, Ukraine, because both of those countries there, their industrial base, the military industrial base is not heavily automated unlike ours.

    What could you do? What can you shut down? So what you shut down the Russian space agency's website, how far did you get into it? Probably not very far. We also have a couple of groups and we talked about these guys many times the Conti group, which has been.

    Terrible and hurting us businesses, individuals, government agencies, and stuff, the Cuming project, both of them have declared their allegiance to Russia. You might remember a few weeks ago, we talked here about how we have had some researchers track down most of these Russian hacker groups and their money.

    And they all ended up in one building in Moscow. [01:11:00] No, that should tell you something, right? In fact, the most expensive real estate right there in downtown Los gal, the tallest building, et cetera. So these groups getting together in order to protect the father land there in Russia. Ah interesting problem.

    How much of this is really controlled by the Kremlin? It's a very good question. Context. Was dismantling its infrastructure. It, some of their top people were arrested by Putins military. Not military, but police state over there. And that was interesting too. That was again before the invasion, but why would Putin be shutting them down at all?

    Apparently they said some things. That they shouldn't have said. So now they've come out and have decided they're going to support Russia in its entirety. Now we mentioned Microsoft and how [01:12:00] Microsoft has decided they are going to protect other countries. As well as you crane, at least as far as the Russian malware goes, and they've been very active in that.

    And there are a number of cybersecurity companies and other organizations that have released free versions of some of their software, these digital defense tools. Free offerings. Our big cranes defend the networks. Google says it's human rights focus de dos protection service project shield is now in use by more than 150 Ukrainian websites.

    So it's very good. Bottom line propped up by the way, published this massive trove of personal data. Allegedly identifying 120,000 Russian soldiers deploy. In Ukraine that was Ukrainian prov, not the old good old Russian Sophia Pramata man. I [01:13:00] remember I bought one of those on new standing Canada once.

    And I had a friend who was from Yugoslavia and he said, oh, can I show that to my wife? He showed it to his wife. She tore it up. I said, I want my Pramata, Craig Peterson got calm.

    1 hr 14 min
  • Did You Hear About the Latest Rip-Off? Non-Fungible Tokens! How Law Enforcement Tracks Bitcoin!

    Did You Hear About the Latest Rip-Off? Non-Fungible Tokens (NFTs) Are Already Losing Steam!

    [10:54] How Law Enforcement Tracks Bitcoin! It is Absolutely NOT Anonymous

    [20:05] The FBI Is Actively Removing Malware From Private Machines -- Without The Owner's Permission [29:10] Why and When You Shouldn't Trust QR Codes [41:08] Cybercrime in Russia Tracked to a Single Office Building in Moscow!

    [52:29] The Newest Phishing Scams

    [01:01:32] Using Wordpress? How Supply Chain Attacks are Hurting Your Business Website

    [01:10:43] Cybersecurity Tools You Should Be Using!

    Jam packed today. We're going to start with non fungible tokens. If you don't know what those are, this is a very big deal because so many people are investing in them right now. Are they really investments? I've got a bit of a blow back here. Most people think that Bitcoin is anonymous. We're going to talk about how it absolutely is not.

    [00:00:20] We're going to talk about anonymous. In fact, the Russians, Microsoft, what they're doing against the Russians and this little comedic thing about cars.

    [00:00:28] NFTs are very big deal.

    [00:00:31] I'm going to pull up here on my screen right now. This is a picture of Mr. Jack Dorsey. We'll go full screen, an article from a website called CoinDesk. CoinDesk is one of these sites that really tries to track what's happening out there in the Bitcoin community. Of course, nowadays it's much more than Bitcoin.

    [00:00:53] Isn't it? We're talking about all kinds of. Different currencies that have a blockchain backend. They're called cryptocurrencies basically. But the big one was of course, Bitcoin. And there is a whole concept. Now, when we're talking about things like cryptocurrencies and these non fungible tokens. People have been investing them in them.

    [00:01:19] Like crazy people are making millions of dollars every week. Now, remember, I am not an investment advisor and particularly I'm not your investment advisor. So take all the. To your investment advisor. I'm not telling you to buy them. I am telling you to be cautious here though, because these non fungible tokens are designed to give you the ability to be able to just, own something in the digital world.

    [00:01:48] What might you own in the digital world? We've had a lot of different stuff. We've seen some just crazy monkey things. Have you seen those? These little pictures of monkeys are. Graphic designed and it's all animated. If you will. It's like cartoons and people pay money for them. One of the things that people paid money for was the rights to the first tweet ever on Twitter.

    [00:02:16] So that's what you're getting. When we're talking about an NFT on a non fungible transaction, it is now yours. So this particular NFT we're talking about was of our friend here, Jack Dorsey. We'll pull it up again, this article, and he had a tweet that was sold last year for $48 million. That is a lot of money.

    [00:02:43] So people look at this as an investment, but it's not the same as hanging art on the wall. You've got a Picasso that has some intrinsic value. It's a painting. It has all the oil paint on that, it was designed by and painted by a crazy man years ago. And you can take that Picasso and you can.

    [00:03:07] Turn it around and sell it. It has some real value. If you own the rights to something, let's say it's one of these monkey pictures. It reminds me of a postage stamp and you paid real money for it. Some of these things are going, as I said, for over a million dollars and this Jack Dorsey first tweet went for $48 million.

    [00:03:27] So let's say that's what you did, right? You bought this thing for $48 million. Really? What do you have? Because anybody can go online and look at that tweet. Anybody can print it up and stick it on a wall. Anybody can go out and get that picture of the monkeys right there. The guy drew, and you can look at it.

    [00:03:51] In fact, I can pull it up right now, if you want to do. But people paid real money for that. So they've got what really? What do they have? You can't take it off the wall, like you're Picasso and salad, right? Or Banksy, if you're into the more modern art, it's just not. What is doable? How do you make this work?

    [00:04:12] Only the NFT only gives you bragging rights in reality. That's what it does. You have bragging rights because you could take that digital picture and make a hundred quadrillion copies. Yeah, you'd still own the NFT you would still have in the blockchain for whatever NFT company you're using the rights to it.

    [00:04:37] They would say this, you owned it. So let's talk about the blockchain behind it. There are a lot of companies that are trying to give you that. Okay. All right. I get it. Yeah, I get to to own it. But who's running the blockchain behind it. Who's validating that you own it with Bitcoin and many of these other blockchain currencies that are out there.

    [00:05:04] There are various. Companies and individuals who are registered, who have all of the paperwork, if you will saying who owns, how much of what, and who paid, who and everything. And that by the way, is why it takes so long for some of these Bitcoin and other transactions to occur. But how about the NFT? There are tons of companies out there that say they will certify the NFT.

    [00:05:34] So it gets to be real problem. And when we get into this Jack Dorsey tweet and this article about it, which are will, let me pull it up again here for you guys. This guy, Sina S bought the very first tweet ever from Twitter founder, Jack Dorsey for $2.9 million last year. And he decided that he wanted to sell it.

    [00:06:03] So he listed it for sale again at $48 million last week. Real. He put it up for open bid and this article and CoinDesk is talking about that. And you can see that if you're watching me on rumble or YouTube, I'm showing you my screen here right now. But this Iranian born crypto entrepreneur named of again.

    [00:06:28] As TAVI purchased it for $2.9 million in March, 2021. Last Thursday, he announced on Twitter where out, that he wanted to sell this and Ft. And he said, Hey, listen, I'm going to put 50% of the proceeds to charity. The auction closed, this was an open auction. People could go and bid on it and head auction closed.

    [00:06:55] With an offer of basically $288, $277 at current prices when this article was written $277 and the lowest bid was $6. And as I recall, this is not in this article, but there were only. I handful of bids. Like when I say handful, I mean a half a dozen beds. Crazy. This is a real problem because the deadline is over.

    [00:07:27] He paid how much for it, right? How much did he pay? Pull that up again. $2.9 million last year. And his highest bid was in the neighborhood of $280. Isn't that crazy. So did he get money on this? Did he win money on this? I don't know. I'm looking at those saying is it worth it to buy something like that?

    [00:07:54] That you might think, oh, the very first apple computer, an apple. While that's going to be worth some serious money. Yeah, it is. It's something, you can grab onto, you can hold onto it, it's something and you can sell it. You can trade it. You can take a picture of it. You can't make digital copies of it.

    [00:08:15] You, you, it's a physical thing. That's worth something. Same thing with that Picasso on the wall, it's really worth something that has some basic intrinsic value. Jack's true tweet. The very first tweet. How much is that thing worth? It basically nothing. So the tweet is showing he'll pull it up on the screen again that he's selling ad Jack 2000 6 0 3 21 at eight 50 14:00 PM.

    [00:08:46] Just setting up my Twitter. So there you go. There's Jack is very first to. And it's absolutely amazing. Is it worth it? Let me pull up some other stuff here for you guys. I'm going to pull this up here is Coinbase launching an NFT marketplace in hopes of appealing to crypto on mainstream users. So here's some examples from a man and FTEs.

    [00:09:11] I'm going to zoom in on this for those of you guys watching on rumble or on Twitter. All right. Mean. Yeah actually you can see it on Twitter too, but YouTube, here you go. Here's some NFTs it's artwork and it's a creature. So you can buy creature number 7, 8 0 6 right now for six Eve. So let me see.

    [00:09:34] Value of six. Ethereum is what ether, M two us dollars. So for 3000. And $84. As of right now, you can get a crappy picture that even I could have draw okay. Of this guy and look at all of the work this artist has put in. There's how many of these up here? 1, 2, 3, 4, or five, 10 of them. And it's the same head.

    [00:10:03] Each time it looks like this almost the same eyes. He changes colors and he's got different background. It's absolutely not. So that's what they're trying to do right now, trying to sell these NFT. So who's going to buy that. Who's going to pay $3,000 for artwork that hunter Biden could have done with a straw.

    [00:10:25] Anchored around. Here's another one. This is from ledger insights. NBA's launching dynamic NFTs for fans, baseball cards for the NBA that are basically just worthless. They're NF. Non fungible tokens. It has taken the crypto world by storm and people are losing millions as you look, but it really is changing the e-commerce world.

    [00:10:54] Bitcoin blockchain. All of the rage, a lot of people are talking about it, but I got to say most people who are talking. I don't know much about it. And when it comes to anonymity, Bitcoin is probably the worst thing you could possibly do. It's amazing.

    [00:11:12] There are a lot of misconceptions out there when it comes to technology, you have almost any kind of technology and blockchain and Bitcoin are examples of a very misunderstood technology.

    [00:11:25] Now I'm not talking about how does it work? How are these ledgers maintained? How does this whole mining thing work? Why has Chan. Bandit. Why are a lot of countries going away from it, one country. Now the dictator said, yeah, we're going to use Bitcoin as our we're official currency. In addition to the U S dollar what's going on.

    [00:11:48] It is complicated behind the scenes. It's complicated to use. Although there are some entrepreneurs that have made some great strides there. I saw a documentary on what has been happening in that one country. I mentioned. They are able to pay in us dollars using Bitcoin. So they'll go up to a vendor on the street.

    [00:12:13] Quite literally they'll have their smartphone with them. The vendor has their smartphone. They type in 15 cents for the taco and a hit send. It goes to the other person and they have 15 cents worth of Bitcoin. By the way, these types of micro-transactions with the way Bitcoin is structured behind the scenes, make things even less manageable in the Bitcoin world than they have been in the past.

    [00:12:40] And that's why in case you didn't know, Bitcoin is making some major changes here fairly soon. They've got to change the way all of this ledger stuff works because it takes too long. To record and authorized transactions. And these ledgers just get way too long when it comes to all of these kinds of microtransaction.

    [00:13:04] So there's stuff going on, Bitcoin, there, there are many of these types of currencies out there. Theories comes one. You've heard about doge coin because of course that's Elon Musk has been talking about and many others and they're all different somewhat, but the main concepts are the. One of the big concepts, I'm going to pull an article up here on the screen for those watching on YouTube or also on rumble.

    [00:13:30] But this is an article from our friends at wired magazine. And now you have subscribed to wired for many years. This particular one is about what wired is calling the crypto. Trap now that's a very big deal. It is a trap and it's a trap and a lot of different ways. And that's what we're going to talk about right now.

    [00:13:56] Crypto is not what its name implies. A lot of people look at it and say, oh, crypto that's cryptography. That's like the German enigma machine in world war two and all of this new, great crypto that we have nowadays. And there are some pretty amazing new cryptographic technologies that we've been using, but no, that's not.

    [00:14:17] What's really going on. You see the basic premise behind all of these technologies is the concept of having a. And this wallet has a unique identifier. It has a number assigned to it. So if I'm sending money to you, I'm going to have your wallet, ID, your wallet number, and I'm going to now send you some amount of fraction, most likely of a cryptocurrency and it's certainly if it's Bitcoin, it's almost certainly a fraction.

    [00:14:49] And so I'm going to send you $100 worth of, let's say. What ends up happening now is these ledgers, which are public, are all going to record the Craig's sent you a hundred dollars worth of Bitcoin. Of course, it's going to be in a fraction of a Bitcoin. So sometimes there's rounding errors is not going to be really exactly a hundred dollars.

    [00:15:12] Plus there's the amazing amount of. Tivoli volatility in the cyber currencies. So even though I meant just hitting a hundred dollars, mine ended up being 110 of it goes up. It might be 90. If it goes down you get that. You don't understand how that works. So the problem now is I have sent you a hundred dollars.

    [00:15:33] And public ledgers that anyone can gain access to now say wallet number 1, 2, 3, 4 cent, a hundred dollars, two wallet, number 5, 6, 7, 8. Obviously the wallet, our bruises, a lot longer than that. So then it's fine. And there's a degree of anonymity there it's really called pseudo anonymity because in reality, it's not completely anonymous because people know the transaction occurred and they know the wallet numbers.

    [00:16:03] Correct. It's like a bank account, and if I'm putting money into your bank account, that bank account number knows that the money came from a check that I wrote. Can you imagine that someone writing a check and that check I had a number on it, a bank account number, right? So it can all be tracked while much.

    [00:16:19] The same thing is true when it comes to cryptocurrencies, these cryptocurrencies are in public ledgers and those public ledgers can be used with a little bit of work to figure out. Who you are. So this article here from our friends at wired gets really hairy. And it might be of interest to you to read, but this is talking about a take-down that happened, and this is a massive take down.

    [00:16:51] This take down was of a whole group of people who were involved in some really nasty stuff. In this particular case, what it was kitty. Just a terrible thing and the abuse surrounding it. So this logical goes into not a lot of detail. I'm not going to read it because here on the air, because I don't want to upset too many people.

    [00:17:15] Cause it's some of the details of this evening to think about them are incredible. But. This the police broke into this middle-class suburb home in the outskirts of Atlanta. And he there was Homeland security. It was a guy from the IRS and they came in, they took all of their electronic devices.

    [00:17:38] They separated the family, putting the father who is an assistant principal at the local high school assistant printers. And he was the target of this investigation. So they had him in one room, they had his wife and another room and they put the two kids into a third room and they started questioning him.

    [00:18:00] Now, this is part of a takedown of a, as I said, a whole ring of these people, including this assistant. Principal at a school. Can you believe that? So this IRS guy had flown in from Washington DC to have a look over what was going on, but this agent from the IRS and his partner whose name is let's see, his name was Jenn S Scouts.

    [00:18:26] I probably got that wrong. And Tigran GAM bar Yan, Cambodian, and they had a small group of investigators and they were at a whole bunch of different federal agencies, not just the IRS. What once seemed to be. Untraceable was no longer untraceable. Now I've talked on this show before about a lecture I went to by the secret service about how they had tracked down and shut down the world's largest website that was being used to sell illegal materials online.

    [00:19:01] And it's fascinating what they did. But frankly, they're calling this particular boss to proof of concept and that's why they are IRS was in on this as well, but it was huge. Here's a quote from the IRS agent in this wired magazine article. He's saying he remembers how the gravity of this whole thing.

    [00:19:21] Let me pull this up on the screen too. So you can read along here, but this was a high school administrator, a husband, and a father of two, whether he was guilty or innocent. The accusations, this team of law enforcement agents were leveling against. There are mere presence in the home would almost certainly ruin his life.

    [00:19:44] And he, as well as these other people were counting on anonymity from Bitcoin. Now, obviously I'm glad they got taken down, but listen, folks, if you think that it's safe, that it's anonymous, it ain't Bitcoin just ain't there. Craig peterson.com stick around.

    [00:20:05] I've been blamed for really complaining about people not updating their software. And that includes things like firewalls. The FBI has stepped in and they are going ahead and doing updates for you.

    [00:20:21] What should we be doing as a country?

    [00:20:26] People are. Updating their software. They're not updating their hardware. And particularly our hardware take a look at what's been happening with the firewalls and the firewall concerns. Everybody has some sort of firewall will almost everybody, but enough people that we can say, everybody has a firewall, you get your internet from you, name it.

    [00:20:50] And because of the fact they're using something called Nat network address translation, they've got some sort of firewall in front of you. So for instance, You've got your phone, right? You're using your phone and it's got internet on it. You're going through whoever your carrier is. And that carrier is giving you internet access, right?

    [00:21:14] They don't have enough IP addresses, particularly IPV four, in order for you to get your very own unique little address out on the. No they do. When it comes to V6 things a little bit different, but your device is not completely exposed on the internet. Windows comes to the fire. And by default, the windows firewall is turned on.

    [00:21:35] Now this gets more than a little concerning because that firewall that's turned on. Isn't really doing anything because I've got a firewall turned on and yet every service is accessible from outside, which is defeating the purpose of the firewall. Again, it's a complaint I've had about Microsoft now for.

    [00:21:55] Decades, which is they have features that are just check boxes. Yes. Yes. It's got a firewall. Yeah, it's turned on, but the features don't work. So having a firewall and having everything open defeats the purpose of a firewall max do not have a firewall turned on by default, but they do have their services to say.

    [00:22:18] Which is just as effective if not more effective. So one of the things we advise people to do is go into your windows system, into the firewalls and your security settings, and turn off any services that you're not using. If you're not sharing file systems, then turn that off. In other words, You're mounting the G drive or whatever you might call it from another computer, then you don't need it.

    [00:22:44] If you're not as server for what's called SMB, then you don't need to share it. So turn off everything that you don't need. That's going to happen is one of your programs isn't going to work, right? And the, what you did last year, you're going to turn it back on and you can do a lot of research online to find out what they are.

    [00:23:04] We have over 200 settings that we change in windows. When we get a customer. Now on the Mac side, you can turn it on. I liked turning it on. I liked turning off the ability to see my machine. So in other words, the ability to be able to. So I turned it on and I enable specific services. And again, you can do some research on that.

    [00:23:30] I've got an improving windows security course that people have taken, and we should probably do that again, if not just have some free webinars on how to do this. So you guys can learn how to do it, but not that hard to do. Anyhow, bottom line is. People aren't updating their computers, even the Macs and windows.

    [00:23:51] We have a client that would just started a new client and we're tightening things up and we've been finding Mac computers that are major multiple major revisions behind. And that to me is shocking. Apple Macs are just so easy to update. It is extremely rare that an apple update will make your computer break unlike in the windows world, where it's pretty common.

    [00:24:17] So windows guys, I can understand, but your even more exposed, your bigger target, you need to keep up to date. So how about all of the other equipment that we. I've had warnings again and again, with you guys about what's happening with our smart devices that are out there, right? Our security cameras we have up in the corner, right?

    [00:24:41] We have these smart thermostats, people are using the list goes on and on of all of this equipment that we're using that is exposing us because when was the last time you have. How about the firmware in your router or your wifi, right? Some of the devices that I recommend to people, and if you have any questions, just email me and [email protected].

    [00:25:05] I can give you recommendations, even if you're a home user. Although my business obviously is working with businesses on what kind of wifi to buy, what you should get, what you should do. I don't charge for any of that stuff. Okay. You get it. But you have to ask. [email protected]. So you get this information and you go ahead and you buy whatever it is, but you don't keep it up to date, which is why I tend to only recommend stuff that automatically updates.

    [00:25:33] But that also means every few years you're going to have to replace it because unless you're using the good Cisco equipment where you can get a seven year life out of it you're not going to find that in consumer grid. So what's happened here. I'm going to pull this up on my screen for people watching this on YouTube or on rumble.

    [00:25:52] But here is a thing that came straight out of our friends here from the FBI. This is from CSO. This is a a magazine that I do follow. But they're talking about what they call psych clock. Blink. So the article says for the second time in a year, the FBI has used search and seizure warrant to clean malware from devices owned by private businesses and users without their explicit approval.

    [00:26:25] The FBI used this approach to disrupt a botnet, believed to be the creation of right. Government hackers. So the calling this SYEP clock cycle clubs, blink malware discovered earlier this year. So here's the problem. What do you do if you're the federal government, how do you try and keep your country safe?

    [00:26:51] Now we know. We've got these military contractors. They make missiles that take out missiles, right? The provide defensive systems. You've heard of iron dome from years ago, all the way through all of the current stuff. That's what they do, but what do they do? What can they do when there's a botnet? A botnet is where there are multiple computers in this case, probably tens of thousands of computers located in the United States that are acting like sleeper.

    [00:27:21] They sit there and they wait for commands as to what they should do. Should they try and attack a machine? Should they try and spread more? Malware, what should they be doing? And the, these things are vicious. They are absolutely nasty. And in this case, we're looking at Russian malware. So Russia effectively like the Americans.

    [00:27:44] You might remember that TV show. It was great show, but that. Computers that are owned by you and me and our businesses and government agencies that are under the control of the Russians. Now you don't even know it. You're using your computer. You're playing games. You're going to Facebook, whatever it is you do on your computer.

    [00:28:06] Your computer is under command and control of the Russians. So the FBI goes to a court and says, Hey, we've got to go ahead and shut this down. We need a warrant. They get the warrant and the search and seizure warrant lets them now. Get on to these machines that are part of the bot net or the controlling machines for the bot net, and either remove the malware or go ahead and take control of the botnet themselves.

    [00:28:34] So it can't be used. And by the way, our friends at Microsoft they've gotten involved in this too, which is really frankly, cool in shutting down some of these botnets, Hey, I want to encourage everyone. Take a couple of minutes, go to Craig peterson.com/subscribe. That's Craig Peterson. CREI G P T R S O N.

    [00:28:57] And subscribe, and I'll be sending you a special report on passwords. Plus two more. I send out the most popular special reports that anybody has ever asked for.

    [00:29:10] Hey, I've got a little bit more to discuss on what's happening with Russia and Microsoft and more, but I'm also going to talk about QR codes. There is a great explanation. That's in your newsletter from Monday about why you shouldn't trust 'em.

    [00:29:26] Let's finish up this Russian thing. And then we're going to get into why you cannot trust QR codes and a brand new way.

    [00:29:36] The bad guys are using QR codes to really mess with us. Now, if you're watching over on either YouTube or on rumble, you'll see this. Let me pull up my screen for you. But here we go. Okay. This is very interesting. Then the last segment, we talked a little bit about what our friends over at the FBI had been doing, which is they have been removing malware from people's computers because people haven't been keeping their computers up-to-date right.

    [00:30:11] Part of the botnets. So we explained. At the FBI, isn't the only one out there trying to stop these Russians and the hackers anonymous has been very big at it. In fact, let me pull up this other article. This is from security affairs. And here we go. And it's talking about this whole army of these anonymous hackers.

    [00:30:35] Now none of us have been a nightmare for many businesses that they didn't like. I had an anonymous we'll go ahead and they'll do usually pretty basic stuff. They'll do denial of service attacks and some other things, so they don't like you because of. The don't say gay bill in Florida, and, without bothering to do any research, they'll just start attacking organizations that support it, or organizations that don't support it depending on how they want to do it. So this is an interesting article here, because it's talking about these various. Websites that they've hacked. Now, some of them are government site and some of them are private industries. Now, one of the cool things, bad things about hacking private industry and releasing the emails is now the competitors to these businesses know what they're doing.

    [00:31:31] And in some cases there's proprietary technology that's being released. Now, when it comes to Russian proprietary technology. The Western world doesn't care a whole lot about some of it, but here's some examples of what these hacktivists of GoDaddy. This is a company called forest 37,000 emails stolen from the company, Russian logging and wood manufacturing firm.

    [00:31:55] Again, it would give a little bit of an idea into the whole Russian, what are they doing? In the forest industry. This one, I think is a little more concerning for the Russians Aero gap. This is an engineering company that focuses in the oil and gas industry. Their clients include a whole bunch of Russian companies.

    [00:32:15] They've leaked approximately 100,000 emails from Aero gas. That is a huge deal because so much of the country's revenue, the number one industry in Russia is oil and gas. Petro Fort one of the largest office space and business centers in St. Petersburg, the hackers have leaked approximately 300,000 emails from Petro fork.

    [00:32:41] Again, you can use that to find out what's happening in your economy. What. Doing how are businesses doing? Are they going to go under so you can see some tweets here. I've got them up on my screen on YouTube and rumble anonymous. What they're saying that they've done and you can follow anonymous directly on Twitter.

    [00:32:59] Particularly fond of them. They've done a lot of things that I disagree with. This is really telling us about a whole new approach to warfare, right back in the day, you and I couldn't get involved, we could potentially take up arms and go and fight right there and think about the Spanish American war.

    [00:33:18] Think about what's happening now in Ukraine, where Americans have just gone over there. Taken up firearms in order to help them defend Ukraine. People who are maybe of Ukrainian descent, maybe not right. We have never seen this type of involvement by average citizens because anonymous is not like some big fancy company or government agency anonymous is a bunch of people who are trying to be anonymous and do something.

    [00:33:50] So they stole 145 gigabytes. Look at this. It's just crazy. So he. The anonymous Twitter thread itself, right? Talking about what. It's absolutely incredible. Incredible. So that's what anonymous is up to. They are hacking Russia and they're hacking Russia in a big way. Now, next stop. We have our friends at Microsoft.

    [00:34:15] Microsoft has been seizing Russian domains that they are accusing of having been linked to these Russian hackers that have been going after think tanks and government agencies in the U S and the. He knew, I shouldn't say which I'm sure includes the UK cause UK has gotten involved. So this article from the verge is talking about how Microsoft has seized seven domains, belonging to fancy bear apt 28 which is we've seen them active in a number of companies here, right in the Northeast United States.

    [00:34:57] These companies who are. Trying to provide materials, software, hardware for government contracts, right? So they're not even direct government contractors for the feds. They are just a sub contractors. And then we've seen fancy bear in there. We've seen the Chinese in these companies. It's incredible.

    [00:35:19] They have no. DIA that all of their intellectual property is being stolen, which is why the federal government has started cracking down on contractors and subcontractors and the, this whole paragraph 70 12 thing. We're getting geeky here, but companies that have to protect even unclassified information, confidential, classified, and they haven't been so Microsoft.

    [00:35:46] Obtained a court order. You can see this on my screen, over at YouTube and at rumble to take control of each domain on April six, that then started redirecting them to a sinkhole. So what they do is they take control of the DNS for the domain. So the root name servers, now, point to a Microsoft name server, and then send them to a sinkhole.

    [00:36:09] A sinkhole is basically nowhere you go there. There's nothing on the site, right? Or in this case also servers used by cybersecurity experts to capture and analyze malicious connections. And they'll do this. Oftentimes, when we're talking about these botnets, like we talked about a little earlier today, so apparently they're trying to establish long-term access to the system.

    [00:36:33] So the targets, what did we just talk about? Long-term acts. But net, right? That's what button that saw. So Microsoft has gotten involved. They've been doing this now for a little while. It's obviously not their normal business model, but it is something that they've been doing. They were also, by the way, the fancy bear link to these cyber attacks on the DNC in 2016.

    [00:36:57] And they also targeted the UFC election in 2020, which is why, part of the reason why anyways, don't use electronic equipment for our elections, have paper ballot, have people count those ballots yet it takes longer. You can't have the instant thing on TV, which is why all of these new services, they all don't do that.

    [00:37:18] That's ridiculous. But it's the only thing we can guarantee that these guys, like I got it up on the screen again. Fancy bear the Chinese et cetera. It's the only way they can get in. And if we were doing paper ballots and we had bipartisan people counting the ballots and independence, counting the ballots, observing this, we wouldn't have all of these problems that we had with the last election where people were saying it was stolen.

    [00:37:48] It was hacked. How do we know it was stolen? How do we know it? Wasn't stolen? How, go back to paper ballots, get rid of the scanning machines and particularly get rid of these electronic voting machines where you touch the screen to cast your vote. Those things are ridiculous. What if there's a software bug in it?

    [00:38:06] How can you go back and change the vote? People that complained about it again, and wait a minute. I voted for this guy and you had to record my vote for the other guy. It's ridiculous. Anyways. Back to QR codes. Okay. I'm going to pull this up on this screen because I think this is a cool article here.

    [00:38:25] This is from a, actually a site over in India. It's called scroll.in, and they're talking in here about how hazardous it can be. To use QR codes. Now they're not saying don't use QR codes, we've all had to use them. I've got up on my screen, this picture of being at a table. And you scan the QR code in order to get the menu.

    [00:38:48] In order to order, I did that. I was in Vermont and we were riding motorcycles or buddy, and I go into the little tiny. Restaurant, small restaurant and I had a half a dozen tables and they didn't have menus. You scanned it, the QR code that was there on the table and you placed your order. And off it goes a lot of places they've been doing that with menus.

    [00:39:11] You've seen that more and more saves them money as well and lets them change their prices more frequently. Yeah. Thanks for that inflation guys. Why shouldn't you use these QR codes? Why should you be extra careful? Here's the answer. QR codes are the URL of a webpage. That's the bottom line. Would you click a random URL that came in an email?

    [00:39:37] Would you click on a random URL in an ad or on a web page? We certainly know better than to cook URLs in our email. But that's exactly what the QR code is. And on top of it, the URL in a QR code tends to be what we call a shortened URL. So it might be Bitly, so might be bit.ally/and then some random characters.

    [00:40:04] How do you know where it's going to take? You don't all you know, is it's going to take you to Bitly, but that Bitly URL could be sending you to a malicious site. And now your phone could be hacked. It could be using your phone for Bitcoin mining for who knows what. So be very careful and the bad guys are using these in a different way that you might not have seen before, which is they are embedding QR code graphics.

    [00:40:34] Into emails. And they're thinking that people are going to hold up their phone to the email and what are they going to do? They're going to scan the QR code that was in their email. And now they're in trouble. Yeah, that's simple. Hey, visit me online. Craig peterson.com. Make sure you sign up for my newsletter.

    [00:40:53] Craig peterson.com/subscribe course, Craig Peterson, S O n.com. And I'm going to send you. Top three special reports, absolutely free. We got to take care of these bad guys.

    [00:41:08] This is a big deal, quite literally a big deal. Russian malware. We have been able to track it down now, track it down to a single site. Yeah. All of these bad guys are in one building in Moscow.

    [00:41:25] Hi everybody. Of course, you're listening to Craig Peterson. Thanks for taking a little bit out of your day today. As we continue to really talk about the stuff that's most important in the world, and there could be nothing more important, I think, than some of our cyber security, our lives, our fortunes, et cetera.

    [00:41:44] Last year we have to pay attention to well, This is a very big story and it's a bit of a scary one as well. We've had a lot of ransomware over the years and a lot of ransomware. Have you had it yourself? I bet you, if you haven't, someone who has had ransomware because frankly it is pervasive in every aspect of pretty much everybody's life out there.

    [00:42:12] So when you get hit with ransomware, Lately something a little different has happened. It's really gone through three phases. The first phase was the ransomware would get on to your system. Usually it came as an attachment, probably embedded in like a word file it's been embedded in PDFs, embedded in all kinds of stuff.

    [00:42:35] Even drive by downloads on websites, have brought malware. But in this case yeah, it was annoying. It was a problem. It would give you a red screen. You've probably seen it before warning about the ransomware and it told you, okay, here's what you can do to get your files back. And in order to get your files back, you usually.

    [00:42:57] To go to some exchange online, take dollars, buy of course, Bitcoin, or some other cryptocurrency. And then that cryptocurrency would be used in exchange now for you to get a key that would hopefully decrypt everything. And in reality, it often didn't encrypt hardly anything. So it's been a problem and a problem for a lot of people.

    [00:43:23] The FBI said that at the time. So this is a gen one of ransomware. You were lucky if 50% of the time you got all your data back, gen two of ransomware is when the bad guys started getting a little bit smarter. They didn't just take your files. Thumb and then say, Hey, pay up buddy. What they did at this point is that got onto your systems and they poked around.

    [00:43:46] They went we call in the industry, east west on the network. So they got onto you, maybe your kid's computer may, maybe you were hooked up via VPN to the office to do work. And it wasn't a great VPN. And the kid's computer had that virus and that virus weaseled his way all the way over the VPN, directly to the office, because remember.

    [00:44:09] VPNs are. A network private in that. Yeah. Okay. It's encrypted. And so someone who's got a wire tap isn't necessarily going to get anything, but it's a VPN, it's a tunnel. And that tunnel was used a many times for malware, like brand summer to creep over to the office network. That's an east west is going from.

    [00:44:30] One machine to another machine. And in businesses, man, you saw that one a lot as that ransomware moved around. So that was the second one. So the rents were going on the machine. It would then look for files that is. You might not want to have exposed. So it looked for files with bank account numbers in them, social security numbers, maybe intellectual property.

    [00:44:57] We saw a lot of that. Theft is continuing to go on primarily from the Chinese and then an intellectual property theft. And what happened next? While of course it ended up moving the data, the files, and then what they would do. It's encrypt your desk. So before they gripped your desk, they got copies of all of the stuff they thought might be important to you.

    [00:45:20] So now the threat was in version two of ransomware pay up, or if you don't pay up, you are going to have to pay us to not release your files. If you didn't want all of that client information online, if by law, you would get nailed for having that client information out online. And that's true in most states now, and the federal government's from putting some teeth on some of their laws as well, then what are you going to do?

    [00:45:49] Yeah, you paid the. So that was version two version three that we're seeing right now of ransomware is simply destructive. And if you go way back in history, you may remember I got hit with the Morris worm, which was one of the first pieces of nastiness out on the internet. And that was early nineties.

    [00:46:13] My business that I owned and was running, got hit with this thing. Even before that, There was ran. There was a nasty where viruses, if you will, that would get on the computer and destroy everything. It was just a malicious, as I remember, somebody at UC Berkeley, some researcher in it. And he didn't like what that of the researchers were saying about him.

    [00:46:35] So he put some floppy disk together and on them, he put. Erasing malware and shared all of the stats with anybody. And of course, you plugged that disc into your, that little floppy disc into your windows computer. And it says, okay, I'm going to go ahead and open it up. And, oh, look at this, a virus.

    [00:46:56] And so he then wiped out the computer of everybody else. That was a competitor of his out there in the industry. Yeah, a little bit of a problem if he asked me, so how did that end up getting around? What ended up happening while everybody got really upset with him, nobody really found out what was happening, who did it, et cetera.

    [00:47:19] That's what's happened. Now, so version three of malware is like some of the very first malware we ever saw version three of ransomware. So some, again, some of that very first ransomware was pretty nasty is not the sort of stuff you want to see running destroying files, but at least you could get back from a.

    [00:47:40] Nowadays, a lot of people are doing backups by attaching a disc directly to their machine, or they're backing up to another machine on the same network. Remember that whole east west thing, you didn't want the data going back and forth, it causes problems. Yeah. So what happens now? The Russians apparently are just trying to cause havoc with businesses, anybody who has decided that they're going to be anti-Russian in any way there they're attacking.

    [00:48:13] So they'll, reraise your desks. They'll erase all of your data. If you have backups on that thumb drive or that USB external. The good news erase that if you have backups on another machine, on the network, hopefully from their standpoint, there'll be able to get onto that machine and erase all of your backups, which is again, why we'd like 3, 2, 1 backups.

    [00:48:34] At the very least, there's some others that are even better. And if you're interested, send me an email [email protected]. I'll send you a webinar that I did on this. I'm not charging you for. But it was a free webinar to begin with what a webinar on backup and how to backup properly and why to do it this way.

    [00:48:54] Again, me, M E Craig peterson.com. Be glad to do that. What we're seeing now is a huge problem. Let me see if this is going to work for us. Yeah. Okay. It is. I am, by the way, live here we go on my computer. So people who are watching. I can see my desktop. So here we go. This is Russian companies who are linked to this Russian malware.

    [00:49:24] Ransomware are hiding in plain sight is what they're calling it. So what does it mean. To hide in plain sight. While in this case, what it means is money that's been paid by American businesses to these Russian ransomware gangs, some of who by the way, are actively going after anyone that criticizes Russia found these American researchers.

    [00:49:50] Yeah. Led to one of Moscow's most prestigious addresses. You can see it up here on my screen. This is a New York times article. It's just a random actor, journalism people, sometimes even the New York times gets it. And they're saying millions of dollars have gone through this. So they've been tracing.

    [00:50:10] Where did they go? The Biden administration has also apparently zeroed in on the building is called Federation tower east. It's the tallest skyscraper in the Russian Capitol. How would that be to have a business and just this beautiful tall skyscraper and have a view that would be really cool. So they have targeted some companies in the tower.

    [00:50:32] As what it's trying to do is stop the ransomware guy gang. Maiden cryptocurrencies. Russian law enforcement usually has an answer to why don't you just shut down these bad guys that are out there trying to steal all of our money. They say there is no case open in Russian jurisdiction. There are no victims.

    [00:50:51] How do you expect us to prosecute these honorable people? That apparently is a quote from this Massachusetts based secure cybersecurity. Called recorded future, but I'm looking at a picture it's up on my screen right now. You guys can see it, but this is the Moscow financial district called Moscow city.

    [00:51:10] 97 floor Federation tower east. This is really pretty, you wouldn't know this isn't like London or any other major European capital. There's some cranes in the background building up new buildings. The cyber crime is really fueling some growth there in Moscow, which is, if you ask me the exact reason why lad is happy as a clam to just go ahead and have these Russian cyber crime guys.

    [00:51:43] Just go and bring money in right. Money is bringing in great money for them. The treasury department, by the way, it's estimated the Americans have paid $1.6 billion in ransom since 2011. Huge one ransomware strain called RIAA committed an estimated $162 million. Last year. It is really something.

    [00:52:07] So when we come back, we've got a lot more to talk about. We're going to talk about the cloud. If it's more secure or why is it calm, broken, give masks work. Why aren't they working right. Anyways, we'll talk about that. When we get back and visit me online, Craig Peter sohn.com.

    [00:52:26] Stick around.

    [00:52:29] I hate to say it, but there's another big scam out there right now. And it is hitting many of us, particularly the elderly quite hard. We're going to talk about that right now, what you can do about it and how you can recognize when it's happening.

    [00:52:45] Interesting article that came out this week in wired.

    [00:52:49] It's actually in Wired's. Let's see, what is a March 2022 issue. It wasn't this week. Nevermind. And it's talking about a serious problem. I'm going to show you guys who are watching I have this on rumble, YouTube, Facebook as well. So you guys can see along and of course, right here, too.

    [00:53:11] Now let's not forget about that, but this is an article that says we were calling or excuse me, they were calling for help. Then they stole. Thousands of dollars. I'm going to read parts of this article. It's just amazing. It's by Becca, Andrew's a back channel. What is that? Okay, so that's just a cat.

    [00:53:33] On December more one December morning, my mother's phone rang. She tugged the iPhone from the holster. She kept clipped to the waist, her blue jeans and wondered who might be calling perhaps somebody from the church who was checking in on her recovery from Corona virus. Hello. She said the voice that greeted her was masculine.

    [00:53:53] This is just great writing. The color sounded concerned and he told her something was. With her Amazon account, somebody has access to your bank accounts through Amazon and they can take all your money. I'm calling to it. Her mind raced or Lord, she prayed silently. The voice was warm and reassuring them.

    [00:54:15] My mom tried to focus closely on his words. My dad was driving to work in his truck and she was home alone. She'd been cooped up in the house for weeks with COVID isolated from her community and she missed the bomb. Friendly voice. I D I just love her language here. It's just phenomenal. She tried to steady herself.

    [00:54:36] The man said he needed to make sure the money was safe. He transferred her to a different male voice. Soothing reassuring, calm. She promised not to hang up a brain injury decades earlier, made it hard for her to follow his instructions, but she stuck with it. The voice explained slowly, carefully, how to swipe and tap her phone until she had installed an app that allowed him to see what was happening on her screen.

    [00:55:07] Now. You followed her every move. After some hour, she mentioned she had to relieve herself hours. It's okay. I'll stay on the line. He said she parked the phone, outside the bathroom and picked it back up. When she was done as Nooner approached, she told him I have to eat. I'll wait. It's okay. Don't hang up.

    [00:55:28] We'll lose all our progress. She set the phone down on the counter to make a sandwich, then pulled some chips from the cabinet and padded over to the kitchen. The phone buzz with the text. It was my father checking in. She typed back that there was a problem, but she was fixing it. She had it all taken care of.

    [00:55:48] She tapped the tiny white arrow next to the message field to send her reply. And then she heard the voice, its volume elevated as sounded angry. She frowned and brought the phone back up to her ear. Why would you do that? You can't tell anyone what if he's in. She felt confused that didn't make any sense, but she also didn't fully trust herself.

    [00:56:10] She was worn. From her slow recovery and the steroid, she was taken as a treatment, gave her a hollow buzz of energy. Now I want you guys to go have a look at this over on wired site. Read the whole article. It is a phenomenal. Absolutely phenomenal. But what it's doing is telling the story of this woman who was trying to, do the right thing, trusting other people, which many of us do?

    [00:56:40] I have a default trust with a little trepidation. I will admit that, but with the whole. Down the thing that happened, many of us have just been longing for a little bit of companionship and to hear a stranger who's trying to help out. That's a huge plus it goes on in this article and talks about how reassuring these guys were and what they did.

    [00:57:06] She installed this cash app and opened up PayPal downloaded. Coinbase set up Zelle so she could send money directly from her bank account. She doesn't know about any of these things. It's just incredible. So the afternoon wore on and the guy said Hey, we're almost done. And her husband of course, was on his way back.

    [00:57:30] And the sun was down. Father got home. He noticed right away that something was off. And she said she took care of it. And you said you took care of what I'm not supposed to tell you. It said, so the scammer had siphoned away. All of her personal information, the scammers had your social security number, date of birth driver's license number, and about $11,000.

    [00:57:55] These new financial apps like Zelle and others that are legitimate PayPal apps, right? Zell, you can use to send money legitimately to someone else. But it links into your bank account. That's why I don't like them. I have a friend that's been pushing me. Oh, this happens. Great. It saves you so much money on gas.

    [00:58:15] Look at how much money I've saved any. He sent a screenshot of it and I re I went online and had a look. And guess what? I read, reviews it again, like this tied into her bank account directly. And. What can happen? Like here, everything was emptied. So in the next few months this author of the story and her father tried to undo the damage.

    [00:58:40] Very frustrating, getting scanned of course, is really dehumanizing and it just breaks your trust and other people. How could someone do something like that? It's just incredible. Got to go through the stages of grief and everything. She got a, she talked to people, she said she got chili half replies, or just as often silence.

    [00:59:05] And she was calling around trying to find someone for some empathy. Okay. It's just incredible. Great article. If you can still find it, the March issue of wired, I'm sure it's available online. This goes on. And talks about her mother's seizures getting worse. And of course now they don't have the cash that they had been saving.

    [00:59:27] And it just very depressing. Now I have this, you might remember about a year ago, I talked about it. I had something like this happen to a friend of mine and I'm still not quite sure what happened, but it looks like it was a password sprain or password stuffing. And they got into his, the app that his company uses to pay people and sure enough, they got in and they directed his next two paychecks to their own account, which went right out of the country like that.

    [01:00:05] These are bad people. And how do you deal with this? It's incredible because if you've got someone like her mother who has mental problems due to no fault of her own and is a very trusting woman, what do you do? She's walking around all day with her phone on her hip. That's how we started this out.

    [01:00:27] Do you take that phone away from him? Th that would be dangerous, frankly. So this is a very problem. They had a USAA account was her bank account. USAA is usually good about this sort of stuff. In fact, my other friend had USAA as well. But they did help deactivate Zelle, but they didn't do anything about the $999 that were transferred through it.

    [01:00:51] Very bad. So they figured out maybe we should change our passwords. She had them change them. And if you would like information about password managers, again, I'm not selling anything. I'd be glad to send them to you. If you sign up for my email list, you're going to get them automatically. Craig peterson.com.

    [01:01:11] I've got a bunch of data information I want in your hands. It talks about the free stuff, talks about the paid stuff. None of which I'm selling you. Craig Peter sohn.com. Sign up right there on the top of the page. Thanks. Stick around.

    [01:01:32] We've had some serious supply chain attacks over the last couple of years. And they have caused all kinds of problems for tens of thousands of businesses. If you use WordPress, there was one of those this week.

    [01:01:47] We have had supply chain problems. Like you wouldn't believe. So let's start out by explaining what is a supply chain problem?

    [01:01:58] In this case, we're narrowing it down to cybersecurity because we've had supply chain problems from everything from our toilet paper to the food we eat. But what I'm talking about right now is. Supply chains when it comes to cyber security. And one of the biggest problems we had was a company that's supposedly providing cyber security for businesses, right?

    [01:02:29] Some of the biggest businesses in the world. And I'm looking at an article right now from security Boulevard, say saying how to protect the supply chain from vulnerable third party code. It can be a script that's downloaded online. It can be an open source library. We've seen big problems with get hub lately and pulling in libraries.

    [01:02:51] We've seen big problems with what are called containers lately, which are little mini versions of computers with all of the software. They're all ready to go. Ready and raring to go. All kinds of supply chain issues for a very long time now. And these supply chain, cyber attacks have been hitting some of our cybersecurity companies, really the hardest I'm pulling this up on my screen right now, if you're watching this on rumble or on YouTube, and you can see links to those, by the way, in my emails, I send out every week.

    [01:03:28] Craig peterson.com. Craig peterson.com. But you can see here, supply chain hits cybersecurity hard supply chain security is not a problem. It's a predicament. That's uninteresting look because we have to use some of the supply chain stuff. Seesaw the FBI or a sheer wean cybersecurity advisories because of the Russian attack over on Ukraine.

    [01:03:55] And then the U S the weakest link in supply chain security fears of rising fuel SISA FBI NSA and gestural partners. Issue is advisories Toyota stops production after possible cyber attack at a supplier. Isn't that something this goes on and on. What's a guy to do, right? Many of us are using websites to, in order to run our businesses.

    [01:04:24] Heck we got websites for our soccer team, for the kids, we got websites for pretty much everything that's out there today and those websites need software in order to run. So the basic idea of the website is nowadays. Content management system, they called CMS CMSs and there have been a lot over the years.

    [01:04:46] I've used quite a few myself off and on. This is very interesting though, because this particular piece of. Is code that runs a website. I'm going to show you this article from ARS Technica here on the screen, but it's talking about millions of WordPress sites that got a forced update to patch critical plugin flaws.

    [01:05:13] So when we're talking about supply chain, in this case, we're talking about something. WordPress right. And this WordPress software as good as it is, can have bugs. So WordPress is the content management system. So you load stuff up into, in fact, I'll bring up my site right now. So I'm going to bring up the Craig peterson.com.

    [01:05:37] And on my site, I have all kinds of stuff, which is why it's so slow to load. I've got to fix that one of these days, but this is an example of a WordPress site. So you can see right at the top of the site, I've got watch this week, show jobs, or top, of course, that was last week. You can watch it on rumble or a new tube, and then it's got my latest show.

    [01:05:59] So if you click on one of these, here you go. And you can listen to it. Starts right out here. C ta-da. So there, you can listen to my podcast right there on the site, and I've got an automated transcript of it. It's for you, depending on what you want. It's got links over here to take you to iTunes or YouTube or Spotify or SoundCloud or iHeart or Google player audible.

    [01:06:26] All of these links take you to different places. And this site in survey, Program a site in HTML. What we're doing is we're working. Putting some data in, so we say, okay, I want a default page. Somebody else has already set it up. Somebody else has already got an old program. It just works. And it's all right there for me.

    [01:06:49] Here's some related posts on the side. Here's the most popular ones that we have right now. This is a content management system. And specifically this of course is WordPress. So what happened. If I had a, yeah. And here's what it looks like over an audible, you can listen for free on. This is what happened this last week, WordPress, which has this great software that I use and tens of thousands of others use out there very popular.

    [01:07:27] And in order to make it easy for me to have my website, probably your business, probably your kids' soccer club, you name it is using WordPress. It's just over the top hop healer. It is using code that was written by other people. The reason we can make programs so quickly nowadays is we're relying on other programs.

    [01:07:51] So we'll go ahead and we'll grab this program that does this part of what we need to have done, and ta-da we're up and we're running. I just have to write the glue right? To put it together. The API calls, whatever it might be, because the idea is let's make it easier for programmers. So you've got something called get hub here.

    [01:08:11] Let me pull it up so you can see that you can go online if you're following along. To get hub.com. And as it says right there on their front page where the world builds software as a beautiful world, isn't it? That blue, you can see the air around it. And that's what it's doing is where the world builds software.

    [01:08:33] So let's say we want something. What do we want? What's a, let's say we want something to make a chess program. We can talk about chess and let's say, oh, you have to. I Dan didn't want to do this, so I'm just going to skip that for now. But it would come up and tell me, okay here's all of the chess programs that are out there and I find one, that's close to what I want to do.

    [01:08:54] So what do I do? Point while I go ahead and have a look at the license, a lot of the programs up there have a very open license, so I can just take that code, modify it. And I have a chess program without having to write a chess. It's really that simple that's part of the supply chain. If you bought my chest program, you would actually not just be getting the code that I wrote, which is typically just glue code with maybe some API APIs or application programming interfaces.

    [01:09:25] In other words, you're using someone else's code would now make it who's program. It's like the Pharaoh's barge. It would make it other people's programs. Not my. So you got to figure out what's in my supply chain. I've got a new client. I do work as a virtual chief information security officer.

    [01:09:46] Actually, it's a fractional Cecil. And as a fractional Cecil, one of the things I have to do is look at the whole supply chain. Who are they buying even physical things from. And could there be. Did it into their software, into their systems, something that might be coming from yet another supplier. Man, does this get complicated?

    [01:10:09] Very fast, but this week, our friends at WordPress, they went ahead and forced all WordPress sites to update. Very good. Okay. Otherwise, people could have downloaded a full backup of the sites that are out there, something you really just don't want to happen. Anyways. Go right now, Craig Peter sohn.com while the bits are still hot and sign up right there.

    [01:10:36] Craig peterson.com for the newsletter and get those special reports that are going to get you started.

    [01:10:43] This is the moment you've been waiting for. We're going to talk about free cybersecurity services and tools that you can use. Now you have to be a little bit of a cybersecurity expert to use them, but not much. This is from the government.

    [01:10:59] This is I think an amazing thing. This only came out within the last few weeks.

    [01:11:07] I have it up on my screen. There we go right now, for those of you who are watching on rumble or YouTube, you can see it right there, free cybersecurity services and tools from. The cybersecurity and infrastructure security agency SISA reminds me of Marvel was shield, that really long name that came up with an acronym for as though they weren't aiming for that acronym in the first place, but there are some tools that you can use there's tools that I use as a cybersecurity professional.

    [01:11:42] And some of them are obviously going to be pretty darn. Complex. And if you're looking at my screen right now, or if you want to go online at csun.gov/free-cybersecurity-services, dash, and the as tools, or just look it up online, you'll find this on my website as well. I'm going to try and make sure I get that up.

    [01:12:07] But what they have done is they're showing you what they call their key or the known exploited vulnerabilities. Okay. And this is where they are showing the CVEs, which are. The frankly, these are the ones that I use. It is published by nest, which is the national institutes of standard and Sanders and technology.

    [01:12:31] And this gives all of the details. So this is CVE 20 21, 27. Okay, and this is detail, and of course I would be using detail. And it's telling you, here's the advisories, there's one from get hub Excel. Leon has one. Here's the weaknesses, the SA the known soccer configurations. So you can find where they all are at and everything.

    [01:12:56] So all of the details. So they're telling you about that. These are the ones, this was in the vendor product. Project, I should say. So we'll look at the data added to catalog. Here are a few in Cisco right now. So this is their small business series of routers, which we do not use for anyone because they don't provide the type of security you want, but Cisco is taking care of the problems, right?

    [01:13:23] Many of these update themselves, here's Microsoft windows. And installer contains an unexpected unspecified vulnerability, which allows for privilege escalation, a lot of stuff this week, this is crazy Apache Tomcat, which I am never been a fan of and problems. So all of these came out. On March 3rd and more rights.

    [01:13:47] This is just page one. So let's look at page two here. Oh wow. More Microsoft Excel exchange server, some more Cisco vulnerabilities. Why Cisco? Why Microsoft? Because they are frankly. The big boys on the block, that why do you Rob the bank? Because that's where the money is. So they list all of those right here, as he said, does the warning you do use multifactor authentication?

    [01:14:16] I don't want to sound like a broken record, so I'm not going to say use multifactor authentication today. Okay. I just refuse to say use multi-factor authentication. And this one talks about what it is, right? Many names. Now they're trying to make this. But really a Fido key fast at any online considered the gold standard or multi-factor authentication Walt for online.

    [01:14:40] It is websites, but not for authors. So how would you know that if you weren't an expert? So yeah, this is the government talking, right? So they have the service. So what does, what do I do right? Me, Mr. Idiot. I click on this and they are talking about the service that they've got them showing it up on the screen.

    [01:15:02] It's called SISA insight. And they're talking about website, defacement, destructive malware, or not Petya want to cry, right? All these things. What can you do to prevent it? And. They make it sound easy. Now I want to say something here because I, I have a couple of mastermind groups and in one of my groups, I rescued a group member from a 40 something thousand dollar loss.

    [01:15:31] And so I was explaining it in our next mastermind meeting. Cause everyone wanted to know. What should I do? How should I do it? And they all tuned out and I thought I was trying to, I was being simple enough. I was trying to be simple, not like simple Kamala Harris explaining that Ukraine is a country beside right next to another country called Russia.

    [01:15:55] And that's why there's an invasion. Okay. I couldn't believe that. Did you guys hear that? It was just incredible, but I didn't get that simple. And I know you guys are the best and brightest, and you're trying to figure this, all this stuff all out, and that's why you need to make sure you sign up for my email list right now, because I do have simple step-by-step stuff.

    [01:16:17] And these tools that they're talking about and services are supposedly available. Now, I went to a bunch of these. And I tried to get some services. So they said they'll do a free scan over the network. So I filled it all out and according to their standards, my company, because I do cybersecurity for everything from government contractors, through dentists and manufacturers and distribution companies.

    [01:16:50] So I, I. The critical infrastructure definition. And I have never heard back from them. I check my spam box at least once a week looking for their reply. So I don't hold up a whole lot of hope, but there is some good information here that you can get email via social media via just all of these different types of things that.

    [01:17:15] You could use for it. And again, I want you to look for it online. It's on csun.gov. If you go to their homepage, you'll see their tools, they've got a shields up a warning right now on their homepage because there have been so many attacks coming from China and coming from Russia, but particularly Russia.

    [01:17:34] And you can see there. Stop ransomware.gov, which has some great tips, particularly for home users and small businesses. The Seesaw culture, height, hygiene services. That they have doing business with CSUN and careers they're looking forward to is okay. It's part of Homeland security. So there's a whole lot that you can do and you can find, but I wanted to let you guys know that this is out there.

    [01:18:04] A lot of the stuff guaranteed is going to be. Above 98% of people's heads out there. Just in general, even it professionals. So look for information, that's going to help you. That's on your level. And to that end we have right now, three things. If you sign up for the email list, or if you're already on my email list, you can just email.

    [01:18:30] [email protected] or just hit reply to any of my emails and I'll see it and ask for them. But we've got stuff on your computer, keeping it secure, keeping your password secure comparison between using a one password manager or using last pass, which I am not advising to use right now, but that's in there.

    [01:18:54] There are a lot of different things that are there that are ready for you to get right away. And then if you have other questions, I've got dozens of little special reports that I've written in response to people's questions. Don't be afraid to send them to me. I'd you know [email protected] and I'll make sure I get you an answer because it's that important.

    [01:19:20] Okay. I'm not here trying to sell you something. I am here because most of you guys can could never get my services. You don't need them. You can't afford them, whatever. I'm a fractional Cecil. I'm one of the guys that keep. It was a cyber security working in a live for businesses. Like it's not going to be everybody, but it's, it is there is, I should say a lot of information you guys need and need to understand, and I want to help you. Okay. I think I've beaten that horse enough and it was probably past dead, but you'll find some of this stuff on my [email protected].

    [01:19:58] I've been working on some other changes to it. I would also ask you guys. If you're hearing part of the show today, I know a lot of people who are listening on the radio are tend to be out and about in their cars, listening, on the weekend, I listened to a lot of radio then, but go ahead and subscribe to either my podcast.

    [01:20:19] And there are a lot of ways to do that. And I showed those people who are watching on video, how to do that. And if you would give me a five star. On whatever platform you're using, hopefully I've earned that. And then also if you'd like video, I have my whole show up. It's like about an hour and a half long on multiple platforms.

    [01:20:44] So rumble.com rumble, R U M B L E. Is a competitor to YouTube. So if you don't like censorship, if you want a site that is trying to keep that information out there, get it out there for you. A rumble is your place. You'll find all kinds of interesting characters there other than myself, right? A lot of conservative people go there to rumble.com.

    [01:21:09] I have it up on YouTube. Because YouTube, isn't the worst platform in the world. They're also not the best, but they are the biggest. Did you know, YouTube is the second largest search engine in the world. Okay. They have a lot of people on YouTube and then on Facebook as well. You'll find me there on Facebook.

    [01:21:28] Of course, Craig Peterson, I had. I excuse me at facebook.com/craig Peterson. And I didn't use it for a long time cause I hated Facebook. Just, I looked at it as a time sink that I just didn't need. I got a lot of stuff. I got a lot of people help and so I didn't really do anything with it. And so somebody else got the slash Craig Peterson, but I do have a trick for you.

    [01:21:52] If you go online with your web browser to Craig peterson.com. That's my website slash. YouTube. It'll take you right to my YouTube page. Ores Craig peterson.com/facebook. Yes. What do your Facebook page? Craig peterson.com/itunes. Good slash sound cloud, et cetera. It'll take you right to my page on all of those sites and have a look at the video.

    [01:22:21] Let me know what you think. I would appreciate that feedback and make sure you tune in on the radio too. It's great. Don't watch this while you're driving to taking the kids to school, a lot of people listen to this while they're taking the kids to school on podcast. Anyways, take care. Thanks for being with us.

    1 hr 23 min
  • Are You Ready For Data Wiping Attacks?

    Are You Ready For Data Wiping Attacks?

    Yet another warning coming out from the federal government about cyber security. And this one is based on what's been happening in Ukraine. So we're going to talk about that situation, the whole cyber security over there and why it's coming here.

    [Automated transcript follows]

    CISA is the cybersecurity and infrastructure security agency. How's that for a name it's not as bad as what does that shield right over from the Marvel universe, but the cybersecurity and infrastructure security agency is the agency that was created to not just protect federal government systems, although they are providing information for.

    [00:00:41] People who protect those systems, but also for businesses and you and me and our homes. So they keep an eye on what's happening, what the various companies out there are finding, because most of the cybersecurity information that we get is from private companies and they. But it altogether, put it in a nice little wrapping paper.

    [00:01:05] In fact, you can go onto their website anytime that you'd like to, and find all kinds of stuff that is going to help you out. They've got a ton of documents that you can download for free little steps that you can take. It's at csun.gov, C I S a.gov. And they've got the known exploited vulnerabilities catalog.

    [00:01:30] That's something that we keep up to date on to help make sure our clients are staying ahead of the game. They've also got their review board securing public gatherings. They also run the stop ransomware.gov site that you might want to check out. And we'll be talking a little bit more about ransomware and the ways to protect yourself a little later today.

    [00:01:52] Now Seesaw is interesting too, because when they are releasing information, most Americans really aren't aware that they even exist. They do. And they've got a big warning for us this week. There's a site that I follow called bleeping computer that you might want to keep an eye on and they have.

    [00:02:15] I'll report just out this week that you, crane government agencies and corporate entities were being attacked. This was a coordinated cyber attack last Friday, a week ago, where websites were defaced data wiping malware was deployed and causing all of these systems to become not just a corrupt, but some of these windows devices to be completely.

    [00:02:45] Operable now that is a bad thing. The reason for this, this is speculation, but it isn't a whole lot of speculation. Right? Am I getting out of, on a limb here particularly, but the whole idea behind this is a cyber war, that Russia's got, what is it now? 130,000 troops, whatever it is over a hundred thousand.

    [00:03:08] On the border of Ukraine, they invaded Ukraine a few years ago. Russians shot down a passenger airline in Ukrainian air space. This that was a few years back. They've been doing all kinds of nastiness to those poor Ukrainians. They also had a massive ransomware attack in Ukraine. That was aimed at their tax software.

    [00:03:35] Some countries do the electronic filing thing a lot differently than the us does. A couple of examples are Ukraine. France is another one that comes to mind. We have clients in France that we've had to help with cyber safety. And we're always getting popups about major security problems in the tax software, because they have to use this software that's provided by the French government.

    [00:04:03] Ukraine's kind of the same way. The biggest. Company providing and the tax filing software for Ukraine was hacked and they use that hack to then get into the tech software and make it so that when that software was run by these Ukrainian companies, they would get ransomware. It was really rather nasty.

    [00:04:30] So the Russians had been playing games over in Ukraine for quite a while. But what's apparently happened now, is that a thing? Those things, same things are coming our way now. It's not just because of the fact that a Ukraine is being threatened, maybe they're going to encroach even more, take more than Crimea, which they did last time.

    [00:04:56] We're in the U S and what are we doing? President? Biden's been sending troops to Europe, troops to Poland, Germany, and also advisors to the Ukraine. He's removed the embassy staff, at least the vast majority of it from Ukraine. And I just I think. To what happened with his completely unplanned withdrawal that we did in Afghanistan and how things just got really bad there.

    [00:05:28] And I'm not worried about what's going to happen in Ukraine because the Russians aren't particularly fond of the idea that we are sending aid and support to. Yeah, it's a bad thing. President Obama sent them blankets, but Biden is sending them military weapons and ordinance, which is what they'd need to fight.

    [00:05:53] So Russia has shown that they will attack a country via electronic means cyber means, right? Cyber attacks. And so what's happening now is the bad guys from. That have been the facing websites and who have been doing more than that, wiping computers and making them completely unusable could well come after us because they're really going to be upset with what's happening now.

    [00:06:27] And that was CNN has reported the Ukrainian it services company that helped develop many of these sites was also a big. And of course that means bottom line, that this is what's called a supply chain attack. What I mentioned earlier with the Ukrainian tax software, that's a supply chain attack where you are buying that software, or you're mandated to use the software to file your taxes by the government.

    [00:06:57] And what happens while it turns out that software is contaminated, that's called a supply chain attack. Now crane issued a press release about a week ago, saying that the entities were hit by both attacks, leading them to believe that they were coordinated. This is a quote here. Thus, it can be argued with high probability that the interface.

    [00:07:24] Of websites have attacked government agencies and destruction of data by Viper are part of a cyber attacking, but causing as much damage to the infrastructure of state electronic resource that's from the Ukrainian government, not the best English, but their English is much better than my Ukrainian or Russian.

    [00:07:44] So you, crane is blaming these attacks on Russia, incomes, CS. So you says now urgent. Business people in the us and other organizations to take some specific steps. So quote, here from the Seesaw insights bulletin, the CSO insights is intended to ensure that senior leaders at the top of every organizational where the cyber risks and take urgent near term steps to reduce the likelihood and impact of a potentially damaging compromise.

    [00:08:19] All organizations, regardless of the sector or side should immediately implement the steps outlined below. So here's the steps and there are a lot of them. One I'm going to do these, you should find in your newsletter today. Hopefully that all made it in. But three basic things. One reduce the likelihood of a damaging cyber intrusion.

    [00:08:46] And we're going to talk about the best way to do backups here a little later on today. Make sure your software is up to date. Make sure your organization's it personnel disabled, all ports and protocols, not essential for business purposes. This is all basic stuff, but I got to say. I bet you, 98% of businesses and organizations, haven't done these things.

    [00:09:07] The next major category here, take steps to quickly detect a potential intrusion, and then ultimately maximize the organizations resilient to destructive. Incident. So that means doing things like testing your backup procedure, make sure your data can be restored rapidly, or you have a way to get your business back online quickly.

    [00:09:31] What we tend to do is in our backup strategy, depending on how much the company can afford, to be down. To be out of business if they lose all of their stock versus what it costs to do this, but we will put a server on site at the company and that server then does some of the backups, right? It does all of the initial backups.

    [00:09:55] And then what happens is it gets relayed to us. It gets pushed to tape and tape is really good. We'll talk about that in just a few minutes, but the other big thing is. The backup that we have local to their business also has what's called a virtual machine infrastructure built on it. So if a machine goes down, If it gets wiped or if it just crashes and can't be recovered easily, we can spin up that machine.

    [00:10:27] A copy of it in our little virtual environment in just a matter of minutes. So these are all things you should be considering. If you're interested, you can send an email to [email protected]. I can send you a checklist that a little more extensive than this, or I can help you with any other questions you have.

    [00:10:47] I get lots of questions every week from everything for on retirees, wondering what they should do all the way through businesses that we help government contractors and others. This isn't good. Russia is likely coming after us. Based on this. Visit me online. Craig peterson.com or email [email protected] with your questions.

    [00:11:14] With all of this talk about hackers, ransomware data, wiping systems. What's the best way to protect yourself, but what do you do to really protect against ransomware? I can tell you, it's not just plugging another hard disk into do backup.

    [00:11:31] We've got so many hackers out there. We're talking about a multi-billion dollar industry to go after us.

    [00:11:39] It's just depressing. Really. When you think about it, I think about the old days where security, wasn't a huge concern, right? Physical security. I had one of my first jobs was at a bank and I was, this was back way back in the a G it would have been the mid seventies and I was one of the operators of the main.

    [00:12:05] And so as a mainframe operator, we'd load up the tapes and we would ship them places. We'd also go ahead and put them in the vault so that they were in a fireproof vault, and we could recover anything we needed to recover. It worked out pretty darn well, and it was a fun job, but most of the time it was cleaning the tape drive heads and taking those tapes, those big round tapes, you might remember those.

    [00:12:33] Nine track tapes and maybe the fancy stuff, 52 50 BPI or 800 BPI of one end or the other, or the spectrum. And we just had to make sure they were physically safe nowadays of course, mainframes are still around and are still absolutely fantastic. They're just phenomenal. Some of the technology IBM has in their mainframes.

    [00:12:59] Most of us, aren't using those. Most of us are using a regular computer or I'm sitting in front of a Mac right now that I use for the radio show. We have windows, computers, Linux machines, right? All of those things that we have in our business and that we maintain securely for our clients. But what do you do when we're talking about random?

    [00:13:23] You can cross your fingers and hope that you'd hope you don't get ransomed. That sort of a practice doesn't usually work out too well for people, but you can do backups and many people do. So let's talk about the backups. Let's say that you have your computer and you're doing a backup and you have one or two generations worth of backups for your company.

    [00:13:47] Ransomware nowadays does not just typically destroy your whole disk. Usually what it does is it encrypts files like doc files, doc X, right? Excel files, all kinds of files that thinks might be useful to you. And then of course, the rest, it pops up says, pay me. And off you go. The reason for that is so your computer still works so that you can enter in the decryption code.

    [00:14:18] Once you've paid the ransom, hopefully it works for you give or take 50% of the time. You will get your data back. If you pay the ransom much of the time. But let's go back to that one or two generations of backup. You're using a cloud service, let's say, and your computer gets ransomware. That cloud service backup software will still work.

    [00:14:43] What if it's working? So you're now backing up your encrypted files to the backup site in the cloud. Do you see where I'm going with this? Your backups? No. Same thing is true. If you're backing up to a local hard disk, many people do it and it's handy. I recommend that you do that, but it's not all you should do.

    [00:15:08] So that disc is attached. We had a. Boy, who was it here? Yeah, we have a client in Maine and they have a really smart system administrator and he designed these disk drives that would physically disconnect themselves from a machine when the backup was not running and would physically connect themselves when the backup.

    [00:15:34] Was running. So the idea there was okay, great. We've got a local backup on a local disk and if the bad guys managed to get a hold of the machine, they're not going to be able to encrypt the. And, as long as the backup isn't running, I thought that was a brilliant solution. Doesn't solve some problems, but it certainly takes care of some others.

    [00:15:58] So if you are doing a backup, you've got to make sure you've got multi generations. I tend to keep a year's worth. Now there's other considerations. There's the federal rules of. Procedures that say you have to have bad cops. They have to go back years. And there are also other things the payment card industry requires certain types of backups.

    [00:16:25] If you are a government contract, We have them as clients and they have certain data retention policies based on the length of the contract. They have keep it for some years afterwards. It goes on and on. So if your data is lost or stolen or encrypted, and your backup is encrypted or deleted, You are in real trouble depending on the type of business you're in.

    [00:16:56] So what's the right answer to this. I've talked about 3, 2, 1 backup for a long time, and it's still a very good methodology for doing backups, but nowadays they're talking about 3, 2, 1, 1 backup, which is again, that's a bit of a different methodology. In doing backups, but the idea is you've got multiple copies of your data on multiple types of media in multiple places.

    [00:17:29] That's the bottom line. What is the gold standard for this? I it's something that gets to be a little expensive. Again, we have another client that we've had for years, and they are looking for a replacement for the backup system. Now. And so we proposed something that's based on what's called LTO technology, which is a type of a tape drive.

    [00:17:55] It's a small cassette, right? It's not those big 12 inch reels of tape that we used to lug around and it's amazingly dance. The new LTO tape drives have space on them for as much as 45. Terabytes of information. It's also great because it's encrypted by hardware, government level encryption automatically, and those tapes can be taken offline.

    [00:18:25] You can take the tape. Now we picked up a client who had been doing backups and they were using little USB drives and every day he'd take the drive home and bring in the next drive. So he had five drives, right? So he had the drive for Monday, Tuesday, Wednesday, Thursday, Friday. And he was taking them home, but he missed one of the key things to check the back.

    [00:18:53] He hadn't checked the backup and their backup had not been running for more than a year and a half. So that's the other thing you have to do? The LTO tapes are really the gold standard. It goes back to that for one of the first jobs of mine, right? The job I mentioned, where I was mounting tapes and filing them and moving them around and mountain disc packs and pulling them out and everything.

    [00:19:19] It still makes sense. They'll last for decades, they cannot be hacked because they are literally offline. You can ship them to places to have them stored. I have a course on backups and if you're really interested, send me a an email to [email protected]. And I'll go ahead and. Send you a link to the course, you can watch it.

    [00:19:48] But yeah, I think this is really important. Of course, I'm not going to charge you for that, but magnetic tape it's established. It's understood. It's proven it's been around for many decades and LTO tape is unique. It needs all five best practices for addressing ransomware. Even be able to recover.

    [00:20:12] If you want more information, just email [email protected] or sign up for my free newsletter. Craig peterson.com.

    [00:20:22] Switching from gasoline powered engines to these new electric cars is no environmental panacea. At least that's what West Virginia university is saying. And the E. Just changed its mind as well.

    [00:20:38] Ford of course, about a year ago, unveiled its new electric.

    [00:20:43] F-150 the lightning and Ford has stopped taking orders for them because they are going to have to make double what they thought they would have to make. Ford also has a similar problem with yet another electric vehicle. The Mustang GM is doing a few different electric. Coles. And so is everybody else, frankly, Porsche even now has an electric car out.

    [00:21:11] That is all well and good. Isn't it. And there's certainly problems, particularly with manufacturing nowadays, trying to get the CPU's and other electronic components you need. They're even having trouble getting electric motors for electric windows in vehicles. Now they're coming. Crank window with a little coupon saying later on, we'll convert it to electric for you all kinds of problems, but there's one that I haven't heard anybody but myself talk about.

    [00:21:44] And so I was online looking around, doing some searches, seeing if I was, like the only one there's no way right now, I'm not the smartest person in the world. I don't pay the most attention to everything. And I found that. Virginia university is in total agreement with that with me, it's just amazing.

    [00:22:06] They looked at recent trends and they're cautioning as I have been for years, at least a decade. Now they're cautioning about what seems to be a race to put more electric vehicles. On the road. And the problem is that these electric vehicles in their demand for electricity may well out, run what's needed to keep the vehicles on the road.

    [00:22:35] So here's a quote from them. The electric grid will struggle to handle the quick charging of very many electric vehicles at the same time. Okay yeah, by the way, like hardly any quick charging is generally what everyone thinks about, like going to the gas station, getting a full charge in 10 to 15 minutes, which would be a tremendous instantaneous load on the local distribution center.

    [00:23:03] My concern is the huge power dumps required at quick charging stations along the interstate. It sounds good, but it'll require a lot of new infrastructure to get the power to the charging stations, as well as building those charging stations. So where does the power come from? Power storage is going to be required if we're going to also move towards fixing.

    [00:23:28] Power sources such as solar and wind. We do not have power storage capability yet in large enough quantities to do this on a large scale. Solar does not work at night. The wind doesn't blow all the time. Also, we do not have the distribution on the streets to move fast charging into residential neighborhoods on mass.

    [00:23:52] Electric vehicles are great, but we have not fully considered the impact it'll have on our electrical grid infrastructure. It will require a lot of expansion of our electrical distribution and charging facilities. Remember, electric power comes from the power company. I heard an interview with a lady the other day, and they asked her, where does the electricity come?

    [00:24:15] She said, From the plugin, the wall, right? We must consider this when considering wide-scale electric vehicle adoption, much as there is to gain from electric vehicles. I don't believe we're ready yet as a society for completely electrical vehicle transportation system. With time and infrastructure development, we can be.

    [00:24:37] I totally agree. This is Rory Nutter, professor lane, department of computer science, electrical engineering, Benjamin M. Slater, college of engineering and mineral resources. I totally agree with that. We don't have the ability to generate the electricity. We don't have the ability to store the excess electricity.

    [00:25:01] So in other words, if we're using solar at nighttime, we don't have the sun, we can't run solar. So we got to store the solar. And in fact, we have to make about twice as much electricity as we need during the day so that if we can store it, we can then use it in. The same thing with wind, right? It's fickle.

    [00:25:24] It just doesn't work that well. So what do we need? Basically right now, we need to stop turning off our coal powered plants, our natural gas plans and our nuclear plant. Because we need to still have electricity. Look at what's happened last year. And this year over in Europe with the crazy cutbacks that they've been doing on some of these plants, coal nowadays with the scrubbers that are on our cold powered, flat plant is clean energy.

    [00:25:58] It's not like the old days where you lived on the south side of the tracks and you got all of the wind blowing towards you that had all of that nasty cold ass. You ever seen any of those pictures? It was just terrible. All of that nasty sitcom. It's not something we need to worry about nowadays.

    [00:26:16] The other big thing that ties into all of this is so how do we generate our electricity cleanly? A hundred percent cleanly? Nothing. Per cent, but just a couple of weeks ago, the European commission presented their 27 members states with new draft rules that classified natural gas and nuclear power as green fuels for electricity generation.

    [00:26:47] Listen, if we want electric cars, which as we've talked about before are highly polluting. Yes. Because of the materials in them, because of the materials that go into the batteries, having to mine it, having to ship it, having to process it and then having to change out those battery packs after 80,000 or a hundred thousand miles.

    [00:27:09] Did you see this guy? There was a meme in the video about this online a few weeks ago. How to test. His Tesla needed a battery replacement. It would cost him, I can't remember what it was. 20, $30,000. A lot of money. So he decided to just blow up the car. That's all it took. I saw another Tesla that had water damage.

    [00:27:33] From, being down in new Orleans or somewhere, the flooding occurred. And the guy bought that Tesla because Tesla won't sell the parts to fix the car after the water damage. And so he ripped out the batteries, ripped out the electric motors and he bought a high power engine. And gasoline and put it into the Tesla and made really, quite a very cool car.

    [00:28:00] You can find it online if you want to look for that, it's quite cool. What they ended up doing. It took us quite a while to do it, but they did it. So now that we're seeing. That nuclear is green. Let's talk about why we've been so afraid of nuclear. One of the biggest problems of course is so what do you do with all of the waste?

    [00:28:20] And that's a legitimate question, but what you're really talking about when you ask that question are the reactors that went online 50 years ago, or that were approved 50 years ago because of the regulations. There are. These nuclear plants that have been provisioned in the last 20 years that are still using that old technology.

    [00:28:43] So when we get back, we're going to talk about this more. What about the waste? What our fourth generation nuclear power plants, how safe are they when they say they're intrinsically safe? What does that mean? And how and why? Because I'm predicting to this point that we're going to have to switch back to nuclear and even the European union, if you can believe it agrees with.

    [00:29:13] Hey, make sure you take a minute. Go online. Craig peterson.com. Subscribe to my free newsletter. You can get it right there. I send you out stuff every week. And this week is no exception. We've got a bunch of bullet points that if you are in a business position, you got to protect yourself immediately. So I tell you how Craig peterson.com.

    [00:29:38] So what are these new rules for nuclear energy? And why is it absolutely necessary that we do something like this? Get fourth generation nuclear online. If we can even consider electric vehicles on our roads.

    [00:29:55] Things have changed in the European union. They've been trying to figure out how they're gonna handle all of these electric vehicles, how they're going to properly handle all of the solar cells and the wind turbines.

    [00:30:09] And there's even some work over in the EU. To get the tide to generate electricity, some very cool stuff. Actually, that's been done, I love tech and I'm into all of this stuff, frankly. I think we should be doing a lot of it. What I don't think we should be doing. Is getting ahead of ourselves. And unfortunately that's really what's being going on.

    [00:30:35] We don't have a grid that can really use the electricity that we can generate from our windmills, from our solar cells, from anything, frankly. And we cannot. All of that electricity that we might be generating and somehow have that electricity be stored and used distributed appropriately to our charging station.

    [00:31:03] And our grid was built and designed to have a few central point where the electricity is made, where it's generated and then distributed to some pretty specific types of things like housing, development, businesses, et cetera. You can't just go ahead and open a big business man. in a residential area.

    [00:31:25] And part of the reason for that is the grid isn't set up for it. You don't have three phase power going into residential areas or even more than that, you don't have the high voltage, the high current, et cetera. So how are you going to be able to quick charge electric cars in the regular residential neighborhoods?

    [00:31:47] I w how about at a hotel? Yeah. Okay. A hotel is probably. Multiple phases and has a fair amount of power there, but the amount of strain that's put on the grid by trying to just rapid charge a single car is huge. So how can we deal with that as well? The quickest and easiest way to deal with it is just put more large power plants online.

    [00:32:13] Some people don't like that. Don't like that idea at all, frankly, but we're not ready. What are we going to do? Look at what happened in Texas with a fairly minor reliability or re reliance, I should say, on these windmills last winter and things with this winter, as cold as it's been, that could really cause some just incredible problems.

    [00:32:40] Nuclear is being reconsidered, particularly fourth generation nuclear power plants. The greenhouse gas emissions from nuclear power are one 700th of those of coal. The nuclear power plants produce one, 400th greenhouse gas emissions of a gas plant, and they produce a quarter of the greenhouse gas emissions from solar.

    [00:33:09] Now you're saying, Hey Craig, come on, I get it. Wait a minute, solar, how can solar produce greenhouse gas? It does. And it produces greenhouse gases because of the manufacturing processes, as well as of course it off gases. So how do we make all of this stuff work? We all saw the China syndrome and we heard from experts like Jane Fonda, how we would all die.

    [00:33:34] If we put a nuclear power plant. These are intrinsically safe, power plants much different than they used to be. Nuclear power frankly is a much safer business than most people think it is. They no longer these new plants produce. The the nastiest what's called high level nuclear waste.

    [00:34:00] They can reprocess it right there in the plant. They can start in fact where some of the nuclear waste though has been generated from the older nuclear plants and get rid of that. It's amazing. So people are asking okay. Plutonium might have a half-life of 24,000 years, but it doesn't emit much radiation.

    [00:34:23] We get that. How about the higher levels of radiation? Because some of it can last for hundreds of thousands of years. According to the U S radiation expert, Robert Gale for every terawatt hour of electricity produced nuclear energy is 10. To 100 times safer than coal or gas. What it does emit are alpha particles, which do not even penetrate human skin.

    [00:34:54] They've done all kinds of risk assessments and tried to figure out what's going to happen. What can we do? And I'm not going get into all the details here, but it is intrinsically safe because. What really happens is that the, these new plants he's fourth generation, a newer plant are instead of using water, for instance, that can do reactors out of Canada, use heavy water in order to cool those rods.

    [00:35:25] It was same sort of thing we've had in the meltdowns before they're using a liquid silica inside. They're set up in such a way that they do not need to have pumps running. So the Fukushima reactor that you might remember in Japan that failed because of the tsunami and the fact that one fact, this is what was their killer that their electrical generation from the diesel generators went offline.

    [00:35:56] Why did it go offline? Oh, I can see the grid going offline, but how about a diesel generator? If you have a below sealer, And the water comes in. You're in big trouble now. They didn't have it like below, permanently below sea level and Fukushima. But when that tsunami wave came in, it was below sea level.

    [00:36:16] They just, man, we could talk for a long time about the problems that they had over there. The nepotism, the line on the forums. They fact they did not do the upgrades that the manufacturer has suggested on and on. So these new reactors can lose all power and you won't have a China store. They won't go through a meltdown and they're even designed in such a way, the way using physics things called the law of gravity, who would have thought, right?

    [00:36:51] So that what happens in the worst case scenario is no one gets hurt. It just eats in on itself and then stops runs out of. So we've got to remember all of this stuff. Okay. The nuclear power of yesteryear is not the nuclear power of today. And the nuclear power of today is so green and so safe that even the European commission presented new draft rules that said to the natural gas, nuclear power, our agreement.

    [00:37:29] Fuels for electricity generation. So assuming the rules are approved and Francis in favor, Germany isn't as into nuclear power. In fact, they plan on having all of their plants shut off by the end of 2025, which is crazy because they're already having serious problems with their solar and wind.

    [00:37:53] And that's why they're buying so much natural gas now for. Yeah, American influence dropping over there. Thank you again, president Biden for allowing that pipeline to go through. All right. Anyhow. They're assuming they're approved Germany. Apparently isn't likely to try and block these rules. It means that nuclear, the new nuclear force generation or newer is going to be right there alongside renewables, like wind and solar on the list of the EUS technology that are approved for financial support.

    [00:38:30] Now, this is very good news because as I mentioned earlier, What happens when it comes to solar at nighttime doesn't work solar. When it's raining, doesn't work solar. When it's snowing, doesn't work solar. When it's cloudy, doesn't work. Ryan, how about the windmills? When the wind is. They don't work when they break down, which happens a lot due to mechanical failures, they don't work.

    [00:39:02] So having the. New nuclear plants that are intrinsically safe, that don't generate this really nasty radiation, and stuff that we have to store for a thousand years, et cetera. The high level nuclear waste makes a lot of sense because unlike the. Solar plants or other things that might be on someone's house that cannot be easily controlled by the central grid.

    [00:39:32] In other words, Hey, stop generating electricity because I got enough right now. And what Germany has been doing is putting it into heat sinks, heating up lakes and other things, to get rid of that extra solar energy people are generating on their homes and businesses. What you can do is, Hey, we are at the point where we don't have enough sun.

    [00:39:54] It's really cold. People are trying to heat their homes, or it's really hot. People are trying to cool to their homes. And yet it's raining heavily or there's a lot of clouds. So all you have to do at that point is turn off. That nuclear power plant or multiple plants. You see the way it's going.

    [00:40:12] You're not going to have some massive plant with a bunch of reactors. No. Where they're going with this is to have community reactors in the multi megawatt range that can be put into communities and the power distributed directly. Into the community and these power plants are good for 20 years and these new ones, they are typically going to be buried in the.

    [00:40:41] And then every 20 years they get dug up, put onto a truck, shipped off, they get recharged, brought back and you're off and running again, a whole different concept. And I love it. We're starting to do this in the United States. We've got some early approvals for some of these, and I was shocked and amazed and happy that the Biden administration has decided.

    [00:41:06] To approve the new nuclear here in the United States. So there'll be some test plants going online relatively soon. That just makes so much sense. These 50 year old nuclear red regulations and plants, they just don't work. Make sure you visit me online. Craig peterson.com. I'm going to have a lot of stuff for you every week.

    [00:41:32] Craig peterson.com.

    [00:41:37] The hacker world got turned upside down this past week as Russian president Putin decided to crack down on the hackers. Now, this is a very big change for Russia. We're going to talk about my theories. Why did this happen?

    [00:41:54] As we keep you up to date, russian hackers have long been known to go after basically whoever they want. They have really gone after the United States and other Western company countries.

    [00:42:10] And as part of what they've been doing, they have been making a lot of money and keeping Vladimir Putin pretty darn happy. He's been a happy because they're bringing more. Into mother Russia, he's happy because they are causing confusion amongst Russia's competitors out there, particularly the United States.

    [00:42:35] But there's one thing that Putin has been absolutely steadfast. And that is not allowing any of the hackers to go and hack any of the countries that are part of their little pact over there. Think of the old Warsaw pack they got that band back together. So as long as they didn't harm any Russian or, a affiliated country, They could do basically whatever they wanted and they did.

    [00:43:09] And they have caused a lot of trouble all over the world. So Friday Russia. As security agency announced that it had arrested members of the cyber gang called reveal. Now we have talked about them for a long time. They have come and gone. The FBI and other countries have shut down their servers.

    [00:43:37] So reveal disappears for awhile. Then pops his head up again. And Russia said that they arrested members of revival who were responsible for massive ransomware crimes against us companies the last year. So why would they do that? I'm looking right now at the Russian website here, that's part of the FSB.

    [00:44:06] And it's saying that the Russian federal security service in cooperation, the investigation department of the ministry of internal affairs of Russia in the cities of Moscow St. Petersburg, Leningrad lips. As, I guess it is regions. They stop the illegal activities, a members of an organized criminal community and the basis for the search activities was the appeal of competent U S authorities who reported on the leader of the criminal community and his involvement in an encroachment on the information, sir, resources of foreign high tech companies by drusen militia software, encrypting information and extorting money for its decreased.

    [00:44:52] Now that all sounds like the stuff that Vlad has been just a happy about in years past. So why did this happen? What brought this about nowadays in this day and age? What is he doing? I've got a little bit of a theory on that one because there have been some interesting development. One of them is this hacker.

    [00:45:19] In Belarus. Now, Belarus is one of those countries that's closely affiliated with Russia friend of Russia, right? Part of the old Warsaw pact. And you might remember that Bella ruse is right there by you. And of course, we've got this whole issue with Ukraine and whether or not Russia is going to invade president and Biden said something incredibly stupid where he said, yeah a moral response is going to depend upon what Russia does, if it's just a minor invasion.

    [00:45:57] You're you remember? The president Biden's saying that just absolutely ridiculous. And then of course, the white house press secretary and various Democrat operatives tried to walk the whole thing back, but it's a problem because Russia has, what is it now like 120,000 troops on the border.

    [00:46:17] Now, if you know anything about history, you know that the military army. March on their stomachs, right? Isn't that the expression you've got to feed them. You have to have a lot of logistics in place. In fact, that's what really got a lot of the German military in world war two. Very nervous because they saw how good our logistics were, how good our supply chain was.

    [00:46:43] We were even sending them. They cakes to men in the field that they discovered these cakes in great shape. And some of the German armies, particularly later in the war, didn't even have adequate food to eat. What do you think is happening with the Russian troops that are sitting there?

    [00:47:01] They need food. They need supplies, including things like tanks, heavy artillery, ammunition. All of that sort of stuff. So how do they do that? They're moving it on rail, which they have done in Russia for a very long time. You might remember as well in world war II, the problems with the in compatibility between the German rail gauge and the Russian rail gauge as Germany tried to move their supplies on Russian rails and Soviet rails, ultimately, but on Russian rails and just wasn't able to do.

    [00:47:37] So hacktivists in Bella ruse right there next to Ukraine said that they had infected the network of Bella Russa's state run railroad system with ransomware and would provide the decryption key. Only if Bella Reuss president stopped. Russian troops ahead of a possible invasion of Ukraine. So this group, they call themselves cyber partisans wrote on telegram.

    [00:48:11] Now I got to warn everybody. Telegram is one of the worst places to post something. If you want some privacy, excuse me, some privacy, some security it's really bad. Okay. No two questions. So they have, apparently this is according to what they wrote on telegram. They have destroyed the backups as part of the pec low cyber campaign.

    [00:48:36] They've encrypted the bulk of the servers, databases and work station. Of the Belarus railroad, dozens of databases have been attacked, including, and they name a bunch of the databases. Automation and security systems were deliberately not affected by a cyber attack in order to avoid emergency situations.

    [00:49:00] They also said in a direct message that this campaign is targeting specific entities and government run companies with the goal of pressuring the Belarus government to release political prisoners. And stop Russian troops from entering Bellaruse to use its ground for the attacks on Ukraine. Now, this is frankly fascinating from a number of different angles.

    [00:49:26] One is, it is very easy nowadays to become a cyber hacker. And in fact, it's so easy. You don't even have to do anything other than send N E. And it's been done, frankly. It's been done people who are upset with a, an ax, for instance upset with a particular company, you can go onto the dark web and you can find companies.

    [00:49:53] And this revival company was one. That will provide you with the ransomware and they will do everything for you except get that ransomware onto a computer. So you could bring it in to an employer. You can send it by email to the ax. As I mentioned, you can do a lot of stuff. And then the. Ms. Cyber hacker guys, the bad guys will go ahead now and they will collect the ransom.

    [00:50:24] They'll even do tech support to help the people buy Bitcoin or whatever currency they want to have used. And then they take a percentage. So they might take 30% of it. There's a whole lot. We can talk about here too, including trust among thieves and everything else. It is easy to do this. So to see an organization like these cyber partisans, which I'm assuming is an organization, it could be as little as one person taking ransomware, going into specific computer systems breaking in.

    [00:50:58] Because again, even here in the U S how many of us have actually got their computer systems all patched up to date? The answer to that is pretty close to zero. And they can now go after a government, they can protect their friends. It's really something. When you start thinking about it, right? No longer do you have to be North Korea or China or Russia in order to hack someone to the point where they commit.

    [00:51:31] And in this case, they're not even after the money, they just want these political prisoners freed and they want Russia to stop shipping in troops supplies, into the area in Belarus next to or close to. Very fascinating. There, there is a whole lot of information about this online. If you're interested, you can read more about it.

    [00:51:55] It's in my newsletter, my show notes. I have links to some articles in there, but it really is a tool for the under. We've never really seen this before. It's quite an interesting turn in the whole ransomware narrative. It's just in crazy. That's a quote from a guy over at Sentinel one. Alright.

    [00:52:21] Lots to consider and lots to know and do, and you can find out about all of the. One way, subscribe right [email protected]. I promise. I'm not going to her Hess. You stick around.

    [00:52:38] We've heard a lot about automated cars. And of course we talked about them a lot here too, but that original vision of what we would have, it's gone now. It's fascinating. We're going to talk about that journey of automated car.

    [00:52:55] To date on technology for years, automakers have been telling this story about how these automated cars are going to drive themselves around and do just wonderful things for us.

    [00:53:10] And as part of that, they've decided that. The way it's going to work. And I remember talking about this, cause I think it's a cool idea is that there will be fleet of these vehicles think about maybe an Uber or Lyft where you get on the phone and you order up a card and it says, Hey that driver will be here.

    [00:53:30] Here's the license plate, the driver's name and picture. It's really cool, but general motors and Lyft haven't gotten there. They signed in agreement. To have electric autonomous cars as part of Lyft's fleet of drivers. They did a back in 2016, a long time ago. Ford promised what it called robo taxis and that they would debut by 2021 Dimeler of course, the company that makes Mercedes-Benz said it would work with Uber to deploy fleets of their car.

    [00:54:12] And the logic was really financial and it made a lot of sense to me, which is why I was so excited. I have car outside. You know about my Mercedes, you. How often do I drive that 40 year old car? Most of the time it's sitting there parked, most of the time, because I don't go very many places very often.

    [00:54:35] What would it be like then to just be able to have an Uber or Lyft type app on my phone that says, okay, tomorrow I have a 10 o'clock meeting in Boston and I want a car to take me there. So the. Checks with the servers and figures out. Okay. At 10 o'clock meaning, that means you're going to have to leave at eight 30 in order to get around the traffic that's normally happening.

    [00:55:03] And so we'll have a car there for you. So all I have to do is walk out the apple, probably remind me, my butt out of bed and get outside. Cause the car is about to arrive. So the car pulls into my driveway or maybe just stops on the road and the app reminds me, Hey, the car's there I go out. I get in.

    [00:55:22] And on the way down, I can work on getting ready for the meeting, getting some things done, just really kicking back, maybe having a nap as we go. And I'm there on time for my 10 o'clock. Just phenomenal. And from a financial standpoint, nowadays, how much is a car costing you? Have you ever done the math on that?

    [00:55:44] How much does a typical car loan run you per month? And I also want to put in how about these leases? How many of us are leasing cars? My daughter leaves to Gargan believe she did that. Didn't leave to me. It didn't make financial sense, but maybe that's just because I've been around a while. But looking right now at some statistics from credit karma, they're saying us auto loans, new cars, your average monthly payment is $568.

    [00:56:17] For an average loan term of 71 months. Good grief used cars, about $400. A month payment and average loan term, 65 months. I can't believe that I've never had a car loan for more than three years. Wow. That's incredible. So we're talking about six year notes on a new car. Wow. I guess that's because people buy cars based on the monthly payment, right?

    [00:56:49] So figure that out. If you're paying $500 a month, how about just paying a subscription service? $500. You can get so many rides a month and you don't have to maintain the car. You don't have to buy insurance. You don't have to make any fixes. You don't have to do anything. And the car will just show up.

    [00:57:08] That's what I was excited about. And it had some just amazing implications. If you think about it, it city dwell over dwellers and people who were directly in the suburbs, it'd be just phenomenal. And you could also have the robo taxis for longer trips. You can abandon that personal car. Really alternate.

    [00:57:31] So now it's been about a decade into this self-driving car thing that was started. And, we were promised all of these cars, it reminds me of the fifties, we're all going to be driving, flying cars by. George Jetson one, when was he flying around the cities, but that's not happening.

    [00:57:52] Okay. The progress on these automated vehicles has really slowed automakers and tech companies have missed all kinds of self-imposed deadlines for the autonomy. Look at what Elon Musk has promised again and again, it's. Basically in 2020, late 2020, it was going to have fully autonomous cars even calls itself dry.

    [00:58:15] When it isn't really self-driving, it certainly isn't fully autonomous it more or less drives. It stays in the lane as it's driving down the highway. But the tech companies are looking for other ways to make money off of self-driving tech. Some of them have completely abandoned. There's self-driving cars, the sensors like the LIDAR, and I've had the LIDAR people on my show before they've all gotten cheaper.

    [00:58:40] It doesn't cost you $50,000. Now just for one LIDAR sensor, think about what that means to these cars. So some of these manufacturers of these future autonomous cars are shifting to a new business strategy. And that is selling automated features directly to customers. In other words, you're going to buy a car, but that car isn't going to do much.

    [00:59:09] Think about the golden key that the tech companies have used for years, right? IBM well-known for that, you buy a mainframe or from IBM or a mini computer from digital equipment corporation, and you have the same computer as someone that has this massive computer. But in fact the difference is that they turn off features and we're seeing that right now.

    [00:59:34] I'm, I've mentioned that Subaru before where they are charging people for upgrades, but some of the companies are charging you monthly to use a remote start feature for instance, and many others. So what's happening is a major change. We have the consumer electronic show, right? January 20, 20 and general motors CEO, Mary Barra said that they would quote, aim to deliver our first personal autonomous vehicles as soon as the middle of this decade.

    [01:00:07] So again, it slipped, right? I'm looking at it, a picture of what they're considering to be. The new Cadillac car that should be out next year. Maybe thereafter. It is gorgeous. Absolutely gorgeous. But this announcement, right? Yeah. We're going to have autonomous vehicles, middle of the 2020s. She had no specific details at all.

    [01:00:33] And apparently this personal robo car project is completely separate from this robo taxi fleet that's been developed by GM's cruise subsidiary. And cruise said it has plans to launch a commercial service in San Francisco this year. So they're going after multiple paths. The logic here is financial.

    [01:00:56] The reasoning has changed and they're offering autonomy as a feature for the consumer market. Tesla, Elon Musk, they've been charging $10,000 now for the autopilot driver assistance feature. They're planning on raising it to $12,000 here early 2022 Tesla technology. Can't drive a car by itself.

    [01:01:22] But he's going to charge you if you want it. And I expect that's going to be true of all of the major manufacturer that's out there. And by the way, they're also looking at customization, like color changing cars and things. They're going to charge them as features. Hey, stick around. Visit me online.

    [01:01:43] Craig peterson.com.

    [01:01:46] Just how secure are our smartphones. We've got the iPhones, we've got Android out there. We've talked a little bit about this before, but new research is showing something I didn't really expect, frankly.

    [01:02:02] We've got some new research that wired had a great article about last week that is talking about the openings that iOS and Android security provide for anyone with the right tools. You're probably familiar at least vaguely with some cases where the FBI or other law enforcement agencies have gone to apple and tried to have.

    [01:02:29] Old break into iPhones. Apples, refuse to do that one in particular, down in Southern California, where they tried to get apple to open up this I phone and tell them who was this person talking to after a shooting of foul of fellow employees at a. It was really something, there was a lot of tense times and we've seen for decades now, the federal government trying to gain access to our devices.

    [01:03:04] They wanted a back door. And whenever you have a back door, there's a potential that someone's going to get in. So let's say you've got a. And your house has a front door. It has a backdoor, probably has some windows, but we'll ignore those for now. Okay. And you have guards posted at that front. All in someone needs to do is figure out to how to get into that back door.

    [01:03:31] If they want to get into your house, it might be easy. It might be difficult, but they know there's a back door and they're going to figure out a way to get in. And maybe what they're going to do is find a friend that works for that security company, that post of the guards out front. And see if that friend can get a copy of the.

    [01:03:51] That'll let them in the back door. And that's where we've had some real concerns over the year years here, a decades, frankly, our first, I remember this coming up during the Clinton administration, very big deal with the. That they were pushing. This was a cryptographic chip that they wanted every manufacturer to use if they wanted to have encryption and the white house and every gov federal government agency, and probably ultimately every local agency had the ability to break any encryption that was created by the clipper.

    [01:04:30] In fact, we were able to track Saddam Hussein and his sons and his inner circle. Because he was using some encrypted phones that were being made by a company in England. And that company in England did have a back door into those encrypted phones. And so we were able to track them and we could listen in, on all of their communications back and forth.

    [01:04:56] And it's really frankly, oppressed. When that sort of thing happens. So what do you do? What are you supposed to do? How can you make it so that your devices are safe? There are some ways to be relatively safe, but these cryptographers over Johns Hopkins university, Use some publicly available documentation that was available from apple and Google, as well as their own analysis.

    [01:05:26] And they looked into Android and iOS encryption and they founded lacking. So they studied more than a decades worth of reports. How about which mobile security features had been bypassed had been a hack. I had been used by law enforcement and criminals in order to get into these phones. They got some of these hacking tools off of the dark web and other places, and they tried to figure.

    [01:05:59] So we've got a quote here from Johns Hopkins, cryptographer, Matthew Green, who oversaw the research. It just really shocked me because I came into this project thinking that these phones are really protecting user data. Now I've come out of the project, thinking almost nothing is protected as much as it could be.

    [01:06:22] So why do we need a backdoor for law enforcement? When the protections that these phones actually offer are so bad. Now there's some real interesting details of if you like this stuff, I followed cryptography for many decades. Now I've always found it. Fascinating. There are some lightweight things I'm going to touch on here.

    [01:06:46] We won't get too deep in this, but here's another quote. Again, Johns Hopkins university on Android. You can not only attack the operating system level, but other different layers of software that can be vulnerable in different ways. Another quote here on iOS in particular, the infrastructure is in place for hierarchal encrypted.

    [01:07:10] Now higher are hierarchical. Encryption is various layers of encryption. If you have an iPhone or an iPad, or if you have most Android phones nowadays, if you use a passcode in order to unlock the phone or even a fingerprint or a face. Your method of authentication is used to encrypt everything on the phone, but in reality, everything on the phone is only fully encrypted when the phone is powered off.

    [01:07:49] Now that's a real, interesting thing to think about because obviously the phone can't work. If everything's encrypted. It needs access to the programs. It needs access to your data. So what they found bottom line was the only way to have a truly safe machine or a smartphone in this case is to turn it off because when you turn it on and it boots up on first boot, now it gets.

    [01:08:20] Either by bio medical information, like your fingerprint or your face sprint or your passcode, it then has a key that it can use to decrypt things. So apple has on the iPhone, something, they call complete protection and that's again, when the iPhone has been turned off on boots up because the user has to unlock the device before anything can happen on the phone.

    [01:08:45] And the is protections are very. Now you could be forced to unlock the phone by a bad guy, for instance, or in some cases, a warrant or an order from a judge, but forensic tools that, that they are using the police and the criminals really would have almost no luck at pulling information off of your phone.

    [01:09:11] That would be useful at all because it would all be encrypted, right? If they could. So once you've unlocked your phone after that first reboot molt, after that reboot, right? You unlocked it after power up. A lot of the data moves into a different mode that apple calls protected until first user authentication.

    [01:09:32] But it's what I call after first unlock. So when you think about it, your phone is almost always in the after first unlocks. Because how often do you reboot your phone? No, it's pretty rare that your phone might do on. And this is particularly true for I-phones might do updates and boot and reboot. And then of course you have to unlock that phone, but it doesn't go much further.

    [01:10:01] The net and that's, what's interesting. That's how law enforcement and the bad guys, these Israeli companies and others have been able to get into iPhones and get into Android devices because ultimately if that computer is turned on and you've logged in, there's a lot of data. That's no longer encrypted.

    [01:10:22] Oh. And by the way, that's also how some of these attacks occur on our laptops. Particularly if you traveled to. In the memory on that laptop that you close the lid on, you have to re log into is the key to UNHCR, unencrypt, everything, right? Because you logged in once. So all they have to do is freeze the memory, duplicate the memory and put it back in part of the reason, by the way that apple laptops have their memory soldered in you can't do that kind of attack.

    [01:10:56] Stick around. We'll be right back.

    [01:11:00] VPNs are good and they are bad. It depends on the type of VPN. Many of these commercial VPNs of people are using are actually very bad for you when it comes to your security.

    [01:11:17] VPNs are Trump problematic. I did a couple of boot camps on VPNs. Probably I think it was about last year.

    [01:11:26] Yeah, it was last spring. And I went through and explained and showed exactly why commercial VPNs are one of the worst things you could possibly do if you want. To stay secure. Now I lemme just give you the high level here. I have given people copies of this, if you're interested in a link to that VPN webinar that I did, I'd be glad to send it to you.

    [01:11:57] Just email me Emmy at Craig Peterson, doc. And ask me for the VPN information and I'll send that all off to you. I also wrote something up that I've been sending out to people that have asked about VPNs. Cause it's one of the most common questions we have Franklin, but here's your problem with commercial VPNs?

    [01:12:18] Most all of them say, oh, your information safe at zero logging, et cetera. And yet we have found again and again that's not. In fact, it can't possibly be true in almost every case because most of these VPN services are running out of other people's data centers. So they might be in an Amazon data center or IBM or Microsoft.

    [01:12:45] And inside that data center, your data is coming in and then it's going to. So let's say you're using a VPN and you're connecting to a website. I don't care. Go to google.com via a VPN. So you're using one of these services. That's advertised all over creation. And what happens now is. Your web request to get to Google passes over that encrypted VPN and comes to an exit point because at some point it has to get onto the regular internet.

    [01:13:20] How else are you going to get to that website? On the other side? You can't, unless you get to the regular internet. So at the other side, now the server is that's receiving the end point of view. VPN is going to send the request to Google. Google is going to respond to that VPN server. It's going to be encrypted and sent back to you.

    [01:13:43] So what's the problem with that? There's multiple problems. One is the data center can see. That there is the request going up to Google. Now he might not be able to tell who it was. But if that VPN server has been hacked. And let me tell you, it is a big target for hackers, government hackers, as well as bad guys.

    [01:14:06] Then they do know who went out there and depending on how it was hacked and how the VPN was set up, they may even be able to see all of the data that you're sending back and forth. It's called a man in the middle of. And some of these VPN services do it by having you install some software on your computer.

    [01:14:28] And as part of that installation, they provide you with a master key that they then use to spoon. The keys for the websites. You're going to some, explain that what happens is if you were to go right now on your web browser, go to Craig peterson.com as an example. So Craig peterson.com. I'm typing it in right now in the browser.

    [01:14:55] That's directly in front of me. Now you'll see a little lock up in the URL. What does that mean? If you click on that lock, it says something about the connection being secure. Are you familiar with that? What's actually happening is it's using SSL TLS keys, but it's using encryption now to send the data from your computer.

    [01:15:24] To my server, that's hosting Craig peterson.com. And then my server is sending all of the webpage back to you. Encrypted. Any fact, a VPN has been established between your web browser and my web server. So why use a third-party VB? Because your data is encrypted already, right? Could it be more simple than that?

    [01:15:59] Now, remember again, that the server on the VPM service that you're using is a prime attack target for everybody else. As I said from government agencies through hackers. So your data is likely less safe because if they get a hold of it, they can do all kinds of things to your data and to. And then on top of it, all the VPN service may well be selling your data in order to make money, to support the VPN service because free VPNs, inexpensive VPN sees the ones that are charging you five or 10 bucks a month cannot possibly afford to provide you with that service.

    [01:16:51] And in the bootcamp, I go through all of the numbers here, the costs involved. With a VPN service it's not possible to do. They can't make any money off of it. So it is a very big problem for you to use one of these public VPN services. Now, I want to talk about an arc article that was on Z.

    [01:17:19] Apparently your old pole, which is of course the police over there in the European nations has seized servers. What servers, VPN servers in Europe. Now they seized the servers because they were used by who was it? Grandma looking at pictures of the grandkids. Was it people watching cat videos who was using the VPN server?

    [01:17:45] The paid VPN service. Wow. It was criminals. And when they seized these VPN servers that were also being used by criminals, they found more than a hundred businesses that had fallen victims to attacks. So who uses VPN services? People who want to hide something as well as people who just want to have their data secure.

    [01:18:14] Another reason not to use VPN services. So as a part of the joint action by Europol Germany's police Hanover police department, the FBI, UK national crime agency, and others seized 15 servers used by VPN lab dot. Okay. So VPN lab.net net, obviously no longer usable. And they started looking at all of the records that were being kept in these servers and use that to find the criminal.

    [01:18:48] Does that make sense to you? So VPN lab.net was according to these charges, facilitating illicit activities, such as malware distribution. Other cases showed the services use in setting up infrastructure and communications behind ransomware campaigns, as well as the actual deployment of ransomware. You like that.

    [01:19:12] Now they were using open VPN technology, which is actually very good. As part of that VPN information, I can send you if you're interested, just email me M [email protected]. Let me know what you're interested in, and I'll whoop you off an email. Give me a few days I can get behind sometimes, but you can set up your own private VPN server if that's what you want to do.

    [01:19:38] And I've gotten instructions on how to do that in that little special report in that email, but They were providing what they called online anonymity, this VPN lab.net service for as little as $60 a year. Okay. You like that? So they provided what they call double VPN servers and a lot of different countries and made it a popular choice for cyber criminals.

    [01:20:04] Very big deal. Okay. So be very careful with VPNs. Also be careful of the VPN you might be using for your business. Let's say you've got something that isn't terribly secure or not secure at all as your firewall, right? So you buy a nice little firewall or this is so great. It's not expensive. And I got it online from a big box retailer.

    [01:20:27] Most of them out there do not meet. The minimum standards you really need in order to keep your business. And there's only two companies that do one of them, Cisco, and one of them's Juniper, that's it? None of the other firewalls with VPNs meet the minimal standards you need to have, but those be glad to sell it to you.

    [01:20:49] They'll be glad to tell you that it's perfectly secure, but it is not okay. Just went through that again with a company this week an engineering firm and at least they understand some of the stuff, but they were trying to do the right thing and they were being misled by these various vendors. So this action against VPN lab took place in January involved with authorities from Germany.

    [01:21:15] The Netherlands Canada, Czech Republic, France, Hungary, Latvia, Ukraine, us UK, as well as your old pole. So there you go. You've gotta be careful don't trust VPNs, right? I've been saying that for a very long time. And then the other thing I want to. Is hopefully this summer we're going to be traveling.

    [01:21:40] And when you're traveling, the temptation is to use public wifi might be at the hotel. It might be at a restaurant coffee shop, whatever. Okay. I admit to doing that myself. But here's two things you need to be careful with. One use, good DNS filtering. Now we sell and provide umbrella, which is a Cisco product, which is extremely good.

    [01:22:08] DNS filtering. You can get free DNS filtering that isn't configurable, doesn't have the options, but is fantastic called open DNS. I've got, again, I did a bootcamp on that. I can send you information on it if you want. It doesn't cost you a dime for any of this stuff, but open DNS. And then the other thing I do, I have a high-end Cisco firewall and VPN.

    [01:22:34] So when I'm on the road, even when I'm using data from the phone company, I have my secure VPN turned on FIPs compliant, by the way, for those who know what that means. Hey, visit me online. Craig peterson.com. Get my show notes. Get my Wednesday, wisdoms everything. Craig peterson.com. It's easy to sign up right there on any page.

    1 hr 24 min
  • Which Anti-Hacker Techniques Can You Use Against the Russian Hackers?

    Weekly Show #1158

    We know the Russians have been attacking us. I've talked a lot about it on the radio and TV over the last couple of weeks. So I am doing something special; we are going through the things you can do to stay safe from the latest Russian attacks.

    Last week, we started doing something I promised we would continue -- how can you protect yourself when it comes to the Russians? The Russians are the bad guys when it comes to bad guys. So there are a few things you can do. And there are a few things; frankly, you shouldn't be doing. And that's precisely what we're going to talk about right now.

    Today, I explain:

    - How to protect your back-end - Preventative measures - The new rules of backing up your computer

    As usual, we'll cover the What, Why, and How's.

    [Automated transcript follows]

    [00:00:39] So last week he went over some steps, some things that you can look at that you should look at that are going to help protect you. And we are going to go into this a whole lot more today. And so I want you to stick around and if you miss anything, you can go online. You can go to Craig peterson.com, make sure you sign up there for my email.

    [00:01:01] And what I'm going to do for you is. Send you a few different documents now where we can chat back and forth about it, but I can send you this. Now I'm recording this on video as well as on audio. So you can follow along if you're watching either on YouTube or. Over on rumble and you can find it also on my website.

    [00:01:26] I've been trying to post it up there too, but right now let's talk about what we call passive backend protections. So you've got the front end and the front end of course, is. Stuff coming at you, maybe to the firewall I've mentioned last week about customers of mine. I was just looking at a few customers this week, just so I could have an idea of their firewalls.

    [00:01:52] And they were getting about 10 attacks per minute. Yeah. And these were customers who have requirements from the department of defense because they are defense sub subcontractors. So again, Potential bad guys. So I looked up their IP addresses and where the attacks were coming from. Now, remember that doesn't mean where they originated because the bad guys can hop through multiple machines and then get onto your machine.

    [00:02:22] What it means is that all, ultimately they ended up. Coming from one machine, right? So there's an IP address of that machine. That's attacking my clients or are attacking my machines. That just happens all the time. A lot of scans, but some definite attacks where they're trying to log in using SSH.

    [00:02:42] And what I found is these were coming from Slovakia, Russia, and Iran. Kind of what you were expecting, right? The Iranians, they just haven't given up yet. They keep trying to attack, particularly our military in our industry. One of the things we found out this week from, again, this was an FBI notice is that the Russians have been going after our industrial base.

    [00:03:09] And that includes, in fact, it's more specifically our automobile manufacturers we've already got problems, right? Try buying a new car, try buying parts. I was with my friend, just this. I helped them because he had his car right. Need to get picked up. So I took him over to pick up his car and we chatted a little bit with this small independent automotive repair shop.

    [00:03:34] And they were telling us that they're getting sometimes six, eight week delays on getting parts and some parts. They just can't. So they're going to everything from junkyards on out, and the worst parts are the parts, the official parts from the car manufacturers. So what's been happening is Russia apparently has been hacking into these various automobile manufacturers and automobile parts manufacturers.

    [00:04:03] And once they're inside, they've been putting in. A remote control button net. And those botnets now have the ability to wake up when they want them to wake up. And then once they've woken up, what do they do? Who knows? They've been busy erasing machines causing nothing, but having they've been doing all kinds of stuff in the past today, they're sitting there.

    [00:04:24] Which makes you think they're waiting, it's accumulate as much as you possibly can. And then once you've got it all accumulated go ahead and attack. So they could control thousands of machines, but they're not just in the U S it's automobile manufacturers in Japan. That we found out about.

    [00:04:44] So that's what they're doing right now. So you've got the kind of that front end and back end protections. So we're going to talk a little bit about the back end. What does that mean? When a cybersecurity guy talks about the backend and the protections. I got it up on my green right now, but here's the things you can do.

    [00:05:03] Okay. Remember, small businesses are just getting nailed from these guys, because again, they're fairly easy targets. One change your passwords, right? How many times do we have to say that? And yet about 70% of businesses out there are not using a good password methodology. If you want more information on passwords, two factor authentication, you name it.

    [00:05:30] Just email me M [email protected]. I want to get the information out now. You got to make sure that all of the passwords on your systems are encrypted are stored in some sort of a good password vault as you really should be looking at 256 bit encryption or better. I have a vendor of. That I use. So if you get my emails every week, when them, there's the little training.

    [00:05:59] And so I'll give you a five minute training. It's written usually it's in bullet point for, I'm just trying to help you understand things. That provider of mine has a big database and there's another provider that I use that is for. So the training guys use the database of my provider.

    [00:06:20] In using that database, they're storing the passwords and the training providers putting passwords in the clinics. Into the database, which is absolutely crazy. So again, if you're a business, if you're storing any sort of personal information, particularly passwords, make sure that you're using good encryption and your S what's called salting the hash, which means.

    [00:06:46] You're not really storing the password, just joining assaulted hash. I can send you more on this. If you are a business and you're developing software that's, this is long tail stuff here. Configure all of the security password settings so that if someone's trying to log in and is failing that, and you block it, many of us that let's say you're a small business.

    [00:07:08] I see this all of the time. Okay. You're not to blame. You, but you have a firewall that came from the cable company. Maybe you bought it at a big box retailer. Maybe you bought it online over at Amazon, as hurricane really great for you. Has it got settings on there that lets you say. There's 20 attempts to log in.

    [00:07:31] Maybe we should stop them. Now, what we do personally for our customers is typically we'll block them at somewhere around three or four failed attempts and then their passwords block. Now you can configure that sort of thing. If you're using. Email. And that's an important thing to do. Let me tell you, because we've had some huge breaches due to email, like Microsoft email and passwords and people logging in and stealing stuff.

    [00:07:59] It was just a total nightmare for the entire industry last year, but limit the number of login retries as well as you're in there. These excessive login attempts or whatever you want to define it as needs to lock the account. And what that means is even if they have the right password, they can't get in and you have to use an administrative password in order to get in.

    [00:08:25] You also want to, what's called throttle, the rate of repeated logins. Now you might've gotten caught on this, right? You went to your bank, you went to E-bay, you went to any of these places and all of a sudden. And denied you write it blocked you. That can happen when your account is on these hackers lists.

    [00:08:45] You remember last week we talked about password spraying while that's a very big deal and hackers are doing the sprain trick all of the time, and that is causing you to get locked out of your own account. So if you do get locked out, remember it might be because someone's trying to break. Obviously you have to enforce the policies.

    [00:09:09] The capture is a very good thing. Again, this is more for software developer. We always recommend that you use multifactor or two factor authentication. Okay. Do not use your SMS, your text messages for that, where they'll send you a text message to verify who you are. If you can avoid that, you're much better off.

    [00:09:30] Cause there's some easy ways to get around that for hackers that are determined. Okay. A multi-factor again, installed an intrusion. system. We put right at the network edge and between workstations and servers, even inside the network, we put detection systems that look for intrusion attempts and block intrusion attempts.

    [00:09:56] A very important use denied lists to block known attackers. We build them automatically. We use some of the higher end Cisco gates. Cisco is a big network provider. They have some of the best hardware and software out there, and you have to subscribe to a lot of people complain. I ain't going to just go buy a firewall for 200 bucks on Amazon.

    [00:10:18] Why would I pay that much a month just to to have a Cisco firewall? And it's like praying pain for the brand. I've got by logo chert on here. Oh, I wouldn't pay for that. No, it's because they are automatically providing block lists that are updated by the minute sometimes. And then make sure you've got an incident response plan in place.

    [00:10:44] What are you going to do when they come for you? What are you going to do? Bad boys. Bad. Stick around. We've got a lot more to talk about here as we go. I am explaining the hacks that are going on right now and what you can do as a business and an individual doubt. Protect yourself. Don't go anywhere.

    [00:11:07] Now we're going to talk about prevention. What can you do an order to stop some of these attacks that are coming from Russia and from other countries, it is huge. People. Believe me, this is a very big problem. And I'm here to help.

    [00:11:23] hi, I'm Craig Peter Sohn, your chief information security officer. We've reviewed a number of things that are important when it comes to your cyber security and your protection.

    [00:11:37] We talked about the front end. We talked about the backend. Now we're going to talk about pure prevention and if you're watching. Online. You'll be able to see my slides as they come up, as we talk about some of this stuff and you'll find me on YouTube and you'll also find me on rumble, a fairly new platform out there platform that doesn't censor you for the things you say.

    [00:12:01] Okay. So here we go. First of all, enabling your active directory password protection is going to. Four's password protection all the way through your business. Now I've had some discussions with people over the months, over the years about this whole thing and what should be done, what can be done, what cannot be done.

    [00:12:26] Hey, it's a very big deal when it comes to password protection and actor directory, believe it or not, even though it's a Microsoft product is pretty darn good at a few things. One of them is. Controlling all the machines and the devices. One of the things we do is we use an MDM or what used to be a mobile device manager called mass 360.

    [00:12:51] It's available from IBM. We have a special version of that allows us as a managed security services provider to be able to control everything on people's machines. Active directory is something you should seriously consider. If you are a Mac based shop. Like I am. In fact, I'm sitting right now in front of two max that I'm using right now, you'll find that active directory is a little bit iffy.

    [00:13:21] Sometimes for max, there are some work around and it's gotten better mastery. 60 is absolutely the way to go, but make sure you've got really good. Passwords and the types of passwords that are most prone to sprain the attacks are the ones you should be banning specifically. Remember the website? Have I been poned?

    [00:13:45] Yeah. It's something that you should go to pretty frequently. And again, if you miss anything today, just email me M [email protected]. Believe me, I am not going to harass you at all. Okay. Now, the next thing that you should be doing is what's called red team blue team. Now the red team is a group of people, usually outside of your organization.

    [00:14:11] If you're a big company they're probably inside, but the red team is the team that attacks you. They're white hat hackers, who are attacking you, looking for vulnerabilities, looking for things that you should or shouldn't be doing. And then the blue team is the side that's trying to defend. So think of, like war games.

    [00:14:29] Remember that movie with Matthew Broderick all of those decades ago and how the, he was trying to defend that computer was trying to defend that it moved into an attack mode, right? Red team's attack, blue team is defend. So you want. To conduct simulated attacks. Now w conducting these attacks include saying, oh my let's now put in place and execute our plan here for what are we going to do once we have a.

    [00:15:01] And you darn well better have a breach plan in place. So that's one of the things that we help as a fractional chief information security officer for companies, right? You've got to get that in place and you have to conduct these simulated attacks and you have to do penetration testing, including password spraying attacks.

    [00:15:21] There's so many things you can do. The one of the things that we like to do and that you might want to do, whether you're a home user, retiree or a business is go and look online, you can just use Google. I use far more advanced tools, but you can use Google and look for your email address right there.

    [00:15:40] Look for the names of people inside your organization. And then say wait a minute, does that data actually need to be there? Or am I really exposing the company exposing people's information that shouldn't be out there because you remember the hackers. One of the things they do is they fish you fish as in pH.

    [00:16:04] So they'll send you an email that looks like. Hey let me see. I know that Mary is the CFO, and I know that Joe's going to be out of town for two weeks in The Bahamas, not a touch. So while he's got. I'm going to send an email to Mary, to get her to do something, to transfer the company's funds to me.

    [00:16:23] Okay. So that's what that's all about. You've got to make sure, where is our information? And if you go to my company's page, mainstream.net, you'll see on there that I don't list any of the officers or any of the people that are in the company, because that again is a security problem.

    [00:16:41] We're letting them know. I go to some of these sites, like professional sites lawyers, doctors, countenance, and I find right there all, are there people right there top people or sometimes all of them. And then we'll say, yeah, I went to McGill university, went to Harvard, whatever my B. It's all there. So now they've got great information to fish you, to fish that company, because all they have to do is send an email to say, Hey, you remember me?

    [00:17:13] We're in Harvard when this class together. And did you have as a professor to see how that works? Okay. You also want to make. That you implement, what's called a passwordless user agent, and this is just so solely effective. If they cannot get into your count, what's going to, what could possibly go wrong, but one of the ways to not allow them into the count is to use.

    [00:17:41] Biometrics. We use something called duo and we have that tied into the single sign-on and the duo single sign-on works great because what it does now is I put in, I go to a site, I put it into my username and. Pulls up a special splash page that is running on one of our servers. That again asks me for my duo username.

    [00:18:04] So I've got my username for the site then to my dual username and my duo password single sign on. And then it sends me. To an app on my smart device, a request saying, Hey, are you trying to log into Microsoft? And w whatever it might be at Microsoft, and you can say yes or no, and it uses biometric.

    [00:18:27] So those biometrics now are great because it says, oh, okay, I need a face ID or I need a thumb print, whatever it might be that allows a generalized, a password, less access. Okay. Password less. Meaning no pass. So those are some of the top things you can do when it comes to prevention. And if you use those, they're never going to be able to get at your data because it's something you have along with something, it works great.

    [00:19:02] And we like to do this. Some customers. I don't like to go through those hoops of the single sign-on and using duo and making that all work right where we're fine with it. We've got to keep ourselves, at least as secure as the DOD regulations require unlike almost anybody else in industry, I'm not going to brag about it.

    [00:19:26] But some of our clients don't like to meet the tightest of controls. And so sometimes they don't. I hate to say that, but they just don't and it's a fine line between. Getting your work done and being secure, but I think there's some compromises it can be readily made. We're going to talk next about saving your data from ransomware and the newest ransomware.

    [00:19:53] We're going to talk about the third generation. That's out there right now. Ransomware, it's getting crazy. Let me tell ya and what it's doing to us and what you can do. What is a good backup that has changed over the last 12 months? It's changed a lot. I used to preach 3, 2, 1. There's a new sheriff in town.

    [00:20:15] Stick around Craig peterson.com.

    [00:20:19] 3, 2, 1 that used to be the standard, the gold standard for backing up. It is no longer the case with now the third generation of ransomware. You should be doing something even better. And we'll talk about it now.

    [00:20:36] We're doing this as a simulcast here. It's on YouTube. It is also on rumble.

    [00:20:43] It's on my [email protected] because we're going through the things that you can do, particularly if you're a business. To stop the Russian invasion because as we've been warned again and again, the Russians are after us and our data. So if you missed part of what we're talking about today, or.

    [00:21:07] Last week show, make sure you send me an email. [email protected]. This is the information you need. If you are responsible in any way for computers, that means in your home, right? Certainly in businesses, because what I'm trying to do is help and save those small businesses that just can't afford to have full-time.

    [00:21:31] True cyber security personnel on site. So that's what the whole fractional chief information security officer thing is about. Because you just, you can't possibly afford it. And believe me, that guy that comes in to fix your computers is no cyber security expert. These people that are attacking our full time cybersecurity experts in the coming from every country in the world, including the coming from the us.

    [00:22:01] We just had more arrests last week. So let's talk about ransomware correctly. Ransomware, very big problem. Been around a long time. The first version of ransomware was software got onto your computer through some mechanism, and then you had that red screen. We've all seen that red screen and it says, Hey, pay up buddy.

    [00:22:23] It says here you need to send so many Bitcoin or a fraction of a Bitcoin or so many dollars worth of Bitcoin. To this Bitcoin wallet. And if you need any help, you can send email here or do a live chat. They're very sophisticated. We should talk about it some more. At some point that was one generation.

    [00:22:45] One generation two was not everybody was paying the ransoms. So what did they do at that point? They said let me see if they, we can ransom the data by encrypting it and having them pay us to get it back. 50% of the time issue got all your data back. Okay. Not very often. Not often enough that's for sure.

    [00:23:05] Or what we could do is let's steal some of their intellectual property. Let's steal some of their data, their social security number, their bank, account numbers, et cetera. They're in a, in an Excel spreadsheet on their company. And then we'll, if they don't pay that first ransom, we'll tell them if they don't pay up, we'll release their information.

    [00:23:26] Sometimes you'll pay that first ransom and then they will hold you ransom a second time, pretending to be a different group of cyber terrorists. Okay. Number three, round three is what we're seeing right now. And this is what's coming from Russia, nears, everything we can tell. And that is. They are erasing our machines.

    [00:23:48] Totally erasing them are pretty sophisticated ways of erasing it as well, so that it sinks in really, it's impossible to recover. It's sophisticated in that it, it doesn't delete some key registry entries until right at the very end and then reboots and computer. And of course, there's. Computer left to reboot, right?

    [00:24:11] It's lost everything off of that hard drive or SSD, whatever your boot devices. So let's talk about the best ways here to do some of this backup and saving your data from ransomware. Now you need to use offsite disconnected. Backups, no question about it. So let's talk about what's been happening.

    [00:24:34] Hospitals, businesses, police departments, schools, they've all been hit, right? And these ransomware attacks are usually started by a person. I'll link in an email. Now this is a poison link. Most of the time, it used to be a little bit more where it was a word document, an Excel document that had something nasty inside Microsoft, as I've said, many times has truly pulled up their socks.

    [00:25:02] Okay. So it doesn't happen as much as it used to. Plus with malware defender turned on in your windows operating system. You're going to be a little bit safer next step. A program tries to run. Okay. And it effectively denies access to all of that data. Because it's encrypted it. And then usually what it does so that your computer still works.

    [00:25:26] Is it encrypts all of you, like your word docs, your Excel docs, your databases, right? Oh, the stuff that matters. And once they've got all of that encrypted, you can't really access it. Yeah. The files there, but it looks like trash now. There's new disturbing trends. It has really developed over the last few months.

    [00:25:48] So in addition to encrypting your PC, it can now encrypt an entire network and all mounted drives, even drives that are marrying cloud services. Remember this, everybody, this is really a big deal because what will happen here is if you have let's say you've got an old driver G drive or some drive mounted off of your network.

    [00:26:14] You have access to it from your computer, right? Yeah. You click on that drive. And now you're in there and in the windows side Unix and max are a little different, but the same general idea you have access to you have right. Access to it. So what they'll do is any mounted drive, like those network drives is going to get encrypted, but the same thing is true.

    [00:26:36] If you are attaching a U S B drive to your company, So that USB drive, now that has your backup on it gets encrypted. So if your network is being used to back up, and if you have a thumb drive a USB drive, it's not really a thumb drive, right? There's external drive, but countered by USP hooked up.

    [00:27:02] And that's where your backup lives. Your. Because you have lost it. And there have been some pieces of software that have done that for awhile. Yeah. When they can encrypt your network drive, it is really going after all whole bunch of people, because everyone that's using that network drive is now effective, and it is absolutely.

    [00:27:27] Devastating. So the best way to do this is you. Obviously you do a bit of a local backup. We will usually put a server at the client's site that is used as a backup destiny. Okay. So that servers, the destination, all of the stuff gets backed up there. It's encrypted. It's not on the network per se. It's using a special encrypted protocol between each machine and the backup server. And then that backup servers data gets pushed off site. Some of our clients, we even go so far as to push it. To a tape drive, which is really important too, because now you have something physical that is by the way, encrypted that cannot be accessed by the attacker.

    [00:28:20] It's offsite. So we have our own data center. The, we run the, we manage the no one else has access to it is ours. And we push all of those backups offsite to our data center, which gives us another advantage. If a machine crashes badly, right? The hard disk fails heaven forbid they get ransomware. We've never had that happen to one of our clients.

    [00:28:46] Just we've had it happen prior to them becoming clients, is that we can now restore. That machine either virtually in the cloud, or we can restore it right onto a piece of hardware and have them up and running in four hours. It can really be that fast, but it's obviously more expensive than in some.

    [00:29:08] Are looking to pay. All right, stick around. We've got more to talk about when we come back and what are the Russians doing? How can you protect your small business? If you're a one, man, one woman operation, believe it. You've got to do this as well. Or you could lose everything. In fact, I think our small guys have even more to lose Craig peterson.com.

    [00:29:32] Backups are important. And we're going to talk about the different types of backups right now, what you should be doing, whether you're a one person, little business, or you are a, multi-national obviously a scale matters.

    [00:29:47] Protecting your data is one of the most important things you can possibly do.

    [00:29:53] I have clients who had their entire operating account emptied out, completely emptied. It's just amazing. I've had people pay. A lot of money to hackers to try and get data back. And I go back to this one lady over in Eastern Europe who built a company out of $45 million. By herself. And of course you probably heard about the shark tank people, right?

    [00:30:23] Barbara Cochran, how she almost lost $400,000 to a hacker. In fact, the money was on its way when she noticed what was going on and was able to stop it. So thank goodness she was able to stop it. But she was aware of these problems was looking for the potential and was able to catch it. How many of us are paying that much attention?

    [00:30:50] And now one of the things you can do that will usually kind of protect you from some of the worst outcomes. And when it comes to ransomware is to backup. And I know everybody says, yeah, I'm backing up. It's really rare. When we go in and we find a company has been backing up properly, it even happens to us sometimes.

    [00:31:15] We put them back up regimen in place and things seem to be going well, but then when you need the backup, oh my gosh, we just had this happen a couple of weeks ago. Actually this last week, this is what happened. We have. Something called an FMC, which is a controller from Cisco that actually controls firewalls in our customer's locations.

    [00:31:42] This is a big machine. It monitors stuff. It's tied into this ice server, which is. Looking for nastiness and we're bad guys trying to break in, right? It's intrusion detection and prevention and tying it into this massive network of a billion data points a day that Cisco manages. Okay. It's absolutely huge.

    [00:32:05] And we're running it in a virtual machine network. So we. Two big blade. Chassies full of blades and blades are each blade is a computer. So it has multiple CPU's and has a whole bunch of memory. It also has in there storage and we're using something that VMware calls visa. So it's a little virtual storage area network.

    [00:32:32] That's located inside this chassis and there are multiple copies of everything. So if a storage unit fails, you're still, okay. Everything stays up, it keeps running. And we have it set up so that there's redundancy on pond redundancy. One of the redundancies was to back it up to a file server that we have that's running ZFS, which is phenomenal.

    [00:32:56] Let me tell you, it is the best file system out there I've never ever had a problem with it. It's just crazy. I can send you more information. If you ever interested, just email [email protected]. Anytime. Be glad to send you the open source information, whatever you need. But what had happened is.

    [00:33:13] Somehow the boot disk of that FMC, that, that firewall controller had been corrupted. So we thought, oh, okay, no problem. Let's look at our backups. Yeah, hadn't backed up since October, 2019. Yeah, and we didn't know it had been silently failing. Obviously we're putting stuff in place to stop that from ever happening again.

    [00:33:43] So we are monitoring the backups, the, that network. Of desks that was making up that storage area network that had the redundancy failed because the machine itself, somehow corrupted its file system, ext four file system right then are supposed to be corruptible, but the journal was messed up and it was man, what a headache.

    [00:34:07] And so they thought, okay, you're going to have to re-install. And we were sitting there saying, oh, you're kidding me. Reinstalling this FMC controller means we've got to configure our clients, firewalls that are being controlled from this FMC, all of their networks, all of their devices. We had to put it out.

    [00:34:23] This is going to take a couple of weeks. So because I've been doing this for so long. I was able to boot up an optics desk and Mount the file system and go in manually underneath the whole FMC, this whole firewall controller and make repairs to it. Got it repaired, and then got it back online. So thank goodness for that.

    [00:34:49] It happens to the best of us, but I have to say I have never had a new client where they had good backups. Ever. Okay. That, and now that should tell you something. So if you are a business, a small business, whatever it might be, check your backups, double check them. Now, when we're running backups, we do a couple of things.

    [00:35:14] We go ahead and make sure the backup is good. So remember I mentioned that we have. Backup server that sits onsite. Usually it depends on the size of the client. But sits onsite at the client's site. So it will perform the backup and then tries to actual restore of that backup to make sure it's good.

    [00:35:35] And we can even. Client, depending on what they want. So a higher level, if a machine goes down, let's say it catches fire, or disk explodes in it, or completely fails. We can actually bring that machine online inside our backup server or the customer. Yeah, how's that for fancy and bring it back online in just a matter of minutes instead of days or weeks.

    [00:36:04] So that's true too. If that machine had been a ransom had this data, you raised whatever might've happened to it. We can restore it now. We've never had to knock on wood, except when there was a physical problem with the machine and as. Starting from scratching it, that machine, the new machine online in four hours or less.

    [00:36:28] And it's really cool the way it works. If you like this stuff, man, it is great. Okay. Protecting your data. I'm rambling a little bit here. You need an archival service there's companies out there like iron mountain, you can at your local bank, depending on the bank. It ain't like it used to be, get a box, right?

    [00:36:50] A special box in the vault that you. The tapes and other things in nowadays there's cloud options, virtual tape backup options, which is a lot of what we use and we do. Okay. We also use straight cloud at the very bottom end again. It's not located on the network. It's up in the cloud. It's double encrypted.

    [00:37:13] It's absolutely the way to do now if you're going to have a backup and if that backup, you want to be secure, it must not be accessible. To the attacker, you've got to put some literal air space between your backups and the cyber criminals. It's called an air gap. So there's no way for them to get to it.

    [00:37:37] Okay. Now I want you to consider seriously using tape these a LTO. These linear tape drives. They've been around for a long time, but their cartridges you can pull in and out. And they're huge. They they're physically small, but they can hold terabytes worth of data. They're absolutely amazing. There's some great disk based backup systems as what we do.

    [00:38:02] Some of them are been around a long time and they can be quite reasonably. Price. All right. So it's something for you to consider, but you've got to have at least that air gap in order to make sure that you're going to be protected. What should you be looking for in a backup system? This is called 3, 2, 2 1, which means maintain at least three copies of your data store the backups on two different meters.

    [00:38:31] Store at least one of the copies at an offsite location store, at least one of the copies offline, and be sure to have verified backups without air. Okay. Does that sound a little complicated? 3, 2, 1, 1 0 is what it's called. Just to be 3, 2, 1. Now it's 3, 2, 1, 1 0. I can send you Karen put together a special report on this based on our research.

    [00:38:57] And I can share that with you. Absolutely free. Hey guys, if you want it, you got it. But you got to ask me, just email me M [email protected]. This is absolutely essential. If you're a small business, a tiny business to do it this way. Let me tell you, okay, this is just huge. Physical backups should be stored off site.

    [00:39:19] I mentioned the bank fault. A lot of people just go ahead and take them home with. That might be a desk. It might be a tape. It can be a little bit complicated to do. And I've picked up customers that thought they were backing up. They were using a USB drive. They were putting it in due to flee every Monday.

    [00:39:41] And then every Wednesday, what happened? Every Wednesday they bring in Wednesdays desk and then they bring that disc home and then Thursday, they bring in the Thursday disc. And none of them had been working. Okay. So be very careful. All of your backups should be encrypted. We encrypted at the customer site and then we reencrypt it when we bring it over to us.

    [00:40:06] Okay. Keys are essential. Particularly if you're using a cloud-based backup, don't use the same keys across multiple backups. Very important there. You should have some good procedures that are well-documented test, test your restores because very frequently. We find they don't work. In fact, that's the number one problem, right?

    [00:40:30] If they had just tried to restore, even once from their backup, they would've known they had problems. And get those backups scheduled on a regular schedule. Okay. So there's a lot more offline backups and more that we can talk about another time, but this is important. If you want any help, send me an email, just put backups in the subject line.

    [00:40:55] I'll send you some stuff. Email me, M [email protected]. Now I am more than glad to help. Pretty much anybody out there. I'm not going to help. What about blah, blah, Amir Putin. But anybody else I'll help, but you got to reach out. Okay. You listen here. And I know some of this stuff is over some of our heads, some of your heads, you're the best and brightest.

    [00:41:20] That's why you're listening and I'll help you out. I'll send you some information. That's going to get you on the right track. Me M [email protected]. That's Craig Peterson, S O N have a great day.

    [00:41:35] We just got an email this week from a customer and they're saying, oh no, my email has been hacked. What does that mean was a really hacked, we're going to talk right now about email spoofing, which is a very big deal.

    [00:41:51] Emails spoofing is being a problem for a long time, really? Since the 1970s. I remember when I got my first spoofed email back in the eighties and they was really a little bit confusing.

    [00:42:05] I went into it more detail, of course, being a very technical kind of guy and looked behind the curtains, figured out what was going on. Just shook my head. I marveled at some people. Why would you do this sort of thing? The whole idea behind email spoofing is for you to receive an email, looks like it's from someone that it's not now, you've all seen examples of this.

    [00:42:30] Everybody has. And those emails that are supposedly from the bank, or maybe from Amazon or some other type of business or family friend, this is part of what we call social engineering, where the bad guys are using a little bit about what they know about you, or maybe another person in order to. Frankly, fool you.

    [00:42:54] That's what spoofing really is. There were a lot of email accounts that were hacked over the last what, 30, 40 years. And you might remember this people sending out an email saying, oh, my account got hacked because you just got emails. Back in the day, what people were trying to do is break into people's email accounts and then the bad guys after having broken in now knew everybody that was in the contact list from the account that was just broken into.

    [00:43:29] Now they know, Hey, listen, this person sends an email. Maybe I can just pretend I'm them. Days it, the same thing still happens. But now typically what you're seeing is a more directed attack. So a person might even look in that email account that they've broken into and poke around a little bit and find out, oh, okay.

    [00:43:52] So this person's account I just broken to is a purchasing manager at a big. So then they take the next step or maybe this tab after that and try and figure out. Okay, so now what do I do? Oh, okay. So really what I can do now is send fake purchase orders or send fake requests for money. I've seen in the past with clients that we've picked up because the email was acting strangely where a bad guy went ahead, found.

    [00:44:25] Invoices that have been sent out by the purchasing person and the send the invoices out and changed the pay to information on the invoice. So they took the PDFs that they found on the file server of the invoices went in and changed them, change the account that they wanted, the funds ACH into. And once they had that happen, they just sent the invoice out again saying overdue.

    [00:44:54] Off goes in the email and the company receives it and says, oh okay, I need to pay this invoice. Now. Sometimes it marked them overdue. Sometimes they didn't mark them overdue. I've seen both cases and now the money gets sent off and that invoice gets paid and then gets paid to the wrong person.

    [00:45:13] Or maybe they go ahead and they don't send the invoice out, but they just send a little notification saying, Hey, our account has changed. Make sure you. Direct all future payments to this account. Instead. Now you might be thinking wait a second here. Now they send this email out. It's going to go into a bank account.

    [00:45:33] I can recover the money while no, you can't. Because what they're doing is they are using mules. Now you've heard of meals before. He might've even seen that recent Clint Eastwood movie. I think it was called. But typically when we think of mules, as people we're thinking about people who are running drugs well, in this case, the bad guys use mules in order to move money around.

    [00:45:59] And now sometimes the people know what they're doing. The FBI has had some really great arrests of some people who were doing this, particularly out in California, some of them cleaned. Yeah. I didn't know what was happening. It was just somebody, asked me to send money. It's like the Nigerian scam where the Nigeria in the Nigerian scam, they say, Hey I'm, I'm Nigerian prince, you've heard of these things before. And I need to get my money out of the country. I need to place to put them. And so if you have a us account, I'm going to transfer money into it. You can keep a thousand dollars of that 5,000 and I'm going to wire in just as a fee. Thanks for doing this. I, this is so important and it's such a hurry and I'm going to send you the.

    [00:46:46] What they'll often do is send you a money order. It couldn't be a bank check, could be a lot of things, and then you go ahead and you cash it and oh, okay. Or cash just fine. And then you wire the $4,000 off to the bad guy. The bad guy gets the money and is off. Running in the meantime, your bank is trying to clear that bank check or that money order.

    [00:47:14] And they find out that there is no money there because frankly what might've happened? I, this is one I've seen, I'm telling you about a story w we helped to solve this problem, but I had taken out a real money order from a bank, and then they made copies of it. Basically, they just forged it. And so they forged a hundred copies of it.

    [00:47:36] So people thought they were getting a legitimate money order. And in some cases, the banks where the money order was, you mean deposited, did conf confirm it? They called up the source bank. Oh yeah. Yeah. That's a legit money order and then they all hit within a week or two. And now the, you are left holding the bag.

    [00:47:58] So that's one thing that happens. But typically with these mules, the money comes to them in that account. They are supposed to then take that money and put it in their PayPal account and send it off to the next. And it might try jump to through two or three different people, and then it ends up overseas and the bad guys have gotten so good at this and have the cooperation of some small countries, sometimes bigger countries that they actually own.

    [00:48:30] The bank overseas of the money ultimately gets transferred into. And of course there's no way to get the money back. It's a real. So with spoofing, they're trying to trick you into believing the emails from someone that you know, or someone that you can trust. Or as I said, maybe a business partner of some sort in most cases, it's some sort of a colleague, a vendor or a trusted brand.

    [00:48:58] And so they exploit the trust that you have, and they ask you to do something or divulge information. They'll try and get you to do something. So there's more complexity tax. Like the ones that I just explained here that are going after financial employees, there might be some, an accountant, a bookkeeper, or bill payer and receivables payables.

    [00:49:24] I've seen CFO attacks, but the really the spoofed email message looks legitimate on the surface. They'll use the legitimate logo of the company that they're trying to pretend that they're from. For instance, PayPal. Phishing attack. They have a spoofed email sender and typical email clients like you might be using for instance, on Microsoft outlook.

    [00:49:48] The sender address is shown on the message, but most of the time nowadays the mail clients hide the actual email address, or if you just glance at it, it looks legit. You've seen those before these forged email headers. Yeah, it gets to be a problem. Now we use some software from Cisco that we buy.

    [00:50:13] You have to buy. I think it's a thousand licenses at a time, but there were some others out there, Cisco again, by far the best and this, the software. Receives the email. So before it even ends up in the exchange server or somewhere else online, that email then goes through that Cisco server. They are comparing it to billions of other emails that they've seen, including in real time emails that are.

    [00:50:41] Right now. And they'll look at the header of the email message. You can do that as well. With any email client, you can look at the header, Microsoft and outlook calls, it view source. But if you look at the email header, you'll see received. Headers that are in there. So say, receive colon from, and they'll give a name of a domain and then you'll see another received header and give another name of a machine.

    [00:51:08] And it'll include the IP address might be IVF IPV four of your six, and you can then follow it all the way through. So what'll happen is partway through. You'll see, it took a hop that is. Not legitimate. That's where it comes in. Nowadays, if you have an email address for your business, man, a domain, you need to be publishing what are called SPF records.

    [00:51:37] And those SPF records are looked at there compared to make sure that the email is properly signed and is from. The correct sender. There's a SPF records. There's a mother's too, that you should have in place, but you'll see that in the headers, if you're looking in the header. So it gets pretty complicated.

    [00:51:59] The SPF, which is the sender policy framework is a security protocol standard. It's been around now for almost a decade. It's working in conjunction with what are called domain based message, authentication, reporting, and conformance. Heather's D mark headers to stop malware and phishing attacks. And they are very good if you use them properly, but unfortunately when I look, I would say it's still 95% of emails that are being sent by businesses are not using this email spoofing and protection.

    [00:52:35] So have a look at that and I can send you a couple articles on it. If you're in trusted Craig Peter sohn.com.

    [00:52:46] So we've established that email spoofing happens. What are the stats to this? And how can you further protect yourself from email spoofing? Particularly if you're not the technical type controlling DNS records, that's what's up right.

    [00:53:02] Everybody Craig Peter sawn here, your cybersecurity strategist. And you're listening to news radio, w G a N a M five 60 and 98.5 FM. Join me on the morning. Drive Wednesday mornings at 7 34. Of course in the am. There's so much going on in the cybersecurity world. It affects all of us. Now, I think back to the good old days 40 years ago where we weren't worried about a lot of this stuff, spoofing, et cetera.

    [00:53:36] But what we're talking about right now is 3.1 billion domain spoof. Emails sent every day. That's a huge thing. More than 90% of cyber attacks. Start with an email message. Email spoofing and phishing have had a worldwide impact costing probably $26 billion over the last five years. A couple of years ago, the FBI, this is 2019.

    [00:54:07] Reported that about a house. A million cyber attacks were successful. 24% of them were email-based and the average scam tricked users out of $75,000. Yeah. So it's no wonder so many people are concerned about their email and whether or not those pieces of email are really a problem for them. And then anybody else.

    [00:54:34] So a common attack that uses spoofing is CEO fraud, also known as business, email compromise. So this is where the attacker is spoofing or modifying, pretending to be a certain person that they're not they're impersonating an executive or owner, maybe of a business. And it targets. People in the financial accounting or accounts payable departments or even the engineering department.

    [00:55:01] And that's what happened with one of our clients this week. They got a very interesting spoofed email. So even when you're smart and you're paying attention, you can be tricked the Canadian city treasurer. Tricked into transferring a hundred grand from taxpayer funds, Mattel tricked into sending 3 million to an accountant, China, a bank in Belgium, tricked into sending the attackers 70 million Euro.

    [00:55:31] It happens and I have seen it personally with many businesses out there. So how do you protect yourself from email? Spoofing now, even with email security in place, there's some malicious email messages that are still going to get through to the inboxes. Now we're able to stop better than 96% of them just based on our stats.

    [00:55:54] In fact, it's very rare that one gets through, but here are some things you can do and watch out for whether you're an employee responsible for financial decisions, or maybe you're someone who is. Personal email at work. Here's some tricks here. So get your pencil ready. Number one, never click links to access a web.

    [00:56:19] Where you're asked to log in, always type in the official URL into your browser and authenticate on the browser. In other words, if you get an email from your bank or someone else, and there's a link in there to click that says, Hey oh man, here's some real problems. You got to respond right away.

    [00:56:42] Don't do that go to paypal.com or your bank or your vendor's site, just type it into your browser, even though you can hover over the email link and see what it is. Sometimes it can be perfectly legitimate and yet it looks weird. For instance, when I send out my emails that people subscribe to that right there on Craig peterson.com, the links are going to come from the people that handle my email lists for me, because I send out thousands of emails at a time to people that have asked to get those emails.

    [00:57:22] So I use a service and the services taking those links, modifying them somewhat in fact dramatically. And using that to make sure the delivery happened, people are opening it and that I'm not bothering you. So you can unsubscribe next step. You can, if you want to dig in more, look at the email headers.

    [00:57:45] Now they're different for every email client. If you're using outlook, you have to select the email, basically in the left-hand side. Okay. You're going to control, click on that email and we'll come up and you'll see something that says view source. So in the outlook world, they hide it from you.

    [00:58:06] If you're using a Mac and Mac mail, all you have to do is go to up in the menu bar email and view, header and cut off. There it is. I have many times in the past just left that turned on. So I'm always seeing the headers that reminds me to keep a look at those headers. So if you look in the header, And if the email sender is let me put it this way.

    [00:58:31] If the person who is supposed to have sent it to you is doing headers proper, properly. You're going to see. A received SPF section of the headers and right in there, you can look for a pass or fail and response, and that'll tell you if it's legit. So in other words, let's use PayPal as an example, PayPal has these records that it publishes that say all of our emails are going to come from this server or that server of.

    [00:59:04] And I do the same thing for my domains and we do the same thing for our clients domains. So it's something that you can really count on if you're doing it right, that this section of the headers. And that's why I was talking about earlier. If you have an email that your sending out from your domain and you don't have those proper headers in it, there's no way.

    [00:59:31] To truly authenticate it. Now I go a step further and I use GPG in order to sign most of my emails. Now I don't do this for the trainings and other things, but direct personal emails from me will usually be cryptographically signed. So you can verify that it was me that sent it. Another thing you can do is copy and paste the text, the body of that email into a search engine.

    [01:00:03] Of course I recommend duck go in most cases. And the chances are that frankly they've sent it to multiple people. That's why I was saying our Cisco based email filter. That's what it does, it looks for common portions of the body for emails that are known to be bad, be suspicious of email from official sources like the IRS, they're not going to be sending you email out of the blue most places. Aren't obviously don't open attachments from people that you don't. Special suspicious ones, particularly people we'll send PDFs that are infected. It's been a real problem. They'll send of course word docs, Excel docs, et cetera, as well.

    [01:00:54] And the more. I have a sense of urgency or danger. That's a part of the email should really get your suspicions up, frankly, because suggesting something bad is going to happen. If you don't act quickly, that kind of gets around part of your brain and it's the fight or flight, right? Hey, I gotta take care of this.

    [01:01:17] I gotta take care of this right away. Ah, and maybe you. So those are the main things that you can pay attention to. In the emails, if you are a tech person, and you're trying to figure this out, how can I make the emails safer for our company? You can always drop me an email as well. Me, M [email protected].

    [01:01:43] I can send you to a couple of good sources. I'll have to put together a training as well on how to do this, but as individually. At least from my standpoint, a lot of this is common sense and unfortunately the bad guys have made it. So email is something we can no longer completely trust. Spoofing is a problem.

    [01:02:05] As I said, we just saw it again this week. Thank goodness. It was all caught and stopped. The account was not. It was just a spoofed email from an account outside the organization that was act Craig peterson.com. Stick around.

    [01:02:24] The value of crypto coins has been going down lately quite a bit across the board, not just Bitcoin, but the amount of crypto mining and crypto jacking going on. That hasn't gone down much at all.

    [01:02:48] hi, I'm Craig Peter Sohn, your cyber security strategist. And you're listening to news radio, w G a N a M five 60 and FM nine. Point five, you can join me on the morning drive every Wednesday morning at 7 34, Matt and I go over some of the latest in news. You know about crypto coins, at least a little bit, right?

    [01:03:15] These are the things like Bitcoin and others that are obstensively private, but in reality, aren't that private. If you receive coins and you spend coins, you are probably trackable. And if you can't spend that, the crypto currencies, why even bother getting it in the first place. One of the big drivers behind the price of these crypto currencies has been criminal activity.

    [01:03:48] We've talked about that before. Here's the problem we're seeing more and more nowadays, even though the price of Bitcoin might go down 30%, which it has, and it's gone down in bigger chunks before. It does not mean that the bad guys don't want more of it. And what better way to mine, cryptocurrency then to not have to pay for.

    [01:04:15] So the bad guys have been doing something called crypto jacking. This is where criminals are using really ransomware like tactics and poisoned website to get your computer, even your smartphone to mine, cryptocurrencies for. No mining, a Bitcoin can cost as much in electric bills that are in fact more in electric bills.

    [01:04:43] Then you get from the value of the Bitcoin itself. So it's expensive for them to run it. Some countries like China have said, no, you're not doing it anymore because they're using so much electricity here in the U S we've even got crypto mining companies that are buying. Old power plant coal-fired or otherwise, and are generating their own electricity there locally in order to be able to mine cryptocurrencies efficiently, effectively so that they can make some profit from it.

    [01:05:18] It's really quite the world out there. Some people have complained about their smartphone getting really hot. Their battery only lasts maybe an hour and it's supposed to last all day. Sometimes what's happened is your smartphone has been hijacked. It's been crypto jacked. So your smartphone, they're not designed to sit there and do heavy computing all day long.

    [01:05:45] Like a workstation is even your regular desktop computer. Probably isn't. To be able to handle day long mining that has to happen. In fact, the most efficient way to do crypto mining of course is using specialized hardware, but that costs them money. So why not just crypto Jack? All right. There are two primary ways.

    [01:06:09] Hackers have been getting victims, computers to secretly mine. Cryptocurrencies one is to trick them into loading. Crypto mining code onto their computers. So that's done through various types of fishing, light tactics. They get a legitimate looking email that tricks people into clicking on a link and the link runs code.

    [01:06:30] Now what's interesting is you don't, even for cryptocurrency crypto jacket, you don't even have to download a program in. To have your computer start mining cryptocurrencies for the bad guys. They can use your browser to run a crypto mining script. And it runs in the background. As you work right, using up electricity, using up the CPU on your computer.

    [01:06:58] They also will put it into ads. They'll put it on a website and your browser goes ahead and runs the code beautifully. So they're really trying to maximize their returns. That's the basics of crypto jacking what's been particularly bad lately has been the hackers breaking into cloud account. And then using those accounts to mine cryptocurrency, one of the trainings that I had on my Wednesday wisdoms has to do with password stuffing and my Wednesday wisdoms, you can get by just subscribing to my email over [email protected].

    [01:07:44] But what happens here is they find your email address. They find. Password on one of these hacks that is occurred on the dark web. You weren't on the dark web, but your username or email address and password are there on the dark web. And then they just try it. So a big site like Amazon, or maybe it was your IBM also has cloud services can be sitting there running along very well, having fun.

    [01:08:16] Life's good. And. Then they go ahead and try your email address and password to try and break in. Now, you know how I keep telling everybody use a good password manager and this week I actually changed my opinion on password managers. So you know, that I really like the password manager that you can get from one password.com.

    [01:08:44] It really is fantastic. Particularly for businesses, various types of enterprises, one password.com. However, where I have changed is that some of these browsers nowadays, particularly thinking about Firefox Google Chrome safari, if you're particularly, if you're on a Mac, all have built in password managers that are actually.

    [01:09:09] Good. Now they check. Have I been poned, which is a site I've talked to you guys about for years. To make sure that your accounts are reasonably safe than not being found on the dark web, the new password that it came up with or that you want to use. They check that as well. Make sure it's not in use. So here's an example here.

    [01:09:32] This is a guy by the name of Chris. He lives out in Seattle, Washington, and he makes mobile apps for local publishers. Just this year, new year's day, he got an alert from Amazon web services. Now Amazon web services, of course, cloud service. They've got some really nice stuff, starting with light ship and going up from there, I've used various services from them for well, since they started offering the services over very many years and.

    [01:10:04] They allow you to have a computer and you can get whatever size computer you want to, or fraction of a computer. You want to, he got this alert because it said that he owed more than $53,000 for a month's worth of hosts. Now his typical Amazon bill is between a hundred and 150 bucks a month. My typical Amazon bell is now 50 to maybe $80 a month.

    [01:10:34] I cannot imagine getting a $53,000 bill from our friends at Amazon. So the poor guy was just totally freaking out, which is a very big deal. So I'm looking at an article from insider that you can find a business insider.com. They were able to confirm that, yes, indeed. He got this $53,000 bill from Amazon and yes, indeed.

    [01:11:00] It looks like his account had been hacked by cryptocurrency miners. So these guys can run up just incredibly large charges for the raw computing power. They need to produce some of these digital cryptocurrencies, like Bitcoin there's many others out there. But this isn't new. This is happening all of the time.

    [01:11:23] Google reported late last year, that 86% of account breaches on its Google cloud platform were used to perform cryptocurrency mining. So make sure you are using a good password manager that generates good passwords. And I have a special report on passwords. You can download it immediately when you sign up for.

    [01:11:48] My email, my weekly email [email protected] and it tells you what to do, how to do it. What is a good password? What the thinking is because it's changed on passwords, but do that and use two factor authentication. Multi-factor authentication as well. And I talk about that in that special report too.

    [01:12:11] And visit me online. Sign up right now. Craig Peter sohn.com.

    [01:12:17] We're moving closer and closer to completely automated cars, but we want to talk right now about car hacks, because there was an interesting one this week that has to do with Tesla. And we'll talk about some of the other hacks on car.

    [01:12:33] Connected cars are coming our way in a very big way.

    [01:12:38] We just talked about the shutdown of two G and 3g in our cars. We, it wasn't really our cars, right? Two G 3g. That was for our cell phones. That was. Years ago course now for four GLTE 5g, even 10 G is being used in the labs. Right now. It's hard to think about some of those older technologies, but they were being used and they were being used by cars, primarily for the navigation features.

    [01:13:13] Some cars use these data links, if you will, that are really on the cell phone network in order to do remote things like remote start. For instance, I have a friend who's Subaru. Of course was using that. And now she's got to do an upgrade on her car because that 3g technology is going away depending on the carrier, by the way, some of it's going away sooner.

    [01:13:40] Some of it's going away later, but it'll all be gone at the end of 2020. What are we looking at? As we look into the future, I'm really concerned. I don't want to buy one of these new cars at the same time as I do, because they are cool, but I don't want to buy one of those because of the real problem that we could have of what well of having that car.

    [01:14:07] I need an upgrade and not been able to do it. I watched a video of a guy who took a Tesla that hadn't been damaged badly in a flood, and it was able to buy it for cheap. Why? Because Tesla will not sell you new motors and a new batteries for a car like that. So he got the car for cheap. He found a Chevy Camaro that had been wrecked, but its engine and transmission were just fine.

    [01:14:37] He ripped everything out of the Tesla and went ahead after that, cause you got to clean that out, and water damage. You spray wash all to the inside. He got right down to the aluminum, everything that wasn't part of the core aluminum chassis was gone. And then he built it back up again. He managed to keep all of those Tesla systems working, that, that screen that you have upfront that does the temperature control, cruise maps, everything out.

    [01:15:09] He kept that it was able to work. The, automated stuff, cruise control type stuff. And now he had a very hot car that looked like a Tesla. He took it out to SEMA, which is pretty cool. I'd love to see that, but it was a Tesla with a big V8 gasoline engine in it. He's done a, quite a good job on it.

    [01:15:33] It was quite amazing to see it took them months. It was him and some of his buddies. These new cars are even more connected than my friend Subaru is they get downloads from the. Some of them are using Wi-Fi and 5g. Really one of the big promises of 5g is, Hey, our cars can talk to each other because now you can get a millisecond delay in going from one car to another versus what you have today, which can be a half a second or more, which can be the difference between having a rear end collision and being able to stop in time when it comes to these automated system.

    [01:16:15] So they are more connected. They connect to the wifi in your homes. They connect to obviously the 5g network, which is where things are going right now. But what's happening with the hackers because really what we're talking about, isn't a computer on wheels. Oh no. Dozens of computers inside that car and your car has a network inside of it and has had for many years, this can bus network and even fancier ones nowadays that connect all of your systems together.

    [01:16:50] So your entertainment system, for instance, is connected to this network. And that was used. You might remember a couple of years ago on a Chrysler product where the bad guy installed. Or using the thumb drive onto that entertainment system and had a reporter drive that car down the road. This is all known.

    [01:17:13] It was all controlled. And was able to the bad guy right there, the demonstration in this case, I guess you'd call them a white hat hacker. He drove that car right off the road while the reporter was trying to steer otherwise because cars nowadays don't have a direct linkage between anything in any.

    [01:17:36] That's why I love my 1980 Mercedes TESOL. You turn the steering wheel. It isn't actually connected to the wheels to that front end of the car. All it's doing is telling the computer you want to turn and how much you want to turn that brake pedal. Doesn't actually. Compress hydraulics and cause the brakes to engage that fuel pedal doesn't actually move the throttle on the car.

    [01:18:01] The throttle is really being controlled and moved by the computers. So the car is completely electronic. It feels like a regular car, right? We're not talking about the Tesla's of today or tomorrow. We're talking about Volvos that have been sold for more than a decade. We're talking about a lot of different cars.

    [01:18:22] So now you have a platform on wheels that can be dangerous because it can be, in some cases, remotely controlled, it can have software that may be crashes. We know that part of the infrastructure quote, unquote bill, which contains almost no infrastructure. It's amazing how they named these things. Isn't it.

    [01:18:43] And what is it like 6% it actual infrastructure and the infrastructure bill? One of the things in there that is not infrastru. Is a demand, a law that says the car manufacturers have to include a remote. Button, if you will, so that a police officer could go ahead and say, okay, I'm pursuing this car and they're not stomping.

    [01:19:09] I don't want to risk people's lives. As this bad guy tries to elude me here in backstreets. Kids can get hit, et cetera. So they push the button and the car stops that all sounds great. The problem is that you could potentially be opening some security problems by having this remote stop button that can be used by anybody really right.

    [01:19:38] Since when is it going to be limited to just law enforcement? Isn't that a problem? According to Caren driver, I'm looking at their magazine right now. They're saying that there were at least 150 automotive cybersecurity incidents in twenty nineteen, a hundred and fifty incidents, part of a 94% year over year increase since 2016.

    [01:20:03] In other words, every year. The number of automotive, cybersecurity and incidences has doubled. And that's according to report from a company called upstream security. So we're lost. So looking at what w maybe ransomware for a car. So that your car gets hacked. You can't hack my 1980 Mercedes diesel.

    [01:20:26] It is impossible to hack into an unconnected car, but if you are driving a vehicle it's likely at risk from some sort of digital true. We've even seen from some of the bugs. We've seen cars from Japan that have decided to drive into the Jersey barrier because it misunderstands exactly what it is. We've seen cars from Tesla.

    [01:20:55] Drive right into the back of a parked fire truck mentioned doing that at speed, right? And cause a fire truck full of water, et cetera. I've actually seen that one happened personally. So the more sophisticated the system is, the more connected your vehicle is. The more exposed you are in Detroit free press has a great little article on that right now.

    [01:21:21] And in there he's saying we have taken. Whatever model car you think of. And we hack them through various places. I can control your steering. I can shut down and start your engine. Control your brakes, your doors, your wipers, open and close your. There's a lot of people who are trying to break into these cars.

    [01:21:44] And there's a lot of people who are trying to protect them. That hacker duo back in 2015, who took control of that Jeep Cherokee, just think about that sort of. There's an Israeli based automotive cybersecurity company who told the free press that he expects the current trend of hackers, holding digital data on computers for ransom to also move to cars.

    [01:22:10] So when this happens, the driver will not be able to start the vehicle until they pay off the rant. Or suffer the consequences, which could be wiping the cars systems operating systems could be Kenning the car to catch on fire. Think of what can happen with each generation with those batteries.

    [01:22:30] There's no way around it. You're going to have to get it towed and get all of the software reloaded in the company. And now this week, it comes out that in 19 year old kid said that he was able to hack into over 25 Teslas that he tried via a bug in a popular. It's an open source tool that people are using to link into their Teslas to do various types of remote control.

    [01:22:59] And he posted a tweet on this guy's name's David Colombo. You'll find them on Twitter, went viral and he reported the vulnerability to the people who are maintaining the software and they fixed it. In fact, the very same day and Tesla also pushed updates to their vehicle. That invalidated the signatures and the key exchanges that we're having.

    [01:23:26] So this is a 19 year old researcher. He's able to hack into cars in 13 countries, 38, 13 countries. Yeah. Worth of Teslas without the owner's knowledge. No, he says I, I can not. Doors, I can turn off the security system. I can open windows. I keyless start and things turn on the stereo, honk the horn view, the cars location, and if the driver was present, but he doesn't think he could actually move the vehicle remotely, but that's a 19 year old.

    [01:24:00] What's going to happen when we implement the law that was just passed that says our cars have to be remotely controllable by anybody basically. Yeah. It's scary. Hey, I want to invite you guys to take a minute, go to Craig peterson.com. Make sure you sign up for my newsletter there, and I'll keep you up to date on all of this stuff and you'll even get my show notes.

    [01:24:26] Craig peterson.com.

    1 hr 25 min
  • Why Is Russia Password Spraying Hurting You? What Are They Trying to Do? And What Is It?

    Why Is Russia Password Spraying Hurting You? What Are They Trying to Do? And What Is It?

    This is one of the top topics I've had people ask about lately: How can you protect yourself and your business against Russian hackers? So I've got a presentation. We're going to run through it. We're going to talk about what you can do about it.

    [Automated transcript follows]

    This has been a long time coming. I have been doing a lot over the years of webinars of online meetings, trying to help people understand what's going on, what can be done.

    [00:00:28] And I got a great email this week from one of the listeners. Who's been a man on my email list now for years, I'm not even sure how many years. And he was saying, Hey, thanks for giving all of this information for free for small businesses. And afford it. And I got to thinking because there've been a lot of requests lately, for instance, backups how should I be doing them?

    [00:00:52] What should I be doing? And a number of other topics that really all go together into the, how do I protect myself, my business. From ransomware from these Russian hackers. So that's what we're going to be talking about today. We're going to go through a few of these. This is going to be a series.

    [00:01:10] We're going to continue this here and weeks ahead, and I appreciate all your feedback. And if you miss part of it, make sure you email me just M. Craig peterson.com. Let me know, and I'll be glad to send some of it to you. Now I'm recording this on video as well. So it's great when you're driving around and listening in picking up some tidbits.

    [00:01:34] And if you do want to see the recorded version again, dropping them in an email to [email protected] or search for me on YouTube or on one of the other sites that are out there like grumble and you'll. This as I release it. Cause this is going to take a few weeks to really get into the whole thing.

    [00:01:55] So let's get started. I'm going to pull this up here. Full screen. For those watching at home and what this is called today, we're talking about protecting your business and your self from Russian hackers because they have been out there. They have been causing just all kinds of problems, but there's a few things that you can do.

    [00:02:18] And I have them up on the screen here. Let me pull them up, but I want to get into the background first. Russian ransomware group. They're a bunch of bad guys and it's called Conti. Now. Conti has been around for a long time. These are the guys that have been ransoming us. They're the guys who ran to mean the businesses they've been rants.

    [00:02:40] Government, you might've heard them. They've got into hospitals. They have been all over the place and they've raised a whole lot of. For the Russians. I'm also going to tell you about a couple of things you can do here. Cause there's a real neat trick when it comes to keeping Russians out of your computers, but Conti decided, Hey, listen, we are all for Russia and president and Putin.

    [00:03:03] So they came out with an official warning, oh, I want to read this to it says if anybody. We'll decide to organize a cyber attack or any war activities against Russia. We are going to use our all possible resources to strike back at the critical infrastructures of an enemy. Yeah, no, not the best English, but much better than my Russian.

    [00:03:25] I got to say that I know two words or so in Russian, but they said that they were announcing full support for president. That's a pretty bad thing. If you asked me, they also have ties to Russian intelligence intelligence, but what are we talking about really? Think of the KGB.

    [00:03:43] The FSB is what they're called nowadays, but directly tie. China and North Korea, Iran, or also now tied in with Russia to varying degrees, but all of them are a little bit concerned about getting into it a little too much, but we're going to talk about their tactics. That's what's important today. What are they doing?

    [00:04:05] Why are they doing it? What can you do about. So the first thing is password sprain. This is big deal. I've got a nice big slide up here. I like that color blue. I don't know about you, but I think it's pretty, but password sprain is something we all need to understand a little bit better. It's a brute force attack that has been really hurting.

    [00:04:30] Many of us. Let me see if I can get this to work. For some reason it has decided it just doesn't want. Let me see here. What is up? Oh, is something isn't it's just, I'm getting a white screen, but it's a brute force attack targets users who have common passwords. Now this is a problem. When we're talking about passwords.

    [00:04:55] If you have a password that has been breached in any of these breaches that have gone on over the last, however long, right? 30 years plus now that password is known to the bad guy. So what they'll do is they'll take that common password and they'll start to try it. So password sprain is where they will go to a bank site or they'll go to Google.

    [00:05:21] The, oftentimes they're trying to get at your email accounts. So if you have Google email or Yahoo or Hotmail, they'll try it. Use passwords that they have found against accounts that they have found on those various sites that ends up being quite a big problem for everybody out there. Okay. I got that screen back here.

    [00:05:42] So I'll put that up for those people who are well. But they will send multiple times attacks using variations of these passwords. And it's known as a low and slow method of password hacking because if they were to go bam, and send all of these passwords and login attempts. They get caught.

    [00:06:06] The automated systems would say, Hey, wait a minute. This is not good. We're going to cut you off. In fact, that's what I do for my client. We have remote access using SSH, which is a an encryption session so that we can have a terminal session. And if you try and log in three times, We automatically zap you, right?

    [00:06:28] We shut you down. So they take a very slow approach to this password sprain technique. And they're also going after volume, which makes a whole lot of sense. And there are right now, billions of passwords usernames, email addresses that have been stolen that are sitting out in the dark. So you've got to make sure that you are not reusing passwords.

    [00:06:54] How many times have we talked about that? You've got one common password that you're using over and again, while that's a problem, but they're not going to keep hacking your account. They're going to switch from one account to another because they don't want to get locked out.

    [00:07:09] Just like I lock out somebody who's trying to get in. So if someone's coming from that same. IP address that same internet site. And they're trying to log into that same account multiple times. Bam. They are gone. So with path's word sprain, they're trying to get around the problem of you noticing they're trying to get into a bunch of different accounts and they try and leverage it.

    [00:07:34] So they'll oftentimes use multiple computers that they've stolen access to. We've talked about that before too. It gets to be a real big. Now they're also targeting these single sign-on and cloud-based applications, because once they're on. Using one of these federated authenticated authentication protocols, they can mask the malicious traffic.

    [00:08:00] We've heard some of these hacks lately where they're using a token that they managed to pick up from somebody's email, I account, or they got onto Microsoft and they got into the email account on Microsoft. That happened recently. In a supply chain attack, solar winds. You heard about that 20, 21, right?

    [00:08:21] So they're going after these email applications, including Microsoft or Microsoft has done they're going after routers and internet of things, devices for a very good reason, those IOT devices, which are things like your smart lights, they can be. Controlling the cameras outside, they go on and on there's thousands, millions of them.

    [00:08:44] Now I actually all the way through your microwave, they tend to not be very well protected. So that's a real big target for them. So step. They want to acquire a list of usernames. Step two, they're going to spray the passwords. Where do they get those passwords in those usernames? Or they get them from breaches.

    [00:09:06] So again, if you have an account that's breached at some online shopping site, a big one, a small one, it doesn't really mean. That particular breach is now well known and they can, will and do gain access to your account which is step three, gain access to it. It gets to be a serious problem.

    [00:09:26] Okay. How do you know if you are under attack? Number one? There is a spike in failed. Log-ins this is where having a system and there's technical terms is tough for this. I'm trying to avoid a lot of those terms, but this is where the system is watching logins, noticing that there's a problem and going ahead and stopping it, not just noticing that, but stop. Very important to do. There are a high number of locked accounts, which means what it means that again, someone's been trying to log in. You should make sure that your account, if there are invalid, lock-ins automatic. Locks it out after some number of attempts and five attempts is usually considered to be okay.

    [00:10:14] I know on my phone, for instance, I have a higher number of the neck, cause sometimes the grandkids get at it. But when it comes to your business account, when it comes to your bank account, you probably don't want to have a whole bunch of. Of a attempts, and then in known or valid or invalid, I should say user attempts again.

    [00:10:36] Why are they trying to log in with a username that just doesn't exist? Yeah, it can be a problem. Hey, when we come back. We're going to talk about some steps. Like you can take here to really remediate, maybe even stop a password spraying attack. I've already given you a few ideas here, but what are some act of things that you can do, particularly for a small business to really protect yourself?

    [00:11:04] Hey, stick around. We'll be right back. Craig peterson.com.

    [00:11:10] Russia has, hacking our computers, Russia's continuing to hack our computers and this is a real problem. So we are going to talk right now about how to stop some of these things. We already talked about password sprain. How do you start?

    [00:11:26] There are a lot of things we have to pay attention to, and that's what I'm going to be doing in the weeks ahead.

    [00:11:33] We're going to be going through some of the things you need to do to keep yourself safe. Keep your business safe in this really dangerous online. There are so many things going on. So many people that are losing their retirement businesses, losing their operating accounts. We've seen it before with clients of ours while you know their clients now.

    [00:11:59] And it was just a devastating thing to them. So I don't want that to happen to you now, if you are interested. All of this is recorded and I am doing this as video as well. We've got slides and you can find out more about it. Just email me M [email protected]. It's really that simple. And I didn't let me know.

    [00:12:24] And I'll be glad to send it off to you. Okay. This is available to anybody I'm trying to help. And we've had a lot of emails recently about some of these things. So th this is covering everything from the password spraying we're talking about right now through backups and other things that you need to do.

    [00:12:43] Let's get going on our sprain problem. So w what are the steps that we need to take an order to really remediate against one of these password spraying attacks? And frankly, it is. Oh, a lot to do. It has a lot to do with our users and what we do, if you're a business, if you are an individual, we need to be using longer passwords.

    [00:13:12] Now we're not talking about all of these random characters that we used to have. I remember having to have my password be at least four characters, long APAC, when didn't even have to have a username, it was just all based on the password. And things changed over the years, the latest standards that are out there right now come from this too, which is the national Institute for science and technology.

    [00:13:37] They are the guys that put together, all of the guidelines said federal government and businesses need to follow. And they're telling us that a longer passwords means elaborate pass phrase. So you should use 15 character passwords. I had an article just a couple of weeks ago saying that an eight character password can be cracked almost instantly, certainly within an hour, any eight character password.

    [00:14:08] So if you're still using that, you've got to make a change. And obviously nine characters is a lot more possibilities, takes a lot longer to crack. I don't have those numbers right in front of me, but 15 is the ideal. So use pass phrases instead of single words. So phrases like I don't know secretary of one, the Kentucky.

    [00:14:34] There you go. There's a phrase. So what you would do is put, maybe dashes between each one of the words. Maybe you would go ahead and use a comma, put some numbers in there, put some special characters in upper lowercase, right? So it's basically on uncrackable at that point. And that's what you want.

    [00:14:53] Next one. When we're talking about rules for your passwords, the best passwords are the passwords that you can remember without writing them down and words that don't make sense to anyone else's. I remember taking a memory course a few years back and they had random words and you had to remember them.

    [00:15:18] And the whole idea was okay, visualize this happening. And as I recall, man, it's been a lot of years I won't say decades, but it hasn't been. Since I did this, I still remember a part of it, it was first word was airplane. Next was all envelope. The next one was paper clip. Next one was pencil.

    [00:15:38] So I visualized an airplane flying into an all envelope and that all envelope then goes into a paper clip and a pencil writes on the outside. Like it's addressing it to someone. That is a good little password, actually airplane or envelope, paperclip, a pencil with a mixed case and maybe a number two or special symbol thrown in.

    [00:16:05] Those are the types of rules that we're talking about. The types of rules that really. Next up here. Oops. Wrong keyboard. Stay away from frequently used passwords. We've talked about this many times. If you're using one of the better password managers, like for instance, one password, you will automatically have any passwords that you are there in Shirin or that it creates you'll have them checked via a website out there.

    [00:16:37] It's called. Yeah. Okay. It's called. Have I been poned I, and I hated to say this because how do you spell it? It's all one big, long word. Have I been poned to.com and poned is P w N E d.com. It will tell you if a password that you're trying to use is a known password. If it has been found out in the wild, okay.

    [00:17:02] Use unique passwords for every site you visit, I can't stress this enough. We were talking about password sprain. If you use the same password and email address on multiple sites, you're in. Because all they have to do is try your email address and your password for whichever site it is that they might want to try out.

    [00:17:27] Remember, many of them are trying to get into your email and they have done that successfully. With Microsoft email, if you have their Microsoft 365 service and you might want to read the fine print there very carefully, because Microsoft does not guarantee much of anything. You make sure you back it up yourself.

    [00:17:50] Make sure you do all of these things because Microsoft just plain, isn't doing them for you. Next one here. Next up is our password manager. And I mentioned this before installing and using a password manager is phenomenal. It automates the generation of passwords. If you have. Integrated with your web browser.

    [00:18:15] It now allows your web browser to work with your password manager. So when you go to a site, you can have it pull up your passwords. How could it be much easier than that? It's really rather simple. That way it's keeping track of your logins. And again, One password.com is the one I recommend and people get confused.

    [00:18:36] When I say that, when I'm saying one password, I don't mean only have one password used for everything. One password is a name of a company. Okay. So it Talking about only having a single password, but use a password manager. And I've got all of these up on the screen right now. If you're interested in getting copies of these, you can go ahead and just email me M [email protected].

    [00:19:04] And I'll make sure I send you a copy of the slide deck of this presentation as well. Cause this is just so important, frankly, but having these points is going to be huge for you. Now strange activity. That's another very big deal. And we're going to talk about this when we get back, what is it?

    [00:19:25] What does it mean? But I'm going to hold off the rest of this, I think for another week. But right now, what let's hit this, we're talking about odd log-in attacks. A lot of login attempts, the excessive login attempts trends in unusual activities take any, you need to basically take measures to block it and determine if this activity is legitimate.

    [00:19:50] Is someone just for forgetting their password and spraying themselves or what's going on? Okay. There you go. Simple. Hey, everybody, you can find out a lot more and you'll be getting links to this automatically to these videos, et cetera. If you're on my email list, Craig peterson.com and you can email me M [email protected].

    [00:20:15] We'd be glad to send you this or any other information I might have. All right. Take care. We'll be right back.

    [00:20:23] Putin has been working for a while. In fact, it looks like as early as September in 2021, Putin started going after major us corporation. So we're going to talk about that. And what does it mean.

    [00:20:39] Putin has been going crazy for a while. I'm going to put this up on the screen for those of you who are watching either on rumble or YouTube, but Putin planned this whole invasion apparently quite a while ago.

    [00:20:56] And I got an article from the Washington post up on MSN talking about what Putin did at least a little bit about what he did. And you can see right here if you're following. That Russian agents came to the home of Google's top executive and Moscow. And what they did is gave an ultimatum. They told that Google, a senior executive that they needed.

    [00:21:24] Pull down an app that was in use in Russia. And this app was polling. It was for people to do polls and say, Hey what do you think about Putin's garden performance, et cetera. We do them in the U S all of the time you hear about the polls right left and center. Poland, which is a small country next to another small country called Ukraine next to a large country called Russia.

    [00:21:50] But we're talking about Paul's favoribility polls. What do you think they should be doing? What do you think that the government should be doing and maybe what they should not be. So Putin didn't like this. He didn't like this at all. And so what he did is he sent a couple of guys ex KGB, FSB, the secret police over in Russia by to visit this Google executive.

    [00:22:16] If you're the Google executive, what are you going to do? If you Google. Yeah, you're going to say, oh my gosh, I'm out of here. So I'm not sure if she, if this executive was an American or Russian, this article doesn't seem to be clear about it, but what happened is they said, okay let's go hide.

    [00:22:41] So they rented a hotel room for the. They put her in it and they rented the room under an assumed name. So it wasn't the real name of the executive. It wasn't tied into Google and they thought, okay, now we're pretty safe. Cause you got a hotel security, I guess there are a couple of Google people hanging out with her and they felt pretty safe.

    [00:23:04] What happens next? There is a knock on the door. These same agents, again, that are believed to be Russian secret. Police showed up at her room and told her that the cock was still ticking because they had given her 24 hours for Google to take down the app because Putin, dental. People weren't particularly pleased with Putin.

    [00:23:31] So at that point, of course it was forget about it. And within hours, Google had pulled down the app. Now you might complain, right? A lot of people might complain about it. It's one thing for a company like Google or apple to capitulate, to a government to do maybe some censorship, like the great firewall of China.

    [00:23:54] You might've heard of that where the Chinese citizens can't get certain information. Russia has something pretty similar and us companies have gone ahead and helped build it, provided the technology for it and put it in place. They sold it to them. I don't like that in case you didn't guess, right?

    [00:24:12] I'm all for free speech. I think it's very important for any form of a democracy. No question about it, but these companies apparently don't have a problem with that. However, now this is something, a little different. If you have employees who are being threatened and I mean threatened to serve 15 years in a Russian prison, what are you going?

    [00:24:39] Are you going to say no, I'm going to leave that app up. And then now all of a sudden your executives, or even a coder, somebody a programmer, like the guy that sweeps the floors, whatever are you going to let them be arrested so that you can have this app up on your Google play store or your app store over the apple side?

    [00:24:59] Probably not because frankly, this is something that is not worth it. So what are you. I think the only answer is what we've seen company after company do, and that is get out of Russia completely. And there was an interesting story. I read this recently about McDonald's you might remember back in the Soviet days, McDonald's worked out this deal with the Soviet union to open a McDonald's right there in downtown Moscow.

    [00:25:32] I guess it was pretty prominent. I don't know if it was, I think I might've been even on red square and there were people like. To have an American hamburger and it's been pretty popular the whole time. McDonald's closed that store and pulled out of the country. Starbucks has pulled out, are they going to reopen?

    [00:25:50] Cause I don't think either one of them said, forget about it. We're not coming back, but I know both of them have closed on operations. Automobile manufacturers from the U S have closed on operations. What is their choice? You can't just go ahead and say, okay yeah. Okay. Yeah. You're just going to arrest people or, we'll keep quiet for now and come back later.

    [00:26:12] What are you supposed to do? That's part of the problem with these oligarchies, with these people who are basically all powerful. Now we actually see some of that here in the us, which is just as shame, just a shame because we see these companies going ahead and cutting out free speech saying, oh, you can't say that there was a time where if you said masks work, that you would have been censored. And then there was a time where if you said masks don't work. You cloth mass don't work, you would have been censored. There was a time when you said masks aren't necessary. You would have been censored right now, but the science is settled.

    [00:26:56] It was just crazy. Science has never settled and oh, we could go on with this for hours and hours, but potent is not a good guy. And this article, I'm going to bring it up on the screen here again. But this article talks about. And a single year. And again, this is MSN. Potent had his political nemesis, Aloxi Novolin novel ne yeah, I got it right.

    [00:27:23] He had him in prison after a poisoning attempt, felled to kill him. Do you remember that whole poison attempt? Where they gave him this really nasty radioactive bride product, as I recall, and potent went ahead and basically shut down. They pushed all of these independent news organizations to the brink of extinction.

    [00:27:46] Look at what happened with Russia today. The entire staff walked off on the. Saying, we're not going to report on any of these lies that are coming out of Moscow. It's happened again and again, Putin orchestrated a Kremlin controlled takeover of Russia's Facebook equivalent, and he's also issued liquidation orders against human rights organizations.

    [00:28:12] And so all this is going on. What are you going to do if you're. If you're a Google, right? I can see the criticism of those countries or companies should say when they're cooperating with the regimes, putting in place, things like facial recognition to, to spy on people, to have a social credit system, these great firewalls in these countries.

    [00:28:34] But when you have something like this happen, I forget about it. There's nothing you can do. And the crackdown is accelerated Facebook and Twitter were knocked offline by the government for millions of Russians news outlets had survived the state harassment for years, shut down in the face of a new law impose.

    [00:28:55] 15 year prison sentences for spreading fake news. It's incredible what has happened. And we've got to be careful here in the U S too, because we see this censorship, there's a lot of complaints about what was happening under Donald Trump president and old Biden, both Obama and Biden.

    [00:29:15] Both of those have done some of these same things to a lesser extent. Stick around. We'll be right back.

    [00:29:23] This whole war with the crane, Ukraine and Russia has brought a few things to light here over the months, and really the more than year that it's been leading up to the beginning of that war even, but we've got clear view in the news again. Yeah.

    [00:29:39] am also besides broadcasting this on the radio, we're doing it in video two. So you can always follow along at rumble or at YouTube, but there's a great article here.

    [00:29:52] I have up on my screen for you to see. And this is from writer. Para carried over on MSN. And it is an exclusive story talking about Ukraine, using something called clear views. AI facial recognition. This to me is absolutely fascinating because what is happening. Is the technology that Clearview develop and has it been selling to police forces in the United States is being used on the battlefield and.

    [00:30:27] How here's what the technology did. And does Clearview illegally went on websites, major websites all over the world and did what we call scraping. Now, scraping is where they go to the site and they grab the pictures. So they scraped Facebook. They scraped you tube. They scraped. Dan and many more.

    [00:30:54] And then they put it all into a big database that told them where they found it, who that person was. And then they also took that biometric information from that image of the face and came up with some unique codes, a hash basically is what they did. And. Now what Clearview is doing is if you are a police organization, you can get a little app that runs right there on your.

    [00:31:22] And you have an encounter with someone you're a policeman, right? Let's say, and you just hold the camera up and it gets a picture of that person. It now finds the background information on them. And then you can use that tied into the police databases to check and see if there's any record of this person.

    [00:31:42] If they've been doing anything illegal. It's really quite cool. What they're able to do and scary at the same time, we use the same basic technology over in Afghanistan. So literary troops as they're out, and they're having encounters with civilians, people in the streets, fighters, et cetera. They could hold the device up.

    [00:32:04] It would identify them. It went further than just the face that actually did retinal scans and things, all kinds of cool stuff, but basically recognize the face. And they were able to tell if this was a friend of foe or. So a friend might be someone who worked as a translator who has been known to be helping the us troops in Afghanistan, et cetera.

    [00:32:29] So we built this huge database of hundreds, of thousands of people's biometrics person, very personal information in it. And if they were getting paid even how much they're getting paid, all of that was in the database, in the backend. And then we abruptly. And we left that equipment behind. I hope the database was destroyed.

    [00:32:52] I haven't found anything. Absolutely conclusive on it. That the withdrawal from Afghanistan was frankly unforgivable. It just I can't believe they did what they did at any rate. This is Clearview. This is this company. So now that same technology has moved to Ukraine. What's interesting. About this whole Ukrainian thing to me was okay, great.

    [00:33:18] Now they can identify people. Can they really identify a pretty much everybody? Who are they going to identify? As it turns out clear Clearview also illegally stole photos of people over in Russia and in Ukraine. So the clear view founder said that they had more than 2 billion images from. How's that right from this social media service called V contact a or somebody like that out of a database of 10 billion photos total.

    [00:33:52] So one out of five of the pictures they scraped was Russian, which surprised me. So the Ukrainians have been using it to identify dead Russian. And it's, they're saying it's much easier than matching fingerprints even works. If there's facial damage, it's scary to think about right. Wars, terrible.

    [00:34:14] Who wants to go to war? I can't believe all of the people that want to jump in there. I really feel for these people in Ukraine, what can we do? I'll start approximately. Research for the department of energy, found the decomposition, reduce the technology's effectiveness while a paper from 2021 showed some promising results.

    [00:34:36] Now, this again is an example of technology being used in a way it's never been used before. And having that ability to identify dead or living combat combatants on a field like this is just amazing. So this is the most comprehensive data set. There's critics, of course, they're saying that the facial recognition could misidentify people at checkpoints, obviously, right?

    [00:35:04] Could miss identify people in a battle mismatch could lead to civilian deaths, just like unfair arrests have risen from police use. And that's from Albert Kahn, executive director of surveillance, technology oversight, product, project, and new. So as usual, these things can backfire and I think they probably will given a little bit of time and that's a sad thing.

    [00:35:31] Now I also want to talk about this. This is cool. Another article here, I'm pulling up on the screen right now. And this is about some hackers. Now we know that the Kremlin's been lying. We know that if a politician's lips are moving their line, isn't that the old standby, but Russians apparently don't know this.

    [00:35:56] And the average Russian on the street is thinking that, okay, we're rescuing Ukraine. Isn't that just a wonderful thing. There's a couple of ways that the hackers have been getting around it. It's called a squad 3 0 3. They have this tool that's hosted at the domain. 1920 dot. There's an Indian domain and it loads a pre-written statement in Russian into your native SMS app.

    [00:36:29] In other words, the app that you use for texting and the idea is they that they've taken, oh, let's see here. Tens of thousands of trying to remember the exact number of stolen phone numbers from Russia. So all of those hacks that we've talked about for all of these years, those hacks have many of them phone numbers in them.

    [00:36:54] And they've been taking those phone numbers from some of those hacks and using them to send out about 6.5. Million text messages. So what happens is you, your phone, your actual phone ends up sending a text in Russia saying something to the effect of dear Russians. Your media is being censored. The Kremlin is lying.

    [00:37:18] Find out the truth about Ukraine on the free internet, and then the telegram app time to overthrow dictator. Yeah, that's not going to cause any problems, is it right? I'll put that up on the screen again for people who might read Russian. Cause it's got it in Cyrillic. Okay. And then you have the option to get an, another set of text and figure it out.

    [00:37:40] So the phone number, you can see there, you can copy it and paste it into your app and off the message goes. It's very cool. And in the daily dog, They're quoting a member of this squad 3 0 3 saying that this is a non-violent communications project. It's bypassing Russia's crackdown on the news.

    [00:38:02] They're sensitive. They're censorship of the news. And by the way, the domain 1920 dot. Refers to Poland's surprise victory against Russian forces just after world war one and the Bolshevik Menshevik revolution. You might remember all that stuff, that you studied all those years ago. So it's interesting.

    [00:38:23] We'll see what happens. But this hacking group also claimed that they were attacked probably again by Russian hackers, the FSB ex. Using a distributed denial of service attack shortly after launch. And they put CloudFlare in front of their domain. Now we use CloudFlare for one of our, something, not one, but some of our customers.

    [00:38:50] What CloudFlare is a website that's designed to basically buffer your website when it's been served. So if all of a sudden you get a ton of legitimate request, your site's going to stay up. It's going to be able to respond to people. The other big advantage to CloudFlare is what's happening here with 1920, Diane CloudFlare goes ahead and will block some of these denial of service attack.

    [00:39:19] So I think that's pretty darn cool. Many texts apparently are met with silence. Some say they've been able to converse with Russian citizens. One user who remained anonymous said they had made. The text messages they'd made using the tool really worked it says, I want the people of Russia to know the truth.

    [00:39:38] The government is doing to the people of Ukraine. This is a quote from the daily dot going to pull this up too. This is a a tweet here on Twitter and. Yeah. It's from the anonymous, that hacker group, you've probably heard of them before. Cause they've done a lot of nasty stuff over the years, but he says it's been doing just absolutely amazing things for him.

    [00:40:02] Let's see here. Can we hear this? Here we go. Ah, I got to unmute it. Let's see. Where is my mute? There it is. So this guy's name is Rodney. He is. D Jang, oh my dog. Get to Django my dog. And he's got a really great little testimonial there about that. It works and his tweet has had 4,300 views and it's good.

    [00:40:30] Again, another way around censorship now, Twitter, of course could decide they're going to sensor and that could be a problem too, but that's also why we now have alternatives to Twitter. And some of these other sites that are out there that are doing a whole bunch of blocking really, they don't like you.

    [00:40:51] And by the way, the reference to Telegraph was fascinating because they are using. In order to get around censorship. Again, many people are using it to to send information about what is really, truly happening in Ukraine. So a lot of stuff from the beginning of the war here, visit me online. Craig peterson.com.

    [00:41:14] Get my newsletter and get the free up-to-date trainings.

    [00:41:20] They pass the infrastructure bill, which means now it's time to figure out what is in the infrastructure bill. And we're going to talk about the technology that they decided to fund the technology. That's going to win the game because it has billions of dollars of federal money behind it.

    [00:41:36] This is disappointing bully it's normal, right?

    [00:41:40] It's absolutely normal because the federal government has always been one that picks winners and losers. If you're old enough, you remember, of course, VHS. Tapes right too. Do you remember beta tapes? Beta max tapes. Beta max was really quite the standard for professional production for the longest time, a better technology, frankly, a lot better than VHS.

    [00:42:06] Same. Thing's true with beta, but beta lost. And of course we ended up with VHS tapes. That's an example of technologies that were backed by investors. And we've seen a lot of that. Look at what's happened with the Serono trial, again, technology backed by investors. And it turned out to not work and in quite a dramatic way, frankly.

    [00:42:33] We've seen that again and again, and keep hitting my mic here and the problem that we really have, isn't so much that investors get things wrong because they. I was talking with a friend of mine. Who's has been an angel investor and part of VC partnerships for a long time. And he was saying, we're lucky if we get maybe one out of 20 times, we get.

    [00:42:57] Now, these are professionals and my friend, he's a technology guy. He and I contracted together at the same time over at digital equipment corporation. And he came to me for a lot of advice about business. Now, I look back and think my gosh, the way he did it. You can have all kinds of decisions in life.

    [00:43:18] Some are going to bring you closer to family. Some are going to bring you more peace and joy and happiness, and some are going to give you very gray hair that you're going to lose very quickly. And he chose the kind of the gray hair. But he was really clear about that. Cause I had said to him, what is a one-time out of 10 VCs make money.

    [00:43:39] And that's when he corrected me. He said, no, it's really one out of 20, if they're lucky, because that doesn't even happen all of the time. Now think about him. He was working on the scuzzy subsystem, which is. Complicated topic, but basically the ability for a computer to be able to talk to its hard desks.

    [00:43:58] Okay. Let's just keep it simple. And I was working in the kernel, which is the core of the operating system and was rewriting kernel modules and routines. To work with a few different types of features and functions. I was in very deep very complicated. He was in rather deep, rather complicated.

    [00:44:19] There's always a battle by the way, between compiler people and kernel people as to who has the more complicated job, but he wasn't either. So he just a Colonel guy guess. So he went on. He started a company. He got VC angel funding and VC funding. He made a card for your computer that you could plug in that would provide not just scuzzy support, but he moved the file system out of the operating system onto the card.

    [00:44:50] I that's something I had actually done a decade earlier with the network moving it out. But anyways, that's a different story entirely. So many things I've done all my life that I wish I'd been able to monetize. But anyways, w he doesn't, he's not a slacker. Let me put it that way. When it comes to technology and neither are his partners, and yet one time out of 20 and along comes the infrastructure.

    [00:45:14] They call it the infrastructure, but it really bothers me to call bills things that they're not the infrastructure bill that had. What was it? About five, 6% actually going to infrastructure. It's like the Democrats under president, the last president Obama they, he had this shovel-ready jobs, which of course wasn't true.

    [00:45:35] And most of the money didn't go to building infrastructure. It just got worse. It's just crazy and we're not paying attention. So I'm going to help you right now. Enough ranting and raving. The infrastructure bill contains money for some things. We'll talk about a few of them here in a minute and also has new regulations.

    [00:45:56] And one of those regulations that I've been talking about on the radio this week is this requirement to put kill switches in all new cars. That is really a big deal. Now a kill switch of course, is something that will stop the engine and it'll stop the car. That's the whole idea. And there's various types that have been bantered bandied about including pulling the car over to the side of the road.

    [00:46:25] If the driver stops responding as a driver might have a heart attack, or maybe they fell asleep, maybe something happened in that car should probably pull over and get out of traffic, turn on the flashers which then makes it a target. Apparently for some of these Teslas, we've seen articles about that in the new.

    [00:46:44] Yeah, don't park on the side of the road. They, I was in emergency medical for a long time. And one of the things I can pass along to that may save your life is if you have to pull over, do not stay in the car, do not stand in front of the. And particularly in the evening or at night because the flashing lights and the car at the side of the road is a beacon for drunk drivers to come and hit you as well as some of these autonomous vehicles, apparently just get out of the car.

    [00:47:16] Behind the car off the road. Okay. Go off the road behind the car, not next to the car off the road, not in front of the car, off the road, behind the car. So if it does get hit, you are less likely to suffer severe damage yourself, but this kills switch. That's part of this bill that was passed in sign, of course, a hidden part requires all manufacturers to include the ability.

    [00:47:44] For police departments and potentially others. And this is where some of the problem comes in to be able to stop the. Now you might remember back in 98, there's a Saifai series called the X-Files. It was very cool series. And there's an episode called kill switch about an artificial intelligence gone wild.

    [00:48:07] And that, that is of course a while ago back when most people were still using dial up modem. But this was a tale of technology, run a muck, and it was warning about handing too much of your life over to technology. Oh, that's one thing. But in this case, isn't it safer, right? Because somebody is whipping through neighborhoods at 80 miles an hour in their car, trying to avoid police.

    [00:48:37] Shouldn't have, please be able to stop that car and pull it. The problem is multifold frankly, and having this kill switch one is what constitutes law abiding. There's a great article in motorists.com and it shows a picture of this down in New Zealand. Our car was pulled over. And the police found the trunk was full of contraband.

    [00:49:02] Now we've seen this before, right? And movies, Miami vice and others, where they pull over the car. It's got all this contraband in the trunk. It's cocaine and various other things. No. This isn't Auckland New Zealand and the trunk was full of Kentucky fried chicken meat. They were running Kentucky fried chicken, just like the Kennedys, running illegal booze back in the day. Yeah. That's how they made their millions. They were running Kentucky fried chicken. Now this bill that was signed into law by president Biden states that this kills switch, which uses referred to as a safety device, must passively monitor the performance of a driver of a motor vehicle to accurately identify whether that driver may be impaired.

    [00:49:54] In other words, big brother will be constantly monitoring how you drive. If you do something that the system has been programmed to recognize as driver impairment or unsafe driving your car could just shut off, which could be incredibly dangerous. I want to point out this week too. There's another article I read about Teslas and how Tesla had introduced last fall, a feature.

    [00:50:23] So you could set how the car was going to drive. Do you want to drive? Real cool, laid back fashion. Do you want the car to drive an average way or do you want it to be aggressive? Just weave in and out of traffic a bit and tailgate and do all of those sorts of things and you could set it and there is a public backlash and Tesla got rid of it.

    [00:50:42] It is back now. How do you tell if a driver's being unsafe? When a car in its autonomous mode will do the same things that a human drivers shouldn't be doing? Or what if you're hauling contraband, Kentucky fried chicken? How is the driving going to be measured as impaired? Now I know in many states you have these breathalyzers that are court ordered, installed in cars.

    [00:51:13] Okay, so that makes sense. Somebody has been drunk driving many times. You don't want them drunk driving ever again, please. And thank you. But how about having that system in every car? Because it fails. It doesn't work sometimes. And how about the back door? Because that's essentially what we're talking about.

    [00:51:34] These cars are going to have a back door that allows someone named government authorities to access it whenever they want. Would they need a warrant to do it? Probably not. Even as hackers could access the back door and shut down your vehicle, think about lad having a kill switch that would kill all of the cars and trucks in the United States.

    [00:52:02] Right? There are so many potential problems here and they haven't been thought about. Oh, obviously it's government, but we're going to talk or we'd get back about the investment that are part of this multi-trillion dollar bill that you and your kids and grandkids are paying for.

    [00:52:23] We know they snuck a backdoor kill, switch into all cars manufactured after 2026 into this infrastructure belt. What else is in there? That's going to affect technology. That's what we're going to talk about right now.

    [00:52:38] We know about this now. After it passed, finally, people had a chance to read it because this provision on the kill switch was not debated in the house.

    [00:52:50] It was not debated in this. Just like they've been doing was so many other things for so long now they just bundle them all together in a bill. They gave it a cute little cuddly title, and then they go ahead and put whatever it is they want into it. These are these omnibus bills that they should have gotten rid of decades ago.

    [00:53:16] It is absolutely crazy to me. I just. Get it. Why are we putting up with this? So now the next step here is the investments that are being made. Now I'm going to type in right now, how successful are angel investments? Okay. So here we go. Bunch of ads for angel investing says you can have an average return of 1.1 X cap.

    [00:53:48] All right. And it goes on and on. This is a company called core associates. The success rate of angel investors. This is from Investopedia, the effective internal rate out return for a successful portfolio for angel investors is approximately 22%. Now, remember that over. So that's pretty amazing. Those numbers are much higher than what my friends said that they can expect absolutely much, much.

    [00:54:19] But I can tell you one thing for sure. Government quote, investments, end quote, rarely ever actually pay out because you've got political motivations in there. It's one thing to be a smart technology guy investing in technology. But how about those people in Congress? That aren't smart technology guys.

    [00:54:44] How about the doctors in Congress? Look at what Senator Paul ran. Paul has been saying he is a doctor and what he's been saying about the whole COVID thing and the way the government has handled it. We are really going down the wrong road to here because government. Taking the money from us at the point of a gun.

    [00:55:06] Try not paying your taxes and see what happens rarely ends up. Okay. So the us Congress passed November six. Biden's trillion. Plus infrastructure bill that includes 65 billion of investments in the power grid to accommodate rising, renewable energy capacity and demonstration clean tech project. So what's that one about?

    [00:55:32] That particular one is because our grid cannot handle solar and also the windmill power. The rates, we would need to have it, our grid set up so that you have a few centralized power stations, and then that power is distributed to the area. It's not set up for having tens of thousands of power stations.

    [00:55:56] So there you go, president Biden, put money into try and figure out well, Hey, how do we accomplish? How do we accommodate them? Noma, Germany has done. Is they've gone ahead and they're using a massive lake as a heat sink to get rid of the extra electricity that's being generated. When it comes to a regular power plant, you can turn it up.

    [00:56:21] You can turn it down the same. Thing's true for every type of power plant, whether it's powered by water or nuclear or cold, you can turn it up. But when it comes to wind and solar you can't turn it down. If it's a nice sunny day, you're not going to be able to turn that power down. It's still coming out.

    [00:56:40] You got to do something with it. You can cut it. Open the circuit. But the power companies that run the grid don't have that kind of fine grain control over the electricity that you're generating in your house or in your business. There's so many problems that start to open up here. So they're spending $65 billion.

    [00:57:02] That is a lot of money to figure this out. Okay. Personally, I'd rather see the private sector do it because they're going to have a better chance of coming up with something that's really going to work next part here. Okay. And by the way, Colin it or trillion dollar plus is being favorable because they played all kinds of gimmicks with this money.

    [00:57:25] Just, I just found out. In fact, I think it was a couple of weeks ago, June. Do you remember. President Biden moved all of the college loans from private sources into the white house. Do you remember that? So the white house is controlling all college loans at the time I thought, okay, it's just them paying back the unions, the teachers unions, right?

    [00:57:49] Because it also included provisions that you cannot have be bankrupt and get rid of your college. Th that's just mind boggling to me, but as it turns out what he was doing. Okay. All of that's true. But what he was actually doing is saying, oh, there's over a trillion dollars in college loans. So we're going to move them into the white house and call those assets to offset all of the money we're spending.

    [00:58:19] You see what we're talking about here? It's just not. Electric vehicles, clean energy, public transit are all part of this trillion dollar plus legislation. It's got $550 billion, a half, a trillion dollars to fund advancements in public transit, clean energy electric vehicles, roads, and bridges. Okay. It's always electric.

    [00:58:48] Really? The right winner here is electric. The beta max that should have won out over VHS. How about hydrogen? How about some other way? How about natural gas or LP gas? What we'll never know because some of that is not going to get funding. However, there is going to be some funding. For nuclear development?

    [00:59:12] No, I've talked a lot about this on the radio before, but the bottom line is nuclear is the only green energy that we can really get. And I can hear some people saying, oh, you're not sure not to know. Look at the current generations of nuclear power. Now, unfortunately, the regulations around nuclear power were written what, 70, 60 years ago, right?

    [00:59:38] When nuclear power was nasty stuff, it came out of the projects that we had in world war II to build nuclear bomb. Now these six generation nuclear power plants are as clean as can be. They only need to be refueled every 10 to 20 years, and they're small enough to fit into a small building smaller than your average home.

    [01:00:02] And you can put one of these in the neighborhood in a small town, and that will power the whole. Thing. Okay. So we're already getting 27%, according to president Biden of our power from these decades, old nuclear and hydro power facilities, they've got 21 and a half billion dollars in this for clean energy demonstrations and research hubs focused on next generation technologies, helping to get us to that net zero by 2050 that they're looking at.

    [01:00:35] To get to, so this will be interesting because there they've got 8 billion earmarked for hydrogen and carbon capture. Guess what's going to get more, yeah. Carbon capture, direct air capture, and we don't know what's going to happen with this. We're turning cow, carbon into stone, basically with some of these plans and experiments are underway.

    [01:00:56] So what happened. When we need that carbon again. But 8 billion is earmarked for hydrogen and carbon capture direct capture, 10 billion, two and a half billion earmarked for advanced nuclear. So I'm happy with that. Not that they're spending the money, not at all, but that they're actually putting it into something that might make a difference.

    [01:01:22] And hydrogen funding in this, by the way, it looks like it's a big win for oil and the whole oil industry stick around.

    [01:01:31] You've heard of this shortage of Silicon, of semiconductors CPU's et cetera. I don't know if you tried to buy a computer lately, order a computer, et cetera, but there is another part of the computer that's really hard to get. And that's what we're going to talk about.

    [01:01:56] CPU is the central processing unit in your computer.

    [01:02:01] And that nowadays might actually not just be on a chip by itself, back in the day. I'm thinking about the, some of the first microchips microcomputers I worked with such as the 65 0 2, that original. Apple chip that they use great little chip, by the way, he was just so clever how they got around some of the problems eight-bit problems or the day that computer with its CPU was a standalone CPU.

    [01:02:30] That in other words, the CPU only did CPU thinks, it went out and grabbed stuff from memory and then did the computing and then. Push the results back to memory. Just simplifying it there today. You look at a CPU like what apple is putting into their iPhones and the iPads, and particularly their desktops with , the M family, really whole family of chips.

    [01:02:56] It is no longer just a CPU on that chip. That chip has all of them. It has, of course, all of the memory controllers on it, the processors, it has low power processors. It has high power processors and it has GPU's that's what I want to talk about right now are the GPU's cause in the apple case, you. One of these M series computers and your stuck with what you buy, which is why you should always be buying the biggest, best just computer you can so that it will last you longer.

    [01:03:32] And I'm not talking about the fact of that study that said your average laptop, nowadays windows, laptop is going to last about seven months. I'm talking about the it's going to last, not because it breaks down or doesn't break down, but it's going to last because it has enough memory to handle future operating systems, et cetera.

    [01:03:53] Now we've got a problem today with TPMS. These are trusted platform modules and apple has actually been using something very similar to that for a long time. TPMS are in the window's case, very simplistic and don't actually provide very much security. They're basically going to help prevent someone putting some malicious code into the boot blocks on your computer.

    [01:04:23] So it's going to do some good, but it's not going to do a lot of good and windows. Now, Microsoft is requiring pretty much TPMS for windows either. Across the board. Now there's some ways around it sometimes depending on what you're doing, how you're doing it, but as a whole, yeah. You gotta have that TPM in order for things to work for you and even installed windows 11.

    [01:04:50] That's a good step, frankly that they made apple is many steps ahead of Microsoft in this case, mainly because they can make their own hardware. Microsoft can't. So when you buy a Microsoft computer inside, it's going to have what we're still calling a CPU, but it's much more than that.

    [01:05:11] Nowadays their CPU might be from Intel. It might be from AMD. Those are the two most likely Microsoft with their surface tablets does support similar chips to what apple is making. So you don't have to use an Intel type of chip in order to run windows anymore, depending on the hardware you're using.

    [01:05:32] But as part of these chips, you have to move graphics around. So the modern chips, like the Intel chips and AMD chips have some GPU capabilities built into. But in most cases, you're going to add a GPU card to your machine. So what is this GPU? What are we talking about here? A GPU is a really interesting piece of hardware because it is designed specifically to move.

    [01:06:05] Bits of information around very efficiently versus a CPU, which is designed to do mathematics on words of data. So in other words, 64 bits at a time. So if you're moving stuff around the memory buses on the CPU, et cetera, are optimized for maybe 128 bits of data all at once. So why would you want something that only handles.

    [01:06:33] A bit at a time. Of course it can do more than that, but we're keeping things simple. You want that because it's efficient at it. And if you think about the graphics processing unit, as the thing that handles the graphics, and you look at a screen, that screen is composed of most likely millions of dots, even on our little smartphone device.

    [01:06:55] Millions of dots. And so you've got to flip those dots around. Sometimes you need to move them as something most, or the most efficient way. For instance, to show a video is not to update that whole screen, because if you look at a screen with video, most of that screen, isn't moving nothing. Tap. What you want to update is just the parts that are moving and that's where compression comes into place.

    [01:07:21] And also where decompression comes into play. So all of this stuff that is part of moving things around on your screen, even if you're dragging a window around on your display, that is most optimally handled by the graphics processing unit, the. So Apple's putting their memory on chip. It's putting the GPU's, CPU's the high power, low power.

    [01:07:45] CPU's everything it can. And then all the memory management and stuff on one chip. And that gives some huge advantages because when you're talking about the speeds that we're using today the less space that electrons have to travel the faster it will be. I know you think about that for a minute, right?

    [01:08:03] You turn on a light switch and lights are on instantly. In reality, it takes a little bit because the electrons have to, first of all, get to the light and then they have to somehow excite something in the light in order to make the light. But electrons, distance traveled matters in. So why are we having such a huge shortage of GPU's while it has to do with their ability to mine, crypto current?

    [01:08:34] Now the best way to mine. Cryptocurrency is using specially made and designed hardware that is designed for that one particular cryptocurrency. So it makes sense to you. That's the best way to do. But in most cases you don't have that specially designed hardware. And in many cases, that hardware is only really viable for a few months, but people are still buying GPU specifically to mine, cryptocurrencies, by the way.

    [01:09:09] It's usually cheaper to buy cryptocurrencies and to mine them because the average electric bill in the United States makes it so that it is impossible to mine. These cryptocurrencies like Bitcoin effectively enough. So the electricity is cheaper than the pit coins worth. So think about that. If a Bitcoin is worth $50,000, Frank.

    [01:09:34] The electricity to mine. Another Bitcoin is more than likely going to cost you more than 50 grand and take a long time. So people are still buying GPU's these high-end GPU's, they're using them to build machines that have a bunch of these cards in them. And that is causing shortages for you and me who might want to make videos efficiently or who might want to do just.

    [01:10:01] Computing and buy a high-end computer. So it's good for you for the next five to 10 years. Oh, and Radian, who makes some of these high-end GPU's just came out with one that is specifically designed to be bad at mining cryptocurrency. So who knows? Maybe there is a little bit of hope here. You can visit me online.

    [01:10:23] I'd appreciate it. If you would, Craig peterson.com, you'll find all kinds of great information there. And if you sign up, I'm going to send you absolutely free. My three most popular, special reports, including. The one-on passwords, Craig peterson.com. Visit me online and stick around because we'll be right back.

    [01:10:49] There are a lot of programs claiming that they are secure. That's what we're going to talk about right now for secure communications. What about telegram? What about signal? What about WhatsApp and WhatsApp? You remember started 20, 21 with a real blackout.

    [01:11:05] Signal is probably the best software that you can use the best app. They've got a desktop version as well in order to keep your communications safe. And that's what you want to do. You don't want. People listening in. You don't want people spying on you. You just want to have a conversation.

    [01:11:27] And there's many things that you'd say in a private conversation that you would not say, if you were sitting here on the radio or standing on the top of a building with a thousand people below you, private conversations are meant to be. What signal is doing to play with fire is they are talking about trying to pull in cryptocurrency payments into part of signals, platinum.

    [01:11:55] It all started with something called mobile calling and signals CEO. And his name is mark C Marlin spike. We've talked to him about him a few times, but he was an advisor to the mobile coin, current cryptocurrency. And it's been built on this stellar blockchains designed to use a view, be used to make anonymous payments that are basically the same mistakes.

    [01:12:20] So it's designed to hide everything from ha from every one. That's the whole idea behind mobile coin. So the problem is if you start to integrate advertising systems into supposedly secure communication channels, what's going to have. If you start to take things like a cryptocurrency and put it into a secure communications channel, then what's going to happen.

    [01:12:48] You can bet that what's going to happen is governments are going to step in saying, Hey, wait a minute. Now you can have money flowing. I remember buying a car. And this was back in I think the early eighties and I went to the bank and I got a loan from the bank in order to buy the car. And they gave me eight, $1,000 bills.

    [01:13:11] Cause I was going down to the auction car auction and I was going to buy a car and I set myself an $8,000. So the idea was like buy the car and I come back, I pay them back the difference, and then they write the rest stop as alone, man. Weren't those the days, right? When a banker knew you, the banker made decisions on things like an $8,000 loan, I don't know.

    [01:13:37] What would that be worth in today's money? 10,020 probably goes to the $15,000 just based on my word. And I walked out of there with thousand dollar bills and. I also had $500 bills. And back then, you used them to pay bills and of course they're worth more today than they were then. Let me put it the other way is actually worth less, right?

    [01:14:03] Because of the, in crazy amounts of inflation that we've had. But the bottom line is you could have. Get thousand dollar bills and put eight of them in your pocket. So it doesn't look like you're walking around with a huge water cash that someone's going to steal from you. And then the government decided that, oh my gosh, that's terrible.

    [01:14:25] Oh no. Wow. Drug dealers might be using those thousand dollar bills. Oh, yeah, this is true. They might be using them and we all want to start off, stop the sale of illegal illicit drugs. That makes sense. But the war on drugs, we're not going to get into that has been an abject failure and it has resulted in things like the fiscal or w you're not even charged criminally or civilly, and they seize the money.

    [01:14:55] You. So they got rid of thousand dollar bills because of course they were only used by drug dealers and people like me, they got rid of $500 bills because of course it was still the drug dealers. And to me who were using them now, the biggest denomination that you can get is a hundred dollar bill.

    [01:15:14] Although the treasury is talking about making minting a 1000, excuse me. $1 trillion coin that they would use in order to make payments, right? Yeah. So that, that balances their budget. Cause yeah, they just printed a trillion dollar coin. Anyhow. The problem is that the government wants its fingers in every transaction, whether or not there are drug dealers involved and that is causing us nothing but headaches and heartaches, frankly, it's a real.

    [01:15:49] Problem. So when you get Marlin spike, tallying people, that signal is going to include a cryptocurrency called mobile calling that is designed to be absolutely private. That's when they government starts freaking. China already has a cryptocurrency. In fact, they've been trying to peddle their cryptocurrency for use by governments around the world to trade for oil.

    [01:16:21] Remember the United States time was when our currency was supposed to be the standard. Remember that the standard for. Doing transactions worldwide crypto type transactions is where China wants to delete it. And what they're trying to do when they lead it over there is get the U S dollar out of the way.

    [01:16:43] He can't say as I blame them lately, but they have been testing it already here. This coin, mobile coin cryptocurrency. What do you do now, if you're trying to have a private conversation, I started out by mentioning telegram, WhatsApp and signal. Now we just talked about the biggest problem with signal right now.

    [01:17:06] We'll talk about it. Security in just a minute. Let's talk about WhatsApp. WhatsApp's biggest problem is that it was bought by Facebook. Should they have been allowed to buy them? It depends on how much of a free market person you are, should the government have stepped in and said, no, you can't do that because frankly, WhatsApp was a competitor to Facebook and Facebook just bought them because they have so much cash.

    [01:17:28] So WhatsApp's problem is Facebook. And remember last year, January, 2021, I think it was. Facebook said from now on, we are going to be inserting ads into your WhatsApp communications. Yeah. That kind of got people a little upset for very good reason. How about telegram? Telegram is not secure. It has never been secure.

    [01:17:55] And a lot of people switched over to telegram because of what happened with WhatsApp and Facebook saying we are going to be putting ads into your WhatsApp channel. So tens of millions of users switched to Della gram. Yeah, it was a nightmare for WhatsApp last year, but frankly, the, it changed. WhatsApp changed Facebook backed off because some people were upset, but they're ultimately going to go that direction.

    [01:18:26] That's who Facebook is, they make their money off of us. Now signal is even more secure than WhatsApp. Telegram is not secure at all. Okay. So forget about it. Don't use telegram. They've got this cloud-based architecture. That's truly, it's a serious risk when compared to end default encryption, that's used by signal.

    [01:18:48] Why? So right off telegram, if you want a secure private conversation, but one tap and signal both have end to end default encryption. So why would I say that signal is more secure than WhatsApp? The bottom line is that WhatsApp keeps some of your data in. Okay. And that's where the problem really comes in with signal.

    [01:19:17] Everything is encrypted. Everything is obfuscated. Okay. Telegram, you can delete messages, chats, call histories, groups, any time that you create them in afterwards deleted items, completely disappear for all participants without our trace. There, there's just all kinds of problems, but now I'm concerned about signal.

    [01:19:36] That signal has been doing a lot of stuff in order to keep the bad guys and snoops out of their streams. And that includes even putting in codes that are known to crash some of the devices, the criminals and law enforcement, even you. Build it right into signal, which I thought was just hilarious because there's this tool that I'm referring to terminate Israeli company is using some open source software that they have not patched in years solely.

    [01:20:10] It's it's absolutely fun. So keep all of that in mind. In reality signal is. Everything it possibly can to keep your data safe. I am concerned about the fact that they're going after this coin mobile thing, trying to integrate it. I can see why they'd try and do that. Facebook has released its own cryptocurrency last year.

    [01:20:36] I didn't really go anywhere. They've relabeled it a couple of times, and Facebook wants to become your payment centers as well. So you can use Facebook messages in order to send money and potentially use WhatsApp as well. Apple, by the way, is using encryption end to end for I message. But there is some concern about iron message particularly lately because apple has been using its own backdoor keys for some of the data that you store.

    [01:21:10] And I'm a little unclear as to how I message fits into that whole. But WhatsApp is free. Signal is free. Telegram is free, but it's becoming clear the price you need to pay for it because Facebook basically broke WhatsApp. And because of that radical change and you can consider it to come out further.

    [01:21:36] And we know that Telegraph is just not there and hopefully signal's going to smarten up here and not try and get the re federal regulators involved because of monetary transactions. Although, technically it's not money, right? It's a cryptocurrency. Should you stop using WhatsApp? The short answer's probably, no, I do use it with one of my mastermind groups.

    [01:22:01] Nothing's really changed after the pushback from people who've been using it. That's the short app answer, but your signal whenever you can, it just makes. Hey, thanks for joining me today. Spend a little time over your weekend and I'd invite you to also go online. Go to Craig peterson.com. Make sure you sign up for the newsletter.

    [01:22:24] I've got a special report on passwords this week.

    1 hr 23 min
  • What Can Be done About Russia? What Can You Do?

    What Can Be done About Russia?What Can You Do?

    There is a whole bunch going on when it comes to Russia, of course, the invasion of Ukraine. Why are people calling to have dot RU deleted?

    This is really a big deal. And if you're watching from home, I'm going to go full screen on this article.

    [Automated transcript follows.]

    [00:00:23] This is an article from ARS Technica, and I've been talking about it all week, which is that I can won't revoke Russian in Jeanette domains, says the effect. Devastating. This is frankly pretty darn fascinating to me because I can, as this international organization, it was put together in order to help make the internet international.

    [00:00:49] And I'm not talking about the data international, but control of it. A lot of countries work. Because of course the internet was created in nodded states. It was created by us tax payers, money for the DOD. And it was designed to be very resilient, in fact, so resilient that there could be a nuclear blast and that nuclear blast and.

    [00:01:13] Causing problems, but yeah. Yeah, the internet is still going to work. And the whole idea behind it was you could have multiple routers. They're all talking to each other nowadays. They're talking BGP four and they can say, how can I get from here? To there. And so the idea behind BGP is they all share this information once the least cost way.

    [00:01:36] What's the easiest way to post way. If you will, for me to get from point a to point B and it changes all the time. So you might be on a phone conversation. You might be listening to me right now, online streaming or watching the video you might be doing, who knows what out there with digital communications.

    [00:01:57] But the communications channel that you think you're using, where the data is going from, let's say my microphone, ultimately to your device, your ears, that data path, once it becomes dated. Can be changing multiple times a second. Now it actually changes quite a bit. Initially as these internet backbone routers, send the least cost, routing information back and forth to, and fro a very good thing, frankly, because it helps to speed everything up.

    [00:02:28] And there's other tricks that we're using you. Might've seen. For instance, Akamai and some of the URLs before have sites that you've gone to, and that's called a content delivery network and that helps get the content to be closer to you. So if you're on a website in California and you're in New Hampshire, that website video, that website graphic, et cetera, is going to be coming from a server local to me here in New Hampshire.

    [00:02:59] All right. That's how that all is supposed to work. So we have names you guys know about that internet, domain names and those domain names. You already know those are turned into internet addresses, and those addresses are then used by the routers to figure out where to go, how to get the data. The problem that we're having right now, of course, is Russia seems to be substantially abusing the intranet Putin, put a kill switch on to the Russian internet sometime ago.

    [00:03:31] And the idea behind the skills, which was, Hey, listen, if we don't want the world to be talking to us, we'll just cut it. Now he's tested it a couple of times, but what he has not done is shut it down and he hasn't shut it down. As part of this Ukraine, more, what they did is they passed laws saying, Hey, if you publish something that disagrees with what we're saying, you get 15 years.

    [00:03:59] And even these people who've been protesting on the streets, they're getting a bound 60 days, 30 to 60 days in jail, just for protesting what's going on. So a lot of people have been saying why don't we just, we turn off the Russian internet now we're not going to use Putin's kill switch in order to shut it all off.

    [00:04:19] We're not going to do a well, a few things. She decided not to do, denial of service attacks, et cetera. Although there are hackers doing that and we are going to talk about that today, but they're saying what? Let's just go ahead and let's kill their dot R E. The country domain. And I can, the guy who heads it up said, Hey, listen our mission is just to make sure that the internet works.

    [00:04:46] So shutting off the dot R U domain so that no one can go ahead and. We send right. A request out to the domain name servers and get a resolution to an IP address. So if you try and go to Kremlin dot REU or something, you will get blocked and you will get blocked. Not blocked. No, I like the great firewall of China or of Russia.

    [00:05:10] Now they've got one going pretty good. Yeah. Thank you. You ain't using us technology. It's crazy. What we've got. But what it does is it says, oh, I hide dot, are you, I don't know. What are you talking about? So there have been a lot of people who have been pushing for it. And you'll see on my screen here that you cranes requested to cut Russia off from some of these core parts of the internet.

    [00:05:35] And I can, which is the internet corporation for assigned names and numbers. I couldn't remember what that was earlier said that I can must remain neutral and their mission they say is not to take punitive actions. It's to make sure the internet works. So are they really taking punitive actions of the cat Russia off?

    [00:05:56] It's really interesting to me because look at what has been going on. You've got companies like Facebook as the great example who has gone ahead and just shut off people. They didn't like what they were saying. My goodness. At one point of you said you should wear a mask during this pandemic.

    [00:06:15] You would be cut off from Facebook. And then of course, if you said, no, you don't, you shouldn't don't need you, you shouldn't wear a mask that at that point you would be cut off, because science right. Sciences, we know exactly what we're doing now. It goes on and on. If you said that it came from a lab in China, you would have your account suspended.

    [00:06:35] Now of course their whole tune has changed and yeah probably came from a lab in China. It's crazy what these people have been doing. So we have arbiters of truth, who are some contractors sitting in their home or wherever it is the contractors for Facebook that are going through posts that people are flagging as Incorrect as fake news.

    [00:07:02] So what happens is people say fake news and then that goes off to their team that then looks at it and says okay. Yeah, fake news because we disagree with it. It just blows my mind. We have to have free and fair and open discussions. Don't we. You have that line at Facebook and Google does some of the same.

    [00:07:22] A lot of these sites do a lot of the same. You get our major media outlets that are all deciding what they want to report on and what they want to label as fake and fake news. I'm just shaking my head because it's hard. It's hard to believe. What about. Russia is putting out fake news, as I've said many times before the E the first casualty in war, this isn't my quote. The first casualty in war is what, it's the truth. So if truth is the first casualty, then that means we've got a lot of propaganda going on. We had propaganda coming out of Ukraine. We've caught some of those, like the, what was it? The. Chat goes, fighter, pilot, whatever it was who had killed, what was it?

    [00:08:12] Five Soviet or Russian jets, Soviet era using silver deer, techno era technology on the part of the Ukrainians turns out well. Okay, that, that was false news. That was fake news. The whole thing about snake island, where you had that Russian military. I know what it was a frigging but anyways boat sitting there saying we are a Russia.

    [00:08:33] Warship, you will surrender or, whatever. Do you remember that snake on just the small place, 13 guys and supposedly they shelled it and they killed all 13 turns out that was probably fake news as well. So that's from the Ukrainian side and on the Russian side they hardly reported I as to how many.

    [00:08:57] The we're in fact, initially for quite a while, they were saying there are no desks. Then at the same time, the Ukrainians are saying they're 2,500 Russians dead. And that number keeps going up, who knows what it is today. It gets really crazy in the time of war. So if Facebook is going to stop someone from saying don't wear masks or do wear masks, depending on what day of the week it is basically right.

    [00:09:20] Wednesday. It's okay to say that Thursday is not okay to say that we're back. No it's not. Or then why can't that type of censorship? Move on to the next. I that's a big question I have now. Should we be shutting it off? I'll pull this back up on the screen again. And it, this article from ARS, Technica is saying that experts have warned, whoever they are that shutting down the dot R U domain.

    [00:09:53] Is going to cause just incredible problems for Russians, which man would it ever talking about a major blow to the economy. And it would also cause problems for people who are trying to find out more truth about. Russia cause you couldn't get to their site. Now we've seen some amazing things in Russia.

    [00:10:15] We had the Russian, one of the Russian news agencies are T which is broadcasting and here in the U S that their entire staff just walked out saying, forget about it. We're not going to promote this fake news, but this is a little to do trip question me personally. I don't think anybody should be censoring any.

    [00:10:38] For almost anything. Yo, there are some limits, but they're pretty extreme in my book. I'd rather know someone is an idiot because they're allowed to say stupid things, and counter, counter it, counter their arguments. You've got to have discussions

    [00:10:54] Microsoft. Yeah, they've been around a long time. They've been helping us. They've had lots of cybersecurity problems. People use Microsoft software on their desktop. Some people use it for servers, which is crazy, but listen to what they're doing now.

    [00:11:10] This is a little concerning. I'm going to pull this article up on the screen.

    [00:11:15] For those of you who are watching a long, either on rumble or YouTube ARS, Technica article, they have some really great articles. This particular one is about our friends at Microsoft. This is cool. Microsoft announced today? This was like a week or so ago that Microsoft would be suspending all new sales of Microsoft products and services in Russia.

    [00:11:45] Following the countries, unjustified, unprovoked, and unlawful invasion of. Now Microsoft didn't give any specifics about the products, but it really is likely to be a blanket ban of all of the Microsoft products. This is very cool because Microsoft has taken an approach I've never seen them do before, which is okay.

    [00:12:10] When. Gets hacked. You get our friends at apple, putting together patches and getting them out. They get them up pretty quick. Microsoft had been doing much the same. The problem was some months there were patches every day that you had to apply. That's how bad this software is. And they decided that man, let's be like politicians here.

    [00:12:34] Let's release some very damning news Friday. At about 4:30 PM before a long weekend. So no one will notice. Yeah. Y'all are friends of politicians do that all the time. What Microsoft decided they do is, Hey, wait a minute. We're going to have patches. It's not going to slow down. And because our code is terrible.

    [00:12:56] So what we're going to do, let me see here. How about we just release all of them at once and we'll just call it patch Tuesday, right? Because people were complaining about how much work it was, how much effort was effort. It was to try. They hate them. These machines apply these patches every day. Huge problem for everybody from home users to big companies out there.

    [00:13:21] So Microsoft has said, okay let's do that. Let's burry it. So nobody will notice okay that's what Microsoft does. And now we've gotten used to that. Now we have. We remember two guys, right? Bill gates followed by Steve Ballmer. Steve Ballmer was a nut job. Bill gates was a bad man.

    [00:13:40] I think he's just been trying extra hard to compensate for all of the evil he did over the years. But what we're looking at now is new management and that he's been in there now for a few years, doing a great job, cleaning up Microsoft, making it a very competitive company. He has done some amazing things.

    [00:14:02] One of the things that he has decided to do, that's been very effective is how about this? How about we go ahead. And we work with various governments to help stop these Russian hackers. And I mentioned this a couple of weeks ago, what was happening and the Microsoft had reached out to the white house and said, Hey, listen.

    [00:14:27] What we have been looking at the hacks that have been coming from the Russian hackers, and we've been preparing fixes for some of those hacks. How about we work directly with some of these other countries? This reminds me a whole lot of the lend lease program in world war two. You might remember this thing, but the us of course, initially was not involved in the war and they decided, okay we've got to help the United Kingdom.

    [00:15:00] How are we going to help them? The UK doesn't have the money to buy ships, to have us make weapons, bullets know. What they did is they had people donate the rifles, the guns, AML from home. Plus they made them the government, instead of selling them to the UK, they lent them to the UK because the UK could not afford everything that it needed in order to fight a war against the national socialist in Germany.

    [00:15:28] So what did they do? We just shipped the stuff over there and called it a lend slash lease. I think that's a great idea. And what Microsoft is doing is also great idea. They have been decoding, reverse compiling, if you will, and interpreting the code, looking at what some of the ransomware and other malicious code the Russia has been using against Ukraine, and they have been providing.

    [00:15:57] All kinds of insight information to these other countries. Now, this is a great idea for a few reasons, one of the reasons, and I think maybe the biggest reason is that the ransomware, the viruses, all of this malware that they're producing is. Not particularly discriminating. Do you guys remember maybe I dunno, what was it?

    [00:16:22] Six months ago, I taught, told you how to avoid getting most of this Russian ransomware. And it was as easy as just installing. Yeah, installing a keyboard on your computer windows or Mac, windows. Those are the machines are always getting attacked quite successfully most of the time, but the windows keyboard.

    [00:16:49] Russian language. Now you didn't even have to use it. You don't have to have a keyboard, right? This isn't a Russian keyboard that I'm holding up here on camera. This is just a regular us keyboard. You can just install a virtual, Russian keyboard. And once that keyboard was installed, you're pretty safe.

    [00:17:06] Why? Because Vladimir poop. Dictator for life of Russia decided he would just go ahead and stop anybody that was trying to hack Russian. Companies businesses, government agencies and what's the best way for the hackers to do that. Cause they didn't want to end up in Siberia for the rest of their lives because of a hack.

    [00:17:29] Now they went ahead and said, okay if there's a Russian Cyrillic keyboard on the machine, we're not going to activate. So if the software, the malware on your computer, all you need to do is have a Russian keyboard. Yeah, that's it pretty simple. I told you that months ago, now what we're seeing is these indiscriminant types of software that are being used in Ukraine.

    [00:17:57] Why doesn't the keyboard trick work while some of Ukrainians peak Russian, we could go in. To the background on that of the massacre, the starvation purposeful starvation of Ukrainians by the Soviet union over many years ago. And how they then gave their property, their homes to Russians to move into in order to occupy Ukraine.

    [00:18:23] So there's people in Ukraine who are Russian speaking of course. Now we're talking two or three generations, four, maybe down the road from when the Soviet union killed all of those millions of people. But there are some fights that to say, there's Russians, Russian speaking people there. Let me put it that way.

    [00:18:41] Perfect. In Southeastern Ukraine anyways I'm going on and on I, this is not an education on war or history. This we're talking about cyber security. So the, they have, they been, Microsoft found many cases of Russians putting destructive. And disruptive or even more than that data wiping malware onto computers, it spreads indiscriminately.

    [00:19:13] So Microsoft looking at what's happening, you crane, trying to get patches together for all of us, letting other countries know about what's going on is going to be. Amazing because this malware, which is wiping computers, primarily, it's not really just straight up ransomware give us money and we'll give you your data back.

    [00:19:35] This is just showing your data, that malware is going to leak outside of Ukraine. Yeah. Cause us all kinds of book tension, probably. When we get back, I want to talk about this here. This is our friend Ilan Musk, and we've been following along with some of the stuff been going on with his new satellite system in Ukraine.

    [00:19:58] The whole concept of these satellites and circling the earth, providing us with internet, just regular guides. It's going to be in our smartphones is changing everything. We're going to talk about Elon Musk and what's happened over in Ukraine.

    [00:20:15] Our friend Elon Musk has done a lot of things over the years. He has really helped us for frankly, the Tesla and what's been happening there.

    [00:20:26] Space sex, his main concern being let's get. Off of a single planet on to multiple planets, right? The movement to Mars, NASA's working on a serious moon base. I reminded him of space 1999. You guys remember that show, but yeah, we're going to have a moon base by then and it makes a lot of sense. So who's going to go to these well, there's some interesting lotteries people have to apply and everything else, but he's done so much, right?

    [00:21:00] He's got the boring company you'd already know about Tesla and boring company in case you didn't know makes underground tunnels. He has also. A few other things has got a huge battery manufacturing facility. They're working on new battery technologies to make all of our lives a little bit better, particularly if we have an electric house or electric car, because this is what good is it to have electricity that you can't use.

    [00:21:25] And that's really what they're trying to do is make it so that electricity is available 24 7 for you. And. Those space X, which is what I mentioned as well as what we're going to talk about right now. I'm going to pull this up on my screen. For those of you who are watching over on rumble, or of course, YouTube, this is fascinating.

    [00:21:49] He said there's a high probability of Russian attacks on Starlink in Ukraine. Now that is fascinating because what he's done is he has sent over truckloads. I'm showing a picture of a truck. In fact, with these Starling terminals in it, that's from ARS Technica. Just double-checking it here, but this is very cool.

    [00:22:12] This is posted by the vice prime minister over there in Ukraine. And they are talking about these terminals. Now a terminal in this case is something that allows your devices to talk to the Starlink satellites, or there's going to be a huge constellation. They've got 2000 satellites up and they're putting another 12,000.

    [00:22:38] These types of satellites are much different than what we've been used to over the years. We typically we've had these massive things sitting up in space. I worked with RCA Astro space many years ago and I saw. They're testing facilities, which are just incredible. They had this huge vacuum chamber that they brought me in to see as we were working on space shuttle software.

    [00:23:05] Yeah. I wrote software that they used to put the space shuttle together yeah. Way back in the day. So that was a pretty proud moment. Anyways. It's we're not talking about these huge satellites, like they used to launch, we're talking about very small cell. And they're not just sitting way, way up there.

    [00:23:26] These are in basically in low orbit around the earth and they're geostationary. In other words, they stay in one spot. I believe this is the way they've got these things set up. So these satellites then allow because they're so close to the earth, allow them to use less power. And also the other advantage to that is.

    [00:23:49] The delay, right? The delay between having to send it all the way up and back down, because electricity takes time, right? Yeah. Travels at the speed of light. But nowadays you might've noticed it can take your quarter second, half a second. When you're talking to someone, when I'm on the radio with some of these radio stations or the delay can be absolutely incredible.

    [00:24:11] Like I half second to a second sometimes. And that's just because they're being cheap. This type of technology where you have these constellations and it isn't just Elon Musk. It isn't just Starling, but constellations with will ultimately we'll have tens of thousands of satellites up there. Not, there's all kinds of other potential problems not getting into that right now.

    [00:24:34] But what it does mean is. Can communicate and we've never had this sort of thing before we had the us military, the Navy in fact, put together a communication system that lives on top of the internet and called nowadays. Generically the dark web. And it was set up to allow our military, our state department to be able to communicate with people in countries that are back in the day under Soviet control, all kinds of potential problems.

    [00:25:10] So whenever those problems existed, they just went ahead and used this onion network, which is a part of the dark web, et cetera, et cetera. So let's say we had before. Now what happens if you're a country like Ukraine, where 100% of your internet comes from Russia, Russia obviously can sit there and listen in.

    [00:25:32] Hopefully your encryptions. Good. A lot of Russians have been using telegram and already get real news about what's happening in their country and other places. And Della Graham is not that secure, frankly. WhatsApp pretty secure signal is the one you want to pay close. Attention to signal is considered to be the most secure of all of these secure communications apps.

    [00:25:57] But there's a level above all of that, because if they can tell that you're communicating, even that is enough to give them some information. So they might not know what was in that transmission, but if the transmission is all of a sudden, a tons of activity coming over, lots of data, lots of messages going back and forth, they can say maybe there's something about to happen.

    [00:26:21] That came out. You might remember the old orange book for security way back in the eighties, I think is when it came out. But part of what you had to do was cover up your. Actual real communication. So it's one thing to have the communications encrypted, but you wanted to always have about the same amount of communications going back and forth.

    [00:26:42] So people couldn't figure out what you're doing now with these types of devices. That kind of problem still exists. And this is part of what Elon Musk is warning about here. Pull it up on my screen again, for those people who are watching Elon Musk is urging users of his satellite system to put their Starlink antennas as far as.

    [00:27:08] From people as possible. Now, why would he be doing that? Because frankly, that terminal is transmitting to the satellite as well as receiving from the satellite. And it is entirely possible that there could be some evil software that is listening in for the satellite transmissions and sends a little missile your way.

    [00:27:36] Also, of course the Russians have satellites in space that can look down on the ground. Now it's something as small as a terminal four Starlink, little hard to see, but Elon Musk is saying, Hey, listen guys, go ahead and camouflage it. You might want to spray paint. It just don't use metallic paint so that they can't see it and place it as far away from where people are as post.

    [00:27:59] So you can still use it and only use it when you need to use it. Don't keep it up and running all the time. But this is the start of something great. Something where you can't easily block people's communication. So Russia has tried to do. And they have been jamming the Starlink satellites. So what did must do?

    [00:28:23] He delivered all of his engineers to working on how can we get around the Russian Jack? And according to Elon Musk, they have gotten around it and they now have their satellite systems completely jammed free from the Russians. I think that's fascinating. They're probably using some good spread spectrum technology that was actually known about it and world war II.

    [00:28:47] And then we can talk about that for a long time. Heady, you might remember her anyways, skip that for now. Stick her out. We got more when we. A whole bunch of pandemonium out there because of what Russia's been doing in Ukraine and how it's flowing over to us as well. Hey, this is not great news.

    [00:29:15] Pandemonium is the name of the game over there in Russia. And they are being very successful. We're going to talk about what happened in Bella ruse. We'll talk a little bit about what happened in Ukraine with cybersecurity and what's happening right here right now.

    [00:29:36] Complete ARS Technica today. They've got some great articles this week, looking into the Russians. What are they doing? What kind of problems is that causing us? But we are seeing some interesting attacks back on. And back in very big way. Russia has been going after you crane in the cyberspace for a long time, we spoke a few years ago about what Russia had been doing with the tax software for Ukraine.

    [00:30:12] We don't do this in the U.S. Or in Canada, but my number of European countries do you, where you have to have. The old official tax preparation software put together by the government for your business or for your person, depending on the country you're living in France is a great example of this. And Ukraine is another one.

    [00:30:36] So Ukraine says, Hey guys, you got to go ahead and use our software. That means every business in Ukraine is using their software. To manage their tax payments and their accounts, frankly. And that wonderful little piece of software was hijacked by our friends in Russia. So they grabbed a hold of it. They in.

    [00:31:02] Did some code into it that added rent somewhere to the software. So now all of the businesses in Ukraine are pretty much guaranteed to be using this hacked software. We have a client who has offices over in France, and we found a really interesting problem with them because. The French software that was being used for taxes for French businesses had an extra little problem.

    [00:31:33] And that extra problem was, it was insecure as can be whoever wrote this, must've taken a Microsoft programming course and had no idea DIA about the consequences of what they were. So it was very insecure. The, it was using a version of SSL, which is an encryption that's based on another type of increase.

    [00:31:57] I don't want to get too wonky here, but that was just one of its many problems and bad keys, et cetera, et cetera. And keys by the way, was using keys that have been revoked, which you should never do. Bottom line. Oh my gosh. Hey, if you want more information on this, just drop me a note.

    [00:32:16] me@craigpetersohndotcomandyoucanalsogetmynewsletterwithallkindsofgreatlittletipsmeatcraigpeterson.com. Just let me know. So in this case, we had to help that company in France. Ignore the security restrictions that were on their systems so they could use the French tax system. So anyways, I told you that, so I could tell you that the same thing happened to Ukraine.

    [00:32:45] In a different way, their software was pre infected. So when they downloaded it, ta-da. They got that piece of ransomware that virus had spread. It was just a nightmare. And of course it robbed. If you will, Ukraine, government of funds, that would have been. So we had now a bit of a shift. I'm going to pull this up on the screen again, this article, because what this shift has shown is that the hackers are now operating on the side of you.

    [00:33:21] Crazy. Which is just fascinating. So the group called anonymous, you might be familiar with them. Of course, they've been doing a lot of hacking for a lot of years, releasing private information, government and information, all that sort of stuff. And they have a mast what they're calling a volunteer.

    [00:33:44] It. And this it army has been going and doing what well hacking Russian sites apparently. So this article is just absolutely fascinating and they pulled some of from wired as well, but the Russian space research Institute, their website was hacked, leaked files that were stolen from the Russian space agency, made it all the way on to the.

    [00:34:13] The space agency was hacked in their website said, leave Ukraine alone, Alto anonymous. Will you up even more? They also did. What's called a D O S. Which is a distributed denial of service attack. Those can be very difficult to protect against unless you're set up in advance to help protect yourself.

    [00:34:39] And that pretty much destroyed Russia's dot are you top level domain? So we've talked about how domain services work, right? So Doug are, you is like.com except dot R U is for running. And so the domain name servers that handled our, you were knocked off the air because no one could really get to them.

    [00:35:02] They used amplifying attacks and stuff without getting into all of the details. So basically they were trying to cut off access and they did for a lot of people to any. That ended in, are you? It's great. These are just some of the latest in this surge of hacktivism. That's been going on one of the ones I mentioned a couple of weeks ago with the Belarusians deciding they were going to hack the Belarus railroad, which was being used.

    [00:35:31] To bring Russian troops, supplies, tanks, et cetera, all on rail, right on down right to the border of Ukraine. So that was hacked so that they couldn't use it in order to go after. Of course Russia was able to get to Ukraine, but there's also been protests around the world. 48 Russian cities raise millions of dollars through cryptocurrency donations.

    [00:36:01] Now, I'm not a big cryptocurrency guy and I'm not a big crypto currency guy because while. Cryptocurrency is likely to be outlawed by most, if not all governments. And they certainly could shut it down and it is not anonymous. All right. So using cryptocurrency does not mean it does not equate to completely anonymous.

    [00:36:28] They have done a lot of donations. They're big companies including, we just talked earlier about Microsoft, but also apple shell, BP, a McDonald's Starbucks. And these hacktivists have really joined in. And w we talked about a couple of other things, so this is messy. Because even more than in peace time, these active combat that are really hacking happening right now, rendering, hacktivism, any effectual and largely just distracting because we are now in a hot war right now.

    [00:37:10] Maybe we don't have our. Eric planes bombing Russian movements or other things, but there is a kinetic war going on over there. There are bullets, et cetera, mean exchanged. So the hacktivist efforts have been, visible. There's no question about that. But what have they done? See, that's an advantage to being a country like Russia, or like the Ukraine, or excuse me, Ukraine, because both of those countries there, their industrial base, the military industrial base is not heavily automated unlike ours.

    [00:37:50] What could you do? What can you shut down? So what you shut down the Russian space agency's website, how far did you get into it? Probably not very far. We also have a couple of groups and we talked about these guys many times the Conti group, which has been.

    [00:38:07] Terrible and hurting us businesses, individuals, government agencies, and stuff, the Cuming project, both of them have declared their allegiance to Russia. You might remember a few weeks ago, we talked here about how we have had some researchers track down most of these Russian hacker groups and their money.

    [00:38:30] And they all ended up in one building in Moscow. No, that should tell you something, right? In fact, the most expensive real estate right there in downtown Los gal, the tallest building, et cetera. So these groups getting together in order to protect the father land there in Russia. Ah interesting problem.

    [00:38:52] How much of this is really controlled by the Kremlin? It's a very good question. Context. Was dismantling its infrastructure. It, some of their top people were arrested by Putins military. Not military, but police state over there. And that was interesting too. That was again before the invasion, but why would Putin be shutting them down at all?

    [00:39:20] Apparently they said some things. That they shouldn't have said. So now they've come out and have decided they're going to support Russia in its entirety. Now we mentioned Microsoft and how Microsoft has decided they are going to protect other countries. As well as you crane, at least as far as the Russian malware goes, and they've been very active in that.

    [00:39:46] And there are a number of cybersecurity companies and other organizations that have released free versions of some of their software, these digital defense tools. Free offerings. Our big cranes defend the networks. Google says it's human rights focus de dos protection service project shield is now in use by more than 150 Ukrainian websites.

    [00:40:12] So it's very good. Bottom line propped up by the way, published this massive trove of personal data. Allegedly identifying 120,000 Russian soldiers deploy. In Ukraine that was Ukrainian prov, not the old good old Russian Sophia Pramata man. I remember I bought one of those on new standing Canada once.

    [00:40:36] And I had a friend who was from Yugoslavia and he said, oh, can I show that to my wife? He showed it to his wife. She tore it up. I said, I want my Pravda, Craig Peterson dot com.

    [00:40:47] The tech world is all a buzz with this log for J or log for shell. However you want to call it because we are looking at what is probably the biggest security vulnerability the internet has had in a long time. I don't know how to express it anymore, but there are multiple problems here. And even the patch that was released to fix this problem was broken as being exploited in the last 24 hours. There've been no less than 30 different new. Variations of the exploit. So what is going on? There is a computer language that's used by many programmers, particularly in larger businesses called Java.

    [00:41:37] You might remember this, I've been following it and using it now, since it first came out very long time ago from sun Microsystems. Java is a language that's designed to have kind of an intimate. CPU processor. So think about it. If you have an Intel chip that is an x86 type chip, what can you use instead of that Intel chip to run that code?

    [00:42:03] There are some compatible chips made mainly by AMD advanced micro devices, but you're really rather limited. You have problems. Power. Guess what you're stuck. You're stuck in that architecture. And then on the other end of the spectrum, you have some of these devices that are designed by companies like apple, Google has their own.

    [00:42:24] Now that our CPU's their graphics processing units as well. And they completely replaced the Intel architecture. But the Intel code, the programs that are written for the Intel architecture that are compiled for Intel are not going to work on the apple chips and vice versa. So what did apple do? Apple, for instance, just moved from Intel over to.

    [00:42:51] Own chipsets and these chips don't run Intel code. So how can you run your old apple apps? Apple has a little translator. They call Rosetta. It sits in the middle and it pretends it's an Intel processor. This really rather simple. And they've done an amazing job on this. And w Rosetta is actually a third party company and they helped apple as well with the transition from the IBM power series chips to the Intel chips.

    [00:43:23] So how do you move the code around while you either have. Recompile it, you may have to redesign it, rearchitect it for the new type of processor and the new types of computers that are supported by that processor. Or you may do what Apple's done here a couple of times now, and that is having an interpreter in the middle that pretends it's something else pretends as an Intel chip.

    [00:43:49] And then you can still run your in. Code because it knows, okay. It was designed originally for this apple Intel architecture. So I know how to make all of this work Java steps in and says why are you doing all of that? That's crazy. Isn't it moving all of your code around all of the time. So Java's original claim to fame was what will make life easy for?

    [00:44:14] What you do is you write your code. Using Java in Java is very similar to C plus in some of these other languages that are out there. And that language, when you're writing your source code will be compiled into an intermediate. Code. So what happened is sun Microsystems designed this virtual machine?

    [00:44:36] Now don't think of it like a normal VM, but we're talking about a CPU architecture and CPU instructions. And so what it did for those CPU instructions. Which is really quite clever, as I said we'll come up with what we think are the most useful. And it's a Cisco architecture for those of you who are ultra geeks like myself.

    [00:44:59] And we will go ahead and implement that. And so the compiler spits out code for this CPU that doesn't actually exist anywhere in the known universe. And then what happened is sun went out and said, okay we'll make an interpreter for. Artificial CPU that'll run on Intel chips and we'll make another one that runs on these chips, that chips and the other chips, beautiful concept, because basically you could write your code once debug it and run it off.

    [00:45:32] Anything that was one of the original claims to fame for Unix, not so the run at anywhere part of it, but the part that says it doesn't take much work to move your code to different machine, and we're not going to get into Unix and its root I've been around the whole time. It's crazy.

    [00:45:51] I just finished reading a book and saying, I remember that. And they were going through all of the history of everything I was in the middle of that. I did that. That was the first one to do this. It was fun. Anyhow, what Java has done now is it's really solidified itself in the larger enterprises.

    [00:46:11] So basically any software that you might be using, like our website that is particularly with a larger business. Is going to be using Java and that Java language is using libraries. So in programmers, instead of doing what I used to do way back when which is write in assembly code, or even in COBOL, and basically you had to write everything, every part of every program, anything you wanted to have done, you had to write, or maybe you borrowed somebody else's code and you embedded it in.

    [00:46:45] And mind you, we only had 32 kilobytes of memory in the mainframe back then the 360 30, for those of you who remember those things, but here is where things really changed. You now had the ability to take that code that you wrote and put it on a smart. You could take that exact same code, no recompiling or anything, and take that code and run it on a mainframe on our super computer in a car.

    [00:47:15] So Java became very popular for that. Very reason in these libraries that Java provided, made it even quicker to program and easier to program. Now there's some problems with languages. Java, which are these object oriented languages where you can, for instance, say one plus one equals two. That will make sense.

    [00:47:38] But what does it mean when you use a plus sign? When you're talking about words? So you say apple plus oranges, what's that going to eat? That's called overloading an operator, and this is not a course on programming languages, but what happens is a person can write the library and says, oh if the programmer says a non-Apple plus an orange or string plus a string, what I want you to do is concatenate the strings.

    [00:48:06] Now that programmer who wrote that has to figure out a couple of things, make some assumptions. Oh I should I put a space between apple and. Or not. And what do they really mean? Okay. So this is how I'm going to interpret it. So that, it's a very simple example. But the concept is that now with these overloaded opera operations and these libraries that can go deep deep, you now have the additional problem of people designing and writing the libraries, making assumptions about what the programmer wants and what the programmer needs.

    [00:48:43] Enter the problem with the log for J vulnerability. This is a very big deal because we're talking about a library function that is being used in Java by programmers. Now, you know that I have been warning everybody. Android for years, the biggest problem with Android isn't its user interface. It isn't that it's made by somebody else.

    [00:49:10] The biggest problem. And of course, this is my opinion is that Android software is provided by Google and. It is given basically to any manufacturer that wants to license it. And then that manufacturer can't just take Google and run it. Have you ever tried to install windows or Linux or free BSD?

    [00:49:36] It's mainly a windows problem, frankly, but you go on ahead and install that. And what do you need in windows? You're going to need driver. Oh wait a minute. This laptop is three years old. So how can I find them? And then you go around and you work on it and takes you a day and you finally find everything you need.

    [00:49:53] And you've got all of the drivers and now it works. But Microsoft provided you with the base operating system. Why do you need drivers? You know the answer to that and it's because every piece of equipment out there is different. Think about this in the smartphone market. Think about it in the more general.

    [00:50:10] Android market. There are thousands of these devices that are out there and those different devices are using different hardware, which require different drivers. So when Google comes up with a software patch, how well we just fix the log for J issue that patch. Has to be given to the devices manufacturer who then has to talk to the manufacturers of the various components and make sure that the device drivers that they're using by the manufacturer are actually compatible.

    [00:50:50] They're going to. Got the upgrades, wire it all together, and then test it on all of the different phones that they have and cars because the cars are running it. Now you see how complicated this get. And most Android devices will never. Get another update. They will never get a security patch versus apple.

    [00:51:14] Right now. They're still supporting the apple six S that came out in 2015. If I remember right, it's five or six years old. Now you don't find that in the Android space. You're lucky if you get two years worth of support, we're going to continue this. But this is this is really important. I'm going to talk more about the actual problem.

    [00:51:36] What is being done about it? What you can do about it as an individual, a home user, and as a business, in fact, keep an eye on your mailboxes. Cause I've got some more links to some sites about what you can do and how to do it and how to test for it.

    [00:51:53] We're talking about what is likely to be the biggest set of hacks in internet history right now. It's absolutely incredible what's going on. So we're going to talk about what it means to you and what's really going on. This whole problem is probably bigger than anybody really realizes because Java, as I explained is a very common computer programming language.

    [00:52:23] And it has a lot of features that bigger businesses love. They love the ability to have multiple programmers working on something at the same time. They love the inheritance and multiple inheritance and all of these wonderful features of Java. One of the really cool features is that you can, while your program is running, have the program change.

    [00:52:48] It's. That's effectively what it's doing. It's pulling in libraries and functions in real time. And that's where this particular problem comes in. This has been a nightmare for Java forever. It's one of the reasons I have never migrated to Java for any of the projects that I have. Don, it just gets to be a nightmare.

    [00:53:12] It reminds me of Adobe flash. It was the biggest security problem that has ever been. And the number two Java and Java is running in the Android operating system. It is the core of the operating system. All of the programs are almost certainly written into. And now we're seeing Java up in the, not just entertainment systems in our cars, but in the actual computers that are driving the cars, running the cars.

    [00:53:45] And I get very concerned about this. We had two major outages just this week before this log for J thing came about over at Amazon. And those two Amazon outages knocked thousands of businesses. Off the air out of business. You couldn't get to them. You remember the big problem with Facebook that we talked about a little while back and in both cases, it looks like they were using some automatic distribution of software sent out the wrong stuff.

    [00:54:15] And now you are effected. What happens? What happens with the cars? If they push out a bad patch, how are we going to know. What's that going to mean? And if your car has Java in it, are you going to be vulnerable to this? You wouldn't be vulnerable to log for J if your computer wasn't hooked up to anything, but nowadays the cars are hooked up to the net.

    [00:54:39] We've had a couple of car dealers for our clients. Who've had the Mercedes we've had Acura Honda and others over the years. And it's interesting going in there now and working with them because they are doing massive downloads of firmware whenever a car comes in. So that car, if they don't have the right kind of networks, that car can take hours to do.

    [00:55:07] Dates. And I got to tell you, man, I'm just shocked by so many businesses, not willing to spend the money that it really takes. So the poor technician is sitting there waiting for it to happen. We could make it happen in 15 minutes, but they're stuck there waiting for three or four hours sometimes for some of these downloads, no it's called cash them locally.

    [00:55:26] These cars, some of them need new and different firmware. Some of them use the same and have. A reliable, fast internet connection. And we've done that for many companies. Anyways, I'm going off on a bit of a tangent here. So forget that let's get back into this with Java. You can have a routine.

    [00:55:48] Call another routine that was not even necessarily thought of by the programmer. Now, can you imagine that? So you're programming and you're not considering adding something that's going to send email out and yet you could have a log in. That's part of the DNS and it gets logged that actually causes an email to be sent or causes anything else to happen.

    [00:56:17] That the exact problem we're seeing right now, it's absolutely crazy patterns in text fields, things like you can put a user desk agent. Which is normal for nature. UDP connection. You say, this is usually a guy who using Chrome version bar or Firefox or safari, but you put the user agent field.

    [00:56:40] And then after that, you've put in some, a little bit of code that tells Java, Hey, what I want you to do is this. This is a problem because we're finding now that I'm, again, I said the last 24 hours, 30 different exploits over a million companies have been attacked on this. And we're talking about 10.

    [00:57:05] Companies, absolutely hacked every minute right now. Can you think of, let's just think about that. And we're in the middle of what, right? The big holiday season, we've had some holidays, there's people online, shopping there's businesses that are trying to buy stuff, business stuff, almost every one of those sites is likely to be compromised.

    [00:57:31] It's that bad. It's absolutely nuts. What's happening here. This is a huge flaw. And by the way, it is flaw. Number this you ready for? This 44,228. In the year 2021. So the written 44,000 flaws that have been discovered and reported, this is the CVE system for those of you who are interested, but this really is a worst case scenario.

    [00:58:02] Because this log for J library is being pulled in to so many pieces of software out there on so many different platforms. The paths to to exploit this vulnerability are almost unlimited. And because there's so many dependencies on this particular log for J library, it's going to make it very difficult to patch without breaking other things.

    [00:58:32] And the fact the exploit itself fits in. Tweet come injected almost anywhere. So it's going to be a very long weekend for a lot of people, but let me tell you this. It is not going to be solved in a few days, a week, a month. We're going to be seen this. Years, because you have to be the person that wrote the program that has the source code to link in the new libraries, distributed out to your customers.

    [00:59:03] Do you see what a nightmare? This is now? Some people are saying let's blame this on open source. This is an open source product. Yeah, it is an open source project and it turns out that even though anyone can grab this, these, this library routine or any of these pieces of code, anybody can grab it.

    [00:59:21] Anybody can look at it. It turns out it's one guy. Who actually maintained this, who has a budget of $2,000 a year to maintain it. Nobody else pitched in. And all of these big companies are all out there grabbing this code that this guy has been working on and not paying much attention to it. Not donating to the project.

    [00:59:46] Which is saving them millions of dollars, not that one project, but all of these projects collectively in the open source community, it's it is more far reaching than this stretch vulnerability. You might remember this drug vulnerability that's was, that was the root cause of the massive breach at Equifax that Explo exposed all of our personal information.

    [01:00:14] To the dark web. That's how bad this is. Oh my gosh. So Hey, if you want information, I've got a links, a bunch of links set up here on what to do while you're waiting for the log for J updates from your vendors, how you can find on your servers. If they have the log for J vulnerability, I've got a bunch of information that I've stored up on that.

    [01:00:41] And some others just email me. M [email protected] asked for the list of the log for Jay's stuff or the Java's stuff. I'll figure it out. Be glad to send it to anyone that's interested. And if you need to scan to find out yourself and your business, let me know to [email protected].

    [01:01:03] Wow. I was just going through a list published by Seesaw, this federal government agency that tracks some of these types of vulnerabilities. And wow, this list is daunting of all of these pieces of software that are vulnerable to this huge hack.

    [01:01:19] This is now a problem for each and every one of us.

    [01:01:23] I think I've established the man. This is nasty. So what do you do? First of all, I sent out. Email a list of things have in fact, a few different lists of things that you can do. So I had one for consumers, one for businesses and a general thing as well. And then a bunch of references.

    [01:01:47] Of course there's even more references and more great information now because I got that email. Pretty early. So I hope hopefully you had a chance to really look through that, but here let's just talk a little bit about this, what to do thing you already know because you guys really are the best and brightest that you need to be careful when you're on.

    [01:02:11] You cannot be online, Willy nilly, clicking on things. And that includes emails and links. And this time of year in fact, all year long, we're looking for. Wow, let's see. Is there a great bonus here? Look at they're having a sale, a discount. Oh no. I've only got three hours to respond or the deal's going to go away.

    [01:02:33] I've usually been of the sort that I just am, not that influenced by some of these deals, but. I do sometimes want to find out what it is. So I find myself this week clicking through on. I'm on a lot of marketing lists because I like to follow what different marketers are doing, that's technology.

    [01:02:55] And it's something I want to keep you guys informed about. And I found myself just crazy amount of double checking to make sure the link was valid. Now I'm sure you guys have, if you're on my email list, you might notice that the from address is not the me at Craig Peterson. Calm email address. You can always send email to [email protected] and it ends up in my email box.

    [01:03:21] And it might take me a few days, or even as much as a week or two to get back to you. If it's something there's an emergency, you really need to fill out the form on my website, but I will get back with you. But the problem that some people have noticed lately is. It doesn't say return address or sent from [email protected].

    [01:03:45] It's got this rather long convoluted convoluted URL that has nothing to do with Craig peterson.com, sows a number of people question it, it is a tracking. When can the idea is if I am going to be able to get back to people and if Karen is going to be able to nudge. I have to have these things tracked.

    [01:04:09] So the email from address, when you hit reply, it is going to go to the, again, my email list server guys, and it is going to get tracked so I know. Okay. Okay. So now I've got a few minutes or an hour. Let's sit down and go through a lot of these emails so I can get back to people. That's a problem for many people, that's even more of a problem today than it ever has been in the past.

    [01:04:38] Now there's been a few sites that have done something about tracking because many people don't like to be tracked. My self included, although, as I've always explained on the show, it's a double-edged sword because I would rather see commercials or ads for a Ford F-150 pickup truck. When I'm looking to buy.

    [01:05:00] Car or certainly a truck. I don't want to see ads for things I don't care about. And you probably don't either. So the tracking, I don't think is a huge deal. The statistics that have come out from apple recently are very interesting because what apple ended up doing is they put some new technology and to stop tracking.

    [01:05:25] And to stop you from being tracked. And basically what they're doing is a couple of things. One, they've got this new feature where they will download images and emails from their website, so that it's not they're not being able to localize where you are and then they're also doing something where you.

    [01:05:49] Are you are, you can't be tracked like you used to be able to be tracked. Let me just put it simply like that applications now have to have that little label warning label in the app store to let you know what they might be tracking, et cetera. So they've been accepting anti tracking behavior that came from our friends from.

    [01:06:13] Apple now Google, Facebook and others have been very upset about this thinking that they were going to lose a lot of business here in the advertising side, because you wouldn't be able to track them. So if you've got an apple iOS device, you probably noticed, it says, allow app to track your activity across other companies.

    [01:06:36] And websites, your data will be used to measure advertising efficiency. I don't know that's such a bad thing. And looking at the stats right now, I'm looking at Google's income. And a lot of that comes from YouTube after. Apple launched its new privacy initiative and it looks like Google really wasn't hit very badly.

    [01:07:00] What Facebook was worried about that they would just be losing all kinds of revenue. Also didn't turn out to be true. So it's an interesting thing to see and I've got to really compliment apple again. At this time on trying to keep our information private, I read a really great book this, so this is how the world ends talking about the whole cyber race and where things are likely going.

    [01:07:30] And it's frankly impressive. To see what Google has done to try and keep out our government from their networks, as well as foreign government and the whole thing with the Chinese hackers we've talked about before, where I've found them. Active inside our customer's network before. And this is where we get called in because there's a problem.

    [01:07:57] We look around, we find indications of compromise. We find the Chinese inside. Okay. So it isn't something that we were protecting them, the Chinese got in, but we come in after the fact and have to clean up the mess. But what we have really seen happen here is the largest transfer in. Of wealth, I should say, in history, the largest transfer of wealth in history to.

    [01:08:25] From us and from other countries, but primarily from us because of what they've stolen. And so Google really has fought hard against it. The Chinese have been in their systems have stolen a lot of stuff. Apple has fire fought hard against it, but we know about the apple stuff. Google's seems to be a little quieter about some of it.

    [01:08:45] So they may be selling our information to advertisers, but there certainly are trying to keep nation states out. I'm really wondering too, what is Google doing? Moving that artificial intelligence lab to China. It just it's insane. We know we, if we're going to get out of this financial position, we're in as a country, we need to have an amazing new technology.

    [01:09:09] So people are coming to the United States and we're certainly not seeing that. At least not yet. It's all been stolen. So what to do, man. I started talking about that and we got a little sidetracked. So I will talk about that a little bit more here coming right up and what to do if you're a consumer, if you're a business person.

    [01:09:32] And of course, as I mentioned earlier, I have. Quite a list. I'm more than glad to send you. If you go ahead and just email me, M [email protected]. I'll keep you up to date, let you know what's happening and give you those links that you can follow to find out exactly what is happening and what you can do.

    [01:09:53] Including some tools. There are some tools out there to check to see if that vulnerability exists inside your networks or systems MI. Ed Craig peterson.com. And I'll be glad to reach out, reach back to you.

    [01:10:09] I'm gonna tell you what to do as a consumer because of this massive internet hack that is underway. It is huge. Also going to talk a little bit about apple and what they're doing with their tracker detect app on Android devices.

    [01:10:24] This will be going on for months and probably years in some cases, because there are many systems that will never.

    [01:10:35] Patched for this vulnerability. So from now on, you need to be doubly cautious about almost everything, the big targets for this. Then people who tend to be the most valuable. Big businesses. And I can send you a list of devices that are known to be either immune to this they've been fixed or patched and devices that are known to have this problem.

    [01:11:03] You send me an email. Excuse me. If you have any questions about it. So it's me M [email protected]. I'd be glad to send you that list. Seesaw has it online. You can certainly search for it yourself. If you're interested in. So for you as an individual, it's just extra caution, use these one time, use credit card numbers.

    [01:11:31] I have talked about this before. And that is, I use fake identities as much as I possibly can online. And I'm not trying to defraud anyone. Of course, that would be legal. What I'm trying to do is not make myself as easy at target. As is frankly pretty much anybody who uses a computer out there, because if you're always using your, in the same name and email address and having forbid password, then you are a bigger target than you have to be.

    [01:12:07] And I have a whole index file. I have a spreadsheet that I put together with 5,000 different identities, different names, of course, different sexes, races, origin stories, everything. And the whole idea behind that is why does some company that's providing me with some little website thing, need my real info.

    [01:12:31] They don't obviously you give you real info to the banks or. Counts, but you don't need to give it to anybody else. And that's what I do. That's my goal. So if you can do that, do that. Apple also has a way for you to use random. Email address a suit can set up a different email address for every website you visit.

    [01:12:57] There are a few services out there that can do it. If you're interested, drop me an email. [email protected]. I'll send you a list of some of them. I think they're all paid except for the app. But you have to have an apple account in order to use it. One of the things that businesses really need to do is do a scan.

    [01:13:19] Again, I can send you a list of scanners so that you can look at your network, see if there's any. Obvious that might have huge implications for your business. Again, [email protected], one of the things apple has come up with that I really have turned out to and I think I mentioned them before on the air, but it's these news.

    [01:13:41] Trackers that apple has, that you can put on things. And we spoke a little bit last week about the problem with these trackers being put on to high-end cars, and then being used to track the car. Now apple got around that problem a while ago, by letting you know, Hey, there is a tracker following you isn't that handy.

    [01:14:04] Wait a minute, somebody dropped one of these little tags into my purse. Coat my car or whatever it might be. And so now you can have a look and see where is this thing that's following me and get rid of it. Of course, in order to know that there's one of these apple tags tracking, you've needed to have an apple phone.

    [01:14:26] Because it'll warn you. Apple now has something called tracker detect. If you are using an Android phone, I would highly advise you to get this app tracker detect app on Android. And it's designed to help you Android users from being tracked by apple airtight. 'cause if you don't know you're being tracked right, then you can't know if you're being tracked.

    [01:14:55] If you don't have an iPhone, unless you get this app so good for them, apple has it up now on the Google play store. That's just in the last week or so, and it lets you locate nearby air tags. So let's I think a very good thing kind of wonder if apple isn't using the Androids also for part of the.

    [01:15:16] Crowdsourcing for the air tags, but that's a different conversation. Great article in vice this week by Aaron Gordon, about how car companies want you to keep paying. Features you already have, and they specifically made a call out about a car manufacturer. Toyota. Who's now charging $80 a year for people who bought their car years ago, six years ago, $80 a year.

    [01:15:51] If you want to keep using the remote start function on your key. Yeah, so you paid for it and life was good. You went a few years, really nice on a cold winter day or a hot summer day, warm up the car or cool it down all automatically. But now Toyota is charging. $80 a year. So people are saying why I bought it?

    [01:16:16] Why would I pay for that? Apple's now claiming that the several first years were merely a free trial period, but this isn't even the big play for these car companies, this $80 a year for marginal features like remote start instead. Is probably going to happen. And I agree with this author as well is we're going to see a, an approach that Elon Musk has used with his Teslas.

    [01:16:47] They're going to charge extra for performance, for range, for safety upgrades, for electric vehicles that actually make the car better car, a better car. So upgrades used to be difficult or impossible with gas cars. A lot of these are trivial for the electric cars, with the dashboards that have games that you can play while you are charging.

    [01:17:13] Some of them were complaining about it being for when they're on the road. Of course that's going to happen because frankly, when, once we get a full autonomous car, what are outs are you going to do? I should also mention this isn't really a, but Mercedes-Benz has been awarded the very first license for the manufacturer sale and distribution of a fully autonomous vehicle.

    [01:17:39] The very first they are licensed for up to, I think it was 37 miles per hour. On their car and anything beyond that, you still have to retain control, but that's an amazing thing. And it only works on roads that are mapped. And what Mercedes is doing is they have these super high definition maps. So the car knows exactly where it is.

    [01:18:08] If you are a Tesla owner, you know that a few years ago, Paid, I think it was $2,000 for your Tesla to be able to drive itself. And of course they haven't been able to drive themselves. They, yeah, there's been features here and there, but how were you getting those features? How will you going to get that self-driving mode?

    [01:18:30] We'll test those, calling them over the air upgrades. And they're also saying. Th this is part of the Tesla ownership experience to quote their website. All right. So they've had all kinds of over the air upgrade. They've had some free software. They've had paid ones, Tesla charges, thousands of dollars for its autopilot.

    [01:18:54] Now a lot of money, I think it was five grand. Now they've got this beta driver assist system as well, and they also have. To others. You might remember the ludicrous speed. Long range model three would dual motors is capable of accelerating from zero to 60 in 3.9 seconds. But when you buy the car, the zero to 60 time is a half a second longer.

    [01:19:25] So pay an extra $2,000 and you get that extra half second and accelerate. Yeah, there's nothing different. They don't even have to change. Really changed the software. There's no hardware differences. It's just, you pay them two grand and they, your cars catheter to the internet and they just unlock a key is not something.

    [01:19:48] Now there some people that hack the way around that paywall, but then Tesla blocked it and reversed the hack as well. Tesla has sold their cars now for years with the same 75 kilowatt hour battery. But software locked them to 60 and 70 kilowatt hours might remember. We talked about this with a hurricane that came ashore down in Texas, where Tesla, anyone in that area provided them with an automatic upgrade for extra batteries.

    [01:20:19] So they could go further in order to get out of the zone of their herd. Before them in software lock-in and a 60 and 70 kilowatt hours, unless you paid an additional $3,000 for that extra 30 or 40 miles of range. Isn't that something. Yeah. So Tesla has temporarily unlocked them, but this is where we're going.

    [01:20:43] You're going to be going into the car dealership while in Tesla's case. It's on the internet, which I think is better. Frankly, dealerships are handy in order to get a repair, but. You can get a repair at some of these little specialty shops it's often better and certainly cheaper than what the dealership sells, but you're not only going to be haggling over the price of the vehicle and delivery times.

    [01:21:08] You're going to be haggling over all of these different features. And it's never going to end because they're going to keep having software upgrades that you're going to have to pay for. Pollstar star. This is an electric vehicle company spun off from Volvo new member. Volvo is now Chinese company.

    [01:21:25] Yeah. Chinese. Yeah. So much for safety, right? They're going to charge an extra thousand dollars for a slight increase in horsepower and torque, just like Tesla does. So this is the future. Of car companies. Hey, I want to remind everyone, if you go to my website, Craig peterson.com. Right now you can sign up for my weekly newsletter.

    [01:21:48] It is packed full of great information for you. Every week. We've got some free boot camps coming up after the first of the year, and you need to be on my email list to find out about it. CraigPeterson.com/subscribe.

    1 hr 23 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who justโ€ฆ