
Sign up to save your podcasts
Or


Are You Ready For Data Wiping Attacks?
Yet another warning coming out from the federal government about cyber security. And this one is based on what's been happening in Ukraine. So we're going to talk about that situation, the whole cyber security over there and why it's coming here.
[Automated transcript follows]
CISA is the cybersecurity and infrastructure security agency. How's that for a name it's not as bad as what does that shield right over from the Marvel universe, but the cybersecurity and infrastructure security agency is the agency that was created to not just protect federal government systems, although they are providing information for.
[00:00:41] People who protect those systems, but also for businesses and you and me and our homes. So they keep an eye on what's happening, what the various companies out there are finding, because most of the cybersecurity information that we get is from private companies and they. But it altogether, put it in a nice little wrapping paper.
[00:01:05] In fact, you can go onto their website anytime that you'd like to, and find all kinds of stuff that is going to help you out. They've got a ton of documents that you can download for free little steps that you can take. It's at csun.gov, C I S a.gov. And they've got the known exploited vulnerabilities catalog.
[00:01:30] That's something that we keep up to date on to help make sure our clients are staying ahead of the game. They've also got their review board securing public gatherings. They also run the stop ransomware.gov site that you might want to check out. And we'll be talking a little bit more about ransomware and the ways to protect yourself a little later today.
[00:01:52] Now Seesaw is interesting too, because when they are releasing information, most Americans really aren't aware that they even exist. They do. And they've got a big warning for us this week. There's a site that I follow called bleeping computer that you might want to keep an eye on and they have.
[00:02:15] I'll report just out this week that you, crane government agencies and corporate entities were being attacked. This was a coordinated cyber attack last Friday, a week ago, where websites were defaced data wiping malware was deployed and causing all of these systems to become not just a corrupt, but some of these windows devices to be completely.
[00:02:45] Operable now that is a bad thing. The reason for this, this is speculation, but it isn't a whole lot of speculation. Right? Am I getting out of, on a limb here particularly, but the whole idea behind this is a cyber war, that Russia's got, what is it now? 130,000 troops, whatever it is over a hundred thousand.
[00:03:08] On the border of Ukraine, they invaded Ukraine a few years ago. Russians shot down a passenger airline in Ukrainian air space. This that was a few years back. They've been doing all kinds of nastiness to those poor Ukrainians. They also had a massive ransomware attack in Ukraine. That was aimed at their tax software.
[00:03:35] Some countries do the electronic filing thing a lot differently than the us does. A couple of examples are Ukraine. France is another one that comes to mind. We have clients in France that we've had to help with cyber safety. And we're always getting popups about major security problems in the tax software, because they have to use this software that's provided by the French government.
[00:04:03] Ukraine's kind of the same way. The biggest. Company providing and the tax filing software for Ukraine was hacked and they use that hack to then get into the tech software and make it so that when that software was run by these Ukrainian companies, they would get ransomware. It was really rather nasty.
[00:04:30] So the Russians had been playing games over in Ukraine for quite a while. But what's apparently happened now, is that a thing? Those things, same things are coming our way now. It's not just because of the fact that a Ukraine is being threatened, maybe they're going to encroach even more, take more than Crimea, which they did last time.
[00:04:56] We're in the U S and what are we doing? President? Biden's been sending troops to Europe, troops to Poland, Germany, and also advisors to the Ukraine. He's removed the embassy staff, at least the vast majority of it from Ukraine. And I just I think. To what happened with his completely unplanned withdrawal that we did in Afghanistan and how things just got really bad there.
[00:05:28] And I'm not worried about what's going to happen in Ukraine because the Russians aren't particularly fond of the idea that we are sending aid and support to. Yeah, it's a bad thing. President Obama sent them blankets, but Biden is sending them military weapons and ordinance, which is what they'd need to fight.
[00:05:53] So Russia has shown that they will attack a country via electronic means cyber means, right? Cyber attacks. And so what's happening now is the bad guys from. That have been the facing websites and who have been doing more than that, wiping computers and making them completely unusable could well come after us because they're really going to be upset with what's happening now.
[00:06:27] And that was CNN has reported the Ukrainian it services company that helped develop many of these sites was also a big. And of course that means bottom line, that this is what's called a supply chain attack. What I mentioned earlier with the Ukrainian tax software, that's a supply chain attack where you are buying that software, or you're mandated to use the software to file your taxes by the government.
[00:06:57] And what happens while it turns out that software is contaminated, that's called a supply chain attack. Now crane issued a press release about a week ago, saying that the entities were hit by both attacks, leading them to believe that they were coordinated. This is a quote here. Thus, it can be argued with high probability that the interface.
[00:07:24] Of websites have attacked government agencies and destruction of data by Viper are part of a cyber attacking, but causing as much damage to the infrastructure of state electronic resource that's from the Ukrainian government, not the best English, but their English is much better than my Ukrainian or Russian.
[00:07:44] So you, crane is blaming these attacks on Russia, incomes, CS. So you says now urgent. Business people in the us and other organizations to take some specific steps. So quote, here from the Seesaw insights bulletin, the CSO insights is intended to ensure that senior leaders at the top of every organizational where the cyber risks and take urgent near term steps to reduce the likelihood and impact of a potentially damaging compromise.
[00:08:19] All organizations, regardless of the sector or side should immediately implement the steps outlined below. So here's the steps and there are a lot of them. One I'm going to do these, you should find in your newsletter today. Hopefully that all made it in. But three basic things. One reduce the likelihood of a damaging cyber intrusion.
[00:08:46] And we're going to talk about the best way to do backups here a little later on today. Make sure your software is up to date. Make sure your organization's it personnel disabled, all ports and protocols, not essential for business purposes. This is all basic stuff, but I got to say. I bet you, 98% of businesses and organizations, haven't done these things.
[00:09:07] The next major category here, take steps to quickly detect a potential intrusion, and then ultimately maximize the organizations resilient to destructive. Incident. So that means doing things like testing your backup procedure, make sure your data can be restored rapidly, or you have a way to get your business back online quickly.
[00:09:31] What we tend to do is in our backup strategy, depending on how much the company can afford, to be down. To be out of business if they lose all of their stock versus what it costs to do this, but we will put a server on site at the company and that server then does some of the backups, right? It does all of the initial backups.
[00:09:55] And then what happens is it gets relayed to us. It gets pushed to tape and tape is really good. We'll talk about that in just a few minutes, but the other big thing is. The backup that we have local to their business also has what's called a virtual machine infrastructure built on it. So if a machine goes down, If it gets wiped or if it just crashes and can't be recovered easily, we can spin up that machine.
[00:10:27] A copy of it in our little virtual environment in just a matter of minutes. So these are all things you should be considering. If you're interested, you can send an email to [email protected]. I can send you a checklist that a little more extensive than this, or I can help you with any other questions you have.
[00:10:47] I get lots of questions every week from everything for on retirees, wondering what they should do all the way through businesses that we help government contractors and others. This isn't good. Russia is likely coming after us. Based on this. Visit me online. Craig peterson.com or email [email protected] with your questions.
[00:11:14] With all of this talk about hackers, ransomware data, wiping systems. What's the best way to protect yourself, but what do you do to really protect against ransomware? I can tell you, it's not just plugging another hard disk into do backup.
[00:11:31] We've got so many hackers out there. We're talking about a multi-billion dollar industry to go after us.
[00:11:39] It's just depressing. Really. When you think about it, I think about the old days where security, wasn't a huge concern, right? Physical security. I had one of my first jobs was at a bank and I was, this was back way back in the a G it would have been the mid seventies and I was one of the operators of the main.
[00:12:05] And so as a mainframe operator, we'd load up the tapes and we would ship them places. We'd also go ahead and put them in the vault so that they were in a fireproof vault, and we could recover anything we needed to recover. It worked out pretty darn well, and it was a fun job, but most of the time it was cleaning the tape drive heads and taking those tapes, those big round tapes, you might remember those.
[00:12:33] Nine track tapes and maybe the fancy stuff, 52 50 BPI or 800 BPI of one end or the other, or the spectrum. And we just had to make sure they were physically safe nowadays of course, mainframes are still around and are still absolutely fantastic. They're just phenomenal. Some of the technology IBM has in their mainframes.
[00:12:59] Most of us, aren't using those. Most of us are using a regular computer or I'm sitting in front of a Mac right now that I use for the radio show. We have windows, computers, Linux machines, right? All of those things that we have in our business and that we maintain securely for our clients. But what do you do when we're talking about random?
[00:13:23] You can cross your fingers and hope that you'd hope you don't get ransomed. That sort of a practice doesn't usually work out too well for people, but you can do backups and many people do. So let's talk about the backups. Let's say that you have your computer and you're doing a backup and you have one or two generations worth of backups for your company.
[00:13:47] Ransomware nowadays does not just typically destroy your whole disk. Usually what it does is it encrypts files like doc files, doc X, right? Excel files, all kinds of files that thinks might be useful to you. And then of course, the rest, it pops up says, pay me. And off you go. The reason for that is so your computer still works so that you can enter in the decryption code.
[00:14:18] Once you've paid the ransom, hopefully it works for you give or take 50% of the time. You will get your data back. If you pay the ransom much of the time. But let's go back to that one or two generations of backup. You're using a cloud service, let's say, and your computer gets ransomware. That cloud service backup software will still work.
[00:14:43] What if it's working? So you're now backing up your encrypted files to the backup site in the cloud. Do you see where I'm going with this? Your backups? No. Same thing is true. If you're backing up to a local hard disk, many people do it and it's handy. I recommend that you do that, but it's not all you should do.
[00:15:08] So that disc is attached. We had a. Boy, who was it here? Yeah, we have a client in Maine and they have a really smart system administrator and he designed these disk drives that would physically disconnect themselves from a machine when the backup was not running and would physically connect themselves when the backup.
[00:15:34] Was running. So the idea there was okay, great. We've got a local backup on a local disk and if the bad guys managed to get a hold of the machine, they're not going to be able to encrypt the. And, as long as the backup isn't running, I thought that was a brilliant solution. Doesn't solve some problems, but it certainly takes care of some others.
[00:15:58] So if you are doing a backup, you've got to make sure you've got multi generations. I tend to keep a year's worth. Now there's other considerations. There's the federal rules of. Procedures that say you have to have bad cops. They have to go back years. And there are also other things the payment card industry requires certain types of backups.
[00:16:25] If you are a government contract, We have them as clients and they have certain data retention policies based on the length of the contract. They have keep it for some years afterwards. It goes on and on. So if your data is lost or stolen or encrypted, and your backup is encrypted or deleted, You are in real trouble depending on the type of business you're in.
[00:16:56] So what's the right answer to this. I've talked about 3, 2, 1 backup for a long time, and it's still a very good methodology for doing backups, but nowadays they're talking about 3, 2, 1, 1 backup, which is again, that's a bit of a different methodology. In doing backups, but the idea is you've got multiple copies of your data on multiple types of media in multiple places.
[00:17:29] That's the bottom line. What is the gold standard for this? I it's something that gets to be a little expensive. Again, we have another client that we've had for years, and they are looking for a replacement for the backup system. Now. And so we proposed something that's based on what's called LTO technology, which is a type of a tape drive.
[00:17:55] It's a small cassette, right? It's not those big 12 inch reels of tape that we used to lug around and it's amazingly dance. The new LTO tape drives have space on them for as much as 45. Terabytes of information. It's also great because it's encrypted by hardware, government level encryption automatically, and those tapes can be taken offline.
[00:18:25] You can take the tape. Now we picked up a client who had been doing backups and they were using little USB drives and every day he'd take the drive home and bring in the next drive. So he had five drives, right? So he had the drive for Monday, Tuesday, Wednesday, Thursday, Friday. And he was taking them home, but he missed one of the key things to check the back.
[00:18:53] He hadn't checked the backup and their backup had not been running for more than a year and a half. So that's the other thing you have to do? The LTO tapes are really the gold standard. It goes back to that for one of the first jobs of mine, right? The job I mentioned, where I was mounting tapes and filing them and moving them around and mountain disc packs and pulling them out and everything.
[00:19:19] It still makes sense. They'll last for decades, they cannot be hacked because they are literally offline. You can ship them to places to have them stored. I have a course on backups and if you're really interested, send me a an email to [email protected]. And I'll go ahead and. Send you a link to the course, you can watch it.
[00:19:48] But yeah, I think this is really important. Of course, I'm not going to charge you for that, but magnetic tape it's established. It's understood. It's proven it's been around for many decades and LTO tape is unique. It needs all five best practices for addressing ransomware. Even be able to recover.
[00:20:12] If you want more information, just email [email protected] or sign up for my free newsletter. Craig peterson.com.
[00:20:22] Switching from gasoline powered engines to these new electric cars is no environmental panacea. At least that's what West Virginia university is saying. And the E. Just changed its mind as well.
[00:20:38] Ford of course, about a year ago, unveiled its new electric.
[00:20:43] F-150 the lightning and Ford has stopped taking orders for them because they are going to have to make double what they thought they would have to make. Ford also has a similar problem with yet another electric vehicle. The Mustang GM is doing a few different electric. Coles. And so is everybody else, frankly, Porsche even now has an electric car out.
[00:21:11] That is all well and good. Isn't it. And there's certainly problems, particularly with manufacturing nowadays, trying to get the CPU's and other electronic components you need. They're even having trouble getting electric motors for electric windows in vehicles. Now they're coming. Crank window with a little coupon saying later on, we'll convert it to electric for you all kinds of problems, but there's one that I haven't heard anybody but myself talk about.
[00:21:44] And so I was online looking around, doing some searches, seeing if I was, like the only one there's no way right now, I'm not the smartest person in the world. I don't pay the most attention to everything. And I found that. Virginia university is in total agreement with that with me, it's just amazing.
[00:22:06] They looked at recent trends and they're cautioning as I have been for years, at least a decade. Now they're cautioning about what seems to be a race to put more electric vehicles. On the road. And the problem is that these electric vehicles in their demand for electricity may well out, run what's needed to keep the vehicles on the road.
[00:22:35] So here's a quote from them. The electric grid will struggle to handle the quick charging of very many electric vehicles at the same time. Okay yeah, by the way, like hardly any quick charging is generally what everyone thinks about, like going to the gas station, getting a full charge in 10 to 15 minutes, which would be a tremendous instantaneous load on the local distribution center.
[00:23:03] My concern is the huge power dumps required at quick charging stations along the interstate. It sounds good, but it'll require a lot of new infrastructure to get the power to the charging stations, as well as building those charging stations. So where does the power come from? Power storage is going to be required if we're going to also move towards fixing.
[00:23:28] Power sources such as solar and wind. We do not have power storage capability yet in large enough quantities to do this on a large scale. Solar does not work at night. The wind doesn't blow all the time. Also, we do not have the distribution on the streets to move fast charging into residential neighborhoods on mass.
[00:23:52] Electric vehicles are great, but we have not fully considered the impact it'll have on our electrical grid infrastructure. It will require a lot of expansion of our electrical distribution and charging facilities. Remember, electric power comes from the power company. I heard an interview with a lady the other day, and they asked her, where does the electricity come?
[00:24:15] She said, From the plugin, the wall, right? We must consider this when considering wide-scale electric vehicle adoption, much as there is to gain from electric vehicles. I don't believe we're ready yet as a society for completely electrical vehicle transportation system. With time and infrastructure development, we can be.
[00:24:37] I totally agree. This is Rory Nutter, professor lane, department of computer science, electrical engineering, Benjamin M. Slater, college of engineering and mineral resources. I totally agree with that. We don't have the ability to generate the electricity. We don't have the ability to store the excess electricity.
[00:25:01] So in other words, if we're using solar at nighttime, we don't have the sun, we can't run solar. So we got to store the solar. And in fact, we have to make about twice as much electricity as we need during the day so that if we can store it, we can then use it in. The same thing with wind, right? It's fickle.
[00:25:24] It just doesn't work that well. So what do we need? Basically right now, we need to stop turning off our coal powered plants, our natural gas plans and our nuclear plant. Because we need to still have electricity. Look at what's happened last year. And this year over in Europe with the crazy cutbacks that they've been doing on some of these plants, coal nowadays with the scrubbers that are on our cold powered, flat plant is clean energy.
[00:25:58] It's not like the old days where you lived on the south side of the tracks and you got all of the wind blowing towards you that had all of that nasty cold ass. You ever seen any of those pictures? It was just terrible. All of that nasty sitcom. It's not something we need to worry about nowadays.
[00:26:16] The other big thing that ties into all of this is so how do we generate our electricity cleanly? A hundred percent cleanly? Nothing. Per cent, but just a couple of weeks ago, the European commission presented their 27 members states with new draft rules that classified natural gas and nuclear power as green fuels for electricity generation.
[00:26:47] Listen, if we want electric cars, which as we've talked about before are highly polluting. Yes. Because of the materials in them, because of the materials that go into the batteries, having to mine it, having to ship it, having to process it and then having to change out those battery packs after 80,000 or a hundred thousand miles.
[00:27:09] Did you see this guy? There was a meme in the video about this online a few weeks ago. How to test. His Tesla needed a battery replacement. It would cost him, I can't remember what it was. 20, $30,000. A lot of money. So he decided to just blow up the car. That's all it took. I saw another Tesla that had water damage.
[00:27:33] From, being down in new Orleans or somewhere, the flooding occurred. And the guy bought that Tesla because Tesla won't sell the parts to fix the car after the water damage. And so he ripped out the batteries, ripped out the electric motors and he bought a high power engine. And gasoline and put it into the Tesla and made really, quite a very cool car.
[00:28:00] You can find it online if you want to look for that, it's quite cool. What they ended up doing. It took us quite a while to do it, but they did it. So now that we're seeing. That nuclear is green. Let's talk about why we've been so afraid of nuclear. One of the biggest problems of course is so what do you do with all of the waste?
[00:28:20] And that's a legitimate question, but what you're really talking about when you ask that question are the reactors that went online 50 years ago, or that were approved 50 years ago because of the regulations. There are. These nuclear plants that have been provisioned in the last 20 years that are still using that old technology.
[00:28:43] So when we get back, we're going to talk about this more. What about the waste? What our fourth generation nuclear power plants, how safe are they when they say they're intrinsically safe? What does that mean? And how and why? Because I'm predicting to this point that we're going to have to switch back to nuclear and even the European union, if you can believe it agrees with.
[00:29:13] Hey, make sure you take a minute. Go online. Craig peterson.com. Subscribe to my free newsletter. You can get it right there. I send you out stuff every week. And this week is no exception. We've got a bunch of bullet points that if you are in a business position, you got to protect yourself immediately. So I tell you how Craig peterson.com.
[00:29:38] So what are these new rules for nuclear energy? And why is it absolutely necessary that we do something like this? Get fourth generation nuclear online. If we can even consider electric vehicles on our roads.
[00:29:55] Things have changed in the European union. They've been trying to figure out how they're gonna handle all of these electric vehicles, how they're going to properly handle all of the solar cells and the wind turbines.
[00:30:09] And there's even some work over in the EU. To get the tide to generate electricity, some very cool stuff. Actually, that's been done, I love tech and I'm into all of this stuff, frankly. I think we should be doing a lot of it. What I don't think we should be doing. Is getting ahead of ourselves. And unfortunately that's really what's being going on.
[00:30:35] We don't have a grid that can really use the electricity that we can generate from our windmills, from our solar cells, from anything, frankly. And we cannot. All of that electricity that we might be generating and somehow have that electricity be stored and used distributed appropriately to our charging station.
[00:31:03] And our grid was built and designed to have a few central point where the electricity is made, where it's generated and then distributed to some pretty specific types of things like housing, development, businesses, et cetera. You can't just go ahead and open a big business man. in a residential area.
[00:31:25] And part of the reason for that is the grid isn't set up for it. You don't have three phase power going into residential areas or even more than that, you don't have the high voltage, the high current, et cetera. So how are you going to be able to quick charge electric cars in the regular residential neighborhoods?
[00:31:47] I w how about at a hotel? Yeah. Okay. A hotel is probably. Multiple phases and has a fair amount of power there, but the amount of strain that's put on the grid by trying to just rapid charge a single car is huge. So how can we deal with that as well? The quickest and easiest way to deal with it is just put more large power plants online.
[00:32:13] Some people don't like that. Don't like that idea at all, frankly, but we're not ready. What are we going to do? Look at what happened in Texas with a fairly minor reliability or re reliance, I should say, on these windmills last winter and things with this winter, as cold as it's been, that could really cause some just incredible problems.
[00:32:40] Nuclear is being reconsidered, particularly fourth generation nuclear power plants. The greenhouse gas emissions from nuclear power are one 700th of those of coal. The nuclear power plants produce one, 400th greenhouse gas emissions of a gas plant, and they produce a quarter of the greenhouse gas emissions from solar.
[00:33:09] Now you're saying, Hey Craig, come on, I get it. Wait a minute, solar, how can solar produce greenhouse gas? It does. And it produces greenhouse gases because of the manufacturing processes, as well as of course it off gases. So how do we make all of this stuff work? We all saw the China syndrome and we heard from experts like Jane Fonda, how we would all die.
[00:33:34] If we put a nuclear power plant. These are intrinsically safe, power plants much different than they used to be. Nuclear power frankly is a much safer business than most people think it is. They no longer these new plants produce. The the nastiest what's called high level nuclear waste.
[00:34:00] They can reprocess it right there in the plant. They can start in fact where some of the nuclear waste though has been generated from the older nuclear plants and get rid of that. It's amazing. So people are asking okay. Plutonium might have a half-life of 24,000 years, but it doesn't emit much radiation.
[00:34:23] We get that. How about the higher levels of radiation? Because some of it can last for hundreds of thousands of years. According to the U S radiation expert, Robert Gale for every terawatt hour of electricity produced nuclear energy is 10. To 100 times safer than coal or gas. What it does emit are alpha particles, which do not even penetrate human skin.
[00:34:54] They've done all kinds of risk assessments and tried to figure out what's going to happen. What can we do? And I'm not going get into all the details here, but it is intrinsically safe because. What really happens is that the, these new plants he's fourth generation, a newer plant are instead of using water, for instance, that can do reactors out of Canada, use heavy water in order to cool those rods.
[00:35:25] It was same sort of thing we've had in the meltdowns before they're using a liquid silica inside. They're set up in such a way that they do not need to have pumps running. So the Fukushima reactor that you might remember in Japan that failed because of the tsunami and the fact that one fact, this is what was their killer that their electrical generation from the diesel generators went offline.
[00:35:56] Why did it go offline? Oh, I can see the grid going offline, but how about a diesel generator? If you have a below sealer, And the water comes in. You're in big trouble now. They didn't have it like below, permanently below sea level and Fukushima. But when that tsunami wave came in, it was below sea level.
[00:36:16] They just, man, we could talk for a long time about the problems that they had over there. The nepotism, the line on the forums. They fact they did not do the upgrades that the manufacturer has suggested on and on. So these new reactors can lose all power and you won't have a China store. They won't go through a meltdown and they're even designed in such a way, the way using physics things called the law of gravity, who would have thought, right?
[00:36:51] So that what happens in the worst case scenario is no one gets hurt. It just eats in on itself and then stops runs out of. So we've got to remember all of this stuff. Okay. The nuclear power of yesteryear is not the nuclear power of today. And the nuclear power of today is so green and so safe that even the European commission presented new draft rules that said to the natural gas, nuclear power, our agreement.
[00:37:29] Fuels for electricity generation. So assuming the rules are approved and Francis in favor, Germany isn't as into nuclear power. In fact, they plan on having all of their plants shut off by the end of 2025, which is crazy because they're already having serious problems with their solar and wind.
[00:37:53] And that's why they're buying so much natural gas now for. Yeah, American influence dropping over there. Thank you again, president Biden for allowing that pipeline to go through. All right. Anyhow. They're assuming they're approved Germany. Apparently isn't likely to try and block these rules. It means that nuclear, the new nuclear force generation or newer is going to be right there alongside renewables, like wind and solar on the list of the EUS technology that are approved for financial support.
[00:38:30] Now, this is very good news because as I mentioned earlier, What happens when it comes to solar at nighttime doesn't work solar. When it's raining, doesn't work solar. When it's snowing, doesn't work solar. When it's cloudy, doesn't work. Ryan, how about the windmills? When the wind is. They don't work when they break down, which happens a lot due to mechanical failures, they don't work.
[00:39:02] So having the. New nuclear plants that are intrinsically safe, that don't generate this really nasty radiation, and stuff that we have to store for a thousand years, et cetera. The high level nuclear waste makes a lot of sense because unlike the. Solar plants or other things that might be on someone's house that cannot be easily controlled by the central grid.
[00:39:32] In other words, Hey, stop generating electricity because I got enough right now. And what Germany has been doing is putting it into heat sinks, heating up lakes and other things, to get rid of that extra solar energy people are generating on their homes and businesses. What you can do is, Hey, we are at the point where we don't have enough sun.
[00:39:54] It's really cold. People are trying to heat their homes, or it's really hot. People are trying to cool to their homes. And yet it's raining heavily or there's a lot of clouds. So all you have to do at that point is turn off. That nuclear power plant or multiple plants. You see the way it's going.
[00:40:12] You're not going to have some massive plant with a bunch of reactors. No. Where they're going with this is to have community reactors in the multi megawatt range that can be put into communities and the power distributed directly. Into the community and these power plants are good for 20 years and these new ones, they are typically going to be buried in the.
[00:40:41] And then every 20 years they get dug up, put onto a truck, shipped off, they get recharged, brought back and you're off and running again, a whole different concept. And I love it. We're starting to do this in the United States. We've got some early approvals for some of these, and I was shocked and amazed and happy that the Biden administration has decided.
[00:41:06] To approve the new nuclear here in the United States. So there'll be some test plants going online relatively soon. That just makes so much sense. These 50 year old nuclear red regulations and plants, they just don't work. Make sure you visit me online. Craig peterson.com. I'm going to have a lot of stuff for you every week.
[00:41:32] Craig peterson.com.
[00:41:37] The hacker world got turned upside down this past week as Russian president Putin decided to crack down on the hackers. Now, this is a very big change for Russia. We're going to talk about my theories. Why did this happen?
[00:41:54] As we keep you up to date, russian hackers have long been known to go after basically whoever they want. They have really gone after the United States and other Western company countries.
[00:42:10] And as part of what they've been doing, they have been making a lot of money and keeping Vladimir Putin pretty darn happy. He's been a happy because they're bringing more. Into mother Russia, he's happy because they are causing confusion amongst Russia's competitors out there, particularly the United States.
[00:42:35] But there's one thing that Putin has been absolutely steadfast. And that is not allowing any of the hackers to go and hack any of the countries that are part of their little pact over there. Think of the old Warsaw pack they got that band back together. So as long as they didn't harm any Russian or, a affiliated country, They could do basically whatever they wanted and they did.
[00:43:09] And they have caused a lot of trouble all over the world. So Friday Russia. As security agency announced that it had arrested members of the cyber gang called reveal. Now we have talked about them for a long time. They have come and gone. The FBI and other countries have shut down their servers.
[00:43:37] So reveal disappears for awhile. Then pops his head up again. And Russia said that they arrested members of revival who were responsible for massive ransomware crimes against us companies the last year. So why would they do that? I'm looking right now at the Russian website here, that's part of the FSB.
[00:44:06] And it's saying that the Russian federal security service in cooperation, the investigation department of the ministry of internal affairs of Russia in the cities of Moscow St. Petersburg, Leningrad lips. As, I guess it is regions. They stop the illegal activities, a members of an organized criminal community and the basis for the search activities was the appeal of competent U S authorities who reported on the leader of the criminal community and his involvement in an encroachment on the information, sir, resources of foreign high tech companies by drusen militia software, encrypting information and extorting money for its decreased.
[00:44:52] Now that all sounds like the stuff that Vlad has been just a happy about in years past. So why did this happen? What brought this about nowadays in this day and age? What is he doing? I've got a little bit of a theory on that one because there have been some interesting development. One of them is this hacker.
[00:45:19] In Belarus. Now, Belarus is one of those countries that's closely affiliated with Russia friend of Russia, right? Part of the old Warsaw pact. And you might remember that Bella ruse is right there by you. And of course, we've got this whole issue with Ukraine and whether or not Russia is going to invade president and Biden said something incredibly stupid where he said, yeah a moral response is going to depend upon what Russia does, if it's just a minor invasion.
[00:45:57] You're you remember? The president Biden's saying that just absolutely ridiculous. And then of course, the white house press secretary and various Democrat operatives tried to walk the whole thing back, but it's a problem because Russia has, what is it now like 120,000 troops on the border.
[00:46:17] Now, if you know anything about history, you know that the military army. March on their stomachs, right? Isn't that the expression you've got to feed them. You have to have a lot of logistics in place. In fact, that's what really got a lot of the German military in world war two. Very nervous because they saw how good our logistics were, how good our supply chain was.
[00:46:43] We were even sending them. They cakes to men in the field that they discovered these cakes in great shape. And some of the German armies, particularly later in the war, didn't even have adequate food to eat. What do you think is happening with the Russian troops that are sitting there?
[00:47:01] They need food. They need supplies, including things like tanks, heavy artillery, ammunition. All of that sort of stuff. So how do they do that? They're moving it on rail, which they have done in Russia for a very long time. You might remember as well in world war II, the problems with the in compatibility between the German rail gauge and the Russian rail gauge as Germany tried to move their supplies on Russian rails and Soviet rails, ultimately, but on Russian rails and just wasn't able to do.
[00:47:37] So hacktivists in Bella ruse right there next to Ukraine said that they had infected the network of Bella Russa's state run railroad system with ransomware and would provide the decryption key. Only if Bella Reuss president stopped. Russian troops ahead of a possible invasion of Ukraine. So this group, they call themselves cyber partisans wrote on telegram.
[00:48:11] Now I got to warn everybody. Telegram is one of the worst places to post something. If you want some privacy, excuse me, some privacy, some security it's really bad. Okay. No two questions. So they have, apparently this is according to what they wrote on telegram. They have destroyed the backups as part of the pec low cyber campaign.
[00:48:36] They've encrypted the bulk of the servers, databases and work station. Of the Belarus railroad, dozens of databases have been attacked, including, and they name a bunch of the databases. Automation and security systems were deliberately not affected by a cyber attack in order to avoid emergency situations.
[00:49:00] They also said in a direct message that this campaign is targeting specific entities and government run companies with the goal of pressuring the Belarus government to release political prisoners. And stop Russian troops from entering Bellaruse to use its ground for the attacks on Ukraine. Now, this is frankly fascinating from a number of different angles.
[00:49:26] One is, it is very easy nowadays to become a cyber hacker. And in fact, it's so easy. You don't even have to do anything other than send N E. And it's been done, frankly. It's been done people who are upset with a, an ax, for instance upset with a particular company, you can go onto the dark web and you can find companies.
[00:49:53] And this revival company was one. That will provide you with the ransomware and they will do everything for you except get that ransomware onto a computer. So you could bring it in to an employer. You can send it by email to the ax. As I mentioned, you can do a lot of stuff. And then the. Ms. Cyber hacker guys, the bad guys will go ahead now and they will collect the ransom.
[00:50:24] They'll even do tech support to help the people buy Bitcoin or whatever currency they want to have used. And then they take a percentage. So they might take 30% of it. There's a whole lot. We can talk about here too, including trust among thieves and everything else. It is easy to do this. So to see an organization like these cyber partisans, which I'm assuming is an organization, it could be as little as one person taking ransomware, going into specific computer systems breaking in.
[00:50:58] Because again, even here in the U S how many of us have actually got their computer systems all patched up to date? The answer to that is pretty close to zero. And they can now go after a government, they can protect their friends. It's really something. When you start thinking about it, right? No longer do you have to be North Korea or China or Russia in order to hack someone to the point where they commit.
[00:51:31] And in this case, they're not even after the money, they just want these political prisoners freed and they want Russia to stop shipping in troops supplies, into the area in Belarus next to or close to. Very fascinating. There, there is a whole lot of information about this online. If you're interested, you can read more about it.
[00:51:55] It's in my newsletter, my show notes. I have links to some articles in there, but it really is a tool for the under. We've never really seen this before. It's quite an interesting turn in the whole ransomware narrative. It's just in crazy. That's a quote from a guy over at Sentinel one. Alright.
[00:52:21] Lots to consider and lots to know and do, and you can find out about all of the. One way, subscribe right [email protected]. I promise. I'm not going to her Hess. You stick around.
[00:52:38] We've heard a lot about automated cars. And of course we talked about them a lot here too, but that original vision of what we would have, it's gone now. It's fascinating. We're going to talk about that journey of automated car.
[00:52:55] To date on technology for years, automakers have been telling this story about how these automated cars are going to drive themselves around and do just wonderful things for us.
[00:53:10] And as part of that, they've decided that. The way it's going to work. And I remember talking about this, cause I think it's a cool idea is that there will be fleet of these vehicles think about maybe an Uber or Lyft where you get on the phone and you order up a card and it says, Hey that driver will be here.
[00:53:30] Here's the license plate, the driver's name and picture. It's really cool, but general motors and Lyft haven't gotten there. They signed in agreement. To have electric autonomous cars as part of Lyft's fleet of drivers. They did a back in 2016, a long time ago. Ford promised what it called robo taxis and that they would debut by 2021 Dimeler of course, the company that makes Mercedes-Benz said it would work with Uber to deploy fleets of their car.
[00:54:12] And the logic was really financial and it made a lot of sense to me, which is why I was so excited. I have car outside. You know about my Mercedes, you. How often do I drive that 40 year old car? Most of the time it's sitting there parked, most of the time, because I don't go very many places very often.
[00:54:35] What would it be like then to just be able to have an Uber or Lyft type app on my phone that says, okay, tomorrow I have a 10 o'clock meeting in Boston and I want a car to take me there. So the. Checks with the servers and figures out. Okay. At 10 o'clock meaning, that means you're going to have to leave at eight 30 in order to get around the traffic that's normally happening.
[00:55:03] And so we'll have a car there for you. So all I have to do is walk out the apple, probably remind me, my butt out of bed and get outside. Cause the car is about to arrive. So the car pulls into my driveway or maybe just stops on the road and the app reminds me, Hey, the car's there I go out. I get in.
[00:55:22] And on the way down, I can work on getting ready for the meeting, getting some things done, just really kicking back, maybe having a nap as we go. And I'm there on time for my 10 o'clock. Just phenomenal. And from a financial standpoint, nowadays, how much is a car costing you? Have you ever done the math on that?
[00:55:44] How much does a typical car loan run you per month? And I also want to put in how about these leases? How many of us are leasing cars? My daughter leaves to Gargan believe she did that. Didn't leave to me. It didn't make financial sense, but maybe that's just because I've been around a while. But looking right now at some statistics from credit karma, they're saying us auto loans, new cars, your average monthly payment is $568.
[00:56:17] For an average loan term of 71 months. Good grief used cars, about $400. A month payment and average loan term, 65 months. I can't believe that I've never had a car loan for more than three years. Wow. That's incredible. So we're talking about six year notes on a new car. Wow. I guess that's because people buy cars based on the monthly payment, right?
[00:56:49] So figure that out. If you're paying $500 a month, how about just paying a subscription service? $500. You can get so many rides a month and you don't have to maintain the car. You don't have to buy insurance. You don't have to make any fixes. You don't have to do anything. And the car will just show up.
[00:57:08] That's what I was excited about. And it had some just amazing implications. If you think about it, it city dwell over dwellers and people who were directly in the suburbs, it'd be just phenomenal. And you could also have the robo taxis for longer trips. You can abandon that personal car. Really alternate.
[00:57:31] So now it's been about a decade into this self-driving car thing that was started. And, we were promised all of these cars, it reminds me of the fifties, we're all going to be driving, flying cars by. George Jetson one, when was he flying around the cities, but that's not happening.
[00:57:52] Okay. The progress on these automated vehicles has really slowed automakers and tech companies have missed all kinds of self-imposed deadlines for the autonomy. Look at what Elon Musk has promised again and again, it's. Basically in 2020, late 2020, it was going to have fully autonomous cars even calls itself dry.
[00:58:15] When it isn't really self-driving, it certainly isn't fully autonomous it more or less drives. It stays in the lane as it's driving down the highway. But the tech companies are looking for other ways to make money off of self-driving tech. Some of them have completely abandoned. There's self-driving cars, the sensors like the LIDAR, and I've had the LIDAR people on my show before they've all gotten cheaper.
[00:58:40] It doesn't cost you $50,000. Now just for one LIDAR sensor, think about what that means to these cars. So some of these manufacturers of these future autonomous cars are shifting to a new business strategy. And that is selling automated features directly to customers. In other words, you're going to buy a car, but that car isn't going to do much.
[00:59:09] Think about the golden key that the tech companies have used for years, right? IBM well-known for that, you buy a mainframe or from IBM or a mini computer from digital equipment corporation, and you have the same computer as someone that has this massive computer. But in fact the difference is that they turn off features and we're seeing that right now.
[00:59:34] I'm, I've mentioned that Subaru before where they are charging people for upgrades, but some of the companies are charging you monthly to use a remote start feature for instance, and many others. So what's happening is a major change. We have the consumer electronic show, right? January 20, 20 and general motors CEO, Mary Barra said that they would quote, aim to deliver our first personal autonomous vehicles as soon as the middle of this decade.
[01:00:07] So again, it slipped, right? I'm looking at it, a picture of what they're considering to be. The new Cadillac car that should be out next year. Maybe thereafter. It is gorgeous. Absolutely gorgeous. But this announcement, right? Yeah. We're going to have autonomous vehicles, middle of the 2020s. She had no specific details at all.
[01:00:33] And apparently this personal robo car project is completely separate from this robo taxi fleet that's been developed by GM's cruise subsidiary. And cruise said it has plans to launch a commercial service in San Francisco this year. So they're going after multiple paths. The logic here is financial.
[01:00:56] The reasoning has changed and they're offering autonomy as a feature for the consumer market. Tesla, Elon Musk, they've been charging $10,000 now for the autopilot driver assistance feature. They're planning on raising it to $12,000 here early 2022 Tesla technology. Can't drive a car by itself.
[01:01:22] But he's going to charge you if you want it. And I expect that's going to be true of all of the major manufacturer that's out there. And by the way, they're also looking at customization, like color changing cars and things. They're going to charge them as features. Hey, stick around. Visit me online.
[01:01:43] Craig peterson.com.
[01:01:46] Just how secure are our smartphones. We've got the iPhones, we've got Android out there. We've talked a little bit about this before, but new research is showing something I didn't really expect, frankly.
[01:02:02] We've got some new research that wired had a great article about last week that is talking about the openings that iOS and Android security provide for anyone with the right tools. You're probably familiar at least vaguely with some cases where the FBI or other law enforcement agencies have gone to apple and tried to have.
[01:02:29] Old break into iPhones. Apples, refuse to do that one in particular, down in Southern California, where they tried to get apple to open up this I phone and tell them who was this person talking to after a shooting of foul of fellow employees at a. It was really something, there was a lot of tense times and we've seen for decades now, the federal government trying to gain access to our devices.
[01:03:04] They wanted a back door. And whenever you have a back door, there's a potential that someone's going to get in. So let's say you've got a. And your house has a front door. It has a backdoor, probably has some windows, but we'll ignore those for now. Okay. And you have guards posted at that front. All in someone needs to do is figure out to how to get into that back door.
[01:03:31] If they want to get into your house, it might be easy. It might be difficult, but they know there's a back door and they're going to figure out a way to get in. And maybe what they're going to do is find a friend that works for that security company, that post of the guards out front. And see if that friend can get a copy of the.
[01:03:51] That'll let them in the back door. And that's where we've had some real concerns over the year years here, a decades, frankly, our first, I remember this coming up during the Clinton administration, very big deal with the. That they were pushing. This was a cryptographic chip that they wanted every manufacturer to use if they wanted to have encryption and the white house and every gov federal government agency, and probably ultimately every local agency had the ability to break any encryption that was created by the clipper.
[01:04:30] In fact, we were able to track Saddam Hussein and his sons and his inner circle. Because he was using some encrypted phones that were being made by a company in England. And that company in England did have a back door into those encrypted phones. And so we were able to track them and we could listen in, on all of their communications back and forth.
[01:04:56] And it's really frankly, oppressed. When that sort of thing happens. So what do you do? What are you supposed to do? How can you make it so that your devices are safe? There are some ways to be relatively safe, but these cryptographers over Johns Hopkins university, Use some publicly available documentation that was available from apple and Google, as well as their own analysis.
[01:05:26] And they looked into Android and iOS encryption and they founded lacking. So they studied more than a decades worth of reports. How about which mobile security features had been bypassed had been a hack. I had been used by law enforcement and criminals in order to get into these phones. They got some of these hacking tools off of the dark web and other places, and they tried to figure.
[01:05:59] So we've got a quote here from Johns Hopkins, cryptographer, Matthew Green, who oversaw the research. It just really shocked me because I came into this project thinking that these phones are really protecting user data. Now I've come out of the project, thinking almost nothing is protected as much as it could be.
[01:06:22] So why do we need a backdoor for law enforcement? When the protections that these phones actually offer are so bad. Now there's some real interesting details of if you like this stuff, I followed cryptography for many decades. Now I've always found it. Fascinating. There are some lightweight things I'm going to touch on here.
[01:06:46] We won't get too deep in this, but here's another quote. Again, Johns Hopkins university on Android. You can not only attack the operating system level, but other different layers of software that can be vulnerable in different ways. Another quote here on iOS in particular, the infrastructure is in place for hierarchal encrypted.
[01:07:10] Now higher are hierarchical. Encryption is various layers of encryption. If you have an iPhone or an iPad, or if you have most Android phones nowadays, if you use a passcode in order to unlock the phone or even a fingerprint or a face. Your method of authentication is used to encrypt everything on the phone, but in reality, everything on the phone is only fully encrypted when the phone is powered off.
[01:07:49] Now that's a real, interesting thing to think about because obviously the phone can't work. If everything's encrypted. It needs access to the programs. It needs access to your data. So what they found bottom line was the only way to have a truly safe machine or a smartphone in this case is to turn it off because when you turn it on and it boots up on first boot, now it gets.
[01:08:20] Either by bio medical information, like your fingerprint or your face sprint or your passcode, it then has a key that it can use to decrypt things. So apple has on the iPhone, something, they call complete protection and that's again, when the iPhone has been turned off on boots up because the user has to unlock the device before anything can happen on the phone.
[01:08:45] And the is protections are very. Now you could be forced to unlock the phone by a bad guy, for instance, or in some cases, a warrant or an order from a judge, but forensic tools that, that they are using the police and the criminals really would have almost no luck at pulling information off of your phone.
[01:09:11] That would be useful at all because it would all be encrypted, right? If they could. So once you've unlocked your phone after that first reboot molt, after that reboot, right? You unlocked it after power up. A lot of the data moves into a different mode that apple calls protected until first user authentication.
[01:09:32] But it's what I call after first unlock. So when you think about it, your phone is almost always in the after first unlocks. Because how often do you reboot your phone? No, it's pretty rare that your phone might do on. And this is particularly true for I-phones might do updates and boot and reboot. And then of course you have to unlock that phone, but it doesn't go much further.
[01:10:01] The net and that's, what's interesting. That's how law enforcement and the bad guys, these Israeli companies and others have been able to get into iPhones and get into Android devices because ultimately if that computer is turned on and you've logged in, there's a lot of data. That's no longer encrypted.
[01:10:22] Oh. And by the way, that's also how some of these attacks occur on our laptops. Particularly if you traveled to. In the memory on that laptop that you close the lid on, you have to re log into is the key to UNHCR, unencrypt, everything, right? Because you logged in once. So all they have to do is freeze the memory, duplicate the memory and put it back in part of the reason, by the way that apple laptops have their memory soldered in you can't do that kind of attack.
[01:10:56] Stick around. We'll be right back.
[01:11:00] VPNs are good and they are bad. It depends on the type of VPN. Many of these commercial VPNs of people are using are actually very bad for you when it comes to your security.
[01:11:17] VPNs are Trump problematic. I did a couple of boot camps on VPNs. Probably I think it was about last year.
[01:11:26] Yeah, it was last spring. And I went through and explained and showed exactly why commercial VPNs are one of the worst things you could possibly do if you want. To stay secure. Now I lemme just give you the high level here. I have given people copies of this, if you're interested in a link to that VPN webinar that I did, I'd be glad to send it to you.
[01:11:57] Just email me Emmy at Craig Peterson, doc. And ask me for the VPN information and I'll send that all off to you. I also wrote something up that I've been sending out to people that have asked about VPNs. Cause it's one of the most common questions we have Franklin, but here's your problem with commercial VPNs?
[01:12:18] Most all of them say, oh, your information safe at zero logging, et cetera. And yet we have found again and again that's not. In fact, it can't possibly be true in almost every case because most of these VPN services are running out of other people's data centers. So they might be in an Amazon data center or IBM or Microsoft.
[01:12:45] And inside that data center, your data is coming in and then it's going to. So let's say you're using a VPN and you're connecting to a website. I don't care. Go to google.com via a VPN. So you're using one of these services. That's advertised all over creation. And what happens now is. Your web request to get to Google passes over that encrypted VPN and comes to an exit point because at some point it has to get onto the regular internet.
[01:13:20] How else are you going to get to that website? On the other side? You can't, unless you get to the regular internet. So at the other side, now the server is that's receiving the end point of view. VPN is going to send the request to Google. Google is going to respond to that VPN server. It's going to be encrypted and sent back to you.
[01:13:43] So what's the problem with that? There's multiple problems. One is the data center can see. That there is the request going up to Google. Now he might not be able to tell who it was. But if that VPN server has been hacked. And let me tell you, it is a big target for hackers, government hackers, as well as bad guys.
[01:14:06] Then they do know who went out there and depending on how it was hacked and how the VPN was set up, they may even be able to see all of the data that you're sending back and forth. It's called a man in the middle of. And some of these VPN services do it by having you install some software on your computer.
[01:14:28] And as part of that installation, they provide you with a master key that they then use to spoon. The keys for the websites. You're going to some, explain that what happens is if you were to go right now on your web browser, go to Craig peterson.com as an example. So Craig peterson.com. I'm typing it in right now in the browser.
[01:14:55] That's directly in front of me. Now you'll see a little lock up in the URL. What does that mean? If you click on that lock, it says something about the connection being secure. Are you familiar with that? What's actually happening is it's using SSL TLS keys, but it's using encryption now to send the data from your computer.
[01:15:24] To my server, that's hosting Craig peterson.com. And then my server is sending all of the webpage back to you. Encrypted. Any fact, a VPN has been established between your web browser and my web server. So why use a third-party VB? Because your data is encrypted already, right? Could it be more simple than that?
[01:15:59] Now, remember again, that the server on the VPM service that you're using is a prime attack target for everybody else. As I said from government agencies through hackers. So your data is likely less safe because if they get a hold of it, they can do all kinds of things to your data and to. And then on top of it, all the VPN service may well be selling your data in order to make money, to support the VPN service because free VPNs, inexpensive VPN sees the ones that are charging you five or 10 bucks a month cannot possibly afford to provide you with that service.
[01:16:51] And in the bootcamp, I go through all of the numbers here, the costs involved. With a VPN service it's not possible to do. They can't make any money off of it. So it is a very big problem for you to use one of these public VPN services. Now, I want to talk about an arc article that was on Z.
[01:17:19] Apparently your old pole, which is of course the police over there in the European nations has seized servers. What servers, VPN servers in Europe. Now they seized the servers because they were used by who was it? Grandma looking at pictures of the grandkids. Was it people watching cat videos who was using the VPN server?
[01:17:45] The paid VPN service. Wow. It was criminals. And when they seized these VPN servers that were also being used by criminals, they found more than a hundred businesses that had fallen victims to attacks. So who uses VPN services? People who want to hide something as well as people who just want to have their data secure.
[01:18:14] Another reason not to use VPN services. So as a part of the joint action by Europol Germany's police Hanover police department, the FBI, UK national crime agency, and others seized 15 servers used by VPN lab dot. Okay. So VPN lab.net net, obviously no longer usable. And they started looking at all of the records that were being kept in these servers and use that to find the criminal.
[01:18:48] Does that make sense to you? So VPN lab.net was according to these charges, facilitating illicit activities, such as malware distribution. Other cases showed the services use in setting up infrastructure and communications behind ransomware campaigns, as well as the actual deployment of ransomware. You like that.
[01:19:12] Now they were using open VPN technology, which is actually very good. As part of that VPN information, I can send you if you're interested, just email me M [email protected]. Let me know what you're interested in, and I'll whoop you off an email. Give me a few days I can get behind sometimes, but you can set up your own private VPN server if that's what you want to do.
[01:19:38] And I've gotten instructions on how to do that in that little special report in that email, but They were providing what they called online anonymity, this VPN lab.net service for as little as $60 a year. Okay. You like that? So they provided what they call double VPN servers and a lot of different countries and made it a popular choice for cyber criminals.
[01:20:04] Very big deal. Okay. So be very careful with VPNs. Also be careful of the VPN you might be using for your business. Let's say you've got something that isn't terribly secure or not secure at all as your firewall, right? So you buy a nice little firewall or this is so great. It's not expensive. And I got it online from a big box retailer.
[01:20:27] Most of them out there do not meet. The minimum standards you really need in order to keep your business. And there's only two companies that do one of them, Cisco, and one of them's Juniper, that's it? None of the other firewalls with VPNs meet the minimal standards you need to have, but those be glad to sell it to you.
[01:20:49] They'll be glad to tell you that it's perfectly secure, but it is not okay. Just went through that again with a company this week an engineering firm and at least they understand some of the stuff, but they were trying to do the right thing and they were being misled by these various vendors. So this action against VPN lab took place in January involved with authorities from Germany.
[01:21:15] The Netherlands Canada, Czech Republic, France, Hungary, Latvia, Ukraine, us UK, as well as your old pole. So there you go. You've gotta be careful don't trust VPNs, right? I've been saying that for a very long time. And then the other thing I want to. Is hopefully this summer we're going to be traveling.
[01:21:40] And when you're traveling, the temptation is to use public wifi might be at the hotel. It might be at a restaurant coffee shop, whatever. Okay. I admit to doing that myself. But here's two things you need to be careful with. One use, good DNS filtering. Now we sell and provide umbrella, which is a Cisco product, which is extremely good.
[01:22:08] DNS filtering. You can get free DNS filtering that isn't configurable, doesn't have the options, but is fantastic called open DNS. I've got, again, I did a bootcamp on that. I can send you information on it if you want. It doesn't cost you a dime for any of this stuff, but open DNS. And then the other thing I do, I have a high-end Cisco firewall and VPN.
[01:22:34] So when I'm on the road, even when I'm using data from the phone company, I have my secure VPN turned on FIPs compliant, by the way, for those who know what that means. Hey, visit me online. Craig peterson.com. Get my show notes. Get my Wednesday, wisdoms everything. Craig peterson.com. It's easy to sign up right there on any page.
Weekly Show #1158
We know the Russians have been attacking us. I've talked a lot about it on the radio and TV over the last couple of weeks. So I am doing something special; we are going through the things you can do to stay safe from the latest Russian attacks.
Last week, we started doing something I promised we would continue -- how can you protect yourself when it comes to the Russians? The Russians are the bad guys when it comes to bad guys. So there are a few things you can do. And there are a few things; frankly, you shouldn't be doing. And that's precisely what we're going to talk about right now.
Today, I explain:
- How to protect your back-end - Preventative measures - The new rules of backing up your computer
As usual, we'll cover the What, Why, and How's.
[Automated transcript follows]
[00:00:39] So last week he went over some steps, some things that you can look at that you should look at that are going to help protect you. And we are going to go into this a whole lot more today. And so I want you to stick around and if you miss anything, you can go online. You can go to Craig peterson.com, make sure you sign up there for my email.
[00:01:01] And what I'm going to do for you is. Send you a few different documents now where we can chat back and forth about it, but I can send you this. Now I'm recording this on video as well as on audio. So you can follow along if you're watching either on YouTube or. Over on rumble and you can find it also on my website.
[00:01:26] I've been trying to post it up there too, but right now let's talk about what we call passive backend protections. So you've got the front end and the front end of course, is. Stuff coming at you, maybe to the firewall I've mentioned last week about customers of mine. I was just looking at a few customers this week, just so I could have an idea of their firewalls.
[00:01:52] And they were getting about 10 attacks per minute. Yeah. And these were customers who have requirements from the department of defense because they are defense sub subcontractors. So again, Potential bad guys. So I looked up their IP addresses and where the attacks were coming from. Now, remember that doesn't mean where they originated because the bad guys can hop through multiple machines and then get onto your machine.
[00:02:22] What it means is that all, ultimately they ended up. Coming from one machine, right? So there's an IP address of that machine. That's attacking my clients or are attacking my machines. That just happens all the time. A lot of scans, but some definite attacks where they're trying to log in using SSH.
[00:02:42] And what I found is these were coming from Slovakia, Russia, and Iran. Kind of what you were expecting, right? The Iranians, they just haven't given up yet. They keep trying to attack, particularly our military in our industry. One of the things we found out this week from, again, this was an FBI notice is that the Russians have been going after our industrial base.
[00:03:09] And that includes, in fact, it's more specifically our automobile manufacturers we've already got problems, right? Try buying a new car, try buying parts. I was with my friend, just this. I helped them because he had his car right. Need to get picked up. So I took him over to pick up his car and we chatted a little bit with this small independent automotive repair shop.
[00:03:34] And they were telling us that they're getting sometimes six, eight week delays on getting parts and some parts. They just can't. So they're going to everything from junkyards on out, and the worst parts are the parts, the official parts from the car manufacturers. So what's been happening is Russia apparently has been hacking into these various automobile manufacturers and automobile parts manufacturers.
[00:04:03] And once they're inside, they've been putting in. A remote control button net. And those botnets now have the ability to wake up when they want them to wake up. And then once they've woken up, what do they do? Who knows? They've been busy erasing machines causing nothing, but having they've been doing all kinds of stuff in the past today, they're sitting there.
[00:04:24] Which makes you think they're waiting, it's accumulate as much as you possibly can. And then once you've got it all accumulated go ahead and attack. So they could control thousands of machines, but they're not just in the U S it's automobile manufacturers in Japan. That we found out about.
[00:04:44] So that's what they're doing right now. So you've got the kind of that front end and back end protections. So we're going to talk a little bit about the back end. What does that mean? When a cybersecurity guy talks about the backend and the protections. I got it up on my green right now, but here's the things you can do.
[00:05:03] Okay. Remember, small businesses are just getting nailed from these guys, because again, they're fairly easy targets. One change your passwords, right? How many times do we have to say that? And yet about 70% of businesses out there are not using a good password methodology. If you want more information on passwords, two factor authentication, you name it.
[00:05:30] Just email me M [email protected]. I want to get the information out now. You got to make sure that all of the passwords on your systems are encrypted are stored in some sort of a good password vault as you really should be looking at 256 bit encryption or better. I have a vendor of. That I use. So if you get my emails every week, when them, there's the little training.
[00:05:59] And so I'll give you a five minute training. It's written usually it's in bullet point for, I'm just trying to help you understand things. That provider of mine has a big database and there's another provider that I use that is for. So the training guys use the database of my provider.
[00:06:20] In using that database, they're storing the passwords and the training providers putting passwords in the clinics. Into the database, which is absolutely crazy. So again, if you're a business, if you're storing any sort of personal information, particularly passwords, make sure that you're using good encryption and your S what's called salting the hash, which means.
[00:06:46] You're not really storing the password, just joining assaulted hash. I can send you more on this. If you are a business and you're developing software that's, this is long tail stuff here. Configure all of the security password settings so that if someone's trying to log in and is failing that, and you block it, many of us that let's say you're a small business.
[00:07:08] I see this all of the time. Okay. You're not to blame. You, but you have a firewall that came from the cable company. Maybe you bought it at a big box retailer. Maybe you bought it online over at Amazon, as hurricane really great for you. Has it got settings on there that lets you say. There's 20 attempts to log in.
[00:07:31] Maybe we should stop them. Now, what we do personally for our customers is typically we'll block them at somewhere around three or four failed attempts and then their passwords block. Now you can configure that sort of thing. If you're using. Email. And that's an important thing to do. Let me tell you, because we've had some huge breaches due to email, like Microsoft email and passwords and people logging in and stealing stuff.
[00:07:59] It was just a total nightmare for the entire industry last year, but limit the number of login retries as well as you're in there. These excessive login attempts or whatever you want to define it as needs to lock the account. And what that means is even if they have the right password, they can't get in and you have to use an administrative password in order to get in.
[00:08:25] You also want to, what's called throttle, the rate of repeated logins. Now you might've gotten caught on this, right? You went to your bank, you went to E-bay, you went to any of these places and all of a sudden. And denied you write it blocked you. That can happen when your account is on these hackers lists.
[00:08:45] You remember last week we talked about password spraying while that's a very big deal and hackers are doing the sprain trick all of the time, and that is causing you to get locked out of your own account. So if you do get locked out, remember it might be because someone's trying to break. Obviously you have to enforce the policies.
[00:09:09] The capture is a very good thing. Again, this is more for software developer. We always recommend that you use multifactor or two factor authentication. Okay. Do not use your SMS, your text messages for that, where they'll send you a text message to verify who you are. If you can avoid that, you're much better off.
[00:09:30] Cause there's some easy ways to get around that for hackers that are determined. Okay. A multi-factor again, installed an intrusion. system. We put right at the network edge and between workstations and servers, even inside the network, we put detection systems that look for intrusion attempts and block intrusion attempts.
[00:09:56] A very important use denied lists to block known attackers. We build them automatically. We use some of the higher end Cisco gates. Cisco is a big network provider. They have some of the best hardware and software out there, and you have to subscribe to a lot of people complain. I ain't going to just go buy a firewall for 200 bucks on Amazon.
[00:10:18] Why would I pay that much a month just to to have a Cisco firewall? And it's like praying pain for the brand. I've got by logo chert on here. Oh, I wouldn't pay for that. No, it's because they are automatically providing block lists that are updated by the minute sometimes. And then make sure you've got an incident response plan in place.
[00:10:44] What are you going to do when they come for you? What are you going to do? Bad boys. Bad. Stick around. We've got a lot more to talk about here as we go. I am explaining the hacks that are going on right now and what you can do as a business and an individual doubt. Protect yourself. Don't go anywhere.
[00:11:07] Now we're going to talk about prevention. What can you do an order to stop some of these attacks that are coming from Russia and from other countries, it is huge. People. Believe me, this is a very big problem. And I'm here to help.
[00:11:23] hi, I'm Craig Peter Sohn, your chief information security officer. We've reviewed a number of things that are important when it comes to your cyber security and your protection.
[00:11:37] We talked about the front end. We talked about the backend. Now we're going to talk about pure prevention and if you're watching. Online. You'll be able to see my slides as they come up, as we talk about some of this stuff and you'll find me on YouTube and you'll also find me on rumble, a fairly new platform out there platform that doesn't censor you for the things you say.
[00:12:01] Okay. So here we go. First of all, enabling your active directory password protection is going to. Four's password protection all the way through your business. Now I've had some discussions with people over the months, over the years about this whole thing and what should be done, what can be done, what cannot be done.
[00:12:26] Hey, it's a very big deal when it comes to password protection and actor directory, believe it or not, even though it's a Microsoft product is pretty darn good at a few things. One of them is. Controlling all the machines and the devices. One of the things we do is we use an MDM or what used to be a mobile device manager called mass 360.
[00:12:51] It's available from IBM. We have a special version of that allows us as a managed security services provider to be able to control everything on people's machines. Active directory is something you should seriously consider. If you are a Mac based shop. Like I am. In fact, I'm sitting right now in front of two max that I'm using right now, you'll find that active directory is a little bit iffy.
[00:13:21] Sometimes for max, there are some work around and it's gotten better mastery. 60 is absolutely the way to go, but make sure you've got really good. Passwords and the types of passwords that are most prone to sprain the attacks are the ones you should be banning specifically. Remember the website? Have I been poned?
[00:13:45] Yeah. It's something that you should go to pretty frequently. And again, if you miss anything today, just email me M [email protected]. Believe me, I am not going to harass you at all. Okay. Now, the next thing that you should be doing is what's called red team blue team. Now the red team is a group of people, usually outside of your organization.
[00:14:11] If you're a big company they're probably inside, but the red team is the team that attacks you. They're white hat hackers, who are attacking you, looking for vulnerabilities, looking for things that you should or shouldn't be doing. And then the blue team is the side that's trying to defend. So think of, like war games.
[00:14:29] Remember that movie with Matthew Broderick all of those decades ago and how the, he was trying to defend that computer was trying to defend that it moved into an attack mode, right? Red team's attack, blue team is defend. So you want. To conduct simulated attacks. Now w conducting these attacks include saying, oh my let's now put in place and execute our plan here for what are we going to do once we have a.
[00:15:01] And you darn well better have a breach plan in place. So that's one of the things that we help as a fractional chief information security officer for companies, right? You've got to get that in place and you have to conduct these simulated attacks and you have to do penetration testing, including password spraying attacks.
[00:15:21] There's so many things you can do. The one of the things that we like to do and that you might want to do, whether you're a home user, retiree or a business is go and look online, you can just use Google. I use far more advanced tools, but you can use Google and look for your email address right there.
[00:15:40] Look for the names of people inside your organization. And then say wait a minute, does that data actually need to be there? Or am I really exposing the company exposing people's information that shouldn't be out there because you remember the hackers. One of the things they do is they fish you fish as in pH.
[00:16:04] So they'll send you an email that looks like. Hey let me see. I know that Mary is the CFO, and I know that Joe's going to be out of town for two weeks in The Bahamas, not a touch. So while he's got. I'm going to send an email to Mary, to get her to do something, to transfer the company's funds to me.
[00:16:23] Okay. So that's what that's all about. You've got to make sure, where is our information? And if you go to my company's page, mainstream.net, you'll see on there that I don't list any of the officers or any of the people that are in the company, because that again is a security problem.
[00:16:41] We're letting them know. I go to some of these sites, like professional sites lawyers, doctors, countenance, and I find right there all, are there people right there top people or sometimes all of them. And then we'll say, yeah, I went to McGill university, went to Harvard, whatever my B. It's all there. So now they've got great information to fish you, to fish that company, because all they have to do is send an email to say, Hey, you remember me?
[00:17:13] We're in Harvard when this class together. And did you have as a professor to see how that works? Okay. You also want to make. That you implement, what's called a passwordless user agent, and this is just so solely effective. If they cannot get into your count, what's going to, what could possibly go wrong, but one of the ways to not allow them into the count is to use.
[00:17:41] Biometrics. We use something called duo and we have that tied into the single sign-on and the duo single sign-on works great because what it does now is I put in, I go to a site, I put it into my username and. Pulls up a special splash page that is running on one of our servers. That again asks me for my duo username.
[00:18:04] So I've got my username for the site then to my dual username and my duo password single sign on. And then it sends me. To an app on my smart device, a request saying, Hey, are you trying to log into Microsoft? And w whatever it might be at Microsoft, and you can say yes or no, and it uses biometric.
[00:18:27] So those biometrics now are great because it says, oh, okay, I need a face ID or I need a thumb print, whatever it might be that allows a generalized, a password, less access. Okay. Password less. Meaning no pass. So those are some of the top things you can do when it comes to prevention. And if you use those, they're never going to be able to get at your data because it's something you have along with something, it works great.
[00:19:02] And we like to do this. Some customers. I don't like to go through those hoops of the single sign-on and using duo and making that all work right where we're fine with it. We've got to keep ourselves, at least as secure as the DOD regulations require unlike almost anybody else in industry, I'm not going to brag about it.
[00:19:26] But some of our clients don't like to meet the tightest of controls. And so sometimes they don't. I hate to say that, but they just don't and it's a fine line between. Getting your work done and being secure, but I think there's some compromises it can be readily made. We're going to talk next about saving your data from ransomware and the newest ransomware.
[00:19:53] We're going to talk about the third generation. That's out there right now. Ransomware, it's getting crazy. Let me tell ya and what it's doing to us and what you can do. What is a good backup that has changed over the last 12 months? It's changed a lot. I used to preach 3, 2, 1. There's a new sheriff in town.
[00:20:15] Stick around Craig peterson.com.
[00:20:19] 3, 2, 1 that used to be the standard, the gold standard for backing up. It is no longer the case with now the third generation of ransomware. You should be doing something even better. And we'll talk about it now.
[00:20:36] We're doing this as a simulcast here. It's on YouTube. It is also on rumble.
[00:20:43] It's on my [email protected] because we're going through the things that you can do, particularly if you're a business. To stop the Russian invasion because as we've been warned again and again, the Russians are after us and our data. So if you missed part of what we're talking about today, or.
[00:21:07] Last week show, make sure you send me an email. [email protected]. This is the information you need. If you are responsible in any way for computers, that means in your home, right? Certainly in businesses, because what I'm trying to do is help and save those small businesses that just can't afford to have full-time.
[00:21:31] True cyber security personnel on site. So that's what the whole fractional chief information security officer thing is about. Because you just, you can't possibly afford it. And believe me, that guy that comes in to fix your computers is no cyber security expert. These people that are attacking our full time cybersecurity experts in the coming from every country in the world, including the coming from the us.
[00:22:01] We just had more arrests last week. So let's talk about ransomware correctly. Ransomware, very big problem. Been around a long time. The first version of ransomware was software got onto your computer through some mechanism, and then you had that red screen. We've all seen that red screen and it says, Hey, pay up buddy.
[00:22:23] It says here you need to send so many Bitcoin or a fraction of a Bitcoin or so many dollars worth of Bitcoin. To this Bitcoin wallet. And if you need any help, you can send email here or do a live chat. They're very sophisticated. We should talk about it some more. At some point that was one generation.
[00:22:45] One generation two was not everybody was paying the ransoms. So what did they do at that point? They said let me see if they, we can ransom the data by encrypting it and having them pay us to get it back. 50% of the time issue got all your data back. Okay. Not very often. Not often enough that's for sure.
[00:23:05] Or what we could do is let's steal some of their intellectual property. Let's steal some of their data, their social security number, their bank, account numbers, et cetera. They're in a, in an Excel spreadsheet on their company. And then we'll, if they don't pay that first ransom, we'll tell them if they don't pay up, we'll release their information.
[00:23:26] Sometimes you'll pay that first ransom and then they will hold you ransom a second time, pretending to be a different group of cyber terrorists. Okay. Number three, round three is what we're seeing right now. And this is what's coming from Russia, nears, everything we can tell. And that is. They are erasing our machines.
[00:23:48] Totally erasing them are pretty sophisticated ways of erasing it as well, so that it sinks in really, it's impossible to recover. It's sophisticated in that it, it doesn't delete some key registry entries until right at the very end and then reboots and computer. And of course, there's. Computer left to reboot, right?
[00:24:11] It's lost everything off of that hard drive or SSD, whatever your boot devices. So let's talk about the best ways here to do some of this backup and saving your data from ransomware. Now you need to use offsite disconnected. Backups, no question about it. So let's talk about what's been happening.
[00:24:34] Hospitals, businesses, police departments, schools, they've all been hit, right? And these ransomware attacks are usually started by a person. I'll link in an email. Now this is a poison link. Most of the time, it used to be a little bit more where it was a word document, an Excel document that had something nasty inside Microsoft, as I've said, many times has truly pulled up their socks.
[00:25:02] Okay. So it doesn't happen as much as it used to. Plus with malware defender turned on in your windows operating system. You're going to be a little bit safer next step. A program tries to run. Okay. And it effectively denies access to all of that data. Because it's encrypted it. And then usually what it does so that your computer still works.
[00:25:26] Is it encrypts all of you, like your word docs, your Excel docs, your databases, right? Oh, the stuff that matters. And once they've got all of that encrypted, you can't really access it. Yeah. The files there, but it looks like trash now. There's new disturbing trends. It has really developed over the last few months.
[00:25:48] So in addition to encrypting your PC, it can now encrypt an entire network and all mounted drives, even drives that are marrying cloud services. Remember this, everybody, this is really a big deal because what will happen here is if you have let's say you've got an old driver G drive or some drive mounted off of your network.
[00:26:14] You have access to it from your computer, right? Yeah. You click on that drive. And now you're in there and in the windows side Unix and max are a little different, but the same general idea you have access to you have right. Access to it. So what they'll do is any mounted drive, like those network drives is going to get encrypted, but the same thing is true.
[00:26:36] If you are attaching a U S B drive to your company, So that USB drive, now that has your backup on it gets encrypted. So if your network is being used to back up, and if you have a thumb drive a USB drive, it's not really a thumb drive, right? There's external drive, but countered by USP hooked up.
[00:27:02] And that's where your backup lives. Your. Because you have lost it. And there have been some pieces of software that have done that for awhile. Yeah. When they can encrypt your network drive, it is really going after all whole bunch of people, because everyone that's using that network drive is now effective, and it is absolutely.
[00:27:27] Devastating. So the best way to do this is you. Obviously you do a bit of a local backup. We will usually put a server at the client's site that is used as a backup destiny. Okay. So that servers, the destination, all of the stuff gets backed up there. It's encrypted. It's not on the network per se. It's using a special encrypted protocol between each machine and the backup server. And then that backup servers data gets pushed off site. Some of our clients, we even go so far as to push it. To a tape drive, which is really important too, because now you have something physical that is by the way, encrypted that cannot be accessed by the attacker.
[00:28:20] It's offsite. So we have our own data center. The, we run the, we manage the no one else has access to it is ours. And we push all of those backups offsite to our data center, which gives us another advantage. If a machine crashes badly, right? The hard disk fails heaven forbid they get ransomware. We've never had that happen to one of our clients.
[00:28:46] Just we've had it happen prior to them becoming clients, is that we can now restore. That machine either virtually in the cloud, or we can restore it right onto a piece of hardware and have them up and running in four hours. It can really be that fast, but it's obviously more expensive than in some.
[00:29:08] Are looking to pay. All right, stick around. We've got more to talk about when we come back and what are the Russians doing? How can you protect your small business? If you're a one, man, one woman operation, believe it. You've got to do this as well. Or you could lose everything. In fact, I think our small guys have even more to lose Craig peterson.com.
[00:29:32] Backups are important. And we're going to talk about the different types of backups right now, what you should be doing, whether you're a one person, little business, or you are a, multi-national obviously a scale matters.
[00:29:47] Protecting your data is one of the most important things you can possibly do.
[00:29:53] I have clients who had their entire operating account emptied out, completely emptied. It's just amazing. I've had people pay. A lot of money to hackers to try and get data back. And I go back to this one lady over in Eastern Europe who built a company out of $45 million. By herself. And of course you probably heard about the shark tank people, right?
[00:30:23] Barbara Cochran, how she almost lost $400,000 to a hacker. In fact, the money was on its way when she noticed what was going on and was able to stop it. So thank goodness she was able to stop it. But she was aware of these problems was looking for the potential and was able to catch it. How many of us are paying that much attention?
[00:30:50] And now one of the things you can do that will usually kind of protect you from some of the worst outcomes. And when it comes to ransomware is to backup. And I know everybody says, yeah, I'm backing up. It's really rare. When we go in and we find a company has been backing up properly, it even happens to us sometimes.
[00:31:15] We put them back up regimen in place and things seem to be going well, but then when you need the backup, oh my gosh, we just had this happen a couple of weeks ago. Actually this last week, this is what happened. We have. Something called an FMC, which is a controller from Cisco that actually controls firewalls in our customer's locations.
[00:31:42] This is a big machine. It monitors stuff. It's tied into this ice server, which is. Looking for nastiness and we're bad guys trying to break in, right? It's intrusion detection and prevention and tying it into this massive network of a billion data points a day that Cisco manages. Okay. It's absolutely huge.
[00:32:05] And we're running it in a virtual machine network. So we. Two big blade. Chassies full of blades and blades are each blade is a computer. So it has multiple CPU's and has a whole bunch of memory. It also has in there storage and we're using something that VMware calls visa. So it's a little virtual storage area network.
[00:32:32] That's located inside this chassis and there are multiple copies of everything. So if a storage unit fails, you're still, okay. Everything stays up, it keeps running. And we have it set up so that there's redundancy on pond redundancy. One of the redundancies was to back it up to a file server that we have that's running ZFS, which is phenomenal.
[00:32:56] Let me tell you, it is the best file system out there I've never ever had a problem with it. It's just crazy. I can send you more information. If you ever interested, just email [email protected]. Anytime. Be glad to send you the open source information, whatever you need. But what had happened is.
[00:33:13] Somehow the boot disk of that FMC, that, that firewall controller had been corrupted. So we thought, oh, okay, no problem. Let's look at our backups. Yeah, hadn't backed up since October, 2019. Yeah, and we didn't know it had been silently failing. Obviously we're putting stuff in place to stop that from ever happening again.
[00:33:43] So we are monitoring the backups, the, that network. Of desks that was making up that storage area network that had the redundancy failed because the machine itself, somehow corrupted its file system, ext four file system right then are supposed to be corruptible, but the journal was messed up and it was man, what a headache.
[00:34:07] And so they thought, okay, you're going to have to re-install. And we were sitting there saying, oh, you're kidding me. Reinstalling this FMC controller means we've got to configure our clients, firewalls that are being controlled from this FMC, all of their networks, all of their devices. We had to put it out.
[00:34:23] This is going to take a couple of weeks. So because I've been doing this for so long. I was able to boot up an optics desk and Mount the file system and go in manually underneath the whole FMC, this whole firewall controller and make repairs to it. Got it repaired, and then got it back online. So thank goodness for that.
[00:34:49] It happens to the best of us, but I have to say I have never had a new client where they had good backups. Ever. Okay. That, and now that should tell you something. So if you are a business, a small business, whatever it might be, check your backups, double check them. Now, when we're running backups, we do a couple of things.
[00:35:14] We go ahead and make sure the backup is good. So remember I mentioned that we have. Backup server that sits onsite. Usually it depends on the size of the client. But sits onsite at the client's site. So it will perform the backup and then tries to actual restore of that backup to make sure it's good.
[00:35:35] And we can even. Client, depending on what they want. So a higher level, if a machine goes down, let's say it catches fire, or disk explodes in it, or completely fails. We can actually bring that machine online inside our backup server or the customer. Yeah, how's that for fancy and bring it back online in just a matter of minutes instead of days or weeks.
[00:36:04] So that's true too. If that machine had been a ransom had this data, you raised whatever might've happened to it. We can restore it now. We've never had to knock on wood, except when there was a physical problem with the machine and as. Starting from scratching it, that machine, the new machine online in four hours or less.
[00:36:28] And it's really cool the way it works. If you like this stuff, man, it is great. Okay. Protecting your data. I'm rambling a little bit here. You need an archival service there's companies out there like iron mountain, you can at your local bank, depending on the bank. It ain't like it used to be, get a box, right?
[00:36:50] A special box in the vault that you. The tapes and other things in nowadays there's cloud options, virtual tape backup options, which is a lot of what we use and we do. Okay. We also use straight cloud at the very bottom end again. It's not located on the network. It's up in the cloud. It's double encrypted.
[00:37:13] It's absolutely the way to do now if you're going to have a backup and if that backup, you want to be secure, it must not be accessible. To the attacker, you've got to put some literal air space between your backups and the cyber criminals. It's called an air gap. So there's no way for them to get to it.
[00:37:37] Okay. Now I want you to consider seriously using tape these a LTO. These linear tape drives. They've been around for a long time, but their cartridges you can pull in and out. And they're huge. They they're physically small, but they can hold terabytes worth of data. They're absolutely amazing. There's some great disk based backup systems as what we do.
[00:38:02] Some of them are been around a long time and they can be quite reasonably. Price. All right. So it's something for you to consider, but you've got to have at least that air gap in order to make sure that you're going to be protected. What should you be looking for in a backup system? This is called 3, 2, 2 1, which means maintain at least three copies of your data store the backups on two different meters.
[00:38:31] Store at least one of the copies at an offsite location store, at least one of the copies offline, and be sure to have verified backups without air. Okay. Does that sound a little complicated? 3, 2, 1, 1 0 is what it's called. Just to be 3, 2, 1. Now it's 3, 2, 1, 1 0. I can send you Karen put together a special report on this based on our research.
[00:38:57] And I can share that with you. Absolutely free. Hey guys, if you want it, you got it. But you got to ask me, just email me M [email protected]. This is absolutely essential. If you're a small business, a tiny business to do it this way. Let me tell you, okay, this is just huge. Physical backups should be stored off site.
[00:39:19] I mentioned the bank fault. A lot of people just go ahead and take them home with. That might be a desk. It might be a tape. It can be a little bit complicated to do. And I've picked up customers that thought they were backing up. They were using a USB drive. They were putting it in due to flee every Monday.
[00:39:41] And then every Wednesday, what happened? Every Wednesday they bring in Wednesdays desk and then they bring that disc home and then Thursday, they bring in the Thursday disc. And none of them had been working. Okay. So be very careful. All of your backups should be encrypted. We encrypted at the customer site and then we reencrypt it when we bring it over to us.
[00:40:06] Okay. Keys are essential. Particularly if you're using a cloud-based backup, don't use the same keys across multiple backups. Very important there. You should have some good procedures that are well-documented test, test your restores because very frequently. We find they don't work. In fact, that's the number one problem, right?
[00:40:30] If they had just tried to restore, even once from their backup, they would've known they had problems. And get those backups scheduled on a regular schedule. Okay. So there's a lot more offline backups and more that we can talk about another time, but this is important. If you want any help, send me an email, just put backups in the subject line.
[00:40:55] I'll send you some stuff. Email me, M [email protected]. Now I am more than glad to help. Pretty much anybody out there. I'm not going to help. What about blah, blah, Amir Putin. But anybody else I'll help, but you got to reach out. Okay. You listen here. And I know some of this stuff is over some of our heads, some of your heads, you're the best and brightest.
[00:41:20] That's why you're listening and I'll help you out. I'll send you some information. That's going to get you on the right track. Me M [email protected]. That's Craig Peterson, S O N have a great day.
[00:41:35] We just got an email this week from a customer and they're saying, oh no, my email has been hacked. What does that mean was a really hacked, we're going to talk right now about email spoofing, which is a very big deal.
[00:41:51] Emails spoofing is being a problem for a long time, really? Since the 1970s. I remember when I got my first spoofed email back in the eighties and they was really a little bit confusing.
[00:42:05] I went into it more detail, of course, being a very technical kind of guy and looked behind the curtains, figured out what was going on. Just shook my head. I marveled at some people. Why would you do this sort of thing? The whole idea behind email spoofing is for you to receive an email, looks like it's from someone that it's not now, you've all seen examples of this.
[00:42:30] Everybody has. And those emails that are supposedly from the bank, or maybe from Amazon or some other type of business or family friend, this is part of what we call social engineering, where the bad guys are using a little bit about what they know about you, or maybe another person in order to. Frankly, fool you.
[00:42:54] That's what spoofing really is. There were a lot of email accounts that were hacked over the last what, 30, 40 years. And you might remember this people sending out an email saying, oh, my account got hacked because you just got emails. Back in the day, what people were trying to do is break into people's email accounts and then the bad guys after having broken in now knew everybody that was in the contact list from the account that was just broken into.
[00:43:29] Now they know, Hey, listen, this person sends an email. Maybe I can just pretend I'm them. Days it, the same thing still happens. But now typically what you're seeing is a more directed attack. So a person might even look in that email account that they've broken into and poke around a little bit and find out, oh, okay.
[00:43:52] So this person's account I just broken to is a purchasing manager at a big. So then they take the next step or maybe this tab after that and try and figure out. Okay, so now what do I do? Oh, okay. So really what I can do now is send fake purchase orders or send fake requests for money. I've seen in the past with clients that we've picked up because the email was acting strangely where a bad guy went ahead, found.
[00:44:25] Invoices that have been sent out by the purchasing person and the send the invoices out and changed the pay to information on the invoice. So they took the PDFs that they found on the file server of the invoices went in and changed them, change the account that they wanted, the funds ACH into. And once they had that happen, they just sent the invoice out again saying overdue.
[00:44:54] Off goes in the email and the company receives it and says, oh okay, I need to pay this invoice. Now. Sometimes it marked them overdue. Sometimes they didn't mark them overdue. I've seen both cases and now the money gets sent off and that invoice gets paid and then gets paid to the wrong person.
[00:45:13] Or maybe they go ahead and they don't send the invoice out, but they just send a little notification saying, Hey, our account has changed. Make sure you. Direct all future payments to this account. Instead. Now you might be thinking wait a second here. Now they send this email out. It's going to go into a bank account.
[00:45:33] I can recover the money while no, you can't. Because what they're doing is they are using mules. Now you've heard of meals before. He might've even seen that recent Clint Eastwood movie. I think it was called. But typically when we think of mules, as people we're thinking about people who are running drugs well, in this case, the bad guys use mules in order to move money around.
[00:45:59] And now sometimes the people know what they're doing. The FBI has had some really great arrests of some people who were doing this, particularly out in California, some of them cleaned. Yeah. I didn't know what was happening. It was just somebody, asked me to send money. It's like the Nigerian scam where the Nigeria in the Nigerian scam, they say, Hey I'm, I'm Nigerian prince, you've heard of these things before. And I need to get my money out of the country. I need to place to put them. And so if you have a us account, I'm going to transfer money into it. You can keep a thousand dollars of that 5,000 and I'm going to wire in just as a fee. Thanks for doing this. I, this is so important and it's such a hurry and I'm going to send you the.
[00:46:46] What they'll often do is send you a money order. It couldn't be a bank check, could be a lot of things, and then you go ahead and you cash it and oh, okay. Or cash just fine. And then you wire the $4,000 off to the bad guy. The bad guy gets the money and is off. Running in the meantime, your bank is trying to clear that bank check or that money order.
[00:47:14] And they find out that there is no money there because frankly what might've happened? I, this is one I've seen, I'm telling you about a story w we helped to solve this problem, but I had taken out a real money order from a bank, and then they made copies of it. Basically, they just forged it. And so they forged a hundred copies of it.
[00:47:36] So people thought they were getting a legitimate money order. And in some cases, the banks where the money order was, you mean deposited, did conf confirm it? They called up the source bank. Oh yeah. Yeah. That's a legit money order and then they all hit within a week or two. And now the, you are left holding the bag.
[00:47:58] So that's one thing that happens. But typically with these mules, the money comes to them in that account. They are supposed to then take that money and put it in their PayPal account and send it off to the next. And it might try jump to through two or three different people, and then it ends up overseas and the bad guys have gotten so good at this and have the cooperation of some small countries, sometimes bigger countries that they actually own.
[00:48:30] The bank overseas of the money ultimately gets transferred into. And of course there's no way to get the money back. It's a real. So with spoofing, they're trying to trick you into believing the emails from someone that you know, or someone that you can trust. Or as I said, maybe a business partner of some sort in most cases, it's some sort of a colleague, a vendor or a trusted brand.
[00:48:58] And so they exploit the trust that you have, and they ask you to do something or divulge information. They'll try and get you to do something. So there's more complexity tax. Like the ones that I just explained here that are going after financial employees, there might be some, an accountant, a bookkeeper, or bill payer and receivables payables.
[00:49:24] I've seen CFO attacks, but the really the spoofed email message looks legitimate on the surface. They'll use the legitimate logo of the company that they're trying to pretend that they're from. For instance, PayPal. Phishing attack. They have a spoofed email sender and typical email clients like you might be using for instance, on Microsoft outlook.
[00:49:48] The sender address is shown on the message, but most of the time nowadays the mail clients hide the actual email address, or if you just glance at it, it looks legit. You've seen those before these forged email headers. Yeah, it gets to be a problem. Now we use some software from Cisco that we buy.
[00:50:13] You have to buy. I think it's a thousand licenses at a time, but there were some others out there, Cisco again, by far the best and this, the software. Receives the email. So before it even ends up in the exchange server or somewhere else online, that email then goes through that Cisco server. They are comparing it to billions of other emails that they've seen, including in real time emails that are.
[00:50:41] Right now. And they'll look at the header of the email message. You can do that as well. With any email client, you can look at the header, Microsoft and outlook calls, it view source. But if you look at the email header, you'll see received. Headers that are in there. So say, receive colon from, and they'll give a name of a domain and then you'll see another received header and give another name of a machine.
[00:51:08] And it'll include the IP address might be IVF IPV four of your six, and you can then follow it all the way through. So what'll happen is partway through. You'll see, it took a hop that is. Not legitimate. That's where it comes in. Nowadays, if you have an email address for your business, man, a domain, you need to be publishing what are called SPF records.
[00:51:37] And those SPF records are looked at there compared to make sure that the email is properly signed and is from. The correct sender. There's a SPF records. There's a mother's too, that you should have in place, but you'll see that in the headers, if you're looking in the header. So it gets pretty complicated.
[00:51:59] The SPF, which is the sender policy framework is a security protocol standard. It's been around now for almost a decade. It's working in conjunction with what are called domain based message, authentication, reporting, and conformance. Heather's D mark headers to stop malware and phishing attacks. And they are very good if you use them properly, but unfortunately when I look, I would say it's still 95% of emails that are being sent by businesses are not using this email spoofing and protection.
[00:52:35] So have a look at that and I can send you a couple articles on it. If you're in trusted Craig Peter sohn.com.
[00:52:46] So we've established that email spoofing happens. What are the stats to this? And how can you further protect yourself from email spoofing? Particularly if you're not the technical type controlling DNS records, that's what's up right.
[00:53:02] Everybody Craig Peter sawn here, your cybersecurity strategist. And you're listening to news radio, w G a N a M five 60 and 98.5 FM. Join me on the morning. Drive Wednesday mornings at 7 34. Of course in the am. There's so much going on in the cybersecurity world. It affects all of us. Now, I think back to the good old days 40 years ago where we weren't worried about a lot of this stuff, spoofing, et cetera.
[00:53:36] But what we're talking about right now is 3.1 billion domain spoof. Emails sent every day. That's a huge thing. More than 90% of cyber attacks. Start with an email message. Email spoofing and phishing have had a worldwide impact costing probably $26 billion over the last five years. A couple of years ago, the FBI, this is 2019.
[00:54:07] Reported that about a house. A million cyber attacks were successful. 24% of them were email-based and the average scam tricked users out of $75,000. Yeah. So it's no wonder so many people are concerned about their email and whether or not those pieces of email are really a problem for them. And then anybody else.
[00:54:34] So a common attack that uses spoofing is CEO fraud, also known as business, email compromise. So this is where the attacker is spoofing or modifying, pretending to be a certain person that they're not they're impersonating an executive or owner, maybe of a business. And it targets. People in the financial accounting or accounts payable departments or even the engineering department.
[00:55:01] And that's what happened with one of our clients this week. They got a very interesting spoofed email. So even when you're smart and you're paying attention, you can be tricked the Canadian city treasurer. Tricked into transferring a hundred grand from taxpayer funds, Mattel tricked into sending 3 million to an accountant, China, a bank in Belgium, tricked into sending the attackers 70 million Euro.
[00:55:31] It happens and I have seen it personally with many businesses out there. So how do you protect yourself from email? Spoofing now, even with email security in place, there's some malicious email messages that are still going to get through to the inboxes. Now we're able to stop better than 96% of them just based on our stats.
[00:55:54] In fact, it's very rare that one gets through, but here are some things you can do and watch out for whether you're an employee responsible for financial decisions, or maybe you're someone who is. Personal email at work. Here's some tricks here. So get your pencil ready. Number one, never click links to access a web.
[00:56:19] Where you're asked to log in, always type in the official URL into your browser and authenticate on the browser. In other words, if you get an email from your bank or someone else, and there's a link in there to click that says, Hey oh man, here's some real problems. You got to respond right away.
[00:56:42] Don't do that go to paypal.com or your bank or your vendor's site, just type it into your browser, even though you can hover over the email link and see what it is. Sometimes it can be perfectly legitimate and yet it looks weird. For instance, when I send out my emails that people subscribe to that right there on Craig peterson.com, the links are going to come from the people that handle my email lists for me, because I send out thousands of emails at a time to people that have asked to get those emails.
[00:57:22] So I use a service and the services taking those links, modifying them somewhat in fact dramatically. And using that to make sure the delivery happened, people are opening it and that I'm not bothering you. So you can unsubscribe next step. You can, if you want to dig in more, look at the email headers.
[00:57:45] Now they're different for every email client. If you're using outlook, you have to select the email, basically in the left-hand side. Okay. You're going to control, click on that email and we'll come up and you'll see something that says view source. So in the outlook world, they hide it from you.
[00:58:06] If you're using a Mac and Mac mail, all you have to do is go to up in the menu bar email and view, header and cut off. There it is. I have many times in the past just left that turned on. So I'm always seeing the headers that reminds me to keep a look at those headers. So if you look in the header, And if the email sender is let me put it this way.
[00:58:31] If the person who is supposed to have sent it to you is doing headers proper, properly. You're going to see. A received SPF section of the headers and right in there, you can look for a pass or fail and response, and that'll tell you if it's legit. So in other words, let's use PayPal as an example, PayPal has these records that it publishes that say all of our emails are going to come from this server or that server of.
[00:59:04] And I do the same thing for my domains and we do the same thing for our clients domains. So it's something that you can really count on if you're doing it right, that this section of the headers. And that's why I was talking about earlier. If you have an email that your sending out from your domain and you don't have those proper headers in it, there's no way.
[00:59:31] To truly authenticate it. Now I go a step further and I use GPG in order to sign most of my emails. Now I don't do this for the trainings and other things, but direct personal emails from me will usually be cryptographically signed. So you can verify that it was me that sent it. Another thing you can do is copy and paste the text, the body of that email into a search engine.
[01:00:03] Of course I recommend duck go in most cases. And the chances are that frankly they've sent it to multiple people. That's why I was saying our Cisco based email filter. That's what it does, it looks for common portions of the body for emails that are known to be bad, be suspicious of email from official sources like the IRS, they're not going to be sending you email out of the blue most places. Aren't obviously don't open attachments from people that you don't. Special suspicious ones, particularly people we'll send PDFs that are infected. It's been a real problem. They'll send of course word docs, Excel docs, et cetera, as well.
[01:00:54] And the more. I have a sense of urgency or danger. That's a part of the email should really get your suspicions up, frankly, because suggesting something bad is going to happen. If you don't act quickly, that kind of gets around part of your brain and it's the fight or flight, right? Hey, I gotta take care of this.
[01:01:17] I gotta take care of this right away. Ah, and maybe you. So those are the main things that you can pay attention to. In the emails, if you are a tech person, and you're trying to figure this out, how can I make the emails safer for our company? You can always drop me an email as well. Me, M [email protected].
[01:01:43] I can send you to a couple of good sources. I'll have to put together a training as well on how to do this, but as individually. At least from my standpoint, a lot of this is common sense and unfortunately the bad guys have made it. So email is something we can no longer completely trust. Spoofing is a problem.
[01:02:05] As I said, we just saw it again this week. Thank goodness. It was all caught and stopped. The account was not. It was just a spoofed email from an account outside the organization that was act Craig peterson.com. Stick around.
[01:02:24] The value of crypto coins has been going down lately quite a bit across the board, not just Bitcoin, but the amount of crypto mining and crypto jacking going on. That hasn't gone down much at all.
[01:02:48] hi, I'm Craig Peter Sohn, your cyber security strategist. And you're listening to news radio, w G a N a M five 60 and FM nine. Point five, you can join me on the morning drive every Wednesday morning at 7 34, Matt and I go over some of the latest in news. You know about crypto coins, at least a little bit, right?
[01:03:15] These are the things like Bitcoin and others that are obstensively private, but in reality, aren't that private. If you receive coins and you spend coins, you are probably trackable. And if you can't spend that, the crypto currencies, why even bother getting it in the first place. One of the big drivers behind the price of these crypto currencies has been criminal activity.
[01:03:48] We've talked about that before. Here's the problem we're seeing more and more nowadays, even though the price of Bitcoin might go down 30%, which it has, and it's gone down in bigger chunks before. It does not mean that the bad guys don't want more of it. And what better way to mine, cryptocurrency then to not have to pay for.
[01:04:15] So the bad guys have been doing something called crypto jacking. This is where criminals are using really ransomware like tactics and poisoned website to get your computer, even your smartphone to mine, cryptocurrencies for. No mining, a Bitcoin can cost as much in electric bills that are in fact more in electric bills.
[01:04:43] Then you get from the value of the Bitcoin itself. So it's expensive for them to run it. Some countries like China have said, no, you're not doing it anymore because they're using so much electricity here in the U S we've even got crypto mining companies that are buying. Old power plant coal-fired or otherwise, and are generating their own electricity there locally in order to be able to mine cryptocurrencies efficiently, effectively so that they can make some profit from it.
[01:05:18] It's really quite the world out there. Some people have complained about their smartphone getting really hot. Their battery only lasts maybe an hour and it's supposed to last all day. Sometimes what's happened is your smartphone has been hijacked. It's been crypto jacked. So your smartphone, they're not designed to sit there and do heavy computing all day long.
[01:05:45] Like a workstation is even your regular desktop computer. Probably isn't. To be able to handle day long mining that has to happen. In fact, the most efficient way to do crypto mining of course is using specialized hardware, but that costs them money. So why not just crypto Jack? All right. There are two primary ways.
[01:06:09] Hackers have been getting victims, computers to secretly mine. Cryptocurrencies one is to trick them into loading. Crypto mining code onto their computers. So that's done through various types of fishing, light tactics. They get a legitimate looking email that tricks people into clicking on a link and the link runs code.
[01:06:30] Now what's interesting is you don't, even for cryptocurrency crypto jacket, you don't even have to download a program in. To have your computer start mining cryptocurrencies for the bad guys. They can use your browser to run a crypto mining script. And it runs in the background. As you work right, using up electricity, using up the CPU on your computer.
[01:06:58] They also will put it into ads. They'll put it on a website and your browser goes ahead and runs the code beautifully. So they're really trying to maximize their returns. That's the basics of crypto jacking what's been particularly bad lately has been the hackers breaking into cloud account. And then using those accounts to mine cryptocurrency, one of the trainings that I had on my Wednesday wisdoms has to do with password stuffing and my Wednesday wisdoms, you can get by just subscribing to my email over [email protected].
[01:07:44] But what happens here is they find your email address. They find. Password on one of these hacks that is occurred on the dark web. You weren't on the dark web, but your username or email address and password are there on the dark web. And then they just try it. So a big site like Amazon, or maybe it was your IBM also has cloud services can be sitting there running along very well, having fun.
[01:08:16] Life's good. And. Then they go ahead and try your email address and password to try and break in. Now, you know how I keep telling everybody use a good password manager and this week I actually changed my opinion on password managers. So you know, that I really like the password manager that you can get from one password.com.
[01:08:44] It really is fantastic. Particularly for businesses, various types of enterprises, one password.com. However, where I have changed is that some of these browsers nowadays, particularly thinking about Firefox Google Chrome safari, if you're particularly, if you're on a Mac, all have built in password managers that are actually.
[01:09:09] Good. Now they check. Have I been poned, which is a site I've talked to you guys about for years. To make sure that your accounts are reasonably safe than not being found on the dark web, the new password that it came up with or that you want to use. They check that as well. Make sure it's not in use. So here's an example here.
[01:09:32] This is a guy by the name of Chris. He lives out in Seattle, Washington, and he makes mobile apps for local publishers. Just this year, new year's day, he got an alert from Amazon web services. Now Amazon web services, of course, cloud service. They've got some really nice stuff, starting with light ship and going up from there, I've used various services from them for well, since they started offering the services over very many years and.
[01:10:04] They allow you to have a computer and you can get whatever size computer you want to, or fraction of a computer. You want to, he got this alert because it said that he owed more than $53,000 for a month's worth of hosts. Now his typical Amazon bill is between a hundred and 150 bucks a month. My typical Amazon bell is now 50 to maybe $80 a month.
[01:10:34] I cannot imagine getting a $53,000 bill from our friends at Amazon. So the poor guy was just totally freaking out, which is a very big deal. So I'm looking at an article from insider that you can find a business insider.com. They were able to confirm that, yes, indeed. He got this $53,000 bill from Amazon and yes, indeed.
[01:11:00] It looks like his account had been hacked by cryptocurrency miners. So these guys can run up just incredibly large charges for the raw computing power. They need to produce some of these digital cryptocurrencies, like Bitcoin there's many others out there. But this isn't new. This is happening all of the time.
[01:11:23] Google reported late last year, that 86% of account breaches on its Google cloud platform were used to perform cryptocurrency mining. So make sure you are using a good password manager that generates good passwords. And I have a special report on passwords. You can download it immediately when you sign up for.
[01:11:48] My email, my weekly email [email protected] and it tells you what to do, how to do it. What is a good password? What the thinking is because it's changed on passwords, but do that and use two factor authentication. Multi-factor authentication as well. And I talk about that in that special report too.
[01:12:11] And visit me online. Sign up right now. Craig Peter sohn.com.
[01:12:17] We're moving closer and closer to completely automated cars, but we want to talk right now about car hacks, because there was an interesting one this week that has to do with Tesla. And we'll talk about some of the other hacks on car.
[01:12:33] Connected cars are coming our way in a very big way.
[01:12:38] We just talked about the shutdown of two G and 3g in our cars. We, it wasn't really our cars, right? Two G 3g. That was for our cell phones. That was. Years ago course now for four GLTE 5g, even 10 G is being used in the labs. Right now. It's hard to think about some of those older technologies, but they were being used and they were being used by cars, primarily for the navigation features.
[01:13:13] Some cars use these data links, if you will, that are really on the cell phone network in order to do remote things like remote start. For instance, I have a friend who's Subaru. Of course was using that. And now she's got to do an upgrade on her car because that 3g technology is going away depending on the carrier, by the way, some of it's going away sooner.
[01:13:40] Some of it's going away later, but it'll all be gone at the end of 2020. What are we looking at? As we look into the future, I'm really concerned. I don't want to buy one of these new cars at the same time as I do, because they are cool, but I don't want to buy one of those because of the real problem that we could have of what well of having that car.
[01:14:07] I need an upgrade and not been able to do it. I watched a video of a guy who took a Tesla that hadn't been damaged badly in a flood, and it was able to buy it for cheap. Why? Because Tesla will not sell you new motors and a new batteries for a car like that. So he got the car for cheap. He found a Chevy Camaro that had been wrecked, but its engine and transmission were just fine.
[01:14:37] He ripped everything out of the Tesla and went ahead after that, cause you got to clean that out, and water damage. You spray wash all to the inside. He got right down to the aluminum, everything that wasn't part of the core aluminum chassis was gone. And then he built it back up again. He managed to keep all of those Tesla systems working, that, that screen that you have upfront that does the temperature control, cruise maps, everything out.
[01:15:09] He kept that it was able to work. The, automated stuff, cruise control type stuff. And now he had a very hot car that looked like a Tesla. He took it out to SEMA, which is pretty cool. I'd love to see that, but it was a Tesla with a big V8 gasoline engine in it. He's done a, quite a good job on it.
[01:15:33] It was quite amazing to see it took them months. It was him and some of his buddies. These new cars are even more connected than my friend Subaru is they get downloads from the. Some of them are using Wi-Fi and 5g. Really one of the big promises of 5g is, Hey, our cars can talk to each other because now you can get a millisecond delay in going from one car to another versus what you have today, which can be a half a second or more, which can be the difference between having a rear end collision and being able to stop in time when it comes to these automated system.
[01:16:15] So they are more connected. They connect to the wifi in your homes. They connect to obviously the 5g network, which is where things are going right now. But what's happening with the hackers because really what we're talking about, isn't a computer on wheels. Oh no. Dozens of computers inside that car and your car has a network inside of it and has had for many years, this can bus network and even fancier ones nowadays that connect all of your systems together.
[01:16:50] So your entertainment system, for instance, is connected to this network. And that was used. You might remember a couple of years ago on a Chrysler product where the bad guy installed. Or using the thumb drive onto that entertainment system and had a reporter drive that car down the road. This is all known.
[01:17:13] It was all controlled. And was able to the bad guy right there, the demonstration in this case, I guess you'd call them a white hat hacker. He drove that car right off the road while the reporter was trying to steer otherwise because cars nowadays don't have a direct linkage between anything in any.
[01:17:36] That's why I love my 1980 Mercedes TESOL. You turn the steering wheel. It isn't actually connected to the wheels to that front end of the car. All it's doing is telling the computer you want to turn and how much you want to turn that brake pedal. Doesn't actually. Compress hydraulics and cause the brakes to engage that fuel pedal doesn't actually move the throttle on the car.
[01:18:01] The throttle is really being controlled and moved by the computers. So the car is completely electronic. It feels like a regular car, right? We're not talking about the Tesla's of today or tomorrow. We're talking about Volvos that have been sold for more than a decade. We're talking about a lot of different cars.
[01:18:22] So now you have a platform on wheels that can be dangerous because it can be, in some cases, remotely controlled, it can have software that may be crashes. We know that part of the infrastructure quote, unquote bill, which contains almost no infrastructure. It's amazing how they named these things. Isn't it.
[01:18:43] And what is it like 6% it actual infrastructure and the infrastructure bill? One of the things in there that is not infrastru. Is a demand, a law that says the car manufacturers have to include a remote. Button, if you will, so that a police officer could go ahead and say, okay, I'm pursuing this car and they're not stomping.
[01:19:09] I don't want to risk people's lives. As this bad guy tries to elude me here in backstreets. Kids can get hit, et cetera. So they push the button and the car stops that all sounds great. The problem is that you could potentially be opening some security problems by having this remote stop button that can be used by anybody really right.
[01:19:38] Since when is it going to be limited to just law enforcement? Isn't that a problem? According to Caren driver, I'm looking at their magazine right now. They're saying that there were at least 150 automotive cybersecurity incidents in twenty nineteen, a hundred and fifty incidents, part of a 94% year over year increase since 2016.
[01:20:03] In other words, every year. The number of automotive, cybersecurity and incidences has doubled. And that's according to report from a company called upstream security. So we're lost. So looking at what w maybe ransomware for a car. So that your car gets hacked. You can't hack my 1980 Mercedes diesel.
[01:20:26] It is impossible to hack into an unconnected car, but if you are driving a vehicle it's likely at risk from some sort of digital true. We've even seen from some of the bugs. We've seen cars from Japan that have decided to drive into the Jersey barrier because it misunderstands exactly what it is. We've seen cars from Tesla.
[01:20:55] Drive right into the back of a parked fire truck mentioned doing that at speed, right? And cause a fire truck full of water, et cetera. I've actually seen that one happened personally. So the more sophisticated the system is, the more connected your vehicle is. The more exposed you are in Detroit free press has a great little article on that right now.
[01:21:21] And in there he's saying we have taken. Whatever model car you think of. And we hack them through various places. I can control your steering. I can shut down and start your engine. Control your brakes, your doors, your wipers, open and close your. There's a lot of people who are trying to break into these cars.
[01:21:44] And there's a lot of people who are trying to protect them. That hacker duo back in 2015, who took control of that Jeep Cherokee, just think about that sort of. There's an Israeli based automotive cybersecurity company who told the free press that he expects the current trend of hackers, holding digital data on computers for ransom to also move to cars.
[01:22:10] So when this happens, the driver will not be able to start the vehicle until they pay off the rant. Or suffer the consequences, which could be wiping the cars systems operating systems could be Kenning the car to catch on fire. Think of what can happen with each generation with those batteries.
[01:22:30] There's no way around it. You're going to have to get it towed and get all of the software reloaded in the company. And now this week, it comes out that in 19 year old kid said that he was able to hack into over 25 Teslas that he tried via a bug in a popular. It's an open source tool that people are using to link into their Teslas to do various types of remote control.
[01:22:59] And he posted a tweet on this guy's name's David Colombo. You'll find them on Twitter, went viral and he reported the vulnerability to the people who are maintaining the software and they fixed it. In fact, the very same day and Tesla also pushed updates to their vehicle. That invalidated the signatures and the key exchanges that we're having.
[01:23:26] So this is a 19 year old researcher. He's able to hack into cars in 13 countries, 38, 13 countries. Yeah. Worth of Teslas without the owner's knowledge. No, he says I, I can not. Doors, I can turn off the security system. I can open windows. I keyless start and things turn on the stereo, honk the horn view, the cars location, and if the driver was present, but he doesn't think he could actually move the vehicle remotely, but that's a 19 year old.
[01:24:00] What's going to happen when we implement the law that was just passed that says our cars have to be remotely controllable by anybody basically. Yeah. It's scary. Hey, I want to invite you guys to take a minute, go to Craig peterson.com. Make sure you sign up for my newsletter there, and I'll keep you up to date on all of this stuff and you'll even get my show notes.
[01:24:26] Craig peterson.com.
Why Is Russia Password Spraying Hurting You? What Are They Trying to Do? And What Is It?
This is one of the top topics I've had people ask about lately: How can you protect yourself and your business against Russian hackers? So I've got a presentation. We're going to run through it. We're going to talk about what you can do about it.
[Automated transcript follows]
This has been a long time coming. I have been doing a lot over the years of webinars of online meetings, trying to help people understand what's going on, what can be done.
[00:00:28] And I got a great email this week from one of the listeners. Who's been a man on my email list now for years, I'm not even sure how many years. And he was saying, Hey, thanks for giving all of this information for free for small businesses. And afford it. And I got to thinking because there've been a lot of requests lately, for instance, backups how should I be doing them?
[00:00:52] What should I be doing? And a number of other topics that really all go together into the, how do I protect myself, my business. From ransomware from these Russian hackers. So that's what we're going to be talking about today. We're going to go through a few of these. This is going to be a series.
[00:01:10] We're going to continue this here and weeks ahead, and I appreciate all your feedback. And if you miss part of it, make sure you email me just M. Craig peterson.com. Let me know, and I'll be glad to send some of it to you. Now I'm recording this on video as well. So it's great when you're driving around and listening in picking up some tidbits.
[00:01:34] And if you do want to see the recorded version again, dropping them in an email to [email protected] or search for me on YouTube or on one of the other sites that are out there like grumble and you'll. This as I release it. Cause this is going to take a few weeks to really get into the whole thing.
[00:01:55] So let's get started. I'm going to pull this up here. Full screen. For those watching at home and what this is called today, we're talking about protecting your business and your self from Russian hackers because they have been out there. They have been causing just all kinds of problems, but there's a few things that you can do.
[00:02:18] And I have them up on the screen here. Let me pull them up, but I want to get into the background first. Russian ransomware group. They're a bunch of bad guys and it's called Conti. Now. Conti has been around for a long time. These are the guys that have been ransoming us. They're the guys who ran to mean the businesses they've been rants.
[00:02:40] Government, you might've heard them. They've got into hospitals. They have been all over the place and they've raised a whole lot of. For the Russians. I'm also going to tell you about a couple of things you can do here. Cause there's a real neat trick when it comes to keeping Russians out of your computers, but Conti decided, Hey, listen, we are all for Russia and president and Putin.
[00:03:03] So they came out with an official warning, oh, I want to read this to it says if anybody. We'll decide to organize a cyber attack or any war activities against Russia. We are going to use our all possible resources to strike back at the critical infrastructures of an enemy. Yeah, no, not the best English, but much better than my Russian.
[00:03:25] I got to say that I know two words or so in Russian, but they said that they were announcing full support for president. That's a pretty bad thing. If you asked me, they also have ties to Russian intelligence intelligence, but what are we talking about really? Think of the KGB.
[00:03:43] The FSB is what they're called nowadays, but directly tie. China and North Korea, Iran, or also now tied in with Russia to varying degrees, but all of them are a little bit concerned about getting into it a little too much, but we're going to talk about their tactics. That's what's important today. What are they doing?
[00:04:05] Why are they doing it? What can you do about. So the first thing is password sprain. This is big deal. I've got a nice big slide up here. I like that color blue. I don't know about you, but I think it's pretty, but password sprain is something we all need to understand a little bit better. It's a brute force attack that has been really hurting.
[00:04:30] Many of us. Let me see if I can get this to work. For some reason it has decided it just doesn't want. Let me see here. What is up? Oh, is something isn't it's just, I'm getting a white screen, but it's a brute force attack targets users who have common passwords. Now this is a problem. When we're talking about passwords.
[00:04:55] If you have a password that has been breached in any of these breaches that have gone on over the last, however long, right? 30 years plus now that password is known to the bad guy. So what they'll do is they'll take that common password and they'll start to try it. So password sprain is where they will go to a bank site or they'll go to Google.
[00:05:21] The, oftentimes they're trying to get at your email accounts. So if you have Google email or Yahoo or Hotmail, they'll try it. Use passwords that they have found against accounts that they have found on those various sites that ends up being quite a big problem for everybody out there. Okay. I got that screen back here.
[00:05:42] So I'll put that up for those people who are well. But they will send multiple times attacks using variations of these passwords. And it's known as a low and slow method of password hacking because if they were to go bam, and send all of these passwords and login attempts. They get caught.
[00:06:06] The automated systems would say, Hey, wait a minute. This is not good. We're going to cut you off. In fact, that's what I do for my client. We have remote access using SSH, which is a an encryption session so that we can have a terminal session. And if you try and log in three times, We automatically zap you, right?
[00:06:28] We shut you down. So they take a very slow approach to this password sprain technique. And they're also going after volume, which makes a whole lot of sense. And there are right now, billions of passwords usernames, email addresses that have been stolen that are sitting out in the dark. So you've got to make sure that you are not reusing passwords.
[00:06:54] How many times have we talked about that? You've got one common password that you're using over and again, while that's a problem, but they're not going to keep hacking your account. They're going to switch from one account to another because they don't want to get locked out.
[00:07:09] Just like I lock out somebody who's trying to get in. So if someone's coming from that same. IP address that same internet site. And they're trying to log into that same account multiple times. Bam. They are gone. So with path's word sprain, they're trying to get around the problem of you noticing they're trying to get into a bunch of different accounts and they try and leverage it.
[00:07:34] So they'll oftentimes use multiple computers that they've stolen access to. We've talked about that before too. It gets to be a real big. Now they're also targeting these single sign-on and cloud-based applications, because once they're on. Using one of these federated authenticated authentication protocols, they can mask the malicious traffic.
[00:08:00] We've heard some of these hacks lately where they're using a token that they managed to pick up from somebody's email, I account, or they got onto Microsoft and they got into the email account on Microsoft. That happened recently. In a supply chain attack, solar winds. You heard about that 20, 21, right?
[00:08:21] So they're going after these email applications, including Microsoft or Microsoft has done they're going after routers and internet of things, devices for a very good reason, those IOT devices, which are things like your smart lights, they can be. Controlling the cameras outside, they go on and on there's thousands, millions of them.
[00:08:44] Now I actually all the way through your microwave, they tend to not be very well protected. So that's a real big target for them. So step. They want to acquire a list of usernames. Step two, they're going to spray the passwords. Where do they get those passwords in those usernames? Or they get them from breaches.
[00:09:06] So again, if you have an account that's breached at some online shopping site, a big one, a small one, it doesn't really mean. That particular breach is now well known and they can, will and do gain access to your account which is step three, gain access to it. It gets to be a serious problem.
[00:09:26] Okay. How do you know if you are under attack? Number one? There is a spike in failed. Log-ins this is where having a system and there's technical terms is tough for this. I'm trying to avoid a lot of those terms, but this is where the system is watching logins, noticing that there's a problem and going ahead and stopping it, not just noticing that, but stop. Very important to do. There are a high number of locked accounts, which means what it means that again, someone's been trying to log in. You should make sure that your account, if there are invalid, lock-ins automatic. Locks it out after some number of attempts and five attempts is usually considered to be okay.
[00:10:14] I know on my phone, for instance, I have a higher number of the neck, cause sometimes the grandkids get at it. But when it comes to your business account, when it comes to your bank account, you probably don't want to have a whole bunch of. Of a attempts, and then in known or valid or invalid, I should say user attempts again.
[00:10:36] Why are they trying to log in with a username that just doesn't exist? Yeah, it can be a problem. Hey, when we come back. We're going to talk about some steps. Like you can take here to really remediate, maybe even stop a password spraying attack. I've already given you a few ideas here, but what are some act of things that you can do, particularly for a small business to really protect yourself?
[00:11:04] Hey, stick around. We'll be right back. Craig peterson.com.
[00:11:10] Russia has, hacking our computers, Russia's continuing to hack our computers and this is a real problem. So we are going to talk right now about how to stop some of these things. We already talked about password sprain. How do you start?
[00:11:26] There are a lot of things we have to pay attention to, and that's what I'm going to be doing in the weeks ahead.
[00:11:33] We're going to be going through some of the things you need to do to keep yourself safe. Keep your business safe in this really dangerous online. There are so many things going on. So many people that are losing their retirement businesses, losing their operating accounts. We've seen it before with clients of ours while you know their clients now.
[00:11:59] And it was just a devastating thing to them. So I don't want that to happen to you now, if you are interested. All of this is recorded and I am doing this as video as well. We've got slides and you can find out more about it. Just email me M [email protected]. It's really that simple. And I didn't let me know.
[00:12:24] And I'll be glad to send it off to you. Okay. This is available to anybody I'm trying to help. And we've had a lot of emails recently about some of these things. So th this is covering everything from the password spraying we're talking about right now through backups and other things that you need to do.
[00:12:43] Let's get going on our sprain problem. So w what are the steps that we need to take an order to really remediate against one of these password spraying attacks? And frankly, it is. Oh, a lot to do. It has a lot to do with our users and what we do, if you're a business, if you are an individual, we need to be using longer passwords.
[00:13:12] Now we're not talking about all of these random characters that we used to have. I remember having to have my password be at least four characters, long APAC, when didn't even have to have a username, it was just all based on the password. And things changed over the years, the latest standards that are out there right now come from this too, which is the national Institute for science and technology.
[00:13:37] They are the guys that put together, all of the guidelines said federal government and businesses need to follow. And they're telling us that a longer passwords means elaborate pass phrase. So you should use 15 character passwords. I had an article just a couple of weeks ago saying that an eight character password can be cracked almost instantly, certainly within an hour, any eight character password.
[00:14:08] So if you're still using that, you've got to make a change. And obviously nine characters is a lot more possibilities, takes a lot longer to crack. I don't have those numbers right in front of me, but 15 is the ideal. So use pass phrases instead of single words. So phrases like I don't know secretary of one, the Kentucky.
[00:14:34] There you go. There's a phrase. So what you would do is put, maybe dashes between each one of the words. Maybe you would go ahead and use a comma, put some numbers in there, put some special characters in upper lowercase, right? So it's basically on uncrackable at that point. And that's what you want.
[00:14:53] Next one. When we're talking about rules for your passwords, the best passwords are the passwords that you can remember without writing them down and words that don't make sense to anyone else's. I remember taking a memory course a few years back and they had random words and you had to remember them.
[00:15:18] And the whole idea was okay, visualize this happening. And as I recall, man, it's been a lot of years I won't say decades, but it hasn't been. Since I did this, I still remember a part of it, it was first word was airplane. Next was all envelope. The next one was paper clip. Next one was pencil.
[00:15:38] So I visualized an airplane flying into an all envelope and that all envelope then goes into a paper clip and a pencil writes on the outside. Like it's addressing it to someone. That is a good little password, actually airplane or envelope, paperclip, a pencil with a mixed case and maybe a number two or special symbol thrown in.
[00:16:05] Those are the types of rules that we're talking about. The types of rules that really. Next up here. Oops. Wrong keyboard. Stay away from frequently used passwords. We've talked about this many times. If you're using one of the better password managers, like for instance, one password, you will automatically have any passwords that you are there in Shirin or that it creates you'll have them checked via a website out there.
[00:16:37] It's called. Yeah. Okay. It's called. Have I been poned I, and I hated to say this because how do you spell it? It's all one big, long word. Have I been poned to.com and poned is P w N E d.com. It will tell you if a password that you're trying to use is a known password. If it has been found out in the wild, okay.
[00:17:02] Use unique passwords for every site you visit, I can't stress this enough. We were talking about password sprain. If you use the same password and email address on multiple sites, you're in. Because all they have to do is try your email address and your password for whichever site it is that they might want to try out.
[00:17:27] Remember, many of them are trying to get into your email and they have done that successfully. With Microsoft email, if you have their Microsoft 365 service and you might want to read the fine print there very carefully, because Microsoft does not guarantee much of anything. You make sure you back it up yourself.
[00:17:50] Make sure you do all of these things because Microsoft just plain, isn't doing them for you. Next one here. Next up is our password manager. And I mentioned this before installing and using a password manager is phenomenal. It automates the generation of passwords. If you have. Integrated with your web browser.
[00:18:15] It now allows your web browser to work with your password manager. So when you go to a site, you can have it pull up your passwords. How could it be much easier than that? It's really rather simple. That way it's keeping track of your logins. And again, One password.com is the one I recommend and people get confused.
[00:18:36] When I say that, when I'm saying one password, I don't mean only have one password used for everything. One password is a name of a company. Okay. So it Talking about only having a single password, but use a password manager. And I've got all of these up on the screen right now. If you're interested in getting copies of these, you can go ahead and just email me M [email protected].
[00:19:04] And I'll make sure I send you a copy of the slide deck of this presentation as well. Cause this is just so important, frankly, but having these points is going to be huge for you. Now strange activity. That's another very big deal. And we're going to talk about this when we get back, what is it?
[00:19:25] What does it mean? But I'm going to hold off the rest of this, I think for another week. But right now, what let's hit this, we're talking about odd log-in attacks. A lot of login attempts, the excessive login attempts trends in unusual activities take any, you need to basically take measures to block it and determine if this activity is legitimate.
[00:19:50] Is someone just for forgetting their password and spraying themselves or what's going on? Okay. There you go. Simple. Hey, everybody, you can find out a lot more and you'll be getting links to this automatically to these videos, et cetera. If you're on my email list, Craig peterson.com and you can email me M [email protected].
[00:20:15] We'd be glad to send you this or any other information I might have. All right. Take care. We'll be right back.
[00:20:23] Putin has been working for a while. In fact, it looks like as early as September in 2021, Putin started going after major us corporation. So we're going to talk about that. And what does it mean.
[00:20:39] Putin has been going crazy for a while. I'm going to put this up on the screen for those of you who are watching either on rumble or YouTube, but Putin planned this whole invasion apparently quite a while ago.
[00:20:56] And I got an article from the Washington post up on MSN talking about what Putin did at least a little bit about what he did. And you can see right here if you're following. That Russian agents came to the home of Google's top executive and Moscow. And what they did is gave an ultimatum. They told that Google, a senior executive that they needed.
[00:21:24] Pull down an app that was in use in Russia. And this app was polling. It was for people to do polls and say, Hey what do you think about Putin's garden performance, et cetera. We do them in the U S all of the time you hear about the polls right left and center. Poland, which is a small country next to another small country called Ukraine next to a large country called Russia.
[00:21:50] But we're talking about Paul's favoribility polls. What do you think they should be doing? What do you think that the government should be doing and maybe what they should not be. So Putin didn't like this. He didn't like this at all. And so what he did is he sent a couple of guys ex KGB, FSB, the secret police over in Russia by to visit this Google executive.
[00:22:16] If you're the Google executive, what are you going to do? If you Google. Yeah, you're going to say, oh my gosh, I'm out of here. So I'm not sure if she, if this executive was an American or Russian, this article doesn't seem to be clear about it, but what happened is they said, okay let's go hide.
[00:22:41] So they rented a hotel room for the. They put her in it and they rented the room under an assumed name. So it wasn't the real name of the executive. It wasn't tied into Google and they thought, okay, now we're pretty safe. Cause you got a hotel security, I guess there are a couple of Google people hanging out with her and they felt pretty safe.
[00:23:04] What happens next? There is a knock on the door. These same agents, again, that are believed to be Russian secret. Police showed up at her room and told her that the cock was still ticking because they had given her 24 hours for Google to take down the app because Putin, dental. People weren't particularly pleased with Putin.
[00:23:31] So at that point, of course it was forget about it. And within hours, Google had pulled down the app. Now you might complain, right? A lot of people might complain about it. It's one thing for a company like Google or apple to capitulate, to a government to do maybe some censorship, like the great firewall of China.
[00:23:54] You might've heard of that where the Chinese citizens can't get certain information. Russia has something pretty similar and us companies have gone ahead and helped build it, provided the technology for it and put it in place. They sold it to them. I don't like that in case you didn't guess, right?
[00:24:12] I'm all for free speech. I think it's very important for any form of a democracy. No question about it, but these companies apparently don't have a problem with that. However, now this is something, a little different. If you have employees who are being threatened and I mean threatened to serve 15 years in a Russian prison, what are you going?
[00:24:39] Are you going to say no, I'm going to leave that app up. And then now all of a sudden your executives, or even a coder, somebody a programmer, like the guy that sweeps the floors, whatever are you going to let them be arrested so that you can have this app up on your Google play store or your app store over the apple side?
[00:24:59] Probably not because frankly, this is something that is not worth it. So what are you. I think the only answer is what we've seen company after company do, and that is get out of Russia completely. And there was an interesting story. I read this recently about McDonald's you might remember back in the Soviet days, McDonald's worked out this deal with the Soviet union to open a McDonald's right there in downtown Moscow.
[00:25:32] I guess it was pretty prominent. I don't know if it was, I think I might've been even on red square and there were people like. To have an American hamburger and it's been pretty popular the whole time. McDonald's closed that store and pulled out of the country. Starbucks has pulled out, are they going to reopen?
[00:25:50] Cause I don't think either one of them said, forget about it. We're not coming back, but I know both of them have closed on operations. Automobile manufacturers from the U S have closed on operations. What is their choice? You can't just go ahead and say, okay yeah. Okay. Yeah. You're just going to arrest people or, we'll keep quiet for now and come back later.
[00:26:12] What are you supposed to do? That's part of the problem with these oligarchies, with these people who are basically all powerful. Now we actually see some of that here in the us, which is just as shame, just a shame because we see these companies going ahead and cutting out free speech saying, oh, you can't say that there was a time where if you said masks work, that you would have been censored. And then there was a time where if you said masks don't work. You cloth mass don't work, you would have been censored. There was a time when you said masks aren't necessary. You would have been censored right now, but the science is settled.
[00:26:56] It was just crazy. Science has never settled and oh, we could go on with this for hours and hours, but potent is not a good guy. And this article, I'm going to bring it up on the screen here again. But this article talks about. And a single year. And again, this is MSN. Potent had his political nemesis, Aloxi Novolin novel ne yeah, I got it right.
[00:27:23] He had him in prison after a poisoning attempt, felled to kill him. Do you remember that whole poison attempt? Where they gave him this really nasty radioactive bride product, as I recall, and potent went ahead and basically shut down. They pushed all of these independent news organizations to the brink of extinction.
[00:27:46] Look at what happened with Russia today. The entire staff walked off on the. Saying, we're not going to report on any of these lies that are coming out of Moscow. It's happened again and again, Putin orchestrated a Kremlin controlled takeover of Russia's Facebook equivalent, and he's also issued liquidation orders against human rights organizations.
[00:28:12] And so all this is going on. What are you going to do if you're. If you're a Google, right? I can see the criticism of those countries or companies should say when they're cooperating with the regimes, putting in place, things like facial recognition to, to spy on people, to have a social credit system, these great firewalls in these countries.
[00:28:34] But when you have something like this happen, I forget about it. There's nothing you can do. And the crackdown is accelerated Facebook and Twitter were knocked offline by the government for millions of Russians news outlets had survived the state harassment for years, shut down in the face of a new law impose.
[00:28:55] 15 year prison sentences for spreading fake news. It's incredible what has happened. And we've got to be careful here in the U S too, because we see this censorship, there's a lot of complaints about what was happening under Donald Trump president and old Biden, both Obama and Biden.
[00:29:15] Both of those have done some of these same things to a lesser extent. Stick around. We'll be right back.
[00:29:23] This whole war with the crane, Ukraine and Russia has brought a few things to light here over the months, and really the more than year that it's been leading up to the beginning of that war even, but we've got clear view in the news again. Yeah.
[00:29:39] am also besides broadcasting this on the radio, we're doing it in video two. So you can always follow along at rumble or at YouTube, but there's a great article here.
[00:29:52] I have up on my screen for you to see. And this is from writer. Para carried over on MSN. And it is an exclusive story talking about Ukraine, using something called clear views. AI facial recognition. This to me is absolutely fascinating because what is happening. Is the technology that Clearview develop and has it been selling to police forces in the United States is being used on the battlefield and.
[00:30:27] How here's what the technology did. And does Clearview illegally went on websites, major websites all over the world and did what we call scraping. Now, scraping is where they go to the site and they grab the pictures. So they scraped Facebook. They scraped you tube. They scraped. Dan and many more.
[00:30:54] And then they put it all into a big database that told them where they found it, who that person was. And then they also took that biometric information from that image of the face and came up with some unique codes, a hash basically is what they did. And. Now what Clearview is doing is if you are a police organization, you can get a little app that runs right there on your.
[00:31:22] And you have an encounter with someone you're a policeman, right? Let's say, and you just hold the camera up and it gets a picture of that person. It now finds the background information on them. And then you can use that tied into the police databases to check and see if there's any record of this person.
[00:31:42] If they've been doing anything illegal. It's really quite cool. What they're able to do and scary at the same time, we use the same basic technology over in Afghanistan. So literary troops as they're out, and they're having encounters with civilians, people in the streets, fighters, et cetera. They could hold the device up.
[00:32:04] It would identify them. It went further than just the face that actually did retinal scans and things, all kinds of cool stuff, but basically recognize the face. And they were able to tell if this was a friend of foe or. So a friend might be someone who worked as a translator who has been known to be helping the us troops in Afghanistan, et cetera.
[00:32:29] So we built this huge database of hundreds, of thousands of people's biometrics person, very personal information in it. And if they were getting paid even how much they're getting paid, all of that was in the database, in the backend. And then we abruptly. And we left that equipment behind. I hope the database was destroyed.
[00:32:52] I haven't found anything. Absolutely conclusive on it. That the withdrawal from Afghanistan was frankly unforgivable. It just I can't believe they did what they did at any rate. This is Clearview. This is this company. So now that same technology has moved to Ukraine. What's interesting. About this whole Ukrainian thing to me was okay, great.
[00:33:18] Now they can identify people. Can they really identify a pretty much everybody? Who are they going to identify? As it turns out clear Clearview also illegally stole photos of people over in Russia and in Ukraine. So the clear view founder said that they had more than 2 billion images from. How's that right from this social media service called V contact a or somebody like that out of a database of 10 billion photos total.
[00:33:52] So one out of five of the pictures they scraped was Russian, which surprised me. So the Ukrainians have been using it to identify dead Russian. And it's, they're saying it's much easier than matching fingerprints even works. If there's facial damage, it's scary to think about right. Wars, terrible.
[00:34:14] Who wants to go to war? I can't believe all of the people that want to jump in there. I really feel for these people in Ukraine, what can we do? I'll start approximately. Research for the department of energy, found the decomposition, reduce the technology's effectiveness while a paper from 2021 showed some promising results.
[00:34:36] Now, this again is an example of technology being used in a way it's never been used before. And having that ability to identify dead or living combat combatants on a field like this is just amazing. So this is the most comprehensive data set. There's critics, of course, they're saying that the facial recognition could misidentify people at checkpoints, obviously, right?
[00:35:04] Could miss identify people in a battle mismatch could lead to civilian deaths, just like unfair arrests have risen from police use. And that's from Albert Kahn, executive director of surveillance, technology oversight, product, project, and new. So as usual, these things can backfire and I think they probably will given a little bit of time and that's a sad thing.
[00:35:31] Now I also want to talk about this. This is cool. Another article here, I'm pulling up on the screen right now. And this is about some hackers. Now we know that the Kremlin's been lying. We know that if a politician's lips are moving their line, isn't that the old standby, but Russians apparently don't know this.
[00:35:56] And the average Russian on the street is thinking that, okay, we're rescuing Ukraine. Isn't that just a wonderful thing. There's a couple of ways that the hackers have been getting around it. It's called a squad 3 0 3. They have this tool that's hosted at the domain. 1920 dot. There's an Indian domain and it loads a pre-written statement in Russian into your native SMS app.
[00:36:29] In other words, the app that you use for texting and the idea is they that they've taken, oh, let's see here. Tens of thousands of trying to remember the exact number of stolen phone numbers from Russia. So all of those hacks that we've talked about for all of these years, those hacks have many of them phone numbers in them.
[00:36:54] And they've been taking those phone numbers from some of those hacks and using them to send out about 6.5. Million text messages. So what happens is you, your phone, your actual phone ends up sending a text in Russia saying something to the effect of dear Russians. Your media is being censored. The Kremlin is lying.
[00:37:18] Find out the truth about Ukraine on the free internet, and then the telegram app time to overthrow dictator. Yeah, that's not going to cause any problems, is it right? I'll put that up on the screen again for people who might read Russian. Cause it's got it in Cyrillic. Okay. And then you have the option to get an, another set of text and figure it out.
[00:37:40] So the phone number, you can see there, you can copy it and paste it into your app and off the message goes. It's very cool. And in the daily dog, They're quoting a member of this squad 3 0 3 saying that this is a non-violent communications project. It's bypassing Russia's crackdown on the news.
[00:38:02] They're sensitive. They're censorship of the news. And by the way, the domain 1920 dot. Refers to Poland's surprise victory against Russian forces just after world war one and the Bolshevik Menshevik revolution. You might remember all that stuff, that you studied all those years ago. So it's interesting.
[00:38:23] We'll see what happens. But this hacking group also claimed that they were attacked probably again by Russian hackers, the FSB ex. Using a distributed denial of service attack shortly after launch. And they put CloudFlare in front of their domain. Now we use CloudFlare for one of our, something, not one, but some of our customers.
[00:38:50] What CloudFlare is a website that's designed to basically buffer your website when it's been served. So if all of a sudden you get a ton of legitimate request, your site's going to stay up. It's going to be able to respond to people. The other big advantage to CloudFlare is what's happening here with 1920, Diane CloudFlare goes ahead and will block some of these denial of service attack.
[00:39:19] So I think that's pretty darn cool. Many texts apparently are met with silence. Some say they've been able to converse with Russian citizens. One user who remained anonymous said they had made. The text messages they'd made using the tool really worked it says, I want the people of Russia to know the truth.
[00:39:38] The government is doing to the people of Ukraine. This is a quote from the daily dot going to pull this up too. This is a a tweet here on Twitter and. Yeah. It's from the anonymous, that hacker group, you've probably heard of them before. Cause they've done a lot of nasty stuff over the years, but he says it's been doing just absolutely amazing things for him.
[00:40:02] Let's see here. Can we hear this? Here we go. Ah, I got to unmute it. Let's see. Where is my mute? There it is. So this guy's name is Rodney. He is. D Jang, oh my dog. Get to Django my dog. And he's got a really great little testimonial there about that. It works and his tweet has had 4,300 views and it's good.
[00:40:30] Again, another way around censorship now, Twitter, of course could decide they're going to sensor and that could be a problem too, but that's also why we now have alternatives to Twitter. And some of these other sites that are out there that are doing a whole bunch of blocking really, they don't like you.
[00:40:51] And by the way, the reference to Telegraph was fascinating because they are using. In order to get around censorship. Again, many people are using it to to send information about what is really, truly happening in Ukraine. So a lot of stuff from the beginning of the war here, visit me online. Craig peterson.com.
[00:41:14] Get my newsletter and get the free up-to-date trainings.
[00:41:20] They pass the infrastructure bill, which means now it's time to figure out what is in the infrastructure bill. And we're going to talk about the technology that they decided to fund the technology. That's going to win the game because it has billions of dollars of federal money behind it.
[00:41:36] This is disappointing bully it's normal, right?
[00:41:40] It's absolutely normal because the federal government has always been one that picks winners and losers. If you're old enough, you remember, of course, VHS. Tapes right too. Do you remember beta tapes? Beta max tapes. Beta max was really quite the standard for professional production for the longest time, a better technology, frankly, a lot better than VHS.
[00:42:06] Same. Thing's true with beta, but beta lost. And of course we ended up with VHS tapes. That's an example of technologies that were backed by investors. And we've seen a lot of that. Look at what's happened with the Serono trial, again, technology backed by investors. And it turned out to not work and in quite a dramatic way, frankly.
[00:42:33] We've seen that again and again, and keep hitting my mic here and the problem that we really have, isn't so much that investors get things wrong because they. I was talking with a friend of mine. Who's has been an angel investor and part of VC partnerships for a long time. And he was saying, we're lucky if we get maybe one out of 20 times, we get.
[00:42:57] Now, these are professionals and my friend, he's a technology guy. He and I contracted together at the same time over at digital equipment corporation. And he came to me for a lot of advice about business. Now, I look back and think my gosh, the way he did it. You can have all kinds of decisions in life.
[00:43:18] Some are going to bring you closer to family. Some are going to bring you more peace and joy and happiness, and some are going to give you very gray hair that you're going to lose very quickly. And he chose the kind of the gray hair. But he was really clear about that. Cause I had said to him, what is a one-time out of 10 VCs make money.
[00:43:39] And that's when he corrected me. He said, no, it's really one out of 20, if they're lucky, because that doesn't even happen all of the time. Now think about him. He was working on the scuzzy subsystem, which is. Complicated topic, but basically the ability for a computer to be able to talk to its hard desks.
[00:43:58] Okay. Let's just keep it simple. And I was working in the kernel, which is the core of the operating system and was rewriting kernel modules and routines. To work with a few different types of features and functions. I was in very deep very complicated. He was in rather deep, rather complicated.
[00:44:19] There's always a battle by the way, between compiler people and kernel people as to who has the more complicated job, but he wasn't either. So he just a Colonel guy guess. So he went on. He started a company. He got VC angel funding and VC funding. He made a card for your computer that you could plug in that would provide not just scuzzy support, but he moved the file system out of the operating system onto the card.
[00:44:50] I that's something I had actually done a decade earlier with the network moving it out. But anyways, that's a different story entirely. So many things I've done all my life that I wish I'd been able to monetize. But anyways, w he doesn't, he's not a slacker. Let me put it that way. When it comes to technology and neither are his partners, and yet one time out of 20 and along comes the infrastructure.
[00:45:14] They call it the infrastructure, but it really bothers me to call bills things that they're not the infrastructure bill that had. What was it? About five, 6% actually going to infrastructure. It's like the Democrats under president, the last president Obama they, he had this shovel-ready jobs, which of course wasn't true.
[00:45:35] And most of the money didn't go to building infrastructure. It just got worse. It's just crazy and we're not paying attention. So I'm going to help you right now. Enough ranting and raving. The infrastructure bill contains money for some things. We'll talk about a few of them here in a minute and also has new regulations.
[00:45:56] And one of those regulations that I've been talking about on the radio this week is this requirement to put kill switches in all new cars. That is really a big deal. Now a kill switch of course, is something that will stop the engine and it'll stop the car. That's the whole idea. And there's various types that have been bantered bandied about including pulling the car over to the side of the road.
[00:46:25] If the driver stops responding as a driver might have a heart attack, or maybe they fell asleep, maybe something happened in that car should probably pull over and get out of traffic, turn on the flashers which then makes it a target. Apparently for some of these Teslas, we've seen articles about that in the new.
[00:46:44] Yeah, don't park on the side of the road. They, I was in emergency medical for a long time. And one of the things I can pass along to that may save your life is if you have to pull over, do not stay in the car, do not stand in front of the. And particularly in the evening or at night because the flashing lights and the car at the side of the road is a beacon for drunk drivers to come and hit you as well as some of these autonomous vehicles, apparently just get out of the car.
[00:47:16] Behind the car off the road. Okay. Go off the road behind the car, not next to the car off the road, not in front of the car, off the road, behind the car. So if it does get hit, you are less likely to suffer severe damage yourself, but this kills switch. That's part of this bill that was passed in sign, of course, a hidden part requires all manufacturers to include the ability.
[00:47:44] For police departments and potentially others. And this is where some of the problem comes in to be able to stop the. Now you might remember back in 98, there's a Saifai series called the X-Files. It was very cool series. And there's an episode called kill switch about an artificial intelligence gone wild.
[00:48:07] And that, that is of course a while ago back when most people were still using dial up modem. But this was a tale of technology, run a muck, and it was warning about handing too much of your life over to technology. Oh, that's one thing. But in this case, isn't it safer, right? Because somebody is whipping through neighborhoods at 80 miles an hour in their car, trying to avoid police.
[00:48:37] Shouldn't have, please be able to stop that car and pull it. The problem is multifold frankly, and having this kill switch one is what constitutes law abiding. There's a great article in motorists.com and it shows a picture of this down in New Zealand. Our car was pulled over. And the police found the trunk was full of contraband.
[00:49:02] Now we've seen this before, right? And movies, Miami vice and others, where they pull over the car. It's got all this contraband in the trunk. It's cocaine and various other things. No. This isn't Auckland New Zealand and the trunk was full of Kentucky fried chicken meat. They were running Kentucky fried chicken, just like the Kennedys, running illegal booze back in the day. Yeah. That's how they made their millions. They were running Kentucky fried chicken. Now this bill that was signed into law by president Biden states that this kills switch, which uses referred to as a safety device, must passively monitor the performance of a driver of a motor vehicle to accurately identify whether that driver may be impaired.
[00:49:54] In other words, big brother will be constantly monitoring how you drive. If you do something that the system has been programmed to recognize as driver impairment or unsafe driving your car could just shut off, which could be incredibly dangerous. I want to point out this week too. There's another article I read about Teslas and how Tesla had introduced last fall, a feature.
[00:50:23] So you could set how the car was going to drive. Do you want to drive? Real cool, laid back fashion. Do you want the car to drive an average way or do you want it to be aggressive? Just weave in and out of traffic a bit and tailgate and do all of those sorts of things and you could set it and there is a public backlash and Tesla got rid of it.
[00:50:42] It is back now. How do you tell if a driver's being unsafe? When a car in its autonomous mode will do the same things that a human drivers shouldn't be doing? Or what if you're hauling contraband, Kentucky fried chicken? How is the driving going to be measured as impaired? Now I know in many states you have these breathalyzers that are court ordered, installed in cars.
[00:51:13] Okay, so that makes sense. Somebody has been drunk driving many times. You don't want them drunk driving ever again, please. And thank you. But how about having that system in every car? Because it fails. It doesn't work sometimes. And how about the back door? Because that's essentially what we're talking about.
[00:51:34] These cars are going to have a back door that allows someone named government authorities to access it whenever they want. Would they need a warrant to do it? Probably not. Even as hackers could access the back door and shut down your vehicle, think about lad having a kill switch that would kill all of the cars and trucks in the United States.
[00:52:02] Right? There are so many potential problems here and they haven't been thought about. Oh, obviously it's government, but we're going to talk or we'd get back about the investment that are part of this multi-trillion dollar bill that you and your kids and grandkids are paying for.
[00:52:23] We know they snuck a backdoor kill, switch into all cars manufactured after 2026 into this infrastructure belt. What else is in there? That's going to affect technology. That's what we're going to talk about right now.
[00:52:38] We know about this now. After it passed, finally, people had a chance to read it because this provision on the kill switch was not debated in the house.
[00:52:50] It was not debated in this. Just like they've been doing was so many other things for so long now they just bundle them all together in a bill. They gave it a cute little cuddly title, and then they go ahead and put whatever it is they want into it. These are these omnibus bills that they should have gotten rid of decades ago.
[00:53:16] It is absolutely crazy to me. I just. Get it. Why are we putting up with this? So now the next step here is the investments that are being made. Now I'm going to type in right now, how successful are angel investments? Okay. So here we go. Bunch of ads for angel investing says you can have an average return of 1.1 X cap.
[00:53:48] All right. And it goes on and on. This is a company called core associates. The success rate of angel investors. This is from Investopedia, the effective internal rate out return for a successful portfolio for angel investors is approximately 22%. Now, remember that over. So that's pretty amazing. Those numbers are much higher than what my friends said that they can expect absolutely much, much.
[00:54:19] But I can tell you one thing for sure. Government quote, investments, end quote, rarely ever actually pay out because you've got political motivations in there. It's one thing to be a smart technology guy investing in technology. But how about those people in Congress? That aren't smart technology guys.
[00:54:44] How about the doctors in Congress? Look at what Senator Paul ran. Paul has been saying he is a doctor and what he's been saying about the whole COVID thing and the way the government has handled it. We are really going down the wrong road to here because government. Taking the money from us at the point of a gun.
[00:55:06] Try not paying your taxes and see what happens rarely ends up. Okay. So the us Congress passed November six. Biden's trillion. Plus infrastructure bill that includes 65 billion of investments in the power grid to accommodate rising, renewable energy capacity and demonstration clean tech project. So what's that one about?
[00:55:32] That particular one is because our grid cannot handle solar and also the windmill power. The rates, we would need to have it, our grid set up so that you have a few centralized power stations, and then that power is distributed to the area. It's not set up for having tens of thousands of power stations.
[00:55:56] So there you go, president Biden, put money into try and figure out well, Hey, how do we accomplish? How do we accommodate them? Noma, Germany has done. Is they've gone ahead and they're using a massive lake as a heat sink to get rid of the extra electricity that's being generated. When it comes to a regular power plant, you can turn it up.
[00:56:21] You can turn it down the same. Thing's true for every type of power plant, whether it's powered by water or nuclear or cold, you can turn it up. But when it comes to wind and solar you can't turn it down. If it's a nice sunny day, you're not going to be able to turn that power down. It's still coming out.
[00:56:40] You got to do something with it. You can cut it. Open the circuit. But the power companies that run the grid don't have that kind of fine grain control over the electricity that you're generating in your house or in your business. There's so many problems that start to open up here. So they're spending $65 billion.
[00:57:02] That is a lot of money to figure this out. Okay. Personally, I'd rather see the private sector do it because they're going to have a better chance of coming up with something that's really going to work next part here. Okay. And by the way, Colin it or trillion dollar plus is being favorable because they played all kinds of gimmicks with this money.
[00:57:25] Just, I just found out. In fact, I think it was a couple of weeks ago, June. Do you remember. President Biden moved all of the college loans from private sources into the white house. Do you remember that? So the white house is controlling all college loans at the time I thought, okay, it's just them paying back the unions, the teachers unions, right?
[00:57:49] Because it also included provisions that you cannot have be bankrupt and get rid of your college. Th that's just mind boggling to me, but as it turns out what he was doing. Okay. All of that's true. But what he was actually doing is saying, oh, there's over a trillion dollars in college loans. So we're going to move them into the white house and call those assets to offset all of the money we're spending.
[00:58:19] You see what we're talking about here? It's just not. Electric vehicles, clean energy, public transit are all part of this trillion dollar plus legislation. It's got $550 billion, a half, a trillion dollars to fund advancements in public transit, clean energy electric vehicles, roads, and bridges. Okay. It's always electric.
[00:58:48] Really? The right winner here is electric. The beta max that should have won out over VHS. How about hydrogen? How about some other way? How about natural gas or LP gas? What we'll never know because some of that is not going to get funding. However, there is going to be some funding. For nuclear development?
[00:59:12] No, I've talked a lot about this on the radio before, but the bottom line is nuclear is the only green energy that we can really get. And I can hear some people saying, oh, you're not sure not to know. Look at the current generations of nuclear power. Now, unfortunately, the regulations around nuclear power were written what, 70, 60 years ago, right?
[00:59:38] When nuclear power was nasty stuff, it came out of the projects that we had in world war II to build nuclear bomb. Now these six generation nuclear power plants are as clean as can be. They only need to be refueled every 10 to 20 years, and they're small enough to fit into a small building smaller than your average home.
[01:00:02] And you can put one of these in the neighborhood in a small town, and that will power the whole. Thing. Okay. So we're already getting 27%, according to president Biden of our power from these decades, old nuclear and hydro power facilities, they've got 21 and a half billion dollars in this for clean energy demonstrations and research hubs focused on next generation technologies, helping to get us to that net zero by 2050 that they're looking at.
[01:00:35] To get to, so this will be interesting because there they've got 8 billion earmarked for hydrogen and carbon capture. Guess what's going to get more, yeah. Carbon capture, direct air capture, and we don't know what's going to happen with this. We're turning cow, carbon into stone, basically with some of these plans and experiments are underway.
[01:00:56] So what happened. When we need that carbon again. But 8 billion is earmarked for hydrogen and carbon capture direct capture, 10 billion, two and a half billion earmarked for advanced nuclear. So I'm happy with that. Not that they're spending the money, not at all, but that they're actually putting it into something that might make a difference.
[01:01:22] And hydrogen funding in this, by the way, it looks like it's a big win for oil and the whole oil industry stick around.
[01:01:31] You've heard of this shortage of Silicon, of semiconductors CPU's et cetera. I don't know if you tried to buy a computer lately, order a computer, et cetera, but there is another part of the computer that's really hard to get. And that's what we're going to talk about.
[01:01:56] CPU is the central processing unit in your computer.
[01:02:01] And that nowadays might actually not just be on a chip by itself, back in the day. I'm thinking about the, some of the first microchips microcomputers I worked with such as the 65 0 2, that original. Apple chip that they use great little chip, by the way, he was just so clever how they got around some of the problems eight-bit problems or the day that computer with its CPU was a standalone CPU.
[01:02:30] That in other words, the CPU only did CPU thinks, it went out and grabbed stuff from memory and then did the computing and then. Push the results back to memory. Just simplifying it there today. You look at a CPU like what apple is putting into their iPhones and the iPads, and particularly their desktops with , the M family, really whole family of chips.
[01:02:56] It is no longer just a CPU on that chip. That chip has all of them. It has, of course, all of the memory controllers on it, the processors, it has low power processors. It has high power processors and it has GPU's that's what I want to talk about right now are the GPU's cause in the apple case, you. One of these M series computers and your stuck with what you buy, which is why you should always be buying the biggest, best just computer you can so that it will last you longer.
[01:03:32] And I'm not talking about the fact of that study that said your average laptop, nowadays windows, laptop is going to last about seven months. I'm talking about the it's going to last, not because it breaks down or doesn't break down, but it's going to last because it has enough memory to handle future operating systems, et cetera.
[01:03:53] Now we've got a problem today with TPMS. These are trusted platform modules and apple has actually been using something very similar to that for a long time. TPMS are in the window's case, very simplistic and don't actually provide very much security. They're basically going to help prevent someone putting some malicious code into the boot blocks on your computer.
[01:04:23] So it's going to do some good, but it's not going to do a lot of good and windows. Now, Microsoft is requiring pretty much TPMS for windows either. Across the board. Now there's some ways around it sometimes depending on what you're doing, how you're doing it, but as a whole, yeah. You gotta have that TPM in order for things to work for you and even installed windows 11.
[01:04:50] That's a good step, frankly that they made apple is many steps ahead of Microsoft in this case, mainly because they can make their own hardware. Microsoft can't. So when you buy a Microsoft computer inside, it's going to have what we're still calling a CPU, but it's much more than that.
[01:05:11] Nowadays their CPU might be from Intel. It might be from AMD. Those are the two most likely Microsoft with their surface tablets does support similar chips to what apple is making. So you don't have to use an Intel type of chip in order to run windows anymore, depending on the hardware you're using.
[01:05:32] But as part of these chips, you have to move graphics around. So the modern chips, like the Intel chips and AMD chips have some GPU capabilities built into. But in most cases, you're going to add a GPU card to your machine. So what is this GPU? What are we talking about here? A GPU is a really interesting piece of hardware because it is designed specifically to move.
[01:06:05] Bits of information around very efficiently versus a CPU, which is designed to do mathematics on words of data. So in other words, 64 bits at a time. So if you're moving stuff around the memory buses on the CPU, et cetera, are optimized for maybe 128 bits of data all at once. So why would you want something that only handles.
[01:06:33] A bit at a time. Of course it can do more than that, but we're keeping things simple. You want that because it's efficient at it. And if you think about the graphics processing unit, as the thing that handles the graphics, and you look at a screen, that screen is composed of most likely millions of dots, even on our little smartphone device.
[01:06:55] Millions of dots. And so you've got to flip those dots around. Sometimes you need to move them as something most, or the most efficient way. For instance, to show a video is not to update that whole screen, because if you look at a screen with video, most of that screen, isn't moving nothing. Tap. What you want to update is just the parts that are moving and that's where compression comes into place.
[01:07:21] And also where decompression comes into play. So all of this stuff that is part of moving things around on your screen, even if you're dragging a window around on your display, that is most optimally handled by the graphics processing unit, the. So Apple's putting their memory on chip. It's putting the GPU's, CPU's the high power, low power.
[01:07:45] CPU's everything it can. And then all the memory management and stuff on one chip. And that gives some huge advantages because when you're talking about the speeds that we're using today the less space that electrons have to travel the faster it will be. I know you think about that for a minute, right?
[01:08:03] You turn on a light switch and lights are on instantly. In reality, it takes a little bit because the electrons have to, first of all, get to the light and then they have to somehow excite something in the light in order to make the light. But electrons, distance traveled matters in. So why are we having such a huge shortage of GPU's while it has to do with their ability to mine, crypto current?
[01:08:34] Now the best way to mine. Cryptocurrency is using specially made and designed hardware that is designed for that one particular cryptocurrency. So it makes sense to you. That's the best way to do. But in most cases you don't have that specially designed hardware. And in many cases, that hardware is only really viable for a few months, but people are still buying GPU specifically to mine, cryptocurrencies, by the way.
[01:09:09] It's usually cheaper to buy cryptocurrencies and to mine them because the average electric bill in the United States makes it so that it is impossible to mine. These cryptocurrencies like Bitcoin effectively enough. So the electricity is cheaper than the pit coins worth. So think about that. If a Bitcoin is worth $50,000, Frank.
[01:09:34] The electricity to mine. Another Bitcoin is more than likely going to cost you more than 50 grand and take a long time. So people are still buying GPU's these high-end GPU's, they're using them to build machines that have a bunch of these cards in them. And that is causing shortages for you and me who might want to make videos efficiently or who might want to do just.
[01:10:01] Computing and buy a high-end computer. So it's good for you for the next five to 10 years. Oh, and Radian, who makes some of these high-end GPU's just came out with one that is specifically designed to be bad at mining cryptocurrency. So who knows? Maybe there is a little bit of hope here. You can visit me online.
[01:10:23] I'd appreciate it. If you would, Craig peterson.com, you'll find all kinds of great information there. And if you sign up, I'm going to send you absolutely free. My three most popular, special reports, including. The one-on passwords, Craig peterson.com. Visit me online and stick around because we'll be right back.
[01:10:49] There are a lot of programs claiming that they are secure. That's what we're going to talk about right now for secure communications. What about telegram? What about signal? What about WhatsApp and WhatsApp? You remember started 20, 21 with a real blackout.
[01:11:05] Signal is probably the best software that you can use the best app. They've got a desktop version as well in order to keep your communications safe. And that's what you want to do. You don't want. People listening in. You don't want people spying on you. You just want to have a conversation.
[01:11:27] And there's many things that you'd say in a private conversation that you would not say, if you were sitting here on the radio or standing on the top of a building with a thousand people below you, private conversations are meant to be. What signal is doing to play with fire is they are talking about trying to pull in cryptocurrency payments into part of signals, platinum.
[01:11:55] It all started with something called mobile calling and signals CEO. And his name is mark C Marlin spike. We've talked to him about him a few times, but he was an advisor to the mobile coin, current cryptocurrency. And it's been built on this stellar blockchains designed to use a view, be used to make anonymous payments that are basically the same mistakes.
[01:12:20] So it's designed to hide everything from ha from every one. That's the whole idea behind mobile coin. So the problem is if you start to integrate advertising systems into supposedly secure communication channels, what's going to have. If you start to take things like a cryptocurrency and put it into a secure communications channel, then what's going to happen.
[01:12:48] You can bet that what's going to happen is governments are going to step in saying, Hey, wait a minute. Now you can have money flowing. I remember buying a car. And this was back in I think the early eighties and I went to the bank and I got a loan from the bank in order to buy the car. And they gave me eight, $1,000 bills.
[01:13:11] Cause I was going down to the auction car auction and I was going to buy a car and I set myself an $8,000. So the idea was like buy the car and I come back, I pay them back the difference, and then they write the rest stop as alone, man. Weren't those the days, right? When a banker knew you, the banker made decisions on things like an $8,000 loan, I don't know.
[01:13:37] What would that be worth in today's money? 10,020 probably goes to the $15,000 just based on my word. And I walked out of there with thousand dollar bills and. I also had $500 bills. And back then, you used them to pay bills and of course they're worth more today than they were then. Let me put it the other way is actually worth less, right?
[01:14:03] Because of the, in crazy amounts of inflation that we've had. But the bottom line is you could have. Get thousand dollar bills and put eight of them in your pocket. So it doesn't look like you're walking around with a huge water cash that someone's going to steal from you. And then the government decided that, oh my gosh, that's terrible.
[01:14:25] Oh no. Wow. Drug dealers might be using those thousand dollar bills. Oh, yeah, this is true. They might be using them and we all want to start off, stop the sale of illegal illicit drugs. That makes sense. But the war on drugs, we're not going to get into that has been an abject failure and it has resulted in things like the fiscal or w you're not even charged criminally or civilly, and they seize the money.
[01:14:55] You. So they got rid of thousand dollar bills because of course they were only used by drug dealers and people like me, they got rid of $500 bills because of course it was still the drug dealers. And to me who were using them now, the biggest denomination that you can get is a hundred dollar bill.
[01:15:14] Although the treasury is talking about making minting a 1000, excuse me. $1 trillion coin that they would use in order to make payments, right? Yeah. So that, that balances their budget. Cause yeah, they just printed a trillion dollar coin. Anyhow. The problem is that the government wants its fingers in every transaction, whether or not there are drug dealers involved and that is causing us nothing but headaches and heartaches, frankly, it's a real.
[01:15:49] Problem. So when you get Marlin spike, tallying people, that signal is going to include a cryptocurrency called mobile calling that is designed to be absolutely private. That's when they government starts freaking. China already has a cryptocurrency. In fact, they've been trying to peddle their cryptocurrency for use by governments around the world to trade for oil.
[01:16:21] Remember the United States time was when our currency was supposed to be the standard. Remember that the standard for. Doing transactions worldwide crypto type transactions is where China wants to delete it. And what they're trying to do when they lead it over there is get the U S dollar out of the way.
[01:16:43] He can't say as I blame them lately, but they have been testing it already here. This coin, mobile coin cryptocurrency. What do you do now, if you're trying to have a private conversation, I started out by mentioning telegram, WhatsApp and signal. Now we just talked about the biggest problem with signal right now.
[01:17:06] We'll talk about it. Security in just a minute. Let's talk about WhatsApp. WhatsApp's biggest problem is that it was bought by Facebook. Should they have been allowed to buy them? It depends on how much of a free market person you are, should the government have stepped in and said, no, you can't do that because frankly, WhatsApp was a competitor to Facebook and Facebook just bought them because they have so much cash.
[01:17:28] So WhatsApp's problem is Facebook. And remember last year, January, 2021, I think it was. Facebook said from now on, we are going to be inserting ads into your WhatsApp communications. Yeah. That kind of got people a little upset for very good reason. How about telegram? Telegram is not secure. It has never been secure.
[01:17:55] And a lot of people switched over to telegram because of what happened with WhatsApp and Facebook saying we are going to be putting ads into your WhatsApp channel. So tens of millions of users switched to Della gram. Yeah, it was a nightmare for WhatsApp last year, but frankly, the, it changed. WhatsApp changed Facebook backed off because some people were upset, but they're ultimately going to go that direction.
[01:18:26] That's who Facebook is, they make their money off of us. Now signal is even more secure than WhatsApp. Telegram is not secure at all. Okay. So forget about it. Don't use telegram. They've got this cloud-based architecture. That's truly, it's a serious risk when compared to end default encryption, that's used by signal.
[01:18:48] Why? So right off telegram, if you want a secure private conversation, but one tap and signal both have end to end default encryption. So why would I say that signal is more secure than WhatsApp? The bottom line is that WhatsApp keeps some of your data in. Okay. And that's where the problem really comes in with signal.
[01:19:17] Everything is encrypted. Everything is obfuscated. Okay. Telegram, you can delete messages, chats, call histories, groups, any time that you create them in afterwards deleted items, completely disappear for all participants without our trace. There, there's just all kinds of problems, but now I'm concerned about signal.
[01:19:36] That signal has been doing a lot of stuff in order to keep the bad guys and snoops out of their streams. And that includes even putting in codes that are known to crash some of the devices, the criminals and law enforcement, even you. Build it right into signal, which I thought was just hilarious because there's this tool that I'm referring to terminate Israeli company is using some open source software that they have not patched in years solely.
[01:20:10] It's it's absolutely fun. So keep all of that in mind. In reality signal is. Everything it possibly can to keep your data safe. I am concerned about the fact that they're going after this coin mobile thing, trying to integrate it. I can see why they'd try and do that. Facebook has released its own cryptocurrency last year.
[01:20:36] I didn't really go anywhere. They've relabeled it a couple of times, and Facebook wants to become your payment centers as well. So you can use Facebook messages in order to send money and potentially use WhatsApp as well. Apple, by the way, is using encryption end to end for I message. But there is some concern about iron message particularly lately because apple has been using its own backdoor keys for some of the data that you store.
[01:21:10] And I'm a little unclear as to how I message fits into that whole. But WhatsApp is free. Signal is free. Telegram is free, but it's becoming clear the price you need to pay for it because Facebook basically broke WhatsApp. And because of that radical change and you can consider it to come out further.
[01:21:36] And we know that Telegraph is just not there and hopefully signal's going to smarten up here and not try and get the re federal regulators involved because of monetary transactions. Although, technically it's not money, right? It's a cryptocurrency. Should you stop using WhatsApp? The short answer's probably, no, I do use it with one of my mastermind groups.
[01:22:01] Nothing's really changed after the pushback from people who've been using it. That's the short app answer, but your signal whenever you can, it just makes. Hey, thanks for joining me today. Spend a little time over your weekend and I'd invite you to also go online. Go to Craig peterson.com. Make sure you sign up for the newsletter.
[01:22:24] I've got a special report on passwords this week.
What Can Be done About Russia?What Can You Do?
There is a whole bunch going on when it comes to Russia, of course, the invasion of Ukraine. Why are people calling to have dot RU deleted?
This is really a big deal. And if you're watching from home, I'm going to go full screen on this article.
[Automated transcript follows.]
[00:00:23] This is an article from ARS Technica, and I've been talking about it all week, which is that I can won't revoke Russian in Jeanette domains, says the effect. Devastating. This is frankly pretty darn fascinating to me because I can, as this international organization, it was put together in order to help make the internet international.
[00:00:49] And I'm not talking about the data international, but control of it. A lot of countries work. Because of course the internet was created in nodded states. It was created by us tax payers, money for the DOD. And it was designed to be very resilient, in fact, so resilient that there could be a nuclear blast and that nuclear blast and.
[00:01:13] Causing problems, but yeah. Yeah, the internet is still going to work. And the whole idea behind it was you could have multiple routers. They're all talking to each other nowadays. They're talking BGP four and they can say, how can I get from here? To there. And so the idea behind BGP is they all share this information once the least cost way.
[00:01:36] What's the easiest way to post way. If you will, for me to get from point a to point B and it changes all the time. So you might be on a phone conversation. You might be listening to me right now, online streaming or watching the video you might be doing, who knows what out there with digital communications.
[00:01:57] But the communications channel that you think you're using, where the data is going from, let's say my microphone, ultimately to your device, your ears, that data path, once it becomes dated. Can be changing multiple times a second. Now it actually changes quite a bit. Initially as these internet backbone routers, send the least cost, routing information back and forth to, and fro a very good thing, frankly, because it helps to speed everything up.
[00:02:28] And there's other tricks that we're using you. Might've seen. For instance, Akamai and some of the URLs before have sites that you've gone to, and that's called a content delivery network and that helps get the content to be closer to you. So if you're on a website in California and you're in New Hampshire, that website video, that website graphic, et cetera, is going to be coming from a server local to me here in New Hampshire.
[00:02:59] All right. That's how that all is supposed to work. So we have names you guys know about that internet, domain names and those domain names. You already know those are turned into internet addresses, and those addresses are then used by the routers to figure out where to go, how to get the data. The problem that we're having right now, of course, is Russia seems to be substantially abusing the intranet Putin, put a kill switch on to the Russian internet sometime ago.
[00:03:31] And the idea behind the skills, which was, Hey, listen, if we don't want the world to be talking to us, we'll just cut it. Now he's tested it a couple of times, but what he has not done is shut it down and he hasn't shut it down. As part of this Ukraine, more, what they did is they passed laws saying, Hey, if you publish something that disagrees with what we're saying, you get 15 years.
[00:03:59] And even these people who've been protesting on the streets, they're getting a bound 60 days, 30 to 60 days in jail, just for protesting what's going on. So a lot of people have been saying why don't we just, we turn off the Russian internet now we're not going to use Putin's kill switch in order to shut it all off.
[00:04:19] We're not going to do a well, a few things. She decided not to do, denial of service attacks, et cetera. Although there are hackers doing that and we are going to talk about that today, but they're saying what? Let's just go ahead and let's kill their dot R E. The country domain. And I can, the guy who heads it up said, Hey, listen our mission is just to make sure that the internet works.
[00:04:46] So shutting off the dot R U domain so that no one can go ahead and. We send right. A request out to the domain name servers and get a resolution to an IP address. So if you try and go to Kremlin dot REU or something, you will get blocked and you will get blocked. Not blocked. No, I like the great firewall of China or of Russia.
[00:05:10] Now they've got one going pretty good. Yeah. Thank you. You ain't using us technology. It's crazy. What we've got. But what it does is it says, oh, I hide dot, are you, I don't know. What are you talking about? So there have been a lot of people who have been pushing for it. And you'll see on my screen here that you cranes requested to cut Russia off from some of these core parts of the internet.
[00:05:35] And I can, which is the internet corporation for assigned names and numbers. I couldn't remember what that was earlier said that I can must remain neutral and their mission they say is not to take punitive actions. It's to make sure the internet works. So are they really taking punitive actions of the cat Russia off?
[00:05:56] It's really interesting to me because look at what has been going on. You've got companies like Facebook as the great example who has gone ahead and just shut off people. They didn't like what they were saying. My goodness. At one point of you said you should wear a mask during this pandemic.
[00:06:15] You would be cut off from Facebook. And then of course, if you said, no, you don't, you shouldn't don't need you, you shouldn't wear a mask that at that point you would be cut off, because science right. Sciences, we know exactly what we're doing now. It goes on and on. If you said that it came from a lab in China, you would have your account suspended.
[00:06:35] Now of course their whole tune has changed and yeah probably came from a lab in China. It's crazy what these people have been doing. So we have arbiters of truth, who are some contractors sitting in their home or wherever it is the contractors for Facebook that are going through posts that people are flagging as Incorrect as fake news.
[00:07:02] So what happens is people say fake news and then that goes off to their team that then looks at it and says okay. Yeah, fake news because we disagree with it. It just blows my mind. We have to have free and fair and open discussions. Don't we. You have that line at Facebook and Google does some of the same.
[00:07:22] A lot of these sites do a lot of the same. You get our major media outlets that are all deciding what they want to report on and what they want to label as fake and fake news. I'm just shaking my head because it's hard. It's hard to believe. What about. Russia is putting out fake news, as I've said many times before the E the first casualty in war, this isn't my quote. The first casualty in war is what, it's the truth. So if truth is the first casualty, then that means we've got a lot of propaganda going on. We had propaganda coming out of Ukraine. We've caught some of those, like the, what was it? The. Chat goes, fighter, pilot, whatever it was who had killed, what was it?
[00:08:12] Five Soviet or Russian jets, Soviet era using silver deer, techno era technology on the part of the Ukrainians turns out well. Okay, that, that was false news. That was fake news. The whole thing about snake island, where you had that Russian military. I know what it was a frigging but anyways boat sitting there saying we are a Russia.
[00:08:33] Warship, you will surrender or, whatever. Do you remember that snake on just the small place, 13 guys and supposedly they shelled it and they killed all 13 turns out that was probably fake news as well. So that's from the Ukrainian side and on the Russian side they hardly reported I as to how many.
[00:08:57] The we're in fact, initially for quite a while, they were saying there are no desks. Then at the same time, the Ukrainians are saying they're 2,500 Russians dead. And that number keeps going up, who knows what it is today. It gets really crazy in the time of war. So if Facebook is going to stop someone from saying don't wear masks or do wear masks, depending on what day of the week it is basically right.
[00:09:20] Wednesday. It's okay to say that Thursday is not okay to say that we're back. No it's not. Or then why can't that type of censorship? Move on to the next. I that's a big question I have now. Should we be shutting it off? I'll pull this back up on the screen again. And it, this article from ARS, Technica is saying that experts have warned, whoever they are that shutting down the dot R U domain.
[00:09:53] Is going to cause just incredible problems for Russians, which man would it ever talking about a major blow to the economy. And it would also cause problems for people who are trying to find out more truth about. Russia cause you couldn't get to their site. Now we've seen some amazing things in Russia.
[00:10:15] We had the Russian, one of the Russian news agencies are T which is broadcasting and here in the U S that their entire staff just walked out saying, forget about it. We're not going to promote this fake news, but this is a little to do trip question me personally. I don't think anybody should be censoring any.
[00:10:38] For almost anything. Yo, there are some limits, but they're pretty extreme in my book. I'd rather know someone is an idiot because they're allowed to say stupid things, and counter, counter it, counter their arguments. You've got to have discussions
[00:10:54] Microsoft. Yeah, they've been around a long time. They've been helping us. They've had lots of cybersecurity problems. People use Microsoft software on their desktop. Some people use it for servers, which is crazy, but listen to what they're doing now.
[00:11:10] This is a little concerning. I'm going to pull this article up on the screen.
[00:11:15] For those of you who are watching a long, either on rumble or YouTube ARS, Technica article, they have some really great articles. This particular one is about our friends at Microsoft. This is cool. Microsoft announced today? This was like a week or so ago that Microsoft would be suspending all new sales of Microsoft products and services in Russia.
[00:11:45] Following the countries, unjustified, unprovoked, and unlawful invasion of. Now Microsoft didn't give any specifics about the products, but it really is likely to be a blanket ban of all of the Microsoft products. This is very cool because Microsoft has taken an approach I've never seen them do before, which is okay.
[00:12:10] When. Gets hacked. You get our friends at apple, putting together patches and getting them out. They get them up pretty quick. Microsoft had been doing much the same. The problem was some months there were patches every day that you had to apply. That's how bad this software is. And they decided that man, let's be like politicians here.
[00:12:34] Let's release some very damning news Friday. At about 4:30 PM before a long weekend. So no one will notice. Yeah. Y'all are friends of politicians do that all the time. What Microsoft decided they do is, Hey, wait a minute. We're going to have patches. It's not going to slow down. And because our code is terrible.
[00:12:56] So what we're going to do, let me see here. How about we just release all of them at once and we'll just call it patch Tuesday, right? Because people were complaining about how much work it was, how much effort was effort. It was to try. They hate them. These machines apply these patches every day. Huge problem for everybody from home users to big companies out there.
[00:13:21] So Microsoft has said, okay let's do that. Let's burry it. So nobody will notice okay that's what Microsoft does. And now we've gotten used to that. Now we have. We remember two guys, right? Bill gates followed by Steve Ballmer. Steve Ballmer was a nut job. Bill gates was a bad man.
[00:13:40] I think he's just been trying extra hard to compensate for all of the evil he did over the years. But what we're looking at now is new management and that he's been in there now for a few years, doing a great job, cleaning up Microsoft, making it a very competitive company. He has done some amazing things.
[00:14:02] One of the things that he has decided to do, that's been very effective is how about this? How about we go ahead. And we work with various governments to help stop these Russian hackers. And I mentioned this a couple of weeks ago, what was happening and the Microsoft had reached out to the white house and said, Hey, listen.
[00:14:27] What we have been looking at the hacks that have been coming from the Russian hackers, and we've been preparing fixes for some of those hacks. How about we work directly with some of these other countries? This reminds me a whole lot of the lend lease program in world war two. You might remember this thing, but the us of course, initially was not involved in the war and they decided, okay we've got to help the United Kingdom.
[00:15:00] How are we going to help them? The UK doesn't have the money to buy ships, to have us make weapons, bullets know. What they did is they had people donate the rifles, the guns, AML from home. Plus they made them the government, instead of selling them to the UK, they lent them to the UK because the UK could not afford everything that it needed in order to fight a war against the national socialist in Germany.
[00:15:28] So what did they do? We just shipped the stuff over there and called it a lend slash lease. I think that's a great idea. And what Microsoft is doing is also great idea. They have been decoding, reverse compiling, if you will, and interpreting the code, looking at what some of the ransomware and other malicious code the Russia has been using against Ukraine, and they have been providing.
[00:15:57] All kinds of insight information to these other countries. Now, this is a great idea for a few reasons, one of the reasons, and I think maybe the biggest reason is that the ransomware, the viruses, all of this malware that they're producing is. Not particularly discriminating. Do you guys remember maybe I dunno, what was it?
[00:16:22] Six months ago, I taught, told you how to avoid getting most of this Russian ransomware. And it was as easy as just installing. Yeah, installing a keyboard on your computer windows or Mac, windows. Those are the machines are always getting attacked quite successfully most of the time, but the windows keyboard.
[00:16:49] Russian language. Now you didn't even have to use it. You don't have to have a keyboard, right? This isn't a Russian keyboard that I'm holding up here on camera. This is just a regular us keyboard. You can just install a virtual, Russian keyboard. And once that keyboard was installed, you're pretty safe.
[00:17:06] Why? Because Vladimir poop. Dictator for life of Russia decided he would just go ahead and stop anybody that was trying to hack Russian. Companies businesses, government agencies and what's the best way for the hackers to do that. Cause they didn't want to end up in Siberia for the rest of their lives because of a hack.
[00:17:29] Now they went ahead and said, okay if there's a Russian Cyrillic keyboard on the machine, we're not going to activate. So if the software, the malware on your computer, all you need to do is have a Russian keyboard. Yeah, that's it pretty simple. I told you that months ago, now what we're seeing is these indiscriminant types of software that are being used in Ukraine.
[00:17:57] Why doesn't the keyboard trick work while some of Ukrainians peak Russian, we could go in. To the background on that of the massacre, the starvation purposeful starvation of Ukrainians by the Soviet union over many years ago. And how they then gave their property, their homes to Russians to move into in order to occupy Ukraine.
[00:18:23] So there's people in Ukraine who are Russian speaking of course. Now we're talking two or three generations, four, maybe down the road from when the Soviet union killed all of those millions of people. But there are some fights that to say, there's Russians, Russian speaking people there. Let me put it that way.
[00:18:41] Perfect. In Southeastern Ukraine anyways I'm going on and on I, this is not an education on war or history. This we're talking about cyber security. So the, they have, they been, Microsoft found many cases of Russians putting destructive. And disruptive or even more than that data wiping malware onto computers, it spreads indiscriminately.
[00:19:13] So Microsoft looking at what's happening, you crane, trying to get patches together for all of us, letting other countries know about what's going on is going to be. Amazing because this malware, which is wiping computers, primarily, it's not really just straight up ransomware give us money and we'll give you your data back.
[00:19:35] This is just showing your data, that malware is going to leak outside of Ukraine. Yeah. Cause us all kinds of book tension, probably. When we get back, I want to talk about this here. This is our friend Ilan Musk, and we've been following along with some of the stuff been going on with his new satellite system in Ukraine.
[00:19:58] The whole concept of these satellites and circling the earth, providing us with internet, just regular guides. It's going to be in our smartphones is changing everything. We're going to talk about Elon Musk and what's happened over in Ukraine.
[00:20:15] Our friend Elon Musk has done a lot of things over the years. He has really helped us for frankly, the Tesla and what's been happening there.
[00:20:26] Space sex, his main concern being let's get. Off of a single planet on to multiple planets, right? The movement to Mars, NASA's working on a serious moon base. I reminded him of space 1999. You guys remember that show, but yeah, we're going to have a moon base by then and it makes a lot of sense. So who's going to go to these well, there's some interesting lotteries people have to apply and everything else, but he's done so much, right?
[00:21:00] He's got the boring company you'd already know about Tesla and boring company in case you didn't know makes underground tunnels. He has also. A few other things has got a huge battery manufacturing facility. They're working on new battery technologies to make all of our lives a little bit better, particularly if we have an electric house or electric car, because this is what good is it to have electricity that you can't use.
[00:21:25] And that's really what they're trying to do is make it so that electricity is available 24 7 for you. And. Those space X, which is what I mentioned as well as what we're going to talk about right now. I'm going to pull this up on my screen. For those of you who are watching over on rumble, or of course, YouTube, this is fascinating.
[00:21:49] He said there's a high probability of Russian attacks on Starlink in Ukraine. Now that is fascinating because what he's done is he has sent over truckloads. I'm showing a picture of a truck. In fact, with these Starling terminals in it, that's from ARS Technica. Just double-checking it here, but this is very cool.
[00:22:12] This is posted by the vice prime minister over there in Ukraine. And they are talking about these terminals. Now a terminal in this case is something that allows your devices to talk to the Starlink satellites, or there's going to be a huge constellation. They've got 2000 satellites up and they're putting another 12,000.
[00:22:38] These types of satellites are much different than what we've been used to over the years. We typically we've had these massive things sitting up in space. I worked with RCA Astro space many years ago and I saw. They're testing facilities, which are just incredible. They had this huge vacuum chamber that they brought me in to see as we were working on space shuttle software.
[00:23:05] Yeah. I wrote software that they used to put the space shuttle together yeah. Way back in the day. So that was a pretty proud moment. Anyways. It's we're not talking about these huge satellites, like they used to launch, we're talking about very small cell. And they're not just sitting way, way up there.
[00:23:26] These are in basically in low orbit around the earth and they're geostationary. In other words, they stay in one spot. I believe this is the way they've got these things set up. So these satellites then allow because they're so close to the earth, allow them to use less power. And also the other advantage to that is.
[00:23:49] The delay, right? The delay between having to send it all the way up and back down, because electricity takes time, right? Yeah. Travels at the speed of light. But nowadays you might've noticed it can take your quarter second, half a second. When you're talking to someone, when I'm on the radio with some of these radio stations or the delay can be absolutely incredible.
[00:24:11] Like I half second to a second sometimes. And that's just because they're being cheap. This type of technology where you have these constellations and it isn't just Elon Musk. It isn't just Starling, but constellations with will ultimately we'll have tens of thousands of satellites up there. Not, there's all kinds of other potential problems not getting into that right now.
[00:24:34] But what it does mean is. Can communicate and we've never had this sort of thing before we had the us military, the Navy in fact, put together a communication system that lives on top of the internet and called nowadays. Generically the dark web. And it was set up to allow our military, our state department to be able to communicate with people in countries that are back in the day under Soviet control, all kinds of potential problems.
[00:25:10] So whenever those problems existed, they just went ahead and used this onion network, which is a part of the dark web, et cetera, et cetera. So let's say we had before. Now what happens if you're a country like Ukraine, where 100% of your internet comes from Russia, Russia obviously can sit there and listen in.
[00:25:32] Hopefully your encryptions. Good. A lot of Russians have been using telegram and already get real news about what's happening in their country and other places. And Della Graham is not that secure, frankly. WhatsApp pretty secure signal is the one you want to pay close. Attention to signal is considered to be the most secure of all of these secure communications apps.
[00:25:57] But there's a level above all of that, because if they can tell that you're communicating, even that is enough to give them some information. So they might not know what was in that transmission, but if the transmission is all of a sudden, a tons of activity coming over, lots of data, lots of messages going back and forth, they can say maybe there's something about to happen.
[00:26:21] That came out. You might remember the old orange book for security way back in the eighties, I think is when it came out. But part of what you had to do was cover up your. Actual real communication. So it's one thing to have the communications encrypted, but you wanted to always have about the same amount of communications going back and forth.
[00:26:42] So people couldn't figure out what you're doing now with these types of devices. That kind of problem still exists. And this is part of what Elon Musk is warning about here. Pull it up on my screen again, for those people who are watching Elon Musk is urging users of his satellite system to put their Starlink antennas as far as.
[00:27:08] From people as possible. Now, why would he be doing that? Because frankly, that terminal is transmitting to the satellite as well as receiving from the satellite. And it is entirely possible that there could be some evil software that is listening in for the satellite transmissions and sends a little missile your way.
[00:27:36] Also, of course the Russians have satellites in space that can look down on the ground. Now it's something as small as a terminal four Starlink, little hard to see, but Elon Musk is saying, Hey, listen guys, go ahead and camouflage it. You might want to spray paint. It just don't use metallic paint so that they can't see it and place it as far away from where people are as post.
[00:27:59] So you can still use it and only use it when you need to use it. Don't keep it up and running all the time. But this is the start of something great. Something where you can't easily block people's communication. So Russia has tried to do. And they have been jamming the Starlink satellites. So what did must do?
[00:28:23] He delivered all of his engineers to working on how can we get around the Russian Jack? And according to Elon Musk, they have gotten around it and they now have their satellite systems completely jammed free from the Russians. I think that's fascinating. They're probably using some good spread spectrum technology that was actually known about it and world war II.
[00:28:47] And then we can talk about that for a long time. Heady, you might remember her anyways, skip that for now. Stick her out. We got more when we. A whole bunch of pandemonium out there because of what Russia's been doing in Ukraine and how it's flowing over to us as well. Hey, this is not great news.
[00:29:15] Pandemonium is the name of the game over there in Russia. And they are being very successful. We're going to talk about what happened in Bella ruse. We'll talk a little bit about what happened in Ukraine with cybersecurity and what's happening right here right now.
[00:29:36] Complete ARS Technica today. They've got some great articles this week, looking into the Russians. What are they doing? What kind of problems is that causing us? But we are seeing some interesting attacks back on. And back in very big way. Russia has been going after you crane in the cyberspace for a long time, we spoke a few years ago about what Russia had been doing with the tax software for Ukraine.
[00:30:12] We don't do this in the U.S. Or in Canada, but my number of European countries do you, where you have to have. The old official tax preparation software put together by the government for your business or for your person, depending on the country you're living in France is a great example of this. And Ukraine is another one.
[00:30:36] So Ukraine says, Hey guys, you got to go ahead and use our software. That means every business in Ukraine is using their software. To manage their tax payments and their accounts, frankly. And that wonderful little piece of software was hijacked by our friends in Russia. So they grabbed a hold of it. They in.
[00:31:02] Did some code into it that added rent somewhere to the software. So now all of the businesses in Ukraine are pretty much guaranteed to be using this hacked software. We have a client who has offices over in France, and we found a really interesting problem with them because. The French software that was being used for taxes for French businesses had an extra little problem.
[00:31:33] And that extra problem was, it was insecure as can be whoever wrote this, must've taken a Microsoft programming course and had no idea DIA about the consequences of what they were. So it was very insecure. The, it was using a version of SSL, which is an encryption that's based on another type of increase.
[00:31:57] I don't want to get too wonky here, but that was just one of its many problems and bad keys, et cetera, et cetera. And keys by the way, was using keys that have been revoked, which you should never do. Bottom line. Oh my gosh. Hey, if you want more information on this, just drop me a note.
[00:32:16] me@craigpetersohndotcomandyoucanalsogetmynewsletterwithallkindsofgreatlittletipsmeatcraigpeterson.com. Just let me know. So in this case, we had to help that company in France. Ignore the security restrictions that were on their systems so they could use the French tax system. So anyways, I told you that, so I could tell you that the same thing happened to Ukraine.
[00:32:45] In a different way, their software was pre infected. So when they downloaded it, ta-da. They got that piece of ransomware that virus had spread. It was just a nightmare. And of course it robbed. If you will, Ukraine, government of funds, that would have been. So we had now a bit of a shift. I'm going to pull this up on the screen again, this article, because what this shift has shown is that the hackers are now operating on the side of you.
[00:33:21] Crazy. Which is just fascinating. So the group called anonymous, you might be familiar with them. Of course, they've been doing a lot of hacking for a lot of years, releasing private information, government and information, all that sort of stuff. And they have a mast what they're calling a volunteer.
[00:33:44] It. And this it army has been going and doing what well hacking Russian sites apparently. So this article is just absolutely fascinating and they pulled some of from wired as well, but the Russian space research Institute, their website was hacked, leaked files that were stolen from the Russian space agency, made it all the way on to the.
[00:34:13] The space agency was hacked in their website said, leave Ukraine alone, Alto anonymous. Will you up even more? They also did. What's called a D O S. Which is a distributed denial of service attack. Those can be very difficult to protect against unless you're set up in advance to help protect yourself.
[00:34:39] And that pretty much destroyed Russia's dot are you top level domain? So we've talked about how domain services work, right? So Doug are, you is like.com except dot R U is for running. And so the domain name servers that handled our, you were knocked off the air because no one could really get to them.
[00:35:02] They used amplifying attacks and stuff without getting into all of the details. So basically they were trying to cut off access and they did for a lot of people to any. That ended in, are you? It's great. These are just some of the latest in this surge of hacktivism. That's been going on one of the ones I mentioned a couple of weeks ago with the Belarusians deciding they were going to hack the Belarus railroad, which was being used.
[00:35:31] To bring Russian troops, supplies, tanks, et cetera, all on rail, right on down right to the border of Ukraine. So that was hacked so that they couldn't use it in order to go after. Of course Russia was able to get to Ukraine, but there's also been protests around the world. 48 Russian cities raise millions of dollars through cryptocurrency donations.
[00:36:01] Now, I'm not a big cryptocurrency guy and I'm not a big crypto currency guy because while. Cryptocurrency is likely to be outlawed by most, if not all governments. And they certainly could shut it down and it is not anonymous. All right. So using cryptocurrency does not mean it does not equate to completely anonymous.
[00:36:28] They have done a lot of donations. They're big companies including, we just talked earlier about Microsoft, but also apple shell, BP, a McDonald's Starbucks. And these hacktivists have really joined in. And w we talked about a couple of other things, so this is messy. Because even more than in peace time, these active combat that are really hacking happening right now, rendering, hacktivism, any effectual and largely just distracting because we are now in a hot war right now.
[00:37:10] Maybe we don't have our. Eric planes bombing Russian movements or other things, but there is a kinetic war going on over there. There are bullets, et cetera, mean exchanged. So the hacktivist efforts have been, visible. There's no question about that. But what have they done? See, that's an advantage to being a country like Russia, or like the Ukraine, or excuse me, Ukraine, because both of those countries there, their industrial base, the military industrial base is not heavily automated unlike ours.
[00:37:50] What could you do? What can you shut down? So what you shut down the Russian space agency's website, how far did you get into it? Probably not very far. We also have a couple of groups and we talked about these guys many times the Conti group, which has been.
[00:38:07] Terrible and hurting us businesses, individuals, government agencies, and stuff, the Cuming project, both of them have declared their allegiance to Russia. You might remember a few weeks ago, we talked here about how we have had some researchers track down most of these Russian hacker groups and their money.
[00:38:30] And they all ended up in one building in Moscow. No, that should tell you something, right? In fact, the most expensive real estate right there in downtown Los gal, the tallest building, et cetera. So these groups getting together in order to protect the father land there in Russia. Ah interesting problem.
[00:38:52] How much of this is really controlled by the Kremlin? It's a very good question. Context. Was dismantling its infrastructure. It, some of their top people were arrested by Putins military. Not military, but police state over there. And that was interesting too. That was again before the invasion, but why would Putin be shutting them down at all?
[00:39:20] Apparently they said some things. That they shouldn't have said. So now they've come out and have decided they're going to support Russia in its entirety. Now we mentioned Microsoft and how Microsoft has decided they are going to protect other countries. As well as you crane, at least as far as the Russian malware goes, and they've been very active in that.
[00:39:46] And there are a number of cybersecurity companies and other organizations that have released free versions of some of their software, these digital defense tools. Free offerings. Our big cranes defend the networks. Google says it's human rights focus de dos protection service project shield is now in use by more than 150 Ukrainian websites.
[00:40:12] So it's very good. Bottom line propped up by the way, published this massive trove of personal data. Allegedly identifying 120,000 Russian soldiers deploy. In Ukraine that was Ukrainian prov, not the old good old Russian Sophia Pramata man. I remember I bought one of those on new standing Canada once.
[00:40:36] And I had a friend who was from Yugoslavia and he said, oh, can I show that to my wife? He showed it to his wife. She tore it up. I said, I want my Pravda, Craig Peterson dot com.
[00:40:47] The tech world is all a buzz with this log for J or log for shell. However you want to call it because we are looking at what is probably the biggest security vulnerability the internet has had in a long time. I don't know how to express it anymore, but there are multiple problems here. And even the patch that was released to fix this problem was broken as being exploited in the last 24 hours. There've been no less than 30 different new. Variations of the exploit. So what is going on? There is a computer language that's used by many programmers, particularly in larger businesses called Java.
[00:41:37] You might remember this, I've been following it and using it now, since it first came out very long time ago from sun Microsystems. Java is a language that's designed to have kind of an intimate. CPU processor. So think about it. If you have an Intel chip that is an x86 type chip, what can you use instead of that Intel chip to run that code?
[00:42:03] There are some compatible chips made mainly by AMD advanced micro devices, but you're really rather limited. You have problems. Power. Guess what you're stuck. You're stuck in that architecture. And then on the other end of the spectrum, you have some of these devices that are designed by companies like apple, Google has their own.
[00:42:24] Now that our CPU's their graphics processing units as well. And they completely replaced the Intel architecture. But the Intel code, the programs that are written for the Intel architecture that are compiled for Intel are not going to work on the apple chips and vice versa. So what did apple do? Apple, for instance, just moved from Intel over to.
[00:42:51] Own chipsets and these chips don't run Intel code. So how can you run your old apple apps? Apple has a little translator. They call Rosetta. It sits in the middle and it pretends it's an Intel processor. This really rather simple. And they've done an amazing job on this. And w Rosetta is actually a third party company and they helped apple as well with the transition from the IBM power series chips to the Intel chips.
[00:43:23] So how do you move the code around while you either have. Recompile it, you may have to redesign it, rearchitect it for the new type of processor and the new types of computers that are supported by that processor. Or you may do what Apple's done here a couple of times now, and that is having an interpreter in the middle that pretends it's something else pretends as an Intel chip.
[00:43:49] And then you can still run your in. Code because it knows, okay. It was designed originally for this apple Intel architecture. So I know how to make all of this work Java steps in and says why are you doing all of that? That's crazy. Isn't it moving all of your code around all of the time. So Java's original claim to fame was what will make life easy for?
[00:44:14] What you do is you write your code. Using Java in Java is very similar to C plus in some of these other languages that are out there. And that language, when you're writing your source code will be compiled into an intermediate. Code. So what happened is sun Microsystems designed this virtual machine?
[00:44:36] Now don't think of it like a normal VM, but we're talking about a CPU architecture and CPU instructions. And so what it did for those CPU instructions. Which is really quite clever, as I said we'll come up with what we think are the most useful. And it's a Cisco architecture for those of you who are ultra geeks like myself.
[00:44:59] And we will go ahead and implement that. And so the compiler spits out code for this CPU that doesn't actually exist anywhere in the known universe. And then what happened is sun went out and said, okay we'll make an interpreter for. Artificial CPU that'll run on Intel chips and we'll make another one that runs on these chips, that chips and the other chips, beautiful concept, because basically you could write your code once debug it and run it off.
[00:45:32] Anything that was one of the original claims to fame for Unix, not so the run at anywhere part of it, but the part that says it doesn't take much work to move your code to different machine, and we're not going to get into Unix and its root I've been around the whole time. It's crazy.
[00:45:51] I just finished reading a book and saying, I remember that. And they were going through all of the history of everything I was in the middle of that. I did that. That was the first one to do this. It was fun. Anyhow, what Java has done now is it's really solidified itself in the larger enterprises.
[00:46:11] So basically any software that you might be using, like our website that is particularly with a larger business. Is going to be using Java and that Java language is using libraries. So in programmers, instead of doing what I used to do way back when which is write in assembly code, or even in COBOL, and basically you had to write everything, every part of every program, anything you wanted to have done, you had to write, or maybe you borrowed somebody else's code and you embedded it in.
[00:46:45] And mind you, we only had 32 kilobytes of memory in the mainframe back then the 360 30, for those of you who remember those things, but here is where things really changed. You now had the ability to take that code that you wrote and put it on a smart. You could take that exact same code, no recompiling or anything, and take that code and run it on a mainframe on our super computer in a car.
[00:47:15] So Java became very popular for that. Very reason in these libraries that Java provided, made it even quicker to program and easier to program. Now there's some problems with languages. Java, which are these object oriented languages where you can, for instance, say one plus one equals two. That will make sense.
[00:47:38] But what does it mean when you use a plus sign? When you're talking about words? So you say apple plus oranges, what's that going to eat? That's called overloading an operator, and this is not a course on programming languages, but what happens is a person can write the library and says, oh if the programmer says a non-Apple plus an orange or string plus a string, what I want you to do is concatenate the strings.
[00:48:06] Now that programmer who wrote that has to figure out a couple of things, make some assumptions. Oh I should I put a space between apple and. Or not. And what do they really mean? Okay. So this is how I'm going to interpret it. So that, it's a very simple example. But the concept is that now with these overloaded opera operations and these libraries that can go deep deep, you now have the additional problem of people designing and writing the libraries, making assumptions about what the programmer wants and what the programmer needs.
[00:48:43] Enter the problem with the log for J vulnerability. This is a very big deal because we're talking about a library function that is being used in Java by programmers. Now, you know that I have been warning everybody. Android for years, the biggest problem with Android isn't its user interface. It isn't that it's made by somebody else.
[00:49:10] The biggest problem. And of course, this is my opinion is that Android software is provided by Google and. It is given basically to any manufacturer that wants to license it. And then that manufacturer can't just take Google and run it. Have you ever tried to install windows or Linux or free BSD?
[00:49:36] It's mainly a windows problem, frankly, but you go on ahead and install that. And what do you need in windows? You're going to need driver. Oh wait a minute. This laptop is three years old. So how can I find them? And then you go around and you work on it and takes you a day and you finally find everything you need.
[00:49:53] And you've got all of the drivers and now it works. But Microsoft provided you with the base operating system. Why do you need drivers? You know the answer to that and it's because every piece of equipment out there is different. Think about this in the smartphone market. Think about it in the more general.
[00:50:10] Android market. There are thousands of these devices that are out there and those different devices are using different hardware, which require different drivers. So when Google comes up with a software patch, how well we just fix the log for J issue that patch. Has to be given to the devices manufacturer who then has to talk to the manufacturers of the various components and make sure that the device drivers that they're using by the manufacturer are actually compatible.
[00:50:50] They're going to. Got the upgrades, wire it all together, and then test it on all of the different phones that they have and cars because the cars are running it. Now you see how complicated this get. And most Android devices will never. Get another update. They will never get a security patch versus apple.
[00:51:14] Right now. They're still supporting the apple six S that came out in 2015. If I remember right, it's five or six years old. Now you don't find that in the Android space. You're lucky if you get two years worth of support, we're going to continue this. But this is this is really important. I'm going to talk more about the actual problem.
[00:51:36] What is being done about it? What you can do about it as an individual, a home user, and as a business, in fact, keep an eye on your mailboxes. Cause I've got some more links to some sites about what you can do and how to do it and how to test for it.
[00:51:53] We're talking about what is likely to be the biggest set of hacks in internet history right now. It's absolutely incredible what's going on. So we're going to talk about what it means to you and what's really going on. This whole problem is probably bigger than anybody really realizes because Java, as I explained is a very common computer programming language.
[00:52:23] And it has a lot of features that bigger businesses love. They love the ability to have multiple programmers working on something at the same time. They love the inheritance and multiple inheritance and all of these wonderful features of Java. One of the really cool features is that you can, while your program is running, have the program change.
[00:52:48] It's. That's effectively what it's doing. It's pulling in libraries and functions in real time. And that's where this particular problem comes in. This has been a nightmare for Java forever. It's one of the reasons I have never migrated to Java for any of the projects that I have. Don, it just gets to be a nightmare.
[00:53:12] It reminds me of Adobe flash. It was the biggest security problem that has ever been. And the number two Java and Java is running in the Android operating system. It is the core of the operating system. All of the programs are almost certainly written into. And now we're seeing Java up in the, not just entertainment systems in our cars, but in the actual computers that are driving the cars, running the cars.
[00:53:45] And I get very concerned about this. We had two major outages just this week before this log for J thing came about over at Amazon. And those two Amazon outages knocked thousands of businesses. Off the air out of business. You couldn't get to them. You remember the big problem with Facebook that we talked about a little while back and in both cases, it looks like they were using some automatic distribution of software sent out the wrong stuff.
[00:54:15] And now you are effected. What happens? What happens with the cars? If they push out a bad patch, how are we going to know. What's that going to mean? And if your car has Java in it, are you going to be vulnerable to this? You wouldn't be vulnerable to log for J if your computer wasn't hooked up to anything, but nowadays the cars are hooked up to the net.
[00:54:39] We've had a couple of car dealers for our clients. Who've had the Mercedes we've had Acura Honda and others over the years. And it's interesting going in there now and working with them because they are doing massive downloads of firmware whenever a car comes in. So that car, if they don't have the right kind of networks, that car can take hours to do.
[00:55:07] Dates. And I got to tell you, man, I'm just shocked by so many businesses, not willing to spend the money that it really takes. So the poor technician is sitting there waiting for it to happen. We could make it happen in 15 minutes, but they're stuck there waiting for three or four hours sometimes for some of these downloads, no it's called cash them locally.
[00:55:26] These cars, some of them need new and different firmware. Some of them use the same and have. A reliable, fast internet connection. And we've done that for many companies. Anyways, I'm going off on a bit of a tangent here. So forget that let's get back into this with Java. You can have a routine.
[00:55:48] Call another routine that was not even necessarily thought of by the programmer. Now, can you imagine that? So you're programming and you're not considering adding something that's going to send email out and yet you could have a log in. That's part of the DNS and it gets logged that actually causes an email to be sent or causes anything else to happen.
[00:56:17] That the exact problem we're seeing right now, it's absolutely crazy patterns in text fields, things like you can put a user desk agent. Which is normal for nature. UDP connection. You say, this is usually a guy who using Chrome version bar or Firefox or safari, but you put the user agent field.
[00:56:40] And then after that, you've put in some, a little bit of code that tells Java, Hey, what I want you to do is this. This is a problem because we're finding now that I'm, again, I said the last 24 hours, 30 different exploits over a million companies have been attacked on this. And we're talking about 10.
[00:57:05] Companies, absolutely hacked every minute right now. Can you think of, let's just think about that. And we're in the middle of what, right? The big holiday season, we've had some holidays, there's people online, shopping there's businesses that are trying to buy stuff, business stuff, almost every one of those sites is likely to be compromised.
[00:57:31] It's that bad. It's absolutely nuts. What's happening here. This is a huge flaw. And by the way, it is flaw. Number this you ready for? This 44,228. In the year 2021. So the written 44,000 flaws that have been discovered and reported, this is the CVE system for those of you who are interested, but this really is a worst case scenario.
[00:58:02] Because this log for J library is being pulled in to so many pieces of software out there on so many different platforms. The paths to to exploit this vulnerability are almost unlimited. And because there's so many dependencies on this particular log for J library, it's going to make it very difficult to patch without breaking other things.
[00:58:32] And the fact the exploit itself fits in. Tweet come injected almost anywhere. So it's going to be a very long weekend for a lot of people, but let me tell you this. It is not going to be solved in a few days, a week, a month. We're going to be seen this. Years, because you have to be the person that wrote the program that has the source code to link in the new libraries, distributed out to your customers.
[00:59:03] Do you see what a nightmare? This is now? Some people are saying let's blame this on open source. This is an open source product. Yeah, it is an open source project and it turns out that even though anyone can grab this, these, this library routine or any of these pieces of code, anybody can grab it.
[00:59:21] Anybody can look at it. It turns out it's one guy. Who actually maintained this, who has a budget of $2,000 a year to maintain it. Nobody else pitched in. And all of these big companies are all out there grabbing this code that this guy has been working on and not paying much attention to it. Not donating to the project.
[00:59:46] Which is saving them millions of dollars, not that one project, but all of these projects collectively in the open source community, it's it is more far reaching than this stretch vulnerability. You might remember this drug vulnerability that's was, that was the root cause of the massive breach at Equifax that Explo exposed all of our personal information.
[01:00:14] To the dark web. That's how bad this is. Oh my gosh. So Hey, if you want information, I've got a links, a bunch of links set up here on what to do while you're waiting for the log for J updates from your vendors, how you can find on your servers. If they have the log for J vulnerability, I've got a bunch of information that I've stored up on that.
[01:00:41] And some others just email me. M [email protected] asked for the list of the log for Jay's stuff or the Java's stuff. I'll figure it out. Be glad to send it to anyone that's interested. And if you need to scan to find out yourself and your business, let me know to [email protected].
[01:01:03] Wow. I was just going through a list published by Seesaw, this federal government agency that tracks some of these types of vulnerabilities. And wow, this list is daunting of all of these pieces of software that are vulnerable to this huge hack.
[01:01:19] This is now a problem for each and every one of us.
[01:01:23] I think I've established the man. This is nasty. So what do you do? First of all, I sent out. Email a list of things have in fact, a few different lists of things that you can do. So I had one for consumers, one for businesses and a general thing as well. And then a bunch of references.
[01:01:47] Of course there's even more references and more great information now because I got that email. Pretty early. So I hope hopefully you had a chance to really look through that, but here let's just talk a little bit about this, what to do thing you already know because you guys really are the best and brightest that you need to be careful when you're on.
[01:02:11] You cannot be online, Willy nilly, clicking on things. And that includes emails and links. And this time of year in fact, all year long, we're looking for. Wow, let's see. Is there a great bonus here? Look at they're having a sale, a discount. Oh no. I've only got three hours to respond or the deal's going to go away.
[01:02:33] I've usually been of the sort that I just am, not that influenced by some of these deals, but. I do sometimes want to find out what it is. So I find myself this week clicking through on. I'm on a lot of marketing lists because I like to follow what different marketers are doing, that's technology.
[01:02:55] And it's something I want to keep you guys informed about. And I found myself just crazy amount of double checking to make sure the link was valid. Now I'm sure you guys have, if you're on my email list, you might notice that the from address is not the me at Craig Peterson. Calm email address. You can always send email to [email protected] and it ends up in my email box.
[01:03:21] And it might take me a few days, or even as much as a week or two to get back to you. If it's something there's an emergency, you really need to fill out the form on my website, but I will get back with you. But the problem that some people have noticed lately is. It doesn't say return address or sent from [email protected].
[01:03:45] It's got this rather long convoluted convoluted URL that has nothing to do with Craig peterson.com, sows a number of people question it, it is a tracking. When can the idea is if I am going to be able to get back to people and if Karen is going to be able to nudge. I have to have these things tracked.
[01:04:09] So the email from address, when you hit reply, it is going to go to the, again, my email list server guys, and it is going to get tracked so I know. Okay. Okay. So now I've got a few minutes or an hour. Let's sit down and go through a lot of these emails so I can get back to people. That's a problem for many people, that's even more of a problem today than it ever has been in the past.
[01:04:38] Now there's been a few sites that have done something about tracking because many people don't like to be tracked. My self included, although, as I've always explained on the show, it's a double-edged sword because I would rather see commercials or ads for a Ford F-150 pickup truck. When I'm looking to buy.
[01:05:00] Car or certainly a truck. I don't want to see ads for things I don't care about. And you probably don't either. So the tracking, I don't think is a huge deal. The statistics that have come out from apple recently are very interesting because what apple ended up doing is they put some new technology and to stop tracking.
[01:05:25] And to stop you from being tracked. And basically what they're doing is a couple of things. One, they've got this new feature where they will download images and emails from their website, so that it's not they're not being able to localize where you are and then they're also doing something where you.
[01:05:49] Are you are, you can't be tracked like you used to be able to be tracked. Let me just put it simply like that applications now have to have that little label warning label in the app store to let you know what they might be tracking, et cetera. So they've been accepting anti tracking behavior that came from our friends from.
[01:06:13] Apple now Google, Facebook and others have been very upset about this thinking that they were going to lose a lot of business here in the advertising side, because you wouldn't be able to track them. So if you've got an apple iOS device, you probably noticed, it says, allow app to track your activity across other companies.
[01:06:36] And websites, your data will be used to measure advertising efficiency. I don't know that's such a bad thing. And looking at the stats right now, I'm looking at Google's income. And a lot of that comes from YouTube after. Apple launched its new privacy initiative and it looks like Google really wasn't hit very badly.
[01:07:00] What Facebook was worried about that they would just be losing all kinds of revenue. Also didn't turn out to be true. So it's an interesting thing to see and I've got to really compliment apple again. At this time on trying to keep our information private, I read a really great book this, so this is how the world ends talking about the whole cyber race and where things are likely going.
[01:07:30] And it's frankly impressive. To see what Google has done to try and keep out our government from their networks, as well as foreign government and the whole thing with the Chinese hackers we've talked about before, where I've found them. Active inside our customer's network before. And this is where we get called in because there's a problem.
[01:07:57] We look around, we find indications of compromise. We find the Chinese inside. Okay. So it isn't something that we were protecting them, the Chinese got in, but we come in after the fact and have to clean up the mess. But what we have really seen happen here is the largest transfer in. Of wealth, I should say, in history, the largest transfer of wealth in history to.
[01:08:25] From us and from other countries, but primarily from us because of what they've stolen. And so Google really has fought hard against it. The Chinese have been in their systems have stolen a lot of stuff. Apple has fire fought hard against it, but we know about the apple stuff. Google's seems to be a little quieter about some of it.
[01:08:45] So they may be selling our information to advertisers, but there certainly are trying to keep nation states out. I'm really wondering too, what is Google doing? Moving that artificial intelligence lab to China. It just it's insane. We know we, if we're going to get out of this financial position, we're in as a country, we need to have an amazing new technology.
[01:09:09] So people are coming to the United States and we're certainly not seeing that. At least not yet. It's all been stolen. So what to do, man. I started talking about that and we got a little sidetracked. So I will talk about that a little bit more here coming right up and what to do if you're a consumer, if you're a business person.
[01:09:32] And of course, as I mentioned earlier, I have. Quite a list. I'm more than glad to send you. If you go ahead and just email me, M [email protected]. I'll keep you up to date, let you know what's happening and give you those links that you can follow to find out exactly what is happening and what you can do.
[01:09:53] Including some tools. There are some tools out there to check to see if that vulnerability exists inside your networks or systems MI. Ed Craig peterson.com. And I'll be glad to reach out, reach back to you.
[01:10:09] I'm gonna tell you what to do as a consumer because of this massive internet hack that is underway. It is huge. Also going to talk a little bit about apple and what they're doing with their tracker detect app on Android devices.
[01:10:24] This will be going on for months and probably years in some cases, because there are many systems that will never.
[01:10:35] Patched for this vulnerability. So from now on, you need to be doubly cautious about almost everything, the big targets for this. Then people who tend to be the most valuable. Big businesses. And I can send you a list of devices that are known to be either immune to this they've been fixed or patched and devices that are known to have this problem.
[01:11:03] You send me an email. Excuse me. If you have any questions about it. So it's me M [email protected]. I'd be glad to send you that list. Seesaw has it online. You can certainly search for it yourself. If you're interested in. So for you as an individual, it's just extra caution, use these one time, use credit card numbers.
[01:11:31] I have talked about this before. And that is, I use fake identities as much as I possibly can online. And I'm not trying to defraud anyone. Of course, that would be legal. What I'm trying to do is not make myself as easy at target. As is frankly pretty much anybody who uses a computer out there, because if you're always using your, in the same name and email address and having forbid password, then you are a bigger target than you have to be.
[01:12:07] And I have a whole index file. I have a spreadsheet that I put together with 5,000 different identities, different names, of course, different sexes, races, origin stories, everything. And the whole idea behind that is why does some company that's providing me with some little website thing, need my real info.
[01:12:31] They don't obviously you give you real info to the banks or. Counts, but you don't need to give it to anybody else. And that's what I do. That's my goal. So if you can do that, do that. Apple also has a way for you to use random. Email address a suit can set up a different email address for every website you visit.
[01:12:57] There are a few services out there that can do it. If you're interested, drop me an email. [email protected]. I'll send you a list of some of them. I think they're all paid except for the app. But you have to have an apple account in order to use it. One of the things that businesses really need to do is do a scan.
[01:13:19] Again, I can send you a list of scanners so that you can look at your network, see if there's any. Obvious that might have huge implications for your business. Again, [email protected], one of the things apple has come up with that I really have turned out to and I think I mentioned them before on the air, but it's these news.
[01:13:41] Trackers that apple has, that you can put on things. And we spoke a little bit last week about the problem with these trackers being put on to high-end cars, and then being used to track the car. Now apple got around that problem a while ago, by letting you know, Hey, there is a tracker following you isn't that handy.
[01:14:04] Wait a minute, somebody dropped one of these little tags into my purse. Coat my car or whatever it might be. And so now you can have a look and see where is this thing that's following me and get rid of it. Of course, in order to know that there's one of these apple tags tracking, you've needed to have an apple phone.
[01:14:26] Because it'll warn you. Apple now has something called tracker detect. If you are using an Android phone, I would highly advise you to get this app tracker detect app on Android. And it's designed to help you Android users from being tracked by apple airtight. 'cause if you don't know you're being tracked right, then you can't know if you're being tracked.
[01:14:55] If you don't have an iPhone, unless you get this app so good for them, apple has it up now on the Google play store. That's just in the last week or so, and it lets you locate nearby air tags. So let's I think a very good thing kind of wonder if apple isn't using the Androids also for part of the.
[01:15:16] Crowdsourcing for the air tags, but that's a different conversation. Great article in vice this week by Aaron Gordon, about how car companies want you to keep paying. Features you already have, and they specifically made a call out about a car manufacturer. Toyota. Who's now charging $80 a year for people who bought their car years ago, six years ago, $80 a year.
[01:15:51] If you want to keep using the remote start function on your key. Yeah, so you paid for it and life was good. You went a few years, really nice on a cold winter day or a hot summer day, warm up the car or cool it down all automatically. But now Toyota is charging. $80 a year. So people are saying why I bought it?
[01:16:16] Why would I pay for that? Apple's now claiming that the several first years were merely a free trial period, but this isn't even the big play for these car companies, this $80 a year for marginal features like remote start instead. Is probably going to happen. And I agree with this author as well is we're going to see a, an approach that Elon Musk has used with his Teslas.
[01:16:47] They're going to charge extra for performance, for range, for safety upgrades, for electric vehicles that actually make the car better car, a better car. So upgrades used to be difficult or impossible with gas cars. A lot of these are trivial for the electric cars, with the dashboards that have games that you can play while you are charging.
[01:17:13] Some of them were complaining about it being for when they're on the road. Of course that's going to happen because frankly, when, once we get a full autonomous car, what are outs are you going to do? I should also mention this isn't really a, but Mercedes-Benz has been awarded the very first license for the manufacturer sale and distribution of a fully autonomous vehicle.
[01:17:39] The very first they are licensed for up to, I think it was 37 miles per hour. On their car and anything beyond that, you still have to retain control, but that's an amazing thing. And it only works on roads that are mapped. And what Mercedes is doing is they have these super high definition maps. So the car knows exactly where it is.
[01:18:08] If you are a Tesla owner, you know that a few years ago, Paid, I think it was $2,000 for your Tesla to be able to drive itself. And of course they haven't been able to drive themselves. They, yeah, there's been features here and there, but how were you getting those features? How will you going to get that self-driving mode?
[01:18:30] We'll test those, calling them over the air upgrades. And they're also saying. Th this is part of the Tesla ownership experience to quote their website. All right. So they've had all kinds of over the air upgrade. They've had some free software. They've had paid ones, Tesla charges, thousands of dollars for its autopilot.
[01:18:54] Now a lot of money, I think it was five grand. Now they've got this beta driver assist system as well, and they also have. To others. You might remember the ludicrous speed. Long range model three would dual motors is capable of accelerating from zero to 60 in 3.9 seconds. But when you buy the car, the zero to 60 time is a half a second longer.
[01:19:25] So pay an extra $2,000 and you get that extra half second and accelerate. Yeah, there's nothing different. They don't even have to change. Really changed the software. There's no hardware differences. It's just, you pay them two grand and they, your cars catheter to the internet and they just unlock a key is not something.
[01:19:48] Now there some people that hack the way around that paywall, but then Tesla blocked it and reversed the hack as well. Tesla has sold their cars now for years with the same 75 kilowatt hour battery. But software locked them to 60 and 70 kilowatt hours might remember. We talked about this with a hurricane that came ashore down in Texas, where Tesla, anyone in that area provided them with an automatic upgrade for extra batteries.
[01:20:19] So they could go further in order to get out of the zone of their herd. Before them in software lock-in and a 60 and 70 kilowatt hours, unless you paid an additional $3,000 for that extra 30 or 40 miles of range. Isn't that something. Yeah. So Tesla has temporarily unlocked them, but this is where we're going.
[01:20:43] You're going to be going into the car dealership while in Tesla's case. It's on the internet, which I think is better. Frankly, dealerships are handy in order to get a repair, but. You can get a repair at some of these little specialty shops it's often better and certainly cheaper than what the dealership sells, but you're not only going to be haggling over the price of the vehicle and delivery times.
[01:21:08] You're going to be haggling over all of these different features. And it's never going to end because they're going to keep having software upgrades that you're going to have to pay for. Pollstar star. This is an electric vehicle company spun off from Volvo new member. Volvo is now Chinese company.
[01:21:25] Yeah. Chinese. Yeah. So much for safety, right? They're going to charge an extra thousand dollars for a slight increase in horsepower and torque, just like Tesla does. So this is the future. Of car companies. Hey, I want to remind everyone, if you go to my website, Craig peterson.com. Right now you can sign up for my weekly newsletter.
[01:21:48] It is packed full of great information for you. Every week. We've got some free boot camps coming up after the first of the year, and you need to be on my email list to find out about it. CraigPeterson.com/subscribe.
Did You Hear About the Latest Phishing Scams to Hit? Get the Latest Free Cybersecurity Tools
This is a big deal, quite literally a big deal. Russian malware. We have been able to track it down now, track it down to a single site. All of these bad guys are in one building in Moscow.
[Following is an automatic transcript]
This is a very big story and it's a bit of a scary one as well. We've had a lot of ransomware over the years and a lot of ransomware. Have you had it yourself? I bet you, if you haven't, someone who has had ransomware because frankly it is pervasive in every aspect of pretty much everybody's life out there.
[00:00:40] So when you get hit with ransomware, Lately something a little different has happened. It's really gone through three phases. The first phase was the ransomware would get on to your system. Usually it came as an attachment, probably embedded in like a word file it's been embedded in PDFs, embedded in all kinds of stuff.
[00:01:03] Even drive by downloads on websites, have brought malware. But in this case yeah, it was annoying. It was a problem. It would give you a red screen. You've probably seen it before warning about the ransomware and it told you, okay, here's what you can do to get your files back. And in order to get your files back, you usually.
[00:01:25] To go to some exchange online, take dollars, buy of course, Bitcoin, or some other cryptocurrency. And then that cryptocurrency would be used in exchange now for you to get a key that would hopefully decrypt everything. And in reality, it often didn't encrypt hardly anything. So it's been a problem and a problem for a lot of people.
[00:01:51] The FBI said that at the time. So this is a gen one of ransomware. You were lucky if 50% of the time you got all your data back, gen two of ransomware is when the bad guys started getting a little bit smarter. They didn't just take your files. Thumb and then say, Hey, pay up buddy. What they did at this point is that got onto your systems and they poked around.
[00:02:14] They went we call in the industry, east west on the network. So they got onto you, maybe your kid's computer may, maybe you were hooked up via VPN to the office to do work. And it wasn't a great VPN. And the kid's computer had that virus and that virus weaseled his way all the way over the VPN, directly to the office, because remember.
[00:02:37] VPNs are. A network private in that. Yeah. Okay. It's encrypted. And so someone who's got a wire tap isn't necessarily going to get anything, but it's a VPN, it's a tunnel. And that tunnel was used a many times for malware, like brand summer to creep over to the office network. That's an east west is going from.
[00:02:57] One machine to another machine. And in businesses, man, you saw that one a lot as that ransomware moved around. So that was the second one. So the rents were going on the machine. It would then look for files that is. You might not want to have exposed. So it looked for files with bank account numbers in them, social security numbers, maybe intellectual property.
[00:03:25] We saw a lot of that. Theft is continuing to go on primarily from the Chinese and then an intellectual property theft. And what happened next? While of course it ended up moving the data, the files, and then what they would do. It's encrypt your desk. So before they gripped your desk, they got copies of all of the stuff they thought might be important to you.
[00:03:48] So now the threat was in version two of ransomware pay up, or if you don't pay up, you are going to have to pay us to not release your files. If you didn't want all of that client information online, if by law, you would get nailed for having that client information out online. And that's true in most states now, and the federal government's from putting some teeth on some of their laws as well, then what are you going to do?
[00:04:17] Yeah, you paid the. So that was version two version three that we're seeing right now of ransomware is simply destructive. And if you go way back in history, you may remember I got hit with the Morris worm, which was one of the first pieces of nastiness out on the internet. And that was early nineties.
[00:04:41] My business that I owned and was running, got hit with this thing. Even before that, There was ran. There was a nasty where viruses, if you will, that would get on the computer and destroy everything. It was just a malicious, as I remember, somebody at UC Berkeley, some researcher in it. And he didn't like what that of the researchers were saying about him.
[00:05:03] So he put some floppy disk together and on them, he put. Erasing malware and shared all of the stats with anybody. And of course, you plugged that disc into your, that little floppy disc into your windows computer. And it says, okay, I'm going to go ahead and open it up. And, oh, look at this, a virus.
[00:05:24] And so he then wiped out the computer of everybody else. That was a competitor of his out there in the industry. Yeah, a little bit of a problem if he asked me, so how did that end up getting around? What ended up happening while everybody got really upset with him, nobody really found out what was happening, who did it, et cetera.
[00:05:47] That's what's happened. Now, so version three of malware is like some of the very first malware we ever saw version three of ransomware. So some, again, some of that very first ransomware was pretty nasty is not the sort of stuff you want to see running destroying files, but at least you could get back from a.
[00:06:08] Nowadays, a lot of people are doing backups by attaching a disc directly to their machine, or they're backing up to another machine on the same network. Remember that whole east west thing, you didn't want the data going back and forth, it causes problems. Yeah. So what happens now? The Russians apparently are just trying to cause havoc with businesses, anybody who has decided that they're going to be anti-Russian in any way there they're attacking.
[00:06:41] So they'll, reraise your desks. They'll erase all of your data. If you have backups on that thumb drive or that USB external. The good news erase that if you have backups on another machine, on the network, hopefully from their standpoint, there'll be able to get onto that machine and erase all of your backups, which is again, why we'd like 3, 2, 1 backups.
[00:07:02] At the very least, there's some others that are even better. And if you're interested, send me an email [email protected]. I'll send you a webinar that I did on this. I'm not charging you for. But it was a free webinar to begin with what a webinar on backup and how to backup properly and why to do it this way.
[00:07:22] Again, me, M E Craig peterson.com. Be glad to do that. What we're seeing now is a huge problem. Let me see if this is going to work for us. Yeah. Okay. It is. I am, by the way, live here we go on my computer. So people who are watching. I can see my desktop. So here we go. This is Russian companies who are linked to this Russian malware.
[00:07:52] Ransomware are hiding in plain sight is what they're calling it. So what does it mean. To hide in plain sight. While in this case, what it means is money that's been paid by American businesses to these Russian ransomware gangs, some of who by the way, are actively going after anyone that criticizes Russia found these American researchers.
[00:08:18] Yeah. Led to one of Moscow's most prestigious addresses. You can see it up here on my screen. This is a New York times article. It's just a random actor, journalism people, sometimes even the New York times gets it. And they're saying millions of dollars have gone through this. So they've been tracing.
[00:08:38] Where did they go? The Biden administration has also apparently zeroed in on the building is called Federation tower east. It's the tallest skyscraper in the Russian Capitol. How would that be to have a business and just this beautiful tall skyscraper and have a view that would be really cool. So they have targeted some companies in the tower.
[00:09:00] As what it's trying to do is stop the ransomware guy gang. Maiden cryptocurrencies. Russian law enforcement usually has an answer to why don't you just shut down these bad guys that are out there trying to steal all of our money. They say there is no case open in Russian jurisdiction. There are no victims.
[00:09:19] How do you expect us to prosecute these honorable people? That apparently is a quote from this Massachusetts based secure cybersecurity. Called recorded future, but I'm looking at a picture it's up on my screen right now. You guys can see it, but this is the Moscow financial district called Moscow city.
[00:09:38] 97 floor Federation tower east. This is really pretty, you wouldn't know this isn't like London or any other major European capital. There's some cranes in the background building up new buildings. Cyber crime is really fueling some growth there in Moscow, which is, if you ask me the exact reason why lad is happy as a clam to just go ahead and have these Russian cyber crime guys.
[00:10:11] Just go and bring money in right. Money is bringing in great money for them. The treasury department, by the way, it's estimated the Americans have paid $1.6 billion in ransom since 2011. Huge one ransomware strain called RIAA committed an estimated $162 million. Last year. It is really something.
[00:10:35] So when we come back, we've got a lot more to talk about. We're going to talk about the cloud. If it's more secure or why is it calm, broken, give masks work. Why aren't they working right. Anyways, we'll talk about that. When we get back and visit me online, Craig Peter sohn.com.
[00:10:54] Stick around.
[00:10:57] I hate to say it, but there's another big scam out there right now. And it is hitting many of us, particularly the elderly quite hard. We're going to talk about that right now, what you can do about it and how you can recognize when it's happening.
[00:11:13] Interesting article that came out in Wired.
[00:11:16] And it's talking about a serious problem. I'm going to show you guys who are watching I have this on Rumble, YouTube, Facebook as well. So you guys can see a long and of course, right here, a two.
[00:11:30] Now let's not forget about that, but this is an article that says we were calling or excuse me, they were calling for help. Then they stole. Thousands of dollars. I'm going to read parts of this article. It's just amazing. It's by Becca, Andrew's a back channel. What is that? Okay, so that's just a cat.
[00:11:52] On December more one December morning, my mother's phone rang. She tugged the iPhone from the holster. She kept clipped to the waist, her blue jeans and wondered who might be calling perhaps somebody from the church who was checking in on her recovery from coronavirus. Hello. She said the voice that greeted her was masculine.
[00:12:12] This is just great writing. The color sounded concerned and he told her something was. With her Amazon account, somebody has access to your bank accounts through Amazon and they can take all your money. I'm calling to them. Her mind raced or Lord, she prayed silently. The voice was warm and reassuring them.
[00:12:34] My mom tried to focus closely on his words. My dad was driving to work in his truck and she was home alone. She'd been cooped up in the house for weeks with COVID isolated from her community and she missed the bomb. Friendly voice. I just love her language here. It's just phenomenal. She tried to steady herself.
[00:12:55] The man said he needed to make sure the money was safe. He transferred her to a different male voice. Soothing reassuring, calm. She promised not to hang up a brain injury decades earlier, made it hard for her to follow his instructions, but she stuck with it. The voice explained slowly, carefully, how to swipe and tap her phone until she had installed an app that allowed him to see what was happening on her screen.
[00:13:26] Now. You followed her every move. After some hour, she mentioned she had to relieve herself hours. It's okay. I'll stay on the line. He said she parked the phone, outside the bathroom and picked it back up. When she was done, as noon approached, she told him I have to eat. I'll wait. It's okay. Don't hang up.
[00:13:47] We'll lose all our progress. She set the phone down on the counter to make a sandwich, then pulled some chips from the cabinet and padded over to the kitchen. The phone buzz with the text. It was my father checking in. She typed back that there was a problem, but she was fixing it. She had it all taken care of.
[00:14:07] She tapped the tiny white arrow next to the message field to send her reply. And then she heard the voice, its volume elevated as sounded angry. She frowned and brought the phone back up to her ear. Why would you do that? You can't tell anyone what if he's in. She felt confused that didn't make any sense, but she also didn't fully trust herself.
[00:14:29] She was worn. From her slow recovery and the steroid, she was taken as a treatment, gave her a hollow buzz of energy. Now I want you guys to go have a look at this over on wired site. Read the whole article. It is a phenomenal. Absolutely phenomenal. But what it's doing is telling the story of this woman who was trying to, do the right thing, trusting other people, which many of us do?
[00:14:59] I have a default trust with a little trepidation. I will admit that, but with the whole. Down the thing that happened, many of us have just been longing for a little bit of companionship and to hear a stranger who's trying to help out. That's a huge plus it goes on in this article and talks about how reassuring these guys were and what they did.
[00:15:25] She installed this cash app and opened up PayPal downloaded. Coinbase set up Zelle so she could send money directly from her bank account. She doesn't know about any of these things. It's just incredible. So the afternoon wore on and the guy said Hey, we're almost done. And her husband of course, was on his way back.
[00:15:49] And the sun was down. Father got home. He noticed right away that something was off. And she said she took care of it. And you said you took care of what I'm not supposed to tell you. It said, so this scammer had siphoned away. All of her personal information, the scammers had your social security number, date of birth driver's license number, and about $11,000.
[00:16:14] These new financial apps like Zell and others that are legitimate PayPal apps, right? Zell, you can use to send money legitimately to someone else. But it links into your bank account. That's why I don't like them. I have a friend that's been pushing me. Oh, this happens. Great. It saves you so much money on gas.
[00:16:34] Look at how much money I've saved any. He sent a screenshot of it and I re I went online and had a look. And guess what? I read, reviews it again, like this tied into her bank account directly. And. What can happen? Like here, everything was emptied. So in the next few months this author of the story and her father tried to undo the damage.
[00:16:59] Very frustrating, getting scanned of course, is really dehumanizing and it just breaks your trust and other people. How could someone do something like that? It's just incredible. Got to go through the stages of grief and everything. She got a, she talked to people, she said she got chili half replies, or just as often silence.
[00:17:24] And she was calling around trying to find someone with some empathy. Okay. It's just incredible. Great article. If you can still find it, the March issue of wired, I'm sure it's available online. This goes on. And talks about her mother's seizures getting worse. And of course now they don't have the cash that they had been saving.
[00:17:46] And it just very depressing. Now I have this, you might remember about a year ago, I talked about it. I had something like this happen to a friend of mine and I'm still not quite sure what happened, but it looks like it was a password sprain or password stuffing. And they got into his, the app that his company uses to pay people and sure enough, they got in and they directed his next two paychecks to their own account, which went right out of the country like that.
[00:18:24] These are bad people. And how do you deal with this? It's incredible because if you've got someone like her mother who has mental problems due to no fault of her own and is a very trusting woman, what do you do? She's walking around all day with her phone on her hip. That's how we started this out.
[00:18:46] Do you take that phone away from him? Th that would be dangerous, frankly. So this is a very problem. They had a USAA account was her bank account. USAA is usually good about this sort of stuff. In fact, my other friend had USAA as well. But they did help deactivate Zelle, but they didn't do anything about the $999 that were transferred through it.
[00:19:10] Very bad. So they figured out maybe we should change our passwords. She had them change them. And if you would like information about password managers, again, I'm not selling anything. I'd be glad to send them to you. If you sign up for my email list, you're going to get them automatically. Craig peterson.com.
[00:19:30] I've got a bunch of data information I want in your hands. It talks about the free stuff, talks about the paid stuff. None of which I'm selling you. Craig Peter sohn.com. Sign up right there on the top of the page. Thanks. Stick around.
[00:19:51] We've had some serious supply chain attacks over the last couple of years. And they have caused all kinds of problems for tens of thousands of businesses. If you use WordPress, there was one of those this week.
[00:20:06] We have had supply chain problems. Like you wouldn't believe. So let's start out by explaining what is a supply chain problem?
[00:20:17] In this case, we're narrowing it down to cybersecurity because we've had supply chain problems from everything from our toilet paper to the food we eat. But what I'm talking about right now is. Supply chains when it comes to cyber security. And one of the biggest problems we had was a company that's supposedly providing cyber security for businesses, right?
[00:20:48] Some of the biggest businesses in the world. And I'm looking at an article right now from security Boulevard, say saying how to protect the supply chain from vulnerable third party code. It can be a script that's downloaded online. It can be an open source library. We've seen big problems with get hub lately and pulling in libraries.
[00:21:10] We've seen big problems with what are called containers lately, which are little mini versions of computers with all of the software. They're all ready to go. Ready and raring to go. All kinds of supply chain issues for a very long time now. And these supply chain, cyber attacks have been hitting some of our cybersecurity companies, really the hardest I'm pulling this up on my screen right now, if you're watching this on rumble or on YouTube, and you can see links to those, by the way, in my emails, I send out every week.
[00:21:47] Craig peterson.com. Craig peterson.com. But you can see here, supply chain hits cybersecurity hard supply chain security is not a problem. It's a predicament. That's uninteresting look because we have to use some of the supply chain stuff. Seesaw the FBI or a sheer wean cybersecurity advisories because of the Russian attack over on Ukraine.
[00:22:14] And then the U S the weakest link in supply chain security fears of rising fuel SISA FBI NSA and gestural partners. Issue is advisories Toyota stops production after possible cyber attack at a supplier. Isn't that something this goes on and on. What's a guy to do, right? Many of us are using websites to, in order to run our businesses.
[00:22:43] Heck we got websites for our soccer team, for the kids, we got websites for pretty much everything that's out there today and those websites need software in order to run. So the basic idea of the website is nowadays. Content management system, they called CMS CMSs and there have been a lot over the years.
[00:23:05] I've used quite a few myself off and on. This is very interesting though, because this particular piece of. Is code that runs a website. I'm going to show you this article from ARS Technica here on the screen, but it's talking about millions of WordPress sites that got a forced update to patch critical plugin flaws.
[00:23:32] So when we're talking about supply chain, in this case, we're talking about something. WordPress right. And this WordPress software as good as it is, can have bugs. So WordPress is the content management system. So you load stuff up into, in fact, I'll bring up my site right now. So I'm going to bring up the Craig peterson.com.
[00:23:55] And on my site, I have all kinds of stuff, which is why it's so slow to load. I've got to fix that one of these days, but this is an example of a WordPress site. So you can see right at the top of the site, I've got watch this week, show jobs, or top, of course, that was last week. You can watch it on rumble or a new tube, and then it's got my latest show.
[00:24:18] So if you click on one of these, here you go. And you can listen to it. Starts right out here. C ta-da. So there, you can listen to my podcast right there on the site, and I've got an automated transcript of it. It's for you, depending on what you want. It's got links over here to take you to iTunes or YouTube or Spotify or SoundCloud or iHeart or Google player audible.
[00:24:45] All of these links take you to different places. And this site in survey, Program a site in HTML. What we're doing is we're working. Putting some data in, so we say, okay, I want a default page. Somebody else has already set it up. Somebody else has already got an old program. It just works. And it's all right there for me.
[00:25:08] Here's some related posts on the side. Here's the most popular ones that we have right now. This is a content management system. And specifically this of course is WordPress. So what happened. If I had a, yeah. And here's what it looks like over an audible, you can listen for free on. This is what happened this last week, WordPress, which has this great software that I use and tens of thousands of others use out there very popular.
[00:25:46] And in order to make it easy for me to have my website, probably your business, probably your kids' soccer club, you name it is using WordPress. It's just over the top hop healer. It is using code that was written by other people. The reason we can make programs so quickly nowadays is we're relying on other programs.
[00:26:10] So we'll go ahead and we'll grab this program that does this part of what we need to have done, and ta-da we're up and we're running. I just have to write the glue right? To put it together. The API calls, whatever it might be, because the idea is let's make it easier for programmers. So you've got something called get hub here.
[00:26:30] Let me pull it up so you can see that you can go online if you're following along. To get hub.com. And as it says right there on their front page where the world builds software as a beautiful world, isn't it? That blue, you can see the air around it. And that's what it's doing is where the world builds software.
[00:26:51] So let's say we want something. What do we want? What's a, let's say we want something to make a chess program. We can talk about chess and let's say, oh, you have to. Dan didn't want to do this, so I'm just going to skip that for now. But it would come up and tell me, okay here's all of the chess programs that are out there and I find one, that's close to what I want to do.
[00:27:13] So what do I do? Point while I go ahead and have a look at the license, a lot of the programs up there have a very open license, so I can just take that code, modify it. And I have a chess program without having to write a chess. It's really that simple that's part of the supply chain. If you bought my chest program, you would actually not just be getting the code that I wrote, which is typically just glue code with maybe some API APIs or application programming interfaces.
[00:27:44] In other words, you're using someone else's code would now make it who's program. It's like the Pharaoh's barge. It would make it other people's programs. Not my. So you got to figure out what's in my supply chain. I've got a new client. I do work as a virtual chief information security officer.
[00:28:05] Actually, it's a fractional Cecil. And as a fractional Cecil, one of the things I have to do is look at the whole supply chain. Who are they buying even physical things from. And could there be. Did it into their software, into their systems, something that might be coming from yet another supplier. Man, does this get complicated?
[00:28:28] Very fast, but this week, our friends at WordPress, they went ahead and forced all WordPress sites to update. Very good. Okay. Otherwise, people could have downloaded a full backup of the sites that are out there, something you really just don't want to happen. Anyways. Go right now, Craig Peter sohn.com while the bits are still hot and sign up right there.
[00:28:55] Craig peterson.com for the newsletter and get those special reports that are going to get you started.
[00:29:02] This is the moment you've been waiting for. We're going to talk about free cybersecurity services and tools that you can use. Now you have to be a little bit of a cybersecurity expert to use them, but not much. This is from the government.
[00:29:18] This is I think an amazing thing. This only came out within the last few weeks.
[00:29:26] I have it up on my screen. There we go right now, for those of you who are watching on Rumble or YouTube, you can see it right there, free cybersecurity services and tools from. The cybersecurity and infrastructure security agency SISA reminds me of Marvel was shield, that really long name that came up with an acronym for as though they weren't aiming for that acronym in the first place, but there are some tools that you can use there's tools that I use as a cybersecurity professional.
[00:30:01] And some of them are obviously going to be pretty darn. Complex. And if you're looking at my screen right now, or if you want to go online at csun.gov/free-cybersecurity-services, dash, and the as tools, or just look it up online, you'll find this on my website as well. I'm going to try and make sure I get that up.
[00:30:26] But what they have done is they're showing you what they call their key or the known exploited vulnerabilities. Okay. And this is where they are showing the CVEs, which are. The frankly, these are the ones that I use. It is published by nest, which is the national institutes of standard and Sanders and technology.
[00:30:50] And this gives all of the details. So this is CVE 20 21, 27. Okay, and this is detail, and of course I would be using detail. And it's telling you, here's the advisories, there's one from get hub Excel. Leon has one. Here's the weaknesses, the SA the known soccer configurations. So you can find where they all are at and everything.
[00:31:15] So all of the details. So they're telling you about that. These are the ones, this was in the vendor product. Project, I should say. So we'll look at the data added to catalog. Here are a few in Cisco right now. So this is their small business series of routers, which we do not use for anyone because they don't provide the type of security you want, but Cisco is taking care of the problems, right?
[00:31:41] Many of these update themselves, here's Microsoft windows. And installer contains an unexpected unspecified vulnerability, which allows for privilege escalation, a lot of stuff this week, this is crazy Apache Tomcat, which I am never been a fan of and problems. So all of these came out. On March 3rd and more rights.
[00:32:05] This is just page one. So let's look at page two here. Oh wow. More Microsoft Excel exchange server, some more Cisco vulnerabilities. Why Cisco? Why Microsoft? Because they are frankly. The big boys on the block, that why do you Rob the bank? Because that's where the money is. So they list all of those right here, as he said, does the warning you do use multifactor authentication?
[00:32:34] I don't want to sound like a broken record, so I'm not going to say use multifactor authentication today. Okay. I just refuse to say use multi-factor authentication. And this one talks about what it is, right? Many names. Now they're trying to make this. But really a Fido key, fast identity online considered the gold standard or multi-factor authentication Walt for online.
[00:32:58] It is websites, but not for authors. So how would you know that if you weren't an expert? So yeah, this is the government talking, right? So they have the service. So what does, what do I do right? Me, Mr. Idiot. I click on this and they are talking about the service that they've got them showing it up on the screen.
[00:33:20] It's called SISA insight. And they're talking about website, defacement, destructive malware, or not Petya want to cry, right? All these things. What can you do to prevent it? And. They make it sound easy. Now I want to say something here because I, I have a couple of mastermind groups and in one of my groups, I rescued a group member from a 40 something thousand dollar loss.
[00:33:50] And so I was explaining it in our next mastermind meeting. Cause everyone wanted to know. What should I do? How should I do it? And they all tuned out and I thought I was trying to, I was being simple enough. I was trying to be simple, not like simple, like Kamala Harris explaining that Ukraine is a country beside right next to another country called Russia.
[00:34:14] And that's why there's an invasion. Okay. I couldn't believe that. Did you guys hear that? It was just incredible, but I didn't get that simple. And I know you guys are the best and brightest, and you're trying to figure this, all this stuff all out, and that's why you need to make sure you sign up for my email list right now, because I do have simple step-by-step stuff.
[00:34:36] And these tools that they're talking about and services are supposedly available. Now, I went to a bunch of these. And I tried to get some services. So they said they'll do a free scan over the network. So I filled it all out and according to their standards, my company, because I do cybersecurity for everything from government contractors, through dentists and manufacturers and distribution companies.
[00:35:09] So I, I. The critical infrastructure definition. And I have never heard back from them. I check my spam box at least once a week looking for their reply. So I don't hold up a whole lot of hope, but there is some good information here that you can get email via social media via just all of these different types of things that you.
[00:35:34] You could use for it. And again, I want you to look for it online. It's on csun.gov. If you go to their homepage, you'll see their tools, they've got a shields up a warning right now on their homepage because there have been so many attacks coming from China and coming from Russia, but particularly Russia.
[00:35:54] And you can see there. Stop ransomware.gov, which has some great tips, particularly for home users and small businesses. The Seesaw culture, height, hygiene services. That they have doing business with CSUN and careers they're looking forward to is okay. It's part of Homeland security. So there's a whole lot that you can do and you can find, but I wanted to let you guys know that this is out there.
[00:36:24] A lot of the stuff guaranteed is going to be. Above 98% of people's heads out there. Just in general, even it professionals. So look for information, that's going to help you. That's on your level. And to that end we have right now, three things. If you sign up for the email list, or if you're already on my email list, you can just email.
[00:36:50] [email protected] or just hit reply to any of my emails and I'll see it and ask for them. But we've got stuff on your computer, keeping it secure, keeping your password secure comparison between using a one password manager or using last pass, which I am not advising to use right now, but that's in there.
[00:37:14] There are a lot of different things that are there that are ready for you to get right away. And then if you have other questions, I've got dozens of little special reports that I've written in response to people's questions. Don't be afraid to send them to me. I'd you know [email protected] and I'll make sure I get you an answer because it's that important.
[00:37:39] Okay. I'm not here trying to sell you something. I am here because most of you guys can could never get my services. You don't need them. You can't afford them, whatever. I'm a fractional Cecil. I'm one of the guys that keep. It was a cyber security working in a live for businesses. Like it's not going to be everybody, but it's, it is there is, I shouldn't say a lot of information you guys need and need to understand that I want to help you. Okay. I think I've beaten that horse enough and it was probably past dead, but you'll find some of this stuff on my [email protected].
[00:38:17] I've been working on some other changes to it. I would also ask you guys. If you're hearing part of the show today, I know a lot of people who are listening on the radio are tend to be out and about in their cars, listening, on the weekend, I listened to a lot of radio then, but go ahead and subscribe to either my podcast.
[00:38:38] And there are a lot of ways to do that. And I showed those people who are watching on video, how to do that. And if you would give me a five star. On whatever platform you're using, hopefully I've earned that. And then also if you'd like video, I have my whole show up. It's like about an hour and a half long on multiple platforms.
[00:39:04] So rumble.com rumble, R U M B L E. Is a competitor to YouTube. So if you don't like censorship, if you want a site that is trying to keep that information out there, get it out there for you. A rumble is your place. You'll find all kinds of interesting characters there other than myself, right? A lot of conservative people go there to rumble.com.
[00:39:28] I have it up on YouTube. Because YouTube, isn't the worst platform in the world. They're also not the best, but they are the biggest. Did you know, YouTube is the second largest search engine in the world. Okay. They have a lot of people on YouTube and then on Facebook as well. You'll find me there on Facebook.
[00:39:48] Of course, Craig Peterson, I had. I excuse me at facebook.com/craig Peterson. And I didn't use it for a long time cause I hated Facebook. Just, I looked at it as a time sink that I just didn't need. I got a lot of stuff. I got a lot of people help and so I didn't really do anything with it. And so somebody else got the slash Craig Peterson, but I do have a trick for you.
[00:40:12] If you go online with your web browser to Craig peterson.com. That's my website slash. YouTube. It'll take you right to my YouTube page. Ores Craig peterson.com/facebook. Yes. What do your Facebook page? Craig peterson.com/itunes. Good slash sound cloud, et cetera. It'll take you right to my page on all of those sites and have a look at the video.
[00:40:41] Let me know what you think. I would appreciate that feedback and make sure you tune in on the radio too. It's great. Don't watch this while you're driving to taking the kids to school, a lot of people listen to this while they're taking the kids to school on podcast. Anyways, take care. Thanks for being with us.
[00:41:01] By now you've heard of tick talk. You might use Tik TOK. A lot of people do. It's their go-to site online, especially if you're a little on the younger side. Here is a danger of some of these tick talk challenges and combine that with Alexa. Oh my
[00:41:17] This is a little bit on the scary side. We built our house some 25 years ago, we contacted a builder and I put together all of the specs and I made sure that the wood he used was better than average.
[00:41:33] It's all plywood, it's not particle board or the composite boards. And I made sure they were thicker than need be that all of the rules. Struts were were closer together than code required. And we had bigger plumbing than what was required all the way through the house. And one of the things I did is I had him wire the house, actually the electrical contractor with a heavier gauge wire than usually.
[00:42:05] So that I had 20 amp sockets at every socket in the house. Now we put the special 20 amp sockets on some of them, like in the kitchen, we have a commercial toaster, as a sort of thing you need, when you got eight kids and a half of our married life, we had other families living with us too, that we were helping out everything from training through just getting them through.
[00:42:29] Bot. So there were times when we had 20 plus people living in my house, it got gotten it crowded, but I wanted to make sure everything was above code so that it would work well and work well for us and knowing how much juice we tend to use. Yeah, you don't want to see my electric bill. I decided yeah, let's do the heavier gauge wire and let's put the sockets in one of the things I had the electrician do in order to make the sockets a little bit safer.
[00:42:59] This was back before you had these. I, frankly, I hate them, but these safety sockets where you push in the plug in Erie really gotta push it in order for something to get plugged in. There are ways to defeat those safety sockets and that's where this problem comes in. I had him install the sockets.
[00:43:21] You might consider them to be upside down. So the top of the socket had the little grounding. And then underneath that you had the hot and the neutral lines. So the idea there was, while if something fell onto a plug that wasn't plugged in all the way, or if the kids decided they'd stick something on it, it would go to ground or made sense to be.
[00:43:47] And apparently it's worked because none of my kids are dead yet. So that's a good thing, there's these challenges on Tik TOK. You've probably heard of them. In fact, that's how they really got themselves going. They had that, that ice bucket challenge and many others that people were doing and they continue to this day.
[00:44:09] One of the tick tock challenges is very stupid and dangerous. And that's where this article from ARS Technica comes. Eric Bankman wrote. The when was this? Oh my gosh, this is right at the beginning of the year, apparently a 10 year old girl and her mother used Amazon Alexa. And what was happening is the kid wanted some challenges.
[00:44:34] Mom wanted some challenges and they were doing a whole bunch of things. Physical challenges, like laying down. Rolling over a holding a shot on your foot from a phys ed teacher on YouTube. And the girl just wanted another one. So for those of you who are uninitiated, the plug challenge consists of.
[00:44:57] Partially plugging a phone charger into an electrical outlet. Now the phone chargers usually do not have a grounding pin. So my little work around of mounting, all of the sockets upside down wouldn't matter. Cause if you look at that a little charger plug, it's usually just two pins and it actually usually doesn't care about the polarity.
[00:45:19] It doesn't have the bigger the side and the smaller side, the. Yeah. I can't remember what they call now, but if they're both the same size, so you can put it in either direction, the spades that you put in. So if you put it in part way, you have defeated the safety mechanism, that's in all of these modern plus.
[00:45:41] So you put it in part way, you have to push hard and in it goes, and then you pull it out part way. So that's part one. Can you plug this phone charger intellectual outlet part way so that those two conductors are exposed and then yeah. Then they ask you the challenge is to drop a penny onto the exposed prongs.
[00:46:11] So you can get anything from a small spark. That little coin may jump off to a full-blown electrical fire. Now mom was there and she yelled. No Alexa, no. And the daughter said she's too smart to do something. Anyway, and I'm looking at a picture here that ARS Technica published of a wall socket, where a short had happened.
[00:46:37] This wall socket is mounted sideways. I don't get that. And the hot side is up. So anything falling against the sock and by the way, the faceplate is metal. And grounded, obviously. So anything falling onto a plug that's only partially plugged in because the sock gets sideways. It falls onto it. It touches the metal face plate, and you've got a fire Bruin.
[00:47:08] So they've got a picture of one of these in a house and you can see where the smoke went up. Now. I don't think the whole house caught on fire here, but it was a major zap. It reminds me of the days when we had. The fuses in the basement. And if a fuse blew, all you really needed to do is go down there and stick a quarter in it.
[00:47:28] And you're fine, which means it's defeated the purpose. Anyways, you gotta be careful. At Amazon confirmed in a statement to the BBC that it has removed that particular challenge from Alex's database. Obviously these are computer generated and they're based on Tik TOK, idiots. You shouldn't be using Tik TOK for a lot of reasons.
[00:47:55] One of them is it has been alleged that they have been spying for the Chinese. It is a Chinese company. It's part of 10 cent. And the, there's just a little stupid thing. So Amazon said, as soon as you became aware of this error, We took action to fix it. So again, you can't necessarily trust your kid at home with a, an Alexa doing challenges.
[00:48:20] I just can't believe it. It's just incredible exactly what happened here. Hey, I want to give you a real quick tip. Last week, we went over how you can find out. If your computer has been hacked, basically. In fact, we were a little bit more specific. We said, okay, what I want to do here is know if not just the computers have been hacked, but as someone's stolen my.
[00:48:50] Email and or my password. And we explained why and everything else. Then if you missed it last week, you can just go right ahead, online to to oh my I'm just having man's beginning of the year, right? That's what happened. Go online to Craig peterson.com/itunes or slash your favorite podcast player.
[00:49:11] And you can listen to it there. So really good little article from. And make use of technology. And they're talking about what are some of the things you can do? You should do. You shouldn't do when it comes to external GPU's and now if you are a regular computer user, you don't even need one of these things and people might've tried to talk you into it.
[00:49:38] Now, also that GPU is these graphical processing units are built into all of our computers nowadays. All of these new computers that our friends at apple have come up with, have some amazing GPS built into them. Those are great. They're used to update your actual windows screen that you're looking at hate Microsoft for stealing words like windows, mean things anyways.
[00:50:05] But the external GPU is something I use on my main production workstation. So I've got GPU's they work great. And when I'm processing video and doing the edits, and then the final renders, that's when an external GPU comes in. So I can guarantee you if you don't know what I'm talking about here, I guarantee you.
[00:50:31] I need an external GPU. Now the couple of other things to know, if you are looking for an, a GPO of any sort to build and put in your existing computer to build in somewhere else, the GPU's are difficult to get right now. And part of the reason for that is so many people have been using them for mining cryptocurrencies, because they're quite good at that.
[00:50:57] Now there's special hardware that's being made. To mine, cryptocurrencies, but GPU's frankly are great little work around for anybody that just has a basic computer and wants to try and do a little crypto mining. So you're going to have a hard time getting a hold of these. GPU's just like many other chip sets out there and my own personal experiences.
[00:51:21] I don't need the top end one because of it takes a few extra minutes to render something. When I'm making a video, it's not a big deal, cause I'm not making videos all day long. So a little tip for you on GPU's and external GPU's. And do you need them, what should do. Use them for, Hey, I am doing some training every week.
[00:51:45] Kind what we just did just now, but about cybersecurity and other things in my weekly newsletter. So make sure you sign up Craig peterson.com AU. And if you could, and if you are a podcast listener, like to invite you to subscribe to my podcast, you can find it at Craig peterson.com/itunes.
[00:52:08] We've got the end of a era for a device that was considered to be quite secure. In fact, some of our presidents, particularly the one that comes to mind is president Obama used it extensively, and it isn't what it was.
[00:52:25] This device that I'm thinking of right now, and we'll see if you can guess what it is, but it was extremely popular.
[00:52:33] It was for sending and receiving messages that even had some other functions, but it was mainly an email thing. I remember having a couple of those back in the day that was strictly email. They were, they actually nice. And then of course texting came along and they kept up with the times a little bit.
[00:52:51] What we're talking about is the end of the line. This was a Canadian company, a company that was well-known worldwide by the name of rim. They were providing the Blackberry operating system. They had servers that were designed and built to be secure. So you could rest assured that all of your data was safe, no loud you to send and receive emails.
[00:53:25] And it had that wonderful little click keyboard on it. Something that went the way of all the world. That keyboard is now gone and it's gone for good as has the ability to use some of those blackberries that you bought over the years to keep yourself. I just had to play taps underneath that, but it's just incredible.
[00:53:53] It is the end of the day for the company, the once dominated the entire smartphone business. If you didn't have a Blackberry, you weren't cool and you weren't secure or secure. And you weren't able to communicate as easily. They were actually. Excellent little devices in their day. I want to add another note here when we're talking about secure, because Blackberry was very big and saying, Hey, listen, it's very secure.
[00:54:23] It's all encrypted. We keep all your emails, encrypted, all your communications and gripped and what we found out by the way, is it turned out that the Canadian government, basically the equivalent of the FBI, CIA NSA had the master key for all Blackberry messages. And not only did it have the master key, it shared the master key with the United States secret agencies, the end of the.
[00:54:55] CIA, et cetera. So if you were thinking you could use your Blackberry and keep your information safe, you are wrong. You remember when president Obama was elected? One of the first things they scrambled for in the tech business was how do we secure our. Mary. And of course all kinds are not our Blackberry, his Blackberry, all kinds of rumors erupted that, it was people controlling president Obama and they were using the Blackberry and they're using it because it was secure.
[00:55:24] You, do you remember the whole uproar around. And the biggest problem was obviously our intelligence knew that they weren't secure and they could read any message they wanted to, as well as the Canadian government. And remember the whole five eyes thing back in the day, these five different governments that shared information on their own citizens.
[00:55:47] So it was a real windfall for the United States because Canada was. EV all of this shop software was developed for the Blackberry. It's where all of the servers were located and data could easily be routed to Canadian servers away from us servers if they wanted to monitor somebody. And so Canada was the one spying on you, technically not your government.
[00:56:10] They'd never do that. So it was an interesting time, frankly. As of January 4th, 2020, These Blackberry phones will no longer be provided with provisioning services, which means they are going to gradually lose the ability to join networks, including the cellular network, by the way. So it's man, it's something that many kids.
[00:56:41] I have never even seen. And I look at it and just think, I remember envied some of the guys that had the blackberries at the time. And I had a couple of other little devices, keyboard driven that were from people who have been guests on my radio show. And I really liked those, but in the Blackberry was just crazy expensive as far as I was concerned.
[00:57:04] But Blackberry's leadership really messed up. The guys who are developing Android at the time realized, oh, wait a minute. The iPhone is a pretty popular. It's going to be extremely popular. So Android then they mimic the Blackberry at first, made it look like a Blackberry. And then they switched over and made the Android operating system be like an iPad.
[00:57:33] So they can pick, can beat with it, but Blackberry didn't see any of this coming. And it took over a year after the iPhone came out for Blackberry, for rim research and motion to come up with its own touchscreen phone. And the software was really quite a mass where they tried to. Basically crowbar in some new features and they had the old features.
[00:57:58] They're still incorporate users during this whole time were falling into love with their apple phones and then eventually the Android phone. Told their IP department, it departments that they needed to support the iPhone and the Android phones. And so they did, and Blackberry eventually gave up on its own phones and they started releasing Android versions.
[00:58:23] Do you remember those, the Android phones from. Mary, they got out of the hardware business entirely. And now what they're doing is they're trying to promote corporate security services. And that's really what they're trying to do. It's a new claim to fame. Yeah. Remember I just told you last time they were promoting that they were secure.
[00:58:44] They weren't at all. No, they were to some extent, but so the last version of Blackberry opera and he said, The very last release that they had was in 2013. Yeah. 2013 year that hold. So the devices affected here by this shutdown are by all standards, extremely low old. And remember you got to get security updates.
[00:59:09] So these machines, I can't even believe this still online when Blackberry hasn't given an update to them since 2013, that's almost a decade now, nine years. So if you're still using it stop, and if you're trying to figure out what to use, get an iPhone. And if you say, oh, Hey, films are too expensive. Don't get the latest, greatest iPhone.
[00:59:33] Get a slightly older one because they are supported for five or more years out, unlike everything else out there now, although. We now have Samsung promising some longer support, like five-year support for some of the devices. So we'll see how that ends up going. But frankly, Blackberry, they're done for.
[00:59:55] It's a shame. So there's a handful of software services that relied on the Blackberry servers to function. So if you were using Blackberry world or Blackberry link, those also stopped functioning on the 4th of January and the number of people still using it. I don't know. When was the last time you saw a Blackberry and have you used one I'd love to hear from you go ahead and drop me into the.
[01:00:23] Craig. Yeah, exactly. [email protected]. Let me know, did you have a Blackberry or were you still using one? And did they bother telling you about the shutdown that was coming up, but this is it. This is the end of what was a very significant technology. So here's to blackberries. All right, stick around everybody.
[01:00:52] Make sure you are on my email list. I'm going to do something new too, with the list. I'm going to start sending you my show notes. Now you can opt out of the show notes, just the show notes, if you want to, but expect to start seeing them show up in your email box. And this is the same show notes I send out to all of the radio and television stations I appear on because it's the most important news of the week.
[01:01:20] Artificial intelligence is making its way into all kinds of aspects of our lives. And one of them that concerns me maybe the most, in some ways it's a benefit and others is AI in the criminal justice system.
[01:01:36] China has developed what it's calls an AI. Or artificial intelligence prosecutor.
[01:01:44] And they're saying that they can identify dissident and press charges for common crimes with 97% accurate. Now that is a very big claim. And the whole idea behind this is their servers services. If you will, in the court system are overloaded. We have the same problem. Most countries have the same problem.
[01:02:11] I was just looking at India. They've got some 37 million backlog court cases. Absolutely. Phenomenal. So the system now in China can press charges for Shanghai's eight most common crimes. There runs on a standard PC and it takes part in the decision-making process. They say, although apparently it's actually making their decisions, but there are fears.
[01:02:40] The machine could be weaponized by the state. Now it's interesting. Looking at the actual charges that it's designed to press right now, they're saying that it was trained using 17,000 real life cases. And it's able to identify and press charges for the eight most common crimes in Shanghai. These include provoking.
[01:03:08] Now that's a term used to stifle dissent in China credit card, fraud, gambling crimes, dangerous driving theft, fraud, intentional injury, and obstructing official duties. In other words pretty much everything, right? You go against the government. It's just going to charge you. And that's what they say high prosecutor's going to do.
[01:03:31] Now I'm looking to it. Some more details. From the management review journal. And they're saying that the system can replace prosecutors in the decision-making process to a certain extent. Now let's look at some other countries we've got, for instance, Germany, and they're using image recognition and digital forensics to help with their case loads.
[01:03:58] China's using a system. No. System 2 0 6 to evaluate evidence a suspect's potential danger and conditions for arrest. Now, we've had some really weird things happening here in the U S with our criminal justice system. Some of them are absolutely idiotic. But things like just letting people out the same day that really should be held because they committed a moderately serious crime.
[01:04:23] And we just had cases just at the end of 2021, where we had people. Who had been arrested and got out that same day and then went on to commit serious crimes, rape, murder, and other things. So what are we doing here in the U S unfortunately we have found out that in the us, we are monitoring the.
[01:04:52] The funds that people need to put up that are called bail in order to be released from jail. So normally you'd go in front of a justice of the peace and maybe a court clerk, and they would look at what the charges are or what your background is, how sticky you are in the community, family, business ties, et cetera, and then set up.
[01:05:18] So you now put up the bail cash or otherwise, and you are released on basically usually your own recognizance. They're very somewhat, so we are all ready in many areas using artificial intelligence for that entire. Process, there's no pleading with the computer's saying I can't afford a $200,000 bail.
[01:05:42] There's no pleading with the computer saying, listen, I've been a member of the rotary club for 20 years and I own a business here. I have tight ties to the community that bail is just way too high because in many communities they are using artificial intelligence and relying on it a hundred percent.
[01:06:00] That's one of the big problems with computers. People because they don't really understand them. Just say fine. Just yeah, go. The computers is almost always right. Yeah. The other problem is we don't know how it was programmed. Now in the case of this Chinese computer, that acts as a prosecutor for charging.
[01:06:23] They fed it 17,000 cases. Do we know what those cases are? Do we know what the computer weighs when it's making its decisions? And we've seen this already, in some cases here in the U S where normally you can face your accuser. Normally you can go to the court and say, this decision by the justice of the peace was not quite right.
[01:06:46] It needs to be fixed right now. They did and all well and good. And so if they had someone or they'd come in and testify to say, yeah, you're not a flight risk, et cetera, you're fine. But when it comes to the computers, people tend to just believe them. What were those 17,000 cases? Were they all nasty dissidents?
[01:07:09] What did the computer learned from it? And some of these cases that we've had in the us we've found. That even the people that provided the software, that AI software, they don't know what the decision-making process actually was because the computer learned how to do it. And you need to understand AI models and how they're fed data and how they work.
[01:07:35] But basically the computers come up with their own way of thinking through things. Just to make this simple. So it's not necessarily totally logic. It's not like back in the day, you'd write software that says, okay, if they have lived in that same home for over twenty-five years, they have kids in school, they own a business, et cetera, et cetera.
[01:07:55] So you set up all of the explicit parameters. And from that, now you can say okay, fine. So you've got, went down this path based on. Person was and what their background was. Therefore, you came to this conclusion. That's not what's happening with this newer AI, not at all. And then you also have the question.
[01:08:16] Okay. What does 97% accurate? Who's going to take responsibility when there is a mistake. Now I'm not talking about the 3% that they're admitting could be mistakes. I'm talking about the 97% of the time. And then if you now move up to the courts, who are they going to talk to? The prosecutor, the machine, the designer of the algorithm.
[01:08:42] Are they going to examine all 17,000 cases that were fed into this? I goes back to what I said before about airplanes. People are not good at monitoring computers, but computers can be good at monitoring people. In other words, in this case, the artificial intelligence may help detect a mistake, but it really cannot replace humans in making a decision.
[01:09:09] It's very true. China's relying more and more on AI to boost productivity. They're using AI with facial recognition systems for their social credit score that allows people to get on. Train you can't get on a train unless you have a high enough social credit score. And if you J rock walk, you have now lost points.
[01:09:32] So it's it's really crazy. So I'm very concerned about this. I found some great information by the way, online from the justice department about what they are looking to have AI do. And it's basically everything making decisions and informing. What should happen? They're looking at using chat chatbox to provide legal advice for pro se litigants.
[01:10:00] In other words, people that are trying to defend themselves can go to a chat box that will give them some direction. That's all in the works. I'm looking at the official documents right now, criminal justice testing and evaluation consortium, looking at artificial intelligence. Hey, make sure you subscribe to my podcast.
[01:10:21] Craig peterson.com/itunes, and I hope I've earned a five star review. And if you could take a minute, just give it right there.
[01:10:31] We all know the children online suffer some pretty serious consequences in certain cases. The federal trade commission has now won a case against Google. We're going to talk about what's going on. With ads.
[01:10:47] The FTC has now been enforcing what's called CAPA, which is the children's online privacy protection rule.
[01:10:58] And they have find. In fact they find them. What was it? Almost 200. Yeah, exactly. Let me just find it here. Sorry about that. They have find Google to the sum total of. 170 million. That's what I thought it was almost $200 million penalty. So what had happened here is YouTube. Now YouTube is owned by Google has been for quite a while.
[01:11:28] And in fact, YouTube. Advertising to advertisers that quote YouTube is today's leader in reaching children age six to 11 against top TV channels. They also said that YouTube is the number one website regularly visited by kids. Now we know that they are not supposed to be directing any content to children under 13.
[01:11:58] Now you could argue, all right, they're not directing content to them, but the facts are the facts of kids are on the site. They're on the site. Yeah. But why would you promote that to advertisers and. You were exactly promoting to children. And that's what the federal trade commission said. Hey, Google, here you are promoting your ability to target these kids by saying you are the number one platform for them.
[01:12:30] So you shouldn't be doing that. So this settlement they came up with Google required you tube to pay $170 million penalty. They were also required to implement a system. That permits channel owners to identify content is child directed. So YouTube can ensure it's complying with the rule going forward.
[01:12:53] So remember YouTube doesn't make the content that's up on their site. They steal it from you. They don't exact this dealer from you, but anything that you're uploading, they may try and monetize. If enough people watch it and stay on their site longer. Which is the goal, by the way, for your content.
[01:13:11] If you put it up, really Facebook's the same way. LinkedIn, everybody, they want eyeballs. They want them to stay on the site so they can show them advertising. The people who are making the content are these content creators, just you and me uploading stuff to YouTube. As well as these people that have somehow become very popular that I just don't understand.
[01:13:32] So here are also some things from our dark reading website here. Alison LeFrak, she's senior vice president of public policy. Ads privacy and children's online privacy protection act compliance at pixelate. So she's come up with five things she thinks should be adopted by the industry. First of all, improve transparency ad networks platforms should consider implementing their system that lets online services, identity.
[01:14:05] To the ad network or platform that their content is child directed, which is something that the courts are demanding here now. The FTC settlement is I should say, number two, stop collecting children's data once an ad network or a platform like YouTube sets up a system where developers can signal that their app or their software or their.
[01:14:30] Oh, the video is directed at children. That ad network needs to take steps to not collect personal information through those websites. Make sense apps or channels. Number three, involve parents when required, even if an ad network is not collecting precise geolocation information from children. If it collects wireless network identifiers to infer precise location, it is required to provide notice.
[01:14:56] Teen consent from the parents. I'm loving all of these number four. Protect sensitive data. If an ad network decides to collect children's data, it must maintain the confidentiality, security and integrity of the information. It should only retain the data as long as necessary to fulfill the purpose for which it was collected.
[01:15:19] And the ad networks should delete the data in a way that protects against its own authorized use. And number five remained stringent on protecting children. So I think all of those make quite a bit of sense. They're all things that ad networks and these platforms should be doing, but they're not required to do it.
[01:15:38] And I, I go back and forth here. My dad and mumble both used to say there ought to be a law. No, that's not how my mom said it, you get the idea. And I'm at the point where I say, man, we got to get rid of most of these laws, rules and regulations, because they are hampering us something.
[01:15:57] If you look at the Scandinavian countries, some people say, oh, there are socialists over that. No, they're not. They have very high taxes and they have a lot of community services, but Switz, they're not Switzerland, Sweden, for instance. They know that they have to keep their businesses healthy so that they can collect taxes.
[01:16:18] So they stay out of the way versus here, where we already have a socialist system. We have all of these rules and regulations that effectively provide the government complete control over businesses. It's absolutely crazy what we've been doing. So I don't know what to do here. I'd like to see the advertisers adopt something like this, but keep an eye out.
[01:16:43] If you have kids, they are targeting them. Now they've been targeted. Kids have been targeted since the early days on radio and television. Remember the Buckaroo, Bonzai and all these other things that were really cooled and some adults listened to them, but. Kids listen to film a lot and watch cartoons as kids and how the cartoons were again, aimed at the kids.
[01:17:08] Right? Saturday morning cartoons it's really don't exist anymore. Nowadays they're doing it online. So have they crossed the line? I don't think they've crossed the line any more than advertisers did all of those decades ago, but yeah it is a bit of an issue and something that we should pay attention to, particularly as parents.
[01:17:30] So the next question I have here, and I'm sighing because it's just a shame that things aren't. A little better. Aren't more open government and everything else. It's just everywhere you turn. Even in my industry, there's a, I'm working on this bootcamp right now that we're going to be doing, and it's going to be a free bootcamp for anyone who wants to attend.
[01:17:53] And we're really going to teach you stuff. We're going to walk through it on, and it's the, on the basics of some of the security stuff you need to do in business and in home. And. When I came across and what really bothered me was this whole concept of the cyber security industry, lying to people.
[01:18:14] And they've been lying to you for years. They are selling antivirus software. That's based on designs that are 20 years old. The stats that really upset me are the antivirus software that you're buying that you're paying good money for. It doesn't work in 70% of the hacks that occurred last year, 70% of the time, it doesn't work.
[01:18:42] Obviously it doesn't work again. Zero day attacks, which are attacks that have a bug that nobody knows about. But so much of even the ransomware, the viruses we had of years past hides itself very well from the antivirus software very well. And that gets to be just a huge problem because it, every time it spread.
[01:19:06] Changes its digital signature, if you will. So now when the antivirus software looks for a specific strings that are in there, when it looks for specific checks, it's not going to find them because the software morphed itself, it changed it. very big deal. And these companies are out there selling their software as though it's a panacea.
[01:19:30] So I'm looking right now and I can send this to you. If you are interested, just drop an email to me. M [email protected]. And I'll send you a link to this, but there's a website out there called AAV comparative. And they are testing different types of software. So in 2021, between August and November, they looked at real-world protection, malware protection, performance, and product review information.
[01:20:02] So they put it all together. And they tested, what is this about a little over a dozen different products, very popular products that are out there. And like a vast business anti-virus pro plus bit defender gravity zone, elite Kaspersky, which you probably shouldn't be using Microsoft defender, antivirus virus with Microsoft endpoint manager.
[01:20:27] Okay. So what are the good ones? Bottom line. What I'm recommending nowadays is that you just use the Microsoft software, Microsoft defender. It is, I'm looking at the chart right now. It is pretty much as good as anything else. Out there. They, the better one is bit defender, which I really like. And I recommended to a lot of people.
[01:20:53] Some of you guys have been writing me the last couple of weeks. I'm guessing because you just got new computers about what antivirus to use and bit defenders. Very good. And there's versions for Mac as well as windows. And remember if you have a Mac and you send something to someone that has windows or you're on a network with windows that the files.
[01:21:14] Affect the Mac at all. If they are exchanged with somebody on windows, could knock that windows and machine completely off the air. So be careful with that. So those are the big guys. Those are the ones that worked really well. And I've got to say most I'm looking right now across These some good ones CrowdStrike's listed really well.
[01:21:39] They're using a low end, Cisco for comparison here, and it did better than cyber reason for instance, or a Cronus or some of these others. But. Yeah, it looks like you're best off sticking with the Microsoft and bit defender. And if you want something that's more professional than get the advanced malware protection from Cisco, which is it's combining a bunch of things and it's really the gold standard.
[01:22:08] It's something that we use with our clients. You cannot buy it directly. To get it from a managed security services provider like us. Anyways, any questions? Email me [email protected] and make sure you're on my email list. Craig peterson.com/subscribe to get all of this stuff for free.
Considering a change in employment? Apple/China/Green Army/Bitcoin seizure and Cybersecurity Jobs!
Apple has upended a lot of industries over the years, and it is about to upend yet another one. Square is a company that has been making a lot of money and its run by same guy that ran Twitter. You know that Rasputen-looking guy? What's Apple doing to the finance industry?
[Following is an automated transcript]
This is a real big deal. Apple has been for a long time upending industries.
[00:00:23] You might remember, of course, the music player. In fact, I still have an old MP3 player. You can't really see it very well from this angle, but it was right over there. And then. And it was a five gigabyte player. Just amazing thing was huge. It was actually designed by digital equipment corporation, licensed by this other manufacturer, put them together.
[00:00:44] Great audio quality. They had these little costs, headphones that came along. I loved the thing. Absolutely loved it. And apple came along, they weren't the first and they introduced their own MP3 player. That was called an iPod. And it did very well. It just slaughtered everybody else. You might remember the Microsoft came out with their zoon and many others came out with their own little MP3 players.
[00:01:12] No, nobody could touch our friends over at apple with their iPod. And then what happened? Around 2010, think for a minute. What new product did apple introduce around 2010? Of course it was this right. It was the I phone now the iPhone cut dramatically into Apple's market and for a good reason. It was a phone.
[00:01:38] It was a smart phone. It could play all of your music. I still have and still use 120 gigabyte. I iPod. At the kind of the classic I think is what they had called it. And 120, it was just amazing. Just that much music. Of course, me, I have a lot of lectures, a lot of audio books and other things I listened to on that, on those iPods and what happened.
[00:02:05] Of course. Now you can get these I-phones with a terabyte of memory in them, just incredible amount of space. And that's a pretty good thing, frankly, because you can store everything. But at the same time, our networks are getting faster. Aren't they? So our networks, like what we have for our cellular phones and stuff are faster than they have ever been.
[00:02:29] So you don't really need as much storage do you, as you used to have. On your phone or your iPod or your MP3 player. So it's an interesting game. How much space do you need? And I'm asked that all of the time and the newest iPhone is coming out, have a lot more memory. I think they have eight gigabytes of Ram in them.
[00:02:48] And as I said, a terabyte of storage. But what apple was doing is saying, Hey, we own this iPod market, the MP3 player market. And of course it's more than just MP3s, lot of other formats out there for the music or audio books, but they owned it. But they knew that if they were going to survive in the industry, they had to do something else.
[00:03:13] Came out with a product that competed with their award winning and just top of the line product, the iPhone and your iPhone works every bit as well as an iPod ever did. And of course ever so much better because now you don't have to download the music on your iPhone to listen to it, to you. You can stream it over the internet, over wifi, right over the cellular data connection, those things we've gotten fast.
[00:03:38] Two great option for. What Apple's doing now is saying we need to append another market. Have you ever had, again, like you, you got your phone, right? And let's say you're a small merchant, maybe your coffee shop, or maybe you're even smaller. Maybe you're just out at a flea market selling stuff that you might want to peddle.
[00:03:59] You have to get an, a credit card. Don't you. And back in the day that credit card reader would plug right into the headphone Jack and with a headphone Jack, you'd be able to go online. No problem. Life is good. And once you're online, then you can take the credit. Now you didn't just have to go online with your iPhone, but you had to be able to go on line with your phone and the reader, because when they got rid of that wonderful little headphone port, you now had to use Bluetooth, didn't you and you still.
[00:04:37] So you get that reader from square or that reader from PayPal or somewhere else it's acting as your merchant account. And that reader then uses Bluetooth to talk to the phone and then it can read the credit card or the chip. And of course, with the chip it's by directional, it has to get the information to, and from that trip, And then you've got the credit card that you can process all well, and good.
[00:05:04] We're all happy about that, but here's your next problem? Bluetooth. Isn't always working. That reader has to be charged. Did you charge it before you brought it before you started using it? So apple said wait a minute. In our I-phones we have built in a few different things. Do you ever used apple pay?
[00:05:25] It's probably the safest way to pay online bar? None. It doesn't actually give the merchant the credit card. And it gives them a code that they can read Dean in order to go ahead and get the money from the transaction so that transaction can then be redeemed by the merchant. And that's all stuff handled by your merchant account.
[00:05:48] You don't have to worry about it makes life. However now what they've done is they've said let's reverse this. You can use your iPhone with apple pay in order to pay for things. And it has, what's called near field technology in it that allows it to act like those tap and go credit cards I've ever used.
[00:06:08] One of those where you can just tap it and it makes the transaction happen. Pretty simple. So it has that in there, but it also has the ability. To read those tap and go transactions. So it's going to be interesting to see exactly what happens here. This is a very big industry. There is a whole lot of money in it, and there's an article this week from our friends over in ink magazine.
[00:06:36] I got up on my screen for those who are watching a video here on rumble or YouTube. And it's talking about this feature that they introduced quite quietly. Because this new capability is going to change things. Now you are still going to have your merchant account. So you still might have to have a Stripe or a PayPal or direct merchant account with your bank.
[00:07:02] But this is allowing contactless credit and debit cards and other digital wallets to be able to be read from any one's iPhone, which is really quite. Now there's things like Venmo and others out there that people use. My kids use a lot more than I do, but they use it to send money back and forth to each other.
[00:07:23] It's a pretty good little thing that they've got going, but with something like this, you wouldn't even need to use a Venmo. So those are the guys that are going to get really nailed by it. And Stripe really is phenomenal. It's so easy to use and I use it as well. I use. For my courses. If you sign up, for course, to almost always going through Stripe, I know there's some other alternatives out there right now that are a little more friendly to the non-mainstream, but I haven't been able to integrate those yet in Vermont payment processors, but there's still going to need it.
[00:08:01] You can use cash app, Venmo. It's not going to stop you from doing any of that, but it does stop you from having to have another. Piece of equipment with you, which is just something else to go bad, or dig to have, get dirty to, to not be able to work for you. So we'll see what happens. This is cutting out.
[00:08:22] These companies like square. They'll no longer be able to. Have from the front to the back, they'll still have the back, frankly, but they'd be able to accept payments from pretty much anything that's contactless, which is I think a very good deal. We'll see what happens. But again, this is not apple going after Apple's existing customer base, like it did with the I Paul.
[00:08:50] Transition to the I phone. This is apple going after another piece of the retail space. And remember what I said earlier, it's not even just that app. Has the ability to enter market, but we've seen time and again, where apple enters a market that's already established. It's not quite mature, right? You haven't had all of those acquisitions going where the companies are buying each other up, but it is going to make a huge difference because again, apple up.
[00:09:23] And apple has ties in to a couple of banks that they use for processing their apple cards. Think it's Goldman Sachs, and they could potentially provide you with the merchant account stuff on the backend. So I think that's pretty cool. And it's going to allow us all to have a cashless. The yeah, if this was a political show, that's probably what we'd be talking about.
[00:09:50] Wouldn't it? Because there's certain problems with doing that as well. Hey, I want to invite everybody to take a few minutes right now. I am making some changes. I've been working on some of these for weeks, but I've got a lot of clients. I've got two. Take care of first, right? I've been doing a lot of CSO work, CIS, so chief information security officer, just on a fractional or part-time basis as a contractor for a few different companies to try and keep them up-to-date with all of the latest in technology.
[00:10:22] So it's been really fun, but I haven't been able to do everything I want to do yet on the radio show. So my wife and I are reaching into our pockets and we're going to be hopefully pulling out somebody to help us with some of this, because what I want to do is send. My show notes to you guys every week.
[00:10:41] So you can see what I'm talking about. You have the direct links, as well as my newsletter, and I want to start doing my Wednesday wisdoms trainings more regularly. It's really hit or miss. So trying to do all of that, and I'd really appreciate it. If you would go right now to Craig peterson.com and make sure you sign up right there for my email list, Craig peterson.com.
[00:11:07] Get it. All right.
[00:11:10] We've been very worried about China for quite a few years, for more than one reason. But one of the biggest is they have dominated some of the most critical markets in the world, including some of these mineral resources that we need.
[00:11:27] China has been a big worry for many countries around the world.
[00:11:32] For a long time, I met with the ambassador from a couple of these African countries and had a great little chat about what was going on there. They wanted to become this one country in particular, the data processing center. For Africa and Africa, of course, very big country or continent, I should say with a lot of countries and a lot of financial transactions.
[00:12:01] And they figured what we need is a good data center. We need data lines coming in. And so they got some of those data lines and they got the data center. The data center provided by our friends in China. And so this data center was being used for a few different things, but it sure was not being used for these financial transactions.
[00:12:27] So they wanted it to be used for because China. Provided the equipment. And we know from a lot of articles, a lot of research and from the federal government, the China has been spying on us. And I have seen it personally with some of these DOD sub subcontractors. In other words, it's not necessarily directly contracting with the department of defense, but providing parts and things via subcontractor relationships.
[00:12:59] And China is a problem. So what do they do? How is this small African countries supposed to become the data processing country for all of Africa, with Chinese equipment? How could they possibly do it without Chinese equipment? And that's what the ambassador was telling. We need this equipment this is it.
[00:13:19] They had Chinese routers, switches processors. They had racks of equipment set up in virtual environments and they were all set to go. China's been doing similar things in other parts of the world where they come in, they might build a port for instance, which has happened many times, one in Indonesia, particularly I'm thinking of, and they financed the port.
[00:13:45] If you don't make the payment on that data center or the payment on the port or the payment on the railroad system, et cetera, that China has installed in your country, guess what's in that contract, you forfeit them. So the data center now becomes absolutely. China's not just a lean on it, not just a lease from China.
[00:14:11] It is China's data center. That port is China's port. In fact, they own the largest port. Now I think in all of Indonesia, maybe the whole Pacific rim over there, I'm not sure, but that's what they've been doing. Same thing with railroads, et cetera, et cetera. So China really has a lot of companies and countries over the.
[00:14:35] That's something we didn't want to have happen here in president Trump, you might remember was very adamant about it. He did a whole lot of work to make sure that none of the Chinese interests would really be able to take over and control our us interest. It makes sense to me. So what has China been doing to us?
[00:14:58] We know about the steel and remember China was dumping cheap steel into the us and world markets that hurts us. We have a need to make things here. If we ever haven't forbid got into a war. And we needed ships or boats or planes, or we needed armaments of some sort or another. We need to be able to make them in the United States or in an allied country.
[00:15:29] You remember how many problems that Britain had during the war? Trying to ship stuff over. I have two kids that were merchant Mariners and the U S merchant Marine academy is the only. Of the military academies, that flies battle standards because they lost cadets who were there at the school during warfare.
[00:15:53] Okay. It's a bad thing. We don't want that to happen. So not having to rely on other countries actually ends up being a bit of a positive thing, depending on what it is. China's sent us things like dog food, that's contaminated, baby food contaminated. Even those, green recyclable bags, people take to the grocery store.
[00:16:16] Yeah, contaminated with lead. It goes on and on. They also had control of 99% of certain precious metals that are needed for some of our key manufacturing here in the U S so we put tariffs on China for steel. We did the same thing in 2021. In fact, they put a tariff of 23% in 2021 to protect the steel manufacturers here in the U S.
[00:16:45] From these cheap Chinese imports, not just cheap, but low quality steel Weiwei, you know about them. They owned the smartphone business in many parts of the world. In fact, here in the United States, you could get cheap Walway phones. Now, Weiwei of course, if much about Canadian history, know about Northern telecomm, who did a little.
[00:17:10] Pioneering in the whole phone business for many decades and the allegations. And there's some proof that I've seen that leads me to believe that these allegations are correct. Are that while always stolen? Northern telecoms designs, its plans, et cetera, and put all of that together to make Walway.
[00:17:32] So they steal the plans, they steal the engineering, they steal the research and development, the intellectual property. They then start making it, of course, without having to worry about the investments into R and D and developing products. Now they just stole them and then they flood the markets worldwide with.
[00:17:52] Equipment paid and manufactured in some cases by slave labor in almost every case by substantially low wages and. They then control of the market. So we said no way to Walway and that was something president Trump started. It's actually a really good thing. And Google apps are now no longer allowed on Huawei phones.
[00:18:19] So China used to have a 99%, almost total monopoly on rare earth metals. I'm going to bring this article up on the screen from our friends over at American. But now they have fallen to less than 60% monopoly. So they've been trying to stop shipments of rare earth metals to countries all over the world to drive up the prices.
[00:18:45] They did the same thing here to Japan because of the contesting in the south China sea of some of these islands of some of these mineral rights. But since then in the last decade, rare earth metal. Are being mined. In other parts of the world, we talked here about what California is doing. California is now going to be mining lithium and some of these other rare earth metals that we need to make batteries.
[00:19:15] We need to make processes. We need to make cars. We need to make light bulbs right on. And. They used to have a near monopoly on foreign off shore investment because companies were going to China like crazy, because the cheap wages over there, 1.4 billion consumers has been leading companies that make movies like Disney to go over to China.
[00:19:39] But things have really stopped in some of these growth areas for China. And in fact, have reversed in a very big way. They're clamped down on business, censoring of wealthy capitalists food, shortages, growth, centralized government corruption. Gross, excuse me, corruption, mismanagement, stagflation, plunging birth rate, all resulted in investments and opportunities.
[00:20:04] Fleeing China. Great article in American thinker. Keep an eye out for it in the newsletter this week and stick around. But first check out Craig peterson.com. Make sure you're on my email list. And if you like watching video, Hey, I'd like to invite you to watch me and follow me on YouTube and rumble.
[00:20:27] This is straight out of the, what were you thinking department? In fact, what are you thinking? Yeah, the us army is planning on going green. Yeah. They want electric vehicles in war.
[00:20:44] This is a plan that you just are going to have to shake your head at a, again, it's a little bit of idiocy, but before we talk specifically about the plan, I want to talk about something related.
[00:20:59] Now, remember this plan is from the U S army and they want some goals read Sean on climate change and electric vehicles here over the next 20, 30 years. So let's look at the science behind what they're talking about, and I'm going to show you the actual statement that came out from the military. And one of president Biden's appointees is just nuts, absolutely nuts, but I'm going to back up a little.
[00:21:34] For those of you who are watching along at home. Let me pull this up for you. This is from slash. And it's quoting a report over on the wall street journal and pulling some stuff together. But what they're doing in this particular article is talking about how our friends who have come up with these super computer designed.
[00:22:02] To model our weather have been be fuddled they've reworked 1.2 million lines of computer code in order to compensate for something that I don't know about you, but if I was writing the code, I probably would have compensated for it in the first place cloud. Clouds. Yeah. Yeah. It turns out this is just to me, absolutely boggling the mind, that great glowing orb that appears in the sky.
[00:22:35] From time to time. Yeah. I'll give or take half of the day. That thing called the sun apparently has something to do with the earth warming up. And do you know what else does, the clouds that are up in the sky? Those clouds can reflect the sun's heat and they can also hold heat in on the ground side, who would have thought.
[00:23:01] So all of these models that they've been using, cause remember by now, as of more than a decade ago, New York Manhattan is underwater. Remember? Yeah. Al gore with his scientific moon movie at this science. Is just cited. It's proven and Florida by now was underwater. And so as Manhattan, and of course neither is true because they had no idea what they were talking about.
[00:23:27] This article in the wall street journal, Totally baffles me. And I'm just showing you the excerpt from slash.here on the screen because the wall street journal was paid. And I don't want to have to push you guys to paid stuff if I can avoid it. But they thought it was really strange cause they updated the simulation in 2018 and in 2018 it turned out that the earth was.
[00:23:55] Way more sensitive to greenhouse gases than they thought. And, oh man, they had to think about that because, in Boulder, the national center for atmospheric research they said if that number was correct, that would be really bad news. Yeah. And at least 20 older climate models disagreed with the new one, but they were simpler and this new one is an open source model.
[00:24:20] So anybody can look at the code and kind of figure it out. So I, then what ended up happening is. More than a dozen other models were released and it turns out wait a minute, now they're agreeing with us. Do you remember that spaghetti code that predicted the COVID 19 was going to kill?
[00:24:40] It was a two and a half million people in the United States. Of course didn't get anywhere near. Close to that, because the way we kept the stats, right? W co dine with COVID versus because of COVID right. Remember that whole controversy. It turns out that the scientists concluded that their new calculations have been thrown off kilter by the physics of clouds in a warming world, which may amplify or.
[00:25:08] Climate change. Isn't that what I had just said, that Kyle taken, they can block the sun and they can also keep heat in. A night with lots of moisture in the air, whether it's humidity or cloud is going to stay warmer than a night where there's no clouds. These are experts. So the fact that they left out clouds and the effect they might have, I must make a whole lot of sense, because this is a science and the science has settled.
[00:25:34] Yeah. So Andrew Gettleman now physicist there in Boulder said that the old way is just wrong. We know that I think our higher sensitivity is wrong to it. It's probably a consequence of other things we did by making clouds better and more realistic to solve one problem and create another I, again, I got to point out science, mind.
[00:25:59] Science is not settled on pretty much anything and it never has been. And until we are all knowing, it never will be. So keep that in mind and quit having your heads just be so inflated that you think that you're absolutely right, because I'm not absolutely right. They're not absolutely right. No, one's absolutely right.
[00:26:23] So let's get into the army here. This is just so exciting. Cause Christine wor Muth is the secretary of the army now, and the army is going to lead by example. And we put this up on the screen. I just realized that I'll have this up on the screen for you guys. We will use our buying power to drive change in the industry and leverage best practices from.
[00:26:47] Sources. There's another great quote here from the secretary of defense. W we face all kinds of threats in our line of work yet. Yeah. Secretary of defense army. Yeah. Okay. But a few of the threats truly deserve to be called existential. The climate crisis does climate change is making the world more unsafe and we need to act right.
[00:27:14] That's what she's saying, that this thing goes on for pages, what the goals are. So I decided, okay, Craig, let's have a look at this. I'm going to do a search in this PDF for the word risk. What are the risks? If we're going to be messing with the military, with the electric vehicles, because in the middle of a war zone, it's great.
[00:27:33] You just, you stop, you plug your electric vehicle and let it charge for half an hour. And then you're off and running. And particularly where tanks are right. Where we're trying to protect our personnel. Maybe have an offensive. They'll wait while we charge our tanks, right? Oh and a little tiny solar cell, or we cover it with solar cells.
[00:27:51] That's going to be enough to charge it if we leave it sitting there for a week. So we're okay. So what are the risks associated with us being idiots and moving towards an electric army? Okay, so risks here. Okay. So this is a risk to the climate. This is climate risks. Oh, this is red mitigating climate risks, assertion of climate change risks impacting the army at all levels from how and where our units operate and train to how to service as a whole.
[00:28:21] Okay. So that's risks of when the climate changes, as we know it will, because those guys wrote 1.2 million new lines of code. Okay. So we know it's going to change. Okay. So let me see risks, climate change, imposes, climate threats, and risks. Address the risks associated with these. Let's see here.
[00:28:43] What else do we got? Climate change risks. Climate change risks. Oh, they're going to install micro grids on every installation. Okay. Climate change risks. This is nuts. And the New York post has a great article on this insanity. Oh my gosh. What are we going to do with these. Yeah, our military, we're going to stop and charge our vehicles.
[00:29:10] Yeah. All right, everybody stick around and visit online. Craig Peter sohn.com. I'll keep you up to date.
[00:29:24] We're going to talk about this Bitcoin laundering case that really turned the internet upside down. Cryptocurrencies, Bitcoin, how safe is it? How secure is it really? And what happened here? Because this Bonnie and Clyde failed.
[00:29:41] This is an article from the New York times.
[00:29:44] Now I know I don't like to, you guys know this show you stuff that you have to pay to go to a paid site and particularly something like the New York times. It's amazing to me how they have some really great journalists that do a good job on some of these stories. And then they just totally go political on so many of the other stories, and I'm not talking about the editorial page, knock yourself out.
[00:30:11] But anyways, this is a fascinating story to me because so many of us think that using Bitcoin is going to be safe after. Cryptocurrency. And crypto means cryptography and cryptography means we're keeping ourselves safer. Isn't it? Isn't that? How that's all supposed to work kind of the bottom line while in reality, it doesn't always work out that way.
[00:30:40] And when it comes to cryptocurrency, it definitely does. And I want to explain a little bit about cryptocurrency for people, if you don't understand it very well, just putting the very, very, basically the way it works is there are ledgers, just like the old ledgers you used to see at the banks or businesses, those big.
[00:31:02] And they'd maybe do double entry ledgers, or maybe some other types. Nowadays. Of course, all of this stuff has done on computers, but the idea is you walk into your bank and you say, I want a hundred dollars from my account. So the bank opens up its ledgers and sees, okay. Your account has X dollars in it.
[00:31:23] They give you a hundred dollars in that ledger. Now they marked down that your account now is a hundred dollars less because you just would do a hundred bucks. That's the simple way it works with the bank. It's actually very similar with the script old currencies, but what happens in cryptocurrencies is you're not dealing with one institution.
[00:31:46] So it isn't just your retirement plan that fidelity friends. With it, when it comes to cryptocurrencies, these ledgers are maintained by hundreds of different businesses and people around the world. Thousands depends on the cryptocurrency itself. And the idea is when you go and you want to take your a hundred dollars for instance, from the bank, they look it up in their one ledger in that ledger is assumed to be correct.
[00:32:15] But when it comes to cryptocurrencies, there have to be the majority of ledgers that agree about how much money. And those ledgers are all public ledgers. So it's like having a Swiss bank account in that your account is represented by a number that's actually where the cryptography comes in and the keys, public keys and everything else.
[00:32:40] But your account is essentially represented by a number. So if you want to pay the a hundred dollars to. In cryptocurrency. So it's probably some fraction of some cryptocurrency what's going to happen is you are going to have half of the ledgers for that particular cryptocurrency agree that you're transferring a hundred dollars.
[00:33:07] From account number 1, 2, 3, 4 to someone else's account, which is 5, 6, 7, 8, just as an example. Very simplified example. So now what happens is the people who are running the ledger that you're using the main ledger, check the other ledgers and push your transaction onto the ledgers. That's why it takes a while for cryptocurrency transactions to occur.
[00:33:32] Because it has to push out to these ledgers. Half of them have to agree in order for it to be a reasonable and accepted transactions. That make sense. Good. So what we have here now because of public ledgers is public information. The amount of money you have in that number to count can be seen by anyone who cares to look.
[00:34:00] It's really that simple. Anybody can see it. So why are people thinking that it's crypto it's safe? It can't be taken by the government or bad guys, et cetera. Those concepts are all insane. The. Sort of privacy or security you have is related to the ledger. So the security is half of the ledgers have to agree.
[00:34:23] So someone hacks one ledger, that's not enough to get control of all of your cryptocurrency or whatever it might. If someone hacks your wallet, that's a different story entirely. Okay. But that's not what we're talking about right now, but everybody can see that you have a hundred dollars in account.
[00:34:43] Number 1, 2, 3, 4, the pro the trick is, and the problem for law enforcement, they don't necessarily know who owns account 1, 2, 3. So what law enforcement does in order to get money back or to arrest people is they watch these accounts. So in this particular case, there's Bonnie and Clyde, if you will hack a cryptocurrency exchange.
[00:35:09] So this is again, one of these ledgers sites and they'll often exchange us dollars for various cryptocurrencies. Back in 2016, Bitfinex was the name of it. And they store $71 million in Bitcoin from effectively wallets are there on that site. But because these trades are publicly. People on the internet knew that it happened.
[00:35:39] In fact, people on the internet were watching that wallet waiting for money to move. And this couple that's alleged to have stolen it's Iliya Lichtenstein and Heather Morgan, that account could, they could see that $71 million was in it. But over time, six years later, the value of Bitcoin had gone up substantially.
[00:36:06] And today is worth about $4 billion. Isn't that just amazing and a lot of money. So they moved it to another account and that's when the got in trouble. So if you have a Swiss bank account, 1, 2, 3, 4, and you transfer money to someone else that I know, I now can trace that account. I say, oh, I know who has that.
[00:36:35] Yeah, that's 71 million worth of Bitcoin. Back in the day, that's now worth 4 billion was in this account and they just bought themselves a new Porsche cayenne at this dealership. And all law enforcement has to do is knock at the dealership, say who was it? And now they know who the people are, but in this particular case, The bad guys had left that money in that Bitcoin account, but that money did get transferred, but guess what?
[00:37:05] It wasn't them, people on the internet were thinking that the hackers had emerged that they were transferring the money to other Bitcoin accounts, which you see fairly frequently for these illegal transactions, but it wasn't the hackers who move that stolen. Bitcoin. This is again from the New York times, it was the government which had seized it as part of investigation into two New York city entrepreneurs, one with a little known Russian emigre and techie investor who had just named the other, his wife, an American businesswoman, and would be social media influencer with an alter ego.
[00:37:44] Is this a terrible rapper named razzle con. Yeah, amazing. You can't make this stuff up. Can you, so they're charged with conspiracy to launder billions of dollars in Bitcoin. Ilya is 34 and Heather's 31 accused of siphoned off chunks of the currency, trying to hide it in this complex network of digital wallets and personas.
[00:38:07] And if they're convicted of it and a second. Spare seat count that has been put against them. They could be facing up to 25 years in prison. So as is always the case, oh, you asked the neighbor, he was a good boy. He was a very good boy. I love that. How we are, but he's that little bit all over the.
[00:38:26] But the couple's neighbors said they're goofy, normal types of people never expected that. But these are part of a real change that we've been seeing over the last few years into investigations in the cryptocurrency field. Now, remember crypto isn't necessarily the best thing.
[00:38:44] Own any, never have owned any. I played around with some mining stuff at one point, just on my regular computer to see what it was all about, but it is not anything that's worth anything to anyone. Frankly, what I did now, a lot of people have been buying it. Of course, part of the problem with it is in order for it to be truly useful, you have to convert it back into something like a us dollar or maybe some other type of currency.
[00:39:11] And that's often when people get caught and nowadays on the tax forms, it even asked you about any sort of crypto holdings that you might have. So remember all of that. They don't know, by the way, this is again from the article, the New York times, if they were directly involved in this breach all those years ago, but this is really crypto culture and it really is the fringe.
[00:39:40] And they went crazy online and started looking at the digital trail. Her videos suddenly shared widely. Yeah. They've become infamous, is the right way to put all of that. Hey, if you like the show, I would really encourage you to follow me. You can follow, listen to my podcast on tune in on any of the major, in fact stream.
[00:40:09] Platforms out there SoundCloud you'll find me on apple, et cetera. And I just started videotaping the shows last week. And this week I've done little things before, but now I'm trying to do the whole. So you can watch me on the show as I'm recording it live and see a little bit behind the scenes, which I've always liked.
[00:40:35] I've been watching how we Carr and grace Curley do their show. And I thought, it's well worth it this week. I did a little bit of editing on. Cut out some of the in between, cause I had some longer coffee and fit and had to stretch my legs a couple of times, but you get to see the whole thing behind the scenes.
[00:40:54] And if you sign up for my newsletter, you're going to get my weekly trainings. You're going to find out about boot camps I'm doing and other things, but you have to. Go to Craig Peter sawn.com. You'll see a right there on any page, frankly, to scroll down a little bit. It'll pop up right at the top of the page.
[00:41:14] Put in your name and email address, and I'm going to send you a few special reports, including my report on passwords. Craig peterson.com.
[00:41:25] You obviously know about the great resignation. It has been a big problem for a lot of companies out there. Great. For job seekers. Great for you. If you're trying to maybe get a raise, et cetera, especially if you're in the tech industry.
[00:41:42] This great resignation thing, man. Has it hit companies? And one of the biggest problems companies are having is with tech workers.
[00:41:55] You might remember back in the day, we had a big shortage of some of the cybersecurity people, right? Where we couldn't find them. There were numbers saying that there's like a million and a half or more open jobs for cybersecurity people. Now I did a little investigation into that number because it sounded high to me.
[00:42:18] Cause I, I was coding it. It was a number that came from some pretty reasonable sources. But I think this is one of those things where you had one news source stating it and then all of a sudden other people started quoting it. I don't think it was really a million and a half. And what I found was that the people that had put that number together were looking at it and saying, if you have a business.
[00:42:46] Who you should, you have working for you when it comes to cybersecurity? So there's like the CSO, the chief information security officer, which is something I do on a fractional basis for businesses all of the time, helping them to up their security. So you had to have a CSO, you needed to have a team.
[00:43:06] Looking at the logs that was paying attention to the networks. If something happened, they would know when they did investigate and maybe they would do patching close bugs. Which is a different person. One is the network operation center people. And if you're going to have a 24 7 network operation center, that means you need at least four people probably.
[00:43:30] And so the added all of this stuff up right there, the desktop people that are making sure the end points are protected and kept up to date and upgraded. That's how they came up with that, one and a half, 2 million open jobs in the us for technology. The reality was different obviously.
[00:43:50] And now with the great resignation where all of these people are. Out of the jobs. And part of the problem was already the beginning of the lockdowns. They had people suspended. They laid them off or they said, okay maybe we'll have you back. It's only two weeks to flatten the curve.
[00:44:11] So yeah, take a couple of weeks off. And so that gave people the opportunity over that. Period, which actually was two years, right? A minute. Maybe it's just my imagination. I'm not sure. But did that whole flatten the curve period that lasted for two years, people said I don't like this job because Frank.
[00:44:32] There is very few jobs. There are very few jobs that are as stressful as the cyber security jobs, because you're dealing all of the time with the senior executives saying I'm not going to double log in. I'm not going to carry a token around with me. I'm not going to have my screen time out after.
[00:44:55] Dean minutes or five minutes? No, it has to be half an hour and I just can't get my work done otherwise. So you're fighting with senior management who approved the budget in the first place, to at least do the minimal stuff. You're fighting with senior management to. The budget you need in order to keep the company safe.
[00:45:15] Because nowadays, if you're not keeping a company safe, you can go out of business like that, lose your reputation, lose your intellectual property. I've seen it before with companies, small companies, bigger companies. You've got to make sure all of your backups are in place there. You're using. 3, 2, 1 strategy nowadays, it's more of a 4, 3, 2, 2 1, 1 zeros hero strategy.
[00:45:40] I'll have to do a webinar on that one or a little meeting. We'll get together and talk about it. But again, if you're interested in that you gotta go to my website and stamped for the email list. Craig peterson.com. Just trying to figure it all out is difficult. And then you get all of these false alerts from software and you got to figure out, was this a legitimate alert or was this a false alert?
[00:46:04] What should I do about this? Or should I do about that? Who's really trying to break in. Why are they trying to break in? All of that sort of stuff gets to be difficult. So it's a stressful job. So a lot of people that were in cyber security at the beginning of the lockdown, I said I got to find something better.
[00:46:21] I know a couple of listeners who decided at the age of 55 to 60 in both cases that they would go change their careers had enough of what they were doing and we're going to go and do cybersecurity, took some of these classes, got the basics together and found jobs. In cybersecurity now they're not going to be experts, but they certainly knew more than the other people at the business, including the I T directors.
[00:46:53] And I say that with air quotes. So they both changed jobs during the. Now that's an interesting thing to me because I, and I'm not pointing my finger at either one of these guys, but the number one thing you have, if you are in cybersecurity, if you are a CSO is the top drawer of your desk.
[00:47:14] Assuming you have a desk, there's two things. One is your resume. And the other is your resignation letter because. Ultimately any business can be hacked. Now, I don't want people to say I'm throwing my hands up because it doesn't matter. Any business can be hacked. I'm not going to deal with this, right?
[00:47:31] Why would I spend any money on it all because you can control. Likely you are to be hacked and you can get like a 98 to a hundred percent effectiveness depending on how you measure things. And if something does happen, what matters is, how can you recover? So if you look at things like the sniffs to cybersecurity framework, you'll see, there's all kinds of provisions in there to make sure the business survives a hack.
[00:48:01] Okay. Stuff you needed to do stuff you need to be concerned about. But the whole cyber security side of the business is. Still in high demand because businesses more and more are realizing they can't just get by with running antivirus software anymore. You can't just say, oh I've got wonderful.
[00:48:24] A windows defender on my PC and that's working great. I don't need anything else. Now you have to have a much more advanced system. There's no two ways about it. So what we're finding is people in the it business right now can find a job if they were. Great article here. Let me show you a little bit.
[00:48:45] If you're watching, you'll see this on the screen. Two articles this week that I thought were really great, and I want to run through a little bit, but one is from. Wired magazine. That's a magazine I've subscribed to for a long time. They got some crazy ideas, but they got some good stuff, dude. And it's talking about the shortage of qualified workers and the competition.
[00:49:11] It's fascinating. And then another one here, I'll show you from the New York times magazine. And it's talking about the recruiters who are trying to recruit in the tech space. Now, in both of these cases, what we're talking about are job vacancies that are open in a minimum, hundreds of thousands in the U S right.
[00:49:36] Yeah, it's hard to tell, but what you can tell and what we are seeing is that these are recruiters who used to be stocked quite literally, sometimes by people looking for a job are now lucky. If they get a return, email, or phone, That's how bad it's gotten for them. And the story goes through this one recruiters kind of background saying, yeah I had this one person who's looking for a job and they stalked me, found my picture on LinkedIn and then stood outside the building, waiting for me to come out and then basically shoved the resume in my face and talked me up.
[00:50:21] Another one saying I had mentioned on the phone that I really liked tophi what shows up the next morning, this beautiful handmade toffee perfectly wrapped. So it has gone in just a few years from that where people will do anything in order to try and get a hold of the hiring manager, to where it is today, where people are just saying.
[00:50:44] Forget about it, it just isn't worth my time. The other thing that the recruiters are fine. Is that people when, if they do get ahold of them are saying basically, Hey, I'm just burned out. No, I don't think I have the energy anymore to do this, which is an interesting response. People because of the lock down have just had their.
[00:51:10] Their excitement, squashed, and ability to look forward to what my career is going to be if you're younger and if you're older, like I am, you're looking at it saying I've still got a lot of good years left and I'd love to do this and have my my wisdom, if you will, from all of these decades in the it world and in cybersecurity put to good use, which is why I said I'm doing the fractional.
[00:51:36] Chief information security officer for businesses. But what we are finding is. People can get the jobs, even people who are already retired to semi retired. I read another article this week that I thought was rather interesting. And we'll talk about that a bit when we get back, because it's going to take a few, but.
[00:51:59] The resume side of things. No, we heard the T of course the tophi trick the standing outside and stocking them tricky, et cetera. So what is happening right now? When you want a job, then maybe you've been in the market before for a lot of years and you're competing against the kids that are out there.
[00:52:21] Things have changed stick around and visit me online. Craig Peterson dot.
[00:52:28] We're going to finish up our discussion about jobs and open it, positions it in general. And also going to talk about some of the tips for older employees on the resume. I had a bit of a shocker this week..
[00:52:44] This article, and I'm going to pull up on my screen for those who are watching online is I think fascinating.
[00:52:51] This is from the New York times, and it's talking about recruiters and it's from a recruiter's perspective, Frank. And it's saying here, this is by the way, the one that had that story about the lady that used to be just hunted down all of the time, but the same recruiters are in such a demand that they too are scarce, which means their fees have never been here.
[00:53:17] In house tech recruiter, salaries are up about 30% organizations looking for help in cloud and cybersecurity positions have increased fees. They're offering two recruiting services to as high as 45% of the first year salary. Isn't that something that's a Robert half. I should have them on the show. They have been on a few times in the past, this particular lady who left her job, where she was always being courted and started freelance recruiting before the lockdown back in 2018.
[00:53:55] But there are big challenges are frankly going beyond finding just regular humans. The New York times says is that people are talking to potential hires. The recruiters have a big picture view of just how quickly the market is moving. And they've got to course take that and translate it into something that hiring managers would understand.
[00:54:17] And that's a fine line. Between, Hey, I'm trying to help you out here. You really should pay attention. And this is a hard sell right solely. It's a really interesting line. And we're also finding that of course of the candidates themselves are getting a lot of money. Salaries are way. Pop and for a good reason, people are in demand, especially if you have the skills.
[00:54:44] And so many people just don't want to work anymore. I have a couple of ways. I've looked at this over the years. I have what I call the McDonald's test. I don't think I've been to McDonald's in more than a year and I was on a road trip at the time, but it's how good is the service at McDonald's?
[00:55:02] Because if typically the service at whatever retail store you go to is pretty good. It usually means, wow. People are looking for jobs and it's hard to find a job. So you've got basically overqualified people working there on the other end. People who are working in the customer service retail space, which unfortunately, that's your face? That's your company. The people that answer the phone or the talk to your customers, those are the people who are out front. So in dealing with those people, w are they the best or the worst? If there are a lot of open positions while typically, and I hate to say this, but typically they're not your best employees.
[00:55:49] So that's kinda my McDonald's test. Did I get great service at McDonald's or Wendy's or burger king or at the mall? Or did I not get great service? And right now, We're not getting great service, any of those sorts of places. It's actually been more than a little frustrating. And sometimes even at the local coffee shop, it's been a little frustrating.
[00:56:10] The other thing, this is surprised me. Th this was this week right now. I've never been a. Another words, just in other words I, it doesn't matter to me if someone's younger or older certainly you can get to a age where there's senility. The other obvious problems with mental function look at president Biden, frankly, and some of the issues he has at least from time to time.
[00:56:38] But other than that, I'd never have. So I was really surprised when I was reading an article that. And it was talking about your resume if you want to get hired. And I'm going to run through some tips here because I spent some time doing some more research on this. You guys know, I'm not a spring chicken.
[00:56:58] I'm not an old man. The brain's obviously functioning just fine. And that's a good thing. Probably will be well into my eighties. Hopefully nineties that's been the history in my family. I at you're 60 years old, even 70 years old, you still got a lot of good years left in you. So when I'm looking at this and saying, okay, I, what I do is what's called a fractional Cecil, fractional chief information security officer for businesses.
[00:57:28] So what I do is I go into a business part time because I limit myself to somewhere between three and four. Customers at a time. And I have a team behind me that helps with all of the paperwork, the documentation, for all the compliance and everything else. It's out there. And as I'm doing all of this stuff for the company I'm bringing them in compliance with the cybersecurity regulations and in a lot of industries, if you're not in compliant, you're in big trouble.
[00:58:00] Okay. Then that makes sense. I think to most people. So I was thinking, okay, how can I promote my fractured? Chief information, security officer stuff. I tied it up a little bit of my LinkedIn page. I really got to get some stuff together on my Craig Peterson page and mainstream page as well, which is my company.
[00:58:21] But I am, I've done what I've done. So I started doing a little research saying what sort of stuff should I have out there on LinkedIn or other places? And this is where I really got surprised. And this is where the aid just stuff comes. And that is. Everybody. And I did a whole bunch more research on this and everybody says if your older do not even put dates on the resume of when you did things, don't put anything on the resume.
[00:58:51] That's more than 10 or 15 years old. And if you've got experience from back then, like I do, I could go in and be a cobalt programmer today. I did a lot of COBOL goading back in the seventies. IBM assembler. I did a lot of that. I even did 65 0 2 assembler for those that might remember that chip.
[00:59:10] And I've done a lot of kernel work over the years. See is my language of choice and was for years as I maintained and developed code for the Unix kernels. So all of that. Out the window. And what you do is you put it under additional experience. And even if you're saying, Hey, listen I've been doing this.
[00:59:30] Like I've mentioned to you guys before that I have what, over 35 years of cybersecurity experience and it's legit, right? You guys know I've been helping to develop the internet since the early 1980s, like 81 is when I got going a little bit in 83 is when I was into it pretty much full time. But apparently that's unknown nowadays.
[00:59:55] So instead of saying, Hey, listen, I've got 40 years of actually I've got closer to 45. I started in 75. I think it was in networking. IBM, networking, the old RJE and stuff. That's a no. I should say 10 plus years of computer network experience, because apparently what's been happening is these machine learning tools that hiring managers are using our age just now businesses are using them because of this problem we just talked about here from the New York times, recruiters are even getting hard to find.
[01:00:37] And employees are some in some towns, some cities wages are up 10% in the it area, just in general, let alone cyber secure. So you've got to go through automated systems now, as opposed to a person that's always been tough dealing with HR because HR, they, they don't know the business. They certainly don't know the jobs.
[01:01:02] They just got some bullet points, outlines that they're working with. So w we'll talk about this more. When we get back, I'm going to go through some points here, Korn ferry, and others have a lot of good points. And as I said, we should probably try and get Robert half on at some point they're local here.
[01:01:19] So anyways, visit me online, sign up right now, Craig Peter sohn.com and stick around. Cause we've got a lot more to go.
[01:01:28] We talked a little bit about the jobs, what it looks like out there, what recruiters are doing. I'm going to review here now the resumes, really? What should you have on them? Particularly if you're a little. Older like me.
[01:01:44] New York times. Great article about this. And I am also going to show you this other little article from wired here. We're going to go full screen for those of you watching here online, but the tech companies are really getting desperate. This is a chief economist over Dorsha. Published in a report saying the people are resigning at the highest rates since 2009.
[01:02:14] Huge numbers are leaving the labor market entirely and more than 80% do not want a job. The highest on record since 1993. That's absolutely amazing looking at these numbers. So this whole great resignation as it's called has really widened the gap. Let me make these, this text a little bigger for you guys.
[01:02:39] And there have been some huge gaping holes. In the workforce out there. S I T in general is really looking for people big time, cybersecurity, also looking for people. And I'm in the process right now of hiring a couple more. And let me tell you, it's more difficult than it's ever been before. In it alone.
[01:03:05] This, again, this is according to wired. 31% of workers actively sought out a new job between July and September last year. That's the highest amongst all industries, according to Gartner guys that make all this, these studies that they sell to businesses, data from global. Knowledge found 76% of global.
[01:03:27] It decision-makers are dealing with critical skills gaps on their teams, multiply the problem across other tech roles. And it's clear that there's a massive skills shortage and it's just amazing. They have. Sign on bonuses on top of sign-on bonuses, they're trying to move. Hey, we've got better snacks.
[01:03:49] And Facebook does out there in the bay area of California. They're having people working from home now. It's Hey, if you want to work from home, you can. Most people are w one of my sons just got a job. He. Performing kind of a CSO function. Like I do. He's worked with me for more than 10 years and that he is just working from home.
[01:04:14] He's never actually stepped foot in the office and he has been doing everything virtual, including the whole interview in process. Absolutely amazing. So they're calling this stuff a golden. Hello. In the business already saying, Hey, I didn't get one of those. Yeah. Cause you've been working there for five years, but everyone internally recognizes it's an unusual situation.
[01:04:40] And for us to continue to grow, we need to be. Competitive there's sign-on bonuses and they found those have not been effective in the it world because candidates are looking to maximize the opportunity to get much higher salaries elsewhere. Now, I did a proposal. I'm working with a company right now, and I did a proposal for them to provide some of these fractional chief information security officers.
[01:05:08] Function. I'm helping to define where they need to go, how they need to get there. I'm doing all the documentation on everything I'm working on, the HR policies everything, including securing the networks, helping them get the hardware, running it, renting them stuff right off the bat so that they can secure themselves very quickly.
[01:05:27] Whole bunch of stuff that I'm doing for. And it, frankly, I think it makes a lot of sense, but how could they possibly hire somebody like me? How could they hire someone like my son? So I went online to glass door. You might know about that website, glassdoor.com. It lets you check out businesses. What jobs might they have open and look at reviews from an employee's standpoint of.
[01:05:57] Glassdoor is pretty good for that. And I looked at salaries right now. Somebody like me, that is a CSO makes between 250 and $900,000 a year, depending on the size of the county. Now that's real money. Last time I checked, even with the inflation that we're looking at right now, I don't know. Maybe I won't keep up with it.
[01:06:23] I saw some inflation numbers. Of course, they move these out of the consumer price index because it would make it look bad. But some of these inflation numbers are over 20%. It's just not. So thank a salary, 250,000 to just shy of $900,000 a year. Salary. Plus load, which you have to add normally what about 30%?
[01:06:48] And then plus all of the equipment, plus the CSO needs a team, everything else. This is a huge problem. And they need to be hiring people to fill those jobs they use. These are just amazing. Permanent remote positions in the us doubled from 9%, 18% during the last quarter of 2021 doubled in the last quarter of last year ladders.
[01:07:18] And. All on jobs. This is according to the ladders. Okay. And it could increase to 25% by 2020 since making the transition to remote. First, we have been able to broaden our hiring options globally and not be restricted to a talent pool in one area. Now that's an interesting thing too, and that presents some interesting problems.
[01:07:42] It's one thing to manage people who are out of the. Upbringing as you are that have the same standards that you are and hiring somebody from somewhere else in the world, they're going to have different expectations. And boy, have I found that by hiring teams in India, Russia, and the Philippines, as well as the us.
[01:08:08] Big differences. So you gotta be, you gotta be careful with all that. Okay. So I promised I would get here into resumes for people like us, right? This is not what they say. And this is particularly interesting to me because again, I'm still working and I do it on a contract basis, obviously. I provide these services.
[01:08:29] This is something I think that applies to me too. So I'm pulling up a page. You can see on the screen, this is from the muse.com and it's called smart moves, age proof resumes for older workers. Okay. And they have four of them set up and they've got a nice picture of a lady. Looks like she's working from home with age, comes, wisdom and experience.
[01:08:51] That's why I was shocked. When I saw what was going hot and right. Where they were going ahead and saying, don't put anything on your resume. That makes it look like you're older. Okay. The quote here is age-ism is an unfortunate and very real part of the job search for older workers. And for some, it can start to creep into their experience as early as their forties.
[01:09:17] Isn't that incredible? Absolutely incredible. It's, I kinda dealt with this way back when, in the eighties, because I was younger then obviously than I am now. And there's this impression, at least there was, and it seems just still be around. But somehow if you're working with newer technologies, you need young people to do.
[01:09:40] That is not true. As I've said a million times, there's only a few ways that you can code something. So if you're a programmer and you want to solve a problem, there's really only a few ways to do it. In fact, there's books published with algorithms. That's the. Programmed stuff, right? The core of the programming that show you how to do things.
[01:10:04] So w we'll be back in just a minute, take a minute. Visit me online. Craig peterson.com. I love to see you there. And when we get back, we're going to finish this discussion, but it's an important one for employers as well as employees here, because I think many businesses are making a huge mistake. Craig peterson.com.
[01:10:32] We just talked some more about hiring. Age-ism the problems that come with that for both the employer and the employee. And we're going to get now more into this from the muse. We're going to talk about the four things you should be doing with your resume.
[01:10:48] There's there's a lot to be said for having experience. I mentioned about how businesses who are hiring programmers should really rethink the idea of hiring the young guy that knows the latest programming languages.
[01:11:07] Because again, There are so many things that you need to know besides how do you code this line? It's what Google did for many years. It probably still does. They don't want you to necessarily write a program in go, which is Google's latest, cool language, but they want you to solve a problem. They want to see your problem solving skills.
[01:11:32] How are you going to do it? Nobody has more skills than someone that's been doing that for decades. Again, there's only so many ways to program something. I don't care what language you're using. We used to have a saying, you can write COBOL in any language, but it's true. That's all we used to say.
[01:11:53] So when it comes to it in general, the older the person is the more experience they have in the field. The better off they're going to be with your company. Because again, there's only so many ways to break into a computer. Yeah. There's the latest, greatest virus out there, but managing people, managing expectations, working with senior staff, doing presentations for investors.
[01:12:23] That's the sort of thing that takes experience. How do you get that experience? There's only one way and that's to get the experience. It takes time learning a new programming language for a programmer, not a big deal at all. Again, there's only so many ways to do something and a programmer like me.
[01:12:41] That's done a lot written hundreds of thousands of lines of code, and at least a dozen computer languages. Pick it up. A new language is easy. I picked up Python and was able to be programming in it. Using API APIs online, all of the newest ways of programming and interfacing with other backend systems.
[01:13:03] I was able to write something that was putting together a whole bunch of cybersecurity stuff from scratch in the matter of a couple of hours on a language I'd never used before. Okay. How do you deal with that? It's the question of the hour, right? So let's have a look at this article here from the muse.
[01:13:24] They've got some suggestions for us. No. If you've been in the work case for workplace, excuse me, for decades, you've got a lot of experience, but putting it all down can be a real liability. I remember I used to have a a dossier. I had a resume, which was like a one pager. Then I had a dossier. The one on for 30 plus pages of all the things I had done.
[01:13:51] I wrote some of the very first I designed and implemented and used for a customer, some of the very first firewalls ever made routers, load sharing. But do I want to put that all on the resume? Probably not, but I understand that technology extremely well. So the resumes don't have to be a single page, but it's saying, remember it doesn't have to be a memoir.
[01:14:19] It doesn't have to be like my dossier going through everything to prove your worth. And what they're saying here specifically. This is a Gary Sussman. It's just a marketing tool whose sole purpose is to land you an interview. It doesn't have to be exhaustive and comprehensive just has to show that you can solve the problem.
[01:14:40] The hiring manager is hiring someone to solve and the beauty right now, again, if you're in the it, if you're in cybersecurity is they need. People. So it's going to be easier to get through. And if you are an older person who has learned a bit about cyber security, maybe taken an online course or two, that you have a much better job or a chance of getting hired for job than you probably have ever had.
[01:15:06] Okay. It goes on and on employers are most interested in how your recent work ties back to the job that you're applying for rather than your experience 15 years ago. Okay. That makes sense. So dedicate more resume space to detailing the positions you've held over the past to 10 to 15 years that are related to the job.
[01:15:30] Number two, do not date yourself. No. I mentioned earlier in the show that most businesses now are using some form of machine learning call it artificial intelligence, whatever you might want to call it, but they are doing the initial cuts. So they're looking for buzzwords that's for sure. Okay. And.
[01:15:53] What they're also looking for is saying, okay this guy's got more than 10 years experience. Who's got 35 years of 40, 45 years of experience in this, so do we want to hire them or are they just burned out? They don't want to do it anymore. What we're finding is the younger kids are definitely get burned down older people, not so much.
[01:16:15] We do what we love. No matter your age here. So Sussman explains that when he included, as number of years of experience, hiring managers told him he was too qualified, which he interpreted to mean they couldn't afford to pay someone his age, what his skills and experience were worth. He had better luck when he focused on more reason to experience and made his age less obvious.
[01:16:40] And if you've heard any professional certifications don't list, the year the certificate was earned. But do provide the expiration date on those certificates. Okay. A while, including a role you held or diploma you earned two decades ago are obvious signs. You're an older worker, there's other subtle clues, older professionals as sometimes.
[01:17:01] As lacking technology savvy. Do you guys think that I lack technology savvy, right? No. When the FBI InfraGuard program needed someone who knew technology could run technology and run their training programs, who did they turn to the FBI InfraGuard program? MI. Okay. So these sorts of assumptions, many people are making are dead wrong.
[01:17:29] I made no, I made sure there's no indication my agent, my resume, no mention my graduation year, no old school email addresses. If you have AOL Yahoo hot. Ditch it open and GML account. Once you've gotten that new email address added to the top of your resume, along with your mobile phone number and the URL to your LinkedIn profile, that's how they're hiring nowadays.
[01:17:52] You don't really need to put your physical address in any more, but you could put in your city and state. But remember, after the lockdown, a lot of people are working remotely and a lot of people have taken jobs and have never. Even gone to the office. And I used, my son is at example earlier he recommends removing all mention of outdated or standard software knowledge.
[01:18:15] This is an interesting point and a potential problem. I mentioned earlier. That I did a lot of cobalt programming back in the day. A lot for banks, market research companies and others. We were sown to COBOL. We wrote an assembler in COBOL. Okay. If you know what that means, that's the opposite of what you normally would do.
[01:18:38] Okay. Here's the issue I want to bring up. There are still COBOL applications out there, and it is very hard to find somebody that wants to write in one of these older programming languages or maintain some of these older programming languages. Okay. So that's the catch 22. Lean into your resume gaps.
[01:19:02] It says where as some older workers have to overcome the perception that they have too much experience, others need to explain a gap in your resume. If you stepped out of the workforce to raise children, to care for parents, or have been unemployed due to layoff. You might be wondering how do you handle it?
[01:19:20] Hiring managers are familiar with resume gaps, so it's not necessarily a cause. So what he's saying here is put volunteer experience in to the gaps. So you were helping somebody out, maybe you worked in a family business. There's things like that are not negatives. Highlight your achievements.
[01:19:42] This is the main thing here. Okay. I've seen this again and again. Older workers might feel intimidated about the job search process, but you've got a credible ACE in the hole that you can confidently present database examples of how you've delivered the delivered impressive benefits and solutions for your employers over the span of your career.
[01:20:06] This is true. Everybody. I don't care if you are 20 years old entering the labor market, or if you are 80 years old, still in the labor market, letting them know your success as what you've done. So for instance, for me as a fraction, Chief information security officer. I can talk about all of the companies that I've done incredible work for and what it's meant to them.
[01:20:36] In some cases, I have saved them from the brink of bankruptcy because of money stolen from operating accounts and because of ransomware and other types of malware, intellectual property theft, just on an. So he gives an example here, I think is pretty good. He says, instead of saying responsible for marketing materials and event promotion say created marketing materials and promoted events through social media, boosting attendance by 80%, over six month period.
[01:21:11] So you see what he's doing. Instead of responsible for keeping records to track contractor costs say developed and implemented a new record keeping system saving the company $12,000 per year in contract costs. You might include summary statements. I've always done that at the top of the resumes to outline what it is.
[01:21:33] I do what I can do for them. This whole thing. It's easy to feel overwhelmed. It's a little disconcerting when you're trying to do a job search. I know that just watching some of my kids just get, looked over. I have another one that's pretty high up in a business and she's been. Overlooked she's applied for jobs and came down to the last two people.
[01:22:01] She was one of the people, and I think the last three times she was overlooked. So you gotta be careful of that. And also because there's so much money out there right now, for people that are hiring work hard to keep the employees you have. That's it for today. Make sure you visit me online. Craig Peter sohn.com.
[01:22:23] If you have any questions, I'm more than glad to answer them. I get emails every day. Me, [email protected] and I'd be glad to help fill in the gaps. Take care everybody. Bye-bye.
Conservative/libertarian host Craig Peterson is heard throughout New England every week giving his opinion on Cybersecurity, new Technologies, and Government involvement.
This week, Craig talks about the latest announcement from the Feds: "Shields Up!" They're warning about Cyber attacks against the US. Coming from Russia, they expect untold carnage. But how likely is it?
Also this week: Senators trying to spy on all our digital information (including a RINO Republican). The "Right to Repair" backfires. Six reasons Meta/Facebook is failing. The top Cyber problems in 2021. More malware attacking Apple Mac computers. The five things businesses need to do for Cyber Security right now.
We've got a big alert from this CISA. That's our cybersecurity and infrastructure agency to come down about a week or so ago. It's been going up and down and of course the tensions out there are causing problems. So let's talk about it.
[The following is an automated transcript.]
[00:00:17] CISA is an agency of the federal government. And it's one that I follow frankly, pretty closely, because they are the ones that are supposed to be helping us in industry, as well as helping the federal government keep their security stuff in order now, are they well, yeah, they are. They are, but the bottom line is they've got a whole bunch of rules.
[00:00:44] Cool new things. And I'm going to show that to you here. This is called shields up over at CISA. For those of you who are watching online, you'll be able to see it right here. So let me just switch over. You've got it up now. Let me just go full screen on that so you can see the whole thing, but this is see.
[00:01:06] C I S A.gov and they have a whole ton of cybersecurity resources there. One of the things I hear the most from people is just how freaking difficult it is to try and keep track of things, even understand the regulations, let alone learn all of this stuff, but you can see on their site that.
[00:01:28] Training and exercises summit, that's coming up, combating cyber crime, and many other things. So what we're concerned about right now is. But this whole thing with Russia. Now you've heard about Russia or a lot, of course we've caught the germ report talking about Russian fake collusion, frankly. And we have Russians who have been hacking us.
[00:01:53] In fact, I've got an article on that today. Let me pull that up as well. You'll be able to see it. It is an incredible thing when you get right down to it. What Russia has been trying to do is attack and steal things directly from our agencies, right? The DOD as well. If you are a contractor, You are in a great deal of trouble.
[00:02:18] I don't have that article handy, but they are going after all of our friends at the DOD and all of their contractors and subcontractors. So what happened? There was technology that was supposed to believe be implemented at all of the contractors that of course did not get implemented. So that's a problem if you ask me, but it's now changed.
[00:02:43] Okay. 2022, what has happened? 20, 20, 22, they decided that the regulations that were in place were not tough enough. Not even close to being tough enough. So what. Is they added teeth, incredible teeth to these what are called CMMC regulations, which are the regulations that are about the cyber security maturity, if you will, of these DOD contractors.
[00:03:12] So now we're looking at this article, I'll pull it up on my screen again here that this has particular ones from security Boulevard, but it is warning about the risk of the Russians really hacking us. Now that's nothing new. We've known about that for a long time. We've known that the Russians and the Chinese are both trying to get in.
[00:03:34] I have customers who I picked up after they'd been hacked. And in fact, in most cases they didn't even know they'd been hacked was just something weird that was going on. So this alerts highlighting several cybersecurity vulnerabilities that these nation states and cybercriminals are likely to be leveraging.
[00:03:56] And they've outlined certain steps that organizations can take to reduce the risk. So what are those steps? I'm going to bring them up right now for those of you who are watching, but I may make it a little. How do you do this while they're saying let's break it down. We want you to reduce the likelihood of a damaging cyber intrusion.
[00:04:19] Again, sisa.gov. If you want to follow along at home, cis.gov, validate that all remote access to the organization's network and privileged or administrative access. Requires multi-factor authentication. We're setting that up for a company right now. In fact, ensure that software is up-to-date prioritizing updates, that address known exploited vulnerabilities identified by CISA.
[00:04:44] So you see that link that's right there. That brings us to this massive. Database, if you will of known vulnerabilities just 38 pages, 377 known vulnerabilities. So how does this work? When you get right down to it, you can look at the CVS. CVS over here on the left. If you cook on one of the CVS.
[00:05:07] It gives you some really good information, including some information about how to fix it, how to patch it and what the severity is. So what you want are those that are being actively exploded in the wild, basically 10 or a nine. There is a scale of zero to 10. Probably not even zero, but that's where the scale is.
[00:05:31] You notice here, by the way I add Dole bay is their top one. They are terrible when it comes to a lot of their software. So you can start. By whatever you might want to sort it by when it was added the action and the due date, which is for again, federal government people and federal government contractors and there's notes there as well.
[00:05:55] So this is something, if you are responsible for the cybersecurity in your business, you might be the office manager. That's so common in small companies and as the office manager, you are supposed to be. In charge of the computers. I can tell you with a great deal of assurance that most of the companies that are providing computers service are not providing these types of updates in a timely manner.
[00:06:25] Why because it's difficult to do so you have to do it. You have to track it. Okay. So shields up, let's go right back to that. They're talking about the other things that you should do. If you're using cloud services, this is just incredible because there's more. To do Microsoft. I had to put this in a proposal this week because the company didn't realize you're using all of this Microsoft 365 thing.
[00:06:53] You've probably heard about that. They've got email, they've got SharePoint, they've got all these other wonderful services and it's nice in an expensive to use, but here's your. The problem is that these particular services don't provide you with backups. It's not a guarantee, data, integrity, any data loss is your problem.
[00:07:15] And Microsoft has been sued on this unsuccessfully so far I might add. So just because it's in the cloud, not only does it mean it's not safe, it is just another word for someone else's computer and it can be completely. Unsafe. So you gotta watch it. You gotta be careful. So CSUs warning about that.
[00:07:35] They've got this free hygiene service. Now I applied for this. I'm going to pull this up again on my screen here for those who are watching live. But. The hygiene services. Very interesting because they say, Hey, listen, we'll go ahead and do it. And these CSUs cyber security assessment services are available at no cost, so who can receive them.
[00:07:58] Now, remember, I'm involved with the infra guard program. I put together their training for two years, I established that whole program training thousands of government and business sector people on cybersecurity. So you'd think they would respond to me. This is a huge program. There are people have probably even been on my webinars that I've held.
[00:08:23] They didn't get back. They say, okay, you can receive these free services while federal state, local tribal territorial, government, public, and private sector, critical infrastructure organizations will that to me, my clients, every last one of my clients is in a critical infrastructure service.
[00:08:43] Now it can be a dentist office. That's pretty critical. Just ask someone, who's got an infection. It, I have other people who are in the DOD. Base or providing materials and also products, manufactured products to government contractors, et cetera. So did these people get ahold of me return my email? No, nothing.
[00:09:07] So you can have look at this if you want to. But I got to tell you, it really turned me off from some of these CSUN people. So anyways, you can sign up, but you can't get it right. Take steps to quickly detect a potential intrusion. There's a lot of subsets here. You can see on my screen, or you can just go to sisa.gov/shields-up.
[00:09:29] I'll try and put a link to this in my newsletter this week ensure the organization is prepared to respond. If an intrusion occurs, that's a very big. As well, you have to have people, you have to have drills. You have to know what's happening when to do it. This is everybody right? This is HR. This is your public relations people.
[00:09:47] This is your it people. This is everybody all the way through the business. They've all got to be involved in this maximize the organization's resilience to destructive cyber incident. What is the. What has been happening lately? Coming out of Russia, isn't just ransomware it's they destroy your data.
[00:10:07] A very bad thing. If he asked me, and if he asked a lot of other companies out there, so you got to understand this, you got to be careful with this. Make sure you are following this rather closely, frankly, and this type of alert it's there. It's going to be there for a long time. No question about it.
[00:10:25] Shields. I liked that. I think it's neat. Obviously we got some star Trek fans in the work, so I don't know, just star wars have the, they have shields, but I don't remember them saying chills up. That was a card thing. Wasn't it? So there you go. Every organization is at risk. This is a big worry.
[00:10:42] It comes and goes. It's like. Orange and green and yellow or whatever those colors were over on the other side, right from our friends at Homeland security.
[00:10:53] We've been legitimately concerned for years about the government, watching what we're doing, listening into what we are saying while there's ways that they've been monitoring us for a very long time. And the senators now want even more.
[00:11:09] Senators, right? What are you going to do about them?
[00:11:12] It is back. I'm going to put this up on the screen for those watching live, but people don't want outsiders reading their private messages, not physical mail, right? Not texts, not DMS. Great little article here from the electronic frontier foundation. These guys are just amazing. I have agreed with most of what they've done and.
[00:11:35] Some of what they've done, but basically what they're saying is we have a right to privacy and it is enshrined in the U S constitution. It's something we're supposed to be paying attention to. Isn't it. And what we're supposed to be secure in includes our papers done. Which papers are we talking about here?
[00:11:58] I've got some paper here. This is an index card, right? I've got some paper here. There's some notes on it. So I'm supposed to be secure in this. So I guess that means that the file cabinet over there is a secure, right? We don't have to worry about the government breaking into my file cabinet.
[00:12:14] How about these things? How about our smart devices, our smartphones? How about our computers, our laptops, et cetera, always supposed to be secure in those, the constitution doesn't mention those things. It's funny how some people look at the second amendment to say, oh, it only covers a blunder buses, it just, It doesn't cover any modern weapons. And yet at the same time, they'll argue the exact opposite way when it comes to being secure in our papers, because we are supposed to be secure with all of our communications. Senator Richard Blumenthal and Lindsey Graham. One's a rhino and one's a dyno, right?
[00:12:54] Richard Blumenthal, a Democrat from Connecticut and Senator Lindsey Graham Republican from South Carolina have re-introduced what they're, what's called the Ernie act, earn it act and incredibly unpopular bill from 2020. Now it had a lot of opposition, which I think is fantastic, frankly. And it whole thing got through.
[00:13:19] But what the eff is concerned about is that in fact, this could end up being a massive new surveillance. It would be run by private companies. You saw what happened with the filings in Washington, DC from the germ investigation, right? Private companies were being used by the Democrats to spy on the sitting president of the United States.
[00:13:46] Incredible way. So Ernie. I have a surveillance system run by private companies would roll back some of the most important privacy and security features in technology that are used by people around the globe. So it's things like using signal, which is generally thought to be the best end to end private communications app out there, signal WhatsApp, which is questionable because it's owned by Facebook.
[00:14:13] But they say it's end to end encrypted, just, be careful about those things. I message on apple is end to end encrypted, but apple does respond to subpoenas and provides information, which again is supposed to be able to do. But should the government be able to go to third parties to get into your private papers?
[00:14:35] That's a completely separate thing, but the earnings act could ensure that hosts. Anything online, we're talking about backups, websites, cloud photos, your voice messages, all kinds of stuff is captured and scan. This is really scary. Now I'm going to put this back up on the screen because it's also talking about how this bill empowers the states and territories to put their own sweeping internet regulations into place and they strip away.
[00:15:14] The critical legal protections for websites, apps, things like social media. That's the whole thing. Section two 30 was about when we talked about two 30 on my Shelby. And two 30 is double-edged you got social media sites saying while section two 30, lots of us limit what people can say on our platform.
[00:15:38] I would tend to think that it actually says the opposite that they're not being held. They can't be held liable for what a third party says on their platform. So it's definitely not the same. And in fact, since they can't be held liable for what set on Facebook or Twitter, et cetera, they should not be censoring it because if they started censoring it now, all of a sudden aren't they a publisher they've got editorial.
[00:16:08] So liability comes into play here. Yeah. They don't want that, but that's what section two 30 is all about. And there's been a lot of debate about that over the last five or 10 years. And there's arguments on the far left and the far right. End in the centers to why it should go away and why it should stay.
[00:16:27] All right. So I tend to be on the, I think it should stay side. I don't like what some of these companies are doing by censoring speech, particularly, libertarian or conservative speech, they sensor like crazy. But the bottom line is if the, they didn't have that, then how about the good sites that are out there?
[00:16:48] The rumbles of the world, et cetera, that are trying to get a good message out to everybody. And are protected by section two 30. If 2 31 away a company like Facebook that has billions of dollars. Would remain the only major social media site, because nobody else could go in. They'd all be sued out of existence and they could not conform to all of these government regulations.
[00:17:14] That's part of the reason big companies love big government. It makes it so they don't have big competition. Absolutely amazing. The, so this document here. Earn it, bill is saying. And another document that came out from the bill sponsors. Amazon is not scanning enough of its content. Now, Amazon is the host of Amazon web services and I've used them before.
[00:17:42] I still use some of their services. For instance, for transcribing this show, I wrote some code that uses API APIs that go into Amazon and upload it and download transcripts and then reformat it for me. So I use some of those, but Amazon. Has the lion share of what's called the cloud data services.
[00:18:07] So they're storing a lot of data for people. Long-term data in a glacier, for instance, and short-term data and ask three. But they're complaining a huge number of websites are hosted there. And this Bill's aim is to ensure that anything hosted online gets scanned and the bill creates this is just, you couldn't make this up a 19 person, federal commission dominated by law enforcement agencies, which are late.
[00:18:36] Best practices for attacking the problem of online child abuse. It's for the children, everybody, regardless of whether state legislatures take their lead from that commission or the bill sponsors themselves, we know where the road will end says CFF. Absolutely. True government approved software, like photo DNA.
[00:18:59] I don't know if you've heard about what happened with photos and with Metta Facebook, but they just lost a huge lawsuit where they were sued by a few different states about you remember the, it would automatically tag people in photos. So it was doing photo recognition, the photo DNA thing. And they got sued because.
[00:19:23] Obeying the law. Yeah. Talk about that one for an hour as well. So earn it. Not something you want, but apparently these senators wanted as well.
[00:19:36] We've got a problem with our cars nowadays. Have you tried to turn a wrench on one of these things? They're all computerized. I don't mean a computer. Some of the cars nowadays have dozens of computers in them. How about repairing them? We're going to talk about right to repair.
[00:19:53] A great article in ARS Technica that you'll find, and this is about the flight.
[00:20:00] For the right to repair. Now, there have been a few right to repair bills that have been released over the years. And the idea behind this is well, having a big fancy car is wonderful. You can drive it all over. But how about when it's time to get that car repaired? What are you going to do? How are you going to do it right?
[00:20:26] Does that make sense to you? It can be a real problem. And this article is fascinating because it talks about this chief Morelli who had a Subaru SUV. Now she bought this in 2018. A lot of people buy Subarus because that engine is incredible. There's nothing like a boxer engine. That's where I'm on. My motorcycle has, and I have 160 something thousand miles on my motorcycle.
[00:20:53] These super engines last, no, the electronics, the motors, the electric motors. I had different story. Are there problems with Subaru's? But it made her feel safe. So off she goes, right? Like Volvos. People buy those for perceived safety as well. I have some issues with those, but her husband mark decided to purchase his own car last summer.
[00:21:18] So they went to the Subaru dealer near their home in south east, Massachusetts. Now here's the catch to all of this Massachusetts passed a right to repair ballot measure that was approved overwhelmingly in 2020. So what that means is that all of the vehicle manufacturers have to use a standard.
[00:21:47] Computer interface in order to do anything on the car, the idea being that you can take it to a regular mechanic that can read from that wonderful little port under your dashboard can maybe do a little bit of reprogramming of the car and not have something different that they have to buy. Like for almost every car.
[00:22:10] I know I have. Oh, for quite a few years, I'll a Honda dealer as a customer of mine on the cybersecurity and computer side. And I ended up having to have help Honda's headquarters in Japan, fix major problems that they had with this little computer device that they were using to fix the car. So they're there.
[00:22:37] They are trying to fix them and the device just isn't working and the device has to be constantly upgraded because there's bugs in their software and there's new features in the cars. So it has to be upgraded and updated and everything. So the idea behind right to repair is we can't have everybody out there constantly trying to upgrade their hardware in order to talk to the car.
[00:23:04] And they shouldn't have to buy multiple pieces of hardware for a single family of cars, let alone multiple pieces of hardware to cover all cars. So Massachusetts voters did the right thing, right? Cause they said. We want the right to repair our cars. You can't keep us out of them anymore. So that's when she and mark, I had a bit of a surprise.
[00:23:30] Because they went and bought a Subaru in mass, another one. And then they found out that the Subaru telematics system and the app that went along with it, and that includes remote engine start, it gets cold up here. New England, no emergency assistant, no automated messages. Tire pressure was low oil needed, changing.
[00:23:56] What's available now, if they had remembered they were living in Southern mass Southeastern mass, but they could have gone just over to Rhode Island or up to New Hampshire. And Bob that same car and would have had all of those features. You see what happened is Subaru said we cannot support this right to repair because that means we have to have a, basically a different car format.
[00:24:28] Now this isn't the first time we've seen this type of problem before California and Massachusetts have both had crazy. If you will laws on the books for a long time defining, oh wow. You can't have diesel. Cause it has this too many particulate matter pieces of matter in it. And it has to have this kind of mileage overriding federal regulations by.
[00:24:50] So let's not the first time now. I'm in New Hampshire, live for your die is our state motto. And all of the states around us, have we effectively banned diesel vehicles, New Hampshire hasn't we could get into this. But basically a diesel vehicle is every bit as clean and non-polluting as an electric car.
[00:25:13] In fact, it's less polluting when you consider the lifetime of the vehicle and the manufacturing of the cars. Okay. With the batteries and everything else. They were pretty upset about it. And this article of ARS Technica talks about this a little bit more. It says Subaru disabled, the telematic system, and the associated features on new cars registered in mass last year as part of a spat over a right to repair ballot measure.
[00:25:42] As I mentioned before, this open data platform that they're talking about here in the LA. It doesn't even exist yet. We've talked about laws before and how really the laws either a few steps behind technology or they try and get in front of technology and just mess it up. Like they have with nuclear power, right?
[00:26:06] The new nuclear, the fourth generation is just amazing stuff. And yet they really messed up. It says that it doesn't exist in automakers have filed suit to prevent the initiative from taking effect. So first Subaru and then Kia turned off telematic systems on their newest cars in mass, which has really gotten some people upset.
[00:26:26] And here's the quote from them. This was not to comply with the law compliance with the law. This time is impossible, but rather to avoid. Violating it now. Isn't that interesting because again, companies and people have to do things to avoid violating. Okay. I'm going to say it stupid laws. So interesting staff.
[00:26:49] This is just the latest dispute in this whole thing about the right to repair. What should you be able to do with your car? What shouldn't you now? I've got some really bad news if you're a right to repair advocate because. All of the newer cars that are coming up, particularly these electric cars that they love so much in Massachusetts, these electric cars are going to be sold as a base model.
[00:27:19] And then what's going to happen is you pay monthly. In order to have certain features turned on you. If you follow Tesla, Tesla has done this thing where it's okay. Six grand and you can get the auto drive. And the course they still don't have the fully autonomous driving. And then they raised it to eight grand.
[00:27:42] I think it's 10 grand now, or maybe even $12,000 for it. And they decide, okay let's step into that and we're going to change it. And some of these companies, I think it was, I'm not going to mention the name because I'm not absolutely positive, but some of these car companies have decided, oh, you, you know that remote start that you paid extra for them and you got your car.
[00:28:02] Unless you pay us $8 a month, you're not going to get the remote start. So think about that for a few minutes. Your car's going to have the ability to drive autonomously. It's going to have the ability to do all kinds of wonderful things, but you won't be able to use them. Unless you pay your monthly fees.
[00:28:22] Talk about right to repair. All right. Hey, I have a weekly newsletter and that newsletter has a little bits of training for everybody business or otherwise, but you have to sign up, go right now to Craig peterson.com.
[00:28:40] About Metta and that Metta has been busy making changes because Metta is really Facebook. And if you've been paying attention, the medicine. Huge stock drop.
[00:28:55] Metta oh my word. I, where to even begin? Mark Zuckerberg and company have known for a while that their company is going to be in trouble.
[00:29:08] Metta is the parent company. Of Facebook just like alphabet, right? The parent company of Google. So it's almost like a reverse merger, or they move them around. So Metta is now the company that owns Facebook as well as other properties. And what Facebook has been doing for years now.
[00:29:29] Over a decade is by. Potential competitors. If you have enough money in the bank, you can just go ahead and spend that money to buy competitors. Then you don't have to worry about competing with them. Look at the Insta. Look at WhatsApp. Look at many of these other things that Facebook has acquired over the years and what they're looking for of course, and always have been looking for is eyeballs.
[00:29:56] And they want to know what are those eyeballs really interesting. They've been doing a good job at that and have been really sucking a lot of data out of us. And I don't need to really say this, but Hey, listen, if you're not paying for it, you are the product. They suffered their biggest one day.
[00:30:18] Wipe out. Ever this year, this is an article from our friends at the New York times. So they're saying Mehta, the company formerly known as Facebook suffered its biggest one day. They called it a wipe out. I love that as that stock plummeted 26% and its market value plunged by more than $230 billion. So they had a really bad earnings report.
[00:30:51] They have been trying to transition from social networking towards what they're calling the virtual world of the metaverse. Now the metaverse has been a promise for a very long time. And you can think of it in a few different ways. One way is the, you have the goggles. I don't know if you've seen ready player one, a scifi movie where this kid is.
[00:31:18] Trying to solve this. Basically you're a riddle that was put in place by this guy, geeky guy that founded this company and they all played this video game against each other. And they had not only the goggles, but they had a whole suit, so they could feel what was going on. Ready player one. Very cool.
[00:31:40] So that's one idea of the metaverse, which is you don't have to live in the real world. You can just live in this virtual world and that's exactly what they did. So they reported some modest games and new users at over at Metta, which includes of course, Instagram messenger and WhatsApp, which are the core of their money.
[00:32:05] I lost about a half a million users over the fourth. How is that a quarter to quarter or half a million users? So that's the first time they've had a decline like that in the company's history. And frankly, Facebook was such a Darlene of the stock market because they were continually growing. It was like the perfect bet.
[00:32:31] There's no way you could lose money, investing it in Facebook. And yet, in fact, What did they do? They lost money. They lost a lot of the money. Now executives over at Facebook are saying, Hey, listen, we can grow this company more. We haven't even done anything with WhatsApp. The, the running that you might remember back in the day, WhatsApp used to charge a dollar a year.
[00:32:57] Now that doesn't sound like much, but when you have a hundred million members or more yeah, that's a fair amount of money to run a small company that has, I think it was like 50 employees at its peak here. So they're saying over at Facebook we could start inserting ads into WhatsApp.
[00:33:17] We could start monitoring communications. What. That's why I don't trust WhatsApp. There's a lot of things that we could, things we could do. We get generated a lot of revenue from WhatsApp users. They're also looking at weather metas, other top apps like Instagram might beginning getting to the top of their user growth.
[00:33:39] Now I've been talking with a couple of. That are in one of my mastermind groups. And they've been talking about how they've found their businesses have grown very well using. Instagram advertising and not just advertising, organic stuff where they post things and people find it on there, which I thought was kinda interesting because we're all pretty much in the business to business world and they really like it.
[00:34:06] So I'm going to try it out too. And if you've used Instagram, And the success been success with it for your business. I'd love to know. Just drop me an email Craig at Maine, or excuse me. [email protected]. mainstream.net is my main business. Where I'm I do the CSO work the chief information security officer stuff.
[00:34:30] So apple introduced what they're calling. App tracking transparency. This is a pretty big deal. Put this up on my screens. You guys can see it, but apple made some changes to I O S and what it's doing is trying to wall off its safari browser from tracking software. The total. What does that mean, frankly, to somebody like Facebook?
[00:35:00] It's going to be very hard for marketers to be able to figure out who is doing what a win now to top that all off our friends at Google who also make money from us in our eyeballs, our friends at Google have said we're not going to use the pixels. Who used. And what Google is doing is incentive tracking you as an individual user.
[00:35:27] They're going to put you in a bucket with a whole bunch of similar users. So in other words, I'm not much of a change on Google's front, but enough of a change that it has made investors more than a little bit worried about what the future holds, because Apple's blocking their access people. You guys, right?
[00:35:49] How many of you guys attended those webinars? I did on how to disable tracking on your computer, on your browsers, et cetera. When you're going online, a lot of you guys did, so we don't want to be tracked. We don't want them to be tracking us. And again, how do they make their money? They make their money by tracking us.
[00:36:13] And that is precisely what they've been doing. No wonder that our friends at Metta had a terrible, no, get good, very bad week earlier this years. So Apple's limiting it. Google is stealing online advertising chair because remember Google has ads all over the place. They're on all kinds of platforms on.
[00:36:42] It's not just on the one Facebook site, for instance, for Facebook. So in Google's earning call the same week, Google reported record sales, particularly in e-commerce search advertising. No. Where you go to Google and you're searching for something that can be bought online. Yeah. That's particularly where they made money.
[00:37:04] Very same category that tripped up Mehta the last three months of 2020. So Google is not heavily dependent on apple for user data. You said it was like to do the Google had far more third-party data for measurement and for optimization purposes to Metis ad platform. All of this great information here in New York times article I've got it up on my screen so you can see it.
[00:37:28] Next one, ticked. They have been stealing young eyeballs, like crazy Tik TOK has been very popular. It is unfortunately owned by a Chinese company. And there has been a lot of talk lately about how tick talk, collects our data. And we don't actually know what they do with it, but we do. That it's in China and all of these businesses in China ties to what the people's liberation army, the Chinese communist party.
[00:38:02] They have more than a billion users on their site and the videos are addictive. Like one of my kids forwarded me one this morning. I was happy. I didn't have to download the Tik. Yeah. I was able to watch it on my web browser. It was actually quite funny, but it has been an amazing competitor for Meadows, Instagram, for eyeballs and attentions people, by the way, have also been a business friends.
[00:38:29] I know have been making some pretty good inroads using tick-tock advertising. So what does Mehta do? I can't buy, tick-tock not for sale, so they introduced something. They call real. And if you're on Instagram, you'll see reels ads been very prominent. R E L S. Yeah. It's currently the number one driver of engagement across the app.
[00:38:56] So reels is attracting users. It isn't making money as well as Instagram is stories in the main feed, make way more money for them and spending on the metaverse. According to the New York times popped up on my screen again. Is bonkers. So Zuckerberg is thinking that the Internet's next generation is this Metro versus this wonderful world of who knows what, that he's willing to spend big money on it. And I'm highlighting some this screen from New York times article because the spending a mounted apparently to more than $10 billion last year, and. Metta is going to spend even more than that in the future. And there's no evidence that it's really going to work, what's going to happen. Now we also have, of course, the specter of antitrust laws here in the us, various similar y'all laws in Canada. It's the anti combines act in Canada, but same thing in. They have already been sued. They're going to be sued again. So Metta is in meta trouble and we'll see what ends up happening with these guys.
[00:40:11] But this is really interesting because frankly. Even though Zuckerberg says they're not a monopoly, regulators are disagreeing. And I agree with the regulators for once. All right. Hey, visit me online. Sign up for that newsletter. Get all of those free little trainings every week and a whole lot more.
[00:40:31] Craig peterson.com.
[00:40:33] And data breaches are a very big problem. So what do we do about them? What are they? That's the first step, right? You got to know what you're protecting and you got to know what the attacks are. So we're going to talk about that. What has been the case in the last 12 months?
[00:40:50] The three most common causes of data breaches in 2021 were.
[00:40:58] This is according to dark reading number one, cyber attacks. And we're going to talk about those different types of cyber attacks. Number two, human errors and system errors. Those are very big ways to get attacked and get breached. And physical attacks was the third one. Now what do all of those things mean?
[00:41:19] And what are they doing? We know the Russians and the Chinese are trying to get our information. In both cases, it's espionage. In both cases, they want to see the information about our military, what the military is doing and how. Can really steal our secrets. Look at the newest fighter in the Chinese air force.
[00:41:44] That fighter looks a lot like our fighter. In fact, they beat us to the punch and making it. Here's what we can tell. Still got some things to work out, but they made it from our designs, which they stall that's the allegation. And certainly looking at the two planes. I think that's probably exactly what happened.
[00:42:07] That's what they're doing. So that's on one end of the scale, right? Way, way up there, where it's major industrial espionage, it's worth billions of dollars. And then there's you and me. So from the you and me standpoint, what are they looking to get? On one end, they just want to cause chaos and confusion.
[00:42:30] We know, for instance, during the 2020 election cycle, there were all. Of social media posts that were not legitimate. They weren't real, they were all fabricated. We know that they were trying to do it, particularly the Russians, just to confuse the issue entirely same thing in 2016, we can expect a lot more of that as elections go forward.
[00:42:56] So that's one thing, how can they do that effectively while they need a lot of computers? How do they get their hands on a lot of computers? Simple, they steal them. So what they want to do is get their hands on your computer, on my computer. And once they've got their hands on our computers, now they can use them in order to do posts online.
[00:43:21] So they it's going to look like it's in 1, 2, 3 main street, downtown USA, because of. They're using your computer to do these posts. Now, the other thing they'll use your computer for is to hack other people and other people's computers. So you've seen it for years. I remember. The Matthew Broderick movie war games, and they were trying to go through, remember back then it was dial up modems going through the network in order to hide where they were and to get around blocks that were in place.
[00:43:56] That sort of thing is continuing to happen today, where they can hop between the computers, but some businesses, for instance, have been hosting videos of just horrific things that are being shared by. Bad guys jihadists over in the middle east, the people all around the world, the using our computers as store and forward.
[00:44:19] The biggest thing right now is what's called fishing. Now fishing has a few different categories and if you're watching this, you can see right now, The eighth, the growth in fishing over the last three years. So in 2019, it was 928 cases. Again, this is reported right to 2020. It went down slightly.
[00:44:45] Yeah. The vid, and then 2021, it doubled to 1600. Isn't that amazing. It doubled. So there's fishing, there's smishing and there's email compromise that amounts to the biggest amount of hacking that's happening. So what does that mean? What is this big hacking that's going on? It's pretty simply put, we're talking about hackers who are trying to fool us into doing things.
[00:45:16] So you've heard about phishing attacks. I'm sure. Before. P H I S H I N G. And that's where a bad guy sends you an email. It looks like it's from some legitimate sores and it might be a bank. It might be the FBI, PayPal, you name it. So you open it up and when you open it up, what ends up happening? Wow. Click on the link inside there.
[00:45:39] There are bugs in various email programs. There haven't been over the years. We're just having that headline show up in the summary, caused your machine to be compromised. But nowadays, most of the time you have to in fact, click on something, doing that. So that's fishing. I just prepared a video for our clients.
[00:46:02] One of whom was having a real bad problem with phishing attacks, using specifics for their business, it's okay, now one of our vendors got hacked and they're using their email server, defend fish, send phishing emails that happens with. So I put together a training video for their people. Okay.
[00:46:23] Here's the vendor. Here's what these things look like. Here's how you report it. Here's what to do about it. The next one is Smith. This is effectively the same thing as fishing, but it's using SMS. It's using text messages to try and get you to do something. So again, it might be a link that sent to you in a text message, or it might be a message saying, call me, I get almost every day I'm asking.
[00:46:52] On WhatsApp. We use WhatsApp for one of my masterminds. I'm not a fan of WhatsApp, you know that, but that's what everybody else is using. It's not the worst thing in the world, but I get I would say at least weekly, maybe every twice a week, who knows, but I get a message saying is this Brian?
[00:47:10] Of course I'm not Brian, right? I'm Craig Peterson. So the normal response from somebody would be. No, this isn't Brian's number, but the problem is that now you have engaged with them. They know there's a real person, they start a conversation, they try and get a little bit of information about you, and then use that against you to get into bank accounts, to steal money, et cetera, which is the third.
[00:47:37] Fishing, which is called BEC, which is the business email compromise. This is absolutely huge. According to the FBI, there have been billions of dollars stolen using BEC I know one company that got really nailed and their operating account got emptied because of a business email compromise. So what is that?
[00:47:59] That's where you get an email. At your business email address and that email again, just like a regular phishing email looks legitimate. So you look at that email and it looks legitimate. You open it up. Okay. So far it's the same thing, but what they're trying to do with the business email compromise is get you to do something that's going to hurt the business.
[00:48:24] In these cases that I've been talking about, what happens is it looks like it's from the CEO or looks like it's from the CFO. We could talk about a lot of the different compromises that have happened. Probably one of the most famous is with Barbara Cochran. She of course, on shark tank and she had about $400,000 almost stolen from her because in the email was.
[00:48:51] To basically her bookkeeper accountant saying, Hey, we need to pay 400 grand. Here's the account number, because remember she's in real estate. So there, rehabs happened in all of the time and the assistant, I think caught it and they were able to stop the transaction, which is amazing because you only.
[00:49:10] Second is quite literally in order to stop those types of transactions. So she stopped it, but that's an example of a business, email compromise. There are fancier ones that happen to this is the problem with having your email addresses or names even on your website. So people can just go to the company website and say who's the CEO, who's the CFO who.
[00:49:37] This person who's that person. And so they go through all of that information and they've now got something they can use against you. So what do they do? They know who the CEO is, so they chum up to the CEO, Facebook or other social media, LinkedIn. Where'd they go to school and then they send us a note on, let's say LinkedIn or Facebook saying, Hey, I want to follow you.
[00:50:01] I want to talk whatever you don't remember me because you put on LinkedIn that you went to Harvard business school. So yeah, you remember me? We were in class together. This is Joanne. And we took econ 1 0 1 at Harvard. So now a conversation starts up, they get LinkedIn to you, they get your Facebook start following you and see, oh, they're going to be in The Bahamas this week.
[00:50:26] That means they're out of touch. So during that week, they go ahead and send an email to the CFOs saying, Hey, we've got this new vendor. And if we don't go ahead and pay this vendor, we're going to lose. Because we haven't paid them in three months. So the CFO then wires the money. Now you might think, oh, that's just too much work.
[00:50:45] First of all, a hundred thousand dollars will support families in Eastern Europe for about three to five years. Okay. Secondly, that particular tactic didn't just get them a hundred thousand dollars. It got them $45 million. Oh. And it wasn't them. It was a, her a single. That was able to do that. So business, email, compromise, you've got to watch it.
[00:51:11] And then of course, all of the normals, right? Ransomware, malware, a unsecured cloud environment, credential stuffing, et cetera, et cetera. All right. Hey, I want you guys to take a minute right now. Go to Craig peterson.com one cheer there. You'll see right at the top of the page, I'm going to pull this up here for those watching on video.
[00:51:34] Subscribe for email updates. You'll get my updates. You'll get my trainings as well. Craig peterson.com.
[00:51:41] I'm a Mac fan and being a Mac fan means that I like max and a lot of people like max, because they are typically safer than a windows computer, but now that they become so popular, Hey, they're a target, too.
[00:51:57] So here's your problem. As it might say, Macs are starting to see the heat. In this case, the heat they're seen is something called update agent. It has been around a while. And many people have downloaded it. And I've known about various types of Mac malware over the years. Some of them worse than others.
[00:52:22] The one in particular that I'm thinking of a friend of mine paid for this stuff that was supposed to keep his Mac clean. So first of all, If you're looking for some anti-malware software for year Mac, I prefer what Cisco has as very nice advanced stack that you can use. But in addition, here, you can use, if you can't get the advanced Cisco stuff, you can use Malwarebytes.
[00:52:49] It is quite good. Now, historically, one of the main reasons you want to protect your Mac against viruses, including. Windows viruses is that your Mac can potentially spread a virus to a windows machine. So let's say the virus is sitting there inside of an Excel file, a word file. Some other document exec, whatever it might be.
[00:53:14] So that virus is sitting inside of there. It's not going to hurt your Mac. It's a windows virus, right? So now you send the file to somebody else and now they are on a windows machine and they are susceptible. They get nailed with it. Okay. So that's been the main reason historically. You want to make sure your Mac machines are clean.
[00:53:36] Cisco on the Mac, advanced mow, worse platinum. Does look for windows malware. Okay. As well as something that might be affecting a Mac, but what we're [email protected] is a piece of malware that is specifically aimed at max. And it's interesting too, because it isn't just max.
[00:54:03] It actually has multiple versions that included. Our friends over on the windows side. So it's called update agent or wizard update. And it is malware that I, as always, it seems is pretending as legitimate software, right? Support agents, video software. It's been around for a couple of years now. Adobe flash.
[00:54:29] Not only was it a serious security problem, but Adobe flash, as it turns out, was shoes to spread a whole lot of malware here over the years. So they've constantly updated this thing. They came up with a new version in October. They've been sending it around using Amazon and cloud front in order to do it.
[00:54:52] So instead of using zip files or. Apple uses, which are called DMGs, which are basically compressed file systems. The new version can use zip files or Mac DMGs. It's not good. Again, be very careful. Now apple has had for quite a while, and a signature based thing where software developers register with apple, they sign the software, they send out, but there are ways around it.
[00:55:24] And some of the hackers have been exploiting those ways. In fact, this version is the fifth version. Of this update agent and wizard software. Okay. So be very careful with it. Don't think that because you have a Mac, you are guaranteed safe because you're not, but they're also talking in this article about jam.
[00:55:49] Now. Jam is a great. Of software for managing your Macs. We use IBM's mass 360 for our clients, and it lets us do mobile device control as well as for desktops. If you're a CSO, how valuable, something like that really can be apple has their own thing built in. If you have Meraki equipment, they have their own lightweight.
[00:56:15] Controller as well, but jam is very well known in the industry and it's one of the better ones out there jam was showing in research last year, that ad where is continuing to be a much bigger threat to Mac users than most other types of malware. Now, what is that? What are we talking about here? Add where is where a piece of software.
[00:56:41] Gets onto your computer and shows you ads. That's one type, right? There's other types of ad wares as well. The most malicious types being, they will run as JavaScript inside your browser. Or sometimes they'll add, they'll run as an extension. That happened to one of the extensions I loved for. And I used it all the time and someone bought it and turned it into ad where spyware.
[00:57:09] Okay. So on the Mac front, it's very hard to get a legitimate piece of nastiness, like ransomware on your. You actually have to go out of your way to allow it to get installed, but this ad where some of it even minds Bitcoin, we've talked about that before, but what will happen is there's just an added in ad network, right?
[00:57:34] So if I pull up my screen again here, this is just the regular webpage here for dark reading. It's the article we're talking about. Here's some sponsors. Content is actually from one password, which is, something. I really if you look down at the very bottom of the screen is kinda hard to see, but it's the link to this takes you to ad click.g.doubleclick.net.
[00:57:58] That down there on my screen. So that particular URL now is going to track. You see how long that URL is. It has all of this other you ID type stuff. That's an ad. And then ad was probably delivered via a network of some sort, these editor choices, things. These are not ads that are purchased.
[00:58:21] These are probably coming from dark reading itself, who knows. But this Menlo security ad is an ad. You click on it. You can see, again, this is doubleclick.net. These ones here are not doubling. Those are direct on this paper. So what is that double click is what we call an ad network. So if I'm an advertiser and I want to get in front of people who really liked technology, maybe the visited the one password page, which I've done, right?
[00:58:53] So I go to the one password page. It deposits a cookie on my browser. Now I'm on dark reading and on the dark reading site, what's it going to do? The ad network is going to show me an ad for things that thinks I'm interested in one password. The guys who bought through paid for the ad to double-click.
[00:59:14] So that's how double clicks making money. They show the ad to me on dark reading. So that's how dark readings making money either by showing the ad or potentially by being paid. When I click on the ad, if I do click on that ad. All right. So if it's a company you liked, don't click on the ads because it's going to cost them money.
[00:59:34] If it's a company you don't like, then click on the ads, there's actually plugins by the way, that will click on every ad on every page you go to. But not really, it's not going to take you to all these sites. It's just going to look like you clicked on it. So these ad networks. Are being used by bad guys to put an ad in that is actually some form of malware.
[00:59:57] So just seeing the ad might cause some JavaScript to start. And you've probably seen this before. All of a sudden your computer screen shot is full of all of this crap. Where did that come from? It probably came from a small window hidden window, but came from some of this ad stuff that's happened.
[01:00:14] All right. Big problem. And it is right now, the biggest problem in the Mac world, according to jam, and it's called malvertising. You got all these cute names for everything malvertising in this case. Hey, thanks for spending a few. Today, if you would, please go right now, go to Craig peterson.com. You'll see at the top subscribe for email updates.
[01:00:43] When you subscribe, you're going to get my top special reports on passwords and other things, and you'll get my weekly emails and trainings stick around.
[01:00:54] Cloud security. Wow. What a mess. If you are using any of these services online, you probably have a cloud security issue. That means your websites, too.
[01:01:09] Security pros like myself are very frustrated by what we loosely call the cloud.
[01:01:19] So the cloud is just a name, frankly, for somebody else's computer. So you might be using a cloud for instance. Salesforce.com system you might be using your email, Hotmail, Yahoo, right? You might be using Microsoft mail. There's a lot of them out there and they're all cloud systems. Being a word for somebody else's computer.
[01:01:48] That doesn't necessarily mean that's somebody else's backing it up or that they're providing adequate cyber security for it. So we've got an article right here. Again, from our friends at dark reading, Robert limos about why security professionals are frustrated with cloud security. So more and more companies are moving their operations to the cloud.
[01:02:16] And because there are so few people available for cyber security. They're really getting in trouble. Okay. They're really getting in trouble. There's a lot of security data that does never get looked at. It's full-time jobs for people, depending on again, how much cyber security they need so many false alerts and we've got warnings from the feds now that are probably going to continue forever.
[01:02:48] Cybersecurity breaches that they're seen and they're thinking they're going to come. So security data they're saying is wasting more than half of the time spent on security issues. That is not a good thing because there are so many false positives when it comes to cyber security. So how does the basic cybersecurity work?
[01:03:13] For instance, if we were to look at one of the firewalls that we maintain for our. Or our clients, you would see attacks coming up every few seconds. I can show two on just one little machine. If you're talking about a bigger company or a contractor for the department of defense or a subcontractor for the government in any angle, you will see.
[01:03:40] Sometimes dozens of attacks per second. So they're pinging. They are trying to connect to services like Microsoft, remote desktop. They're trying to break in any way they can. That is frankly, a pretty huge problem. Are those legitimate security alerts? Yeah, I guess they are. I have stuff set up so that if someone is trying to, for instance, log in remotely on one of these remote type protocols and they fail three times in a row, they are automatically added to the firewall automatically.
[01:04:22] And they are. Now it removes that ban after a while, but if they do it again, they get banned again. So we know who the bad guys are. And let me tell you, there are a lot of bad guys out there. I don't know if I can get on that machine right now, because I think you might find that. Interesting. Yeah. It's not going to let me on right now, so I'm not going to do that, but it is a very big problem.
[01:04:53] Should I be looking at each one of those security alerts about somebody trying to remotely connect to one of these connection services, right? Desktop services, SSH services. Probably not, it's probably not the best use of my time. So what we have is other canaries, if you will, in the networks. So other points that, okay, they're trying to get in from the outside, but people are always trying to get in past the gate.
[01:05:23] But if they are not successful getting past the gate, I don't really care so much about. Okay. So how do we tell if they're inside the network? So we have other security probes inside the network. We have probes in the switches themselves. We have every network segment. Firewall from each other.
[01:05:46] And in some cases we have absolutely zero trust. So every connection to any machine is checked and firewalled depends on how much cybersecurity you need. So this is a report from a Cod automation firm called Lacework and they talked to 500 security practitioners, blah, blah, blah. They are saying that the vast majority of respondents regularly have to deal with at least a 20% false positive rate and a third deal with a 50% false positive rate.
[01:06:25] The analysts are not alone. Only a third of developers believe that the time spent on security is meaningful. According to the survey and frankly, that's what we have found as well. And that's why we have automated systems and the automated systems say, whoa, this looks really bad. And that's when a person gets involved.
[01:06:48] So it's a real problem. Now here's the next step. And the next step is while we had so many people who were working from home. And because of the lockdowns. Following the start of the Corona virus pandemic, according to this article or dark w reading organizations quickly moved operations to the cloud, we know that's true. We've seen it. We've helped companies secure themselves from their hasty moves to the CRA the cloud. But after two years, companies still have a long way to go before moving. All of the operations to a cloud is less than half of respondents consider the most important applications to be cloud native.
[01:07:34] Now, this is really important because some companies have been moving in, particularly some of the larger ones moving critical applications back in house. Now the cloud is wonderful. A lot of vendors love the cloud because it's MRR monthly recurring revenue. Yeah, you can use my software, but you have to pay me every month.
[01:07:57] Oh. And by the way, I don't want to support you guys anymore. I don't want to have to get onto your servers and take this apart girls. So I'm going to do all of this on my servers. We'll call it the cloud. Maybe it's on Amazon or Azure. Maybe it's in my data center, whatever. And I'm going to charge you a premium.
[01:08:14] What's happening with your data when it's sitting on their computer or Amazons or Microsoft's computers out there, right? It's a very legitimate question and a very concerning question, frankly, cloud apps, particularly those that aren't specifically security related. Won't have the types of details on security that are really needed.
[01:08:41] So you talk about all of the false positives that you have as a business in your own networks. How about false positives that these guys would have in the cloud? The bottom line is forget about. You can't see any of those security breaches. You don't know if your data has been stolen, et cetera, et cetera.
[01:09:04] And that's why we use a cloud lock in front of all of these cloud apps. Now, this is fascinating too. This is from our friends. Over at a glass. What is it about burning glass technologies? Only professionals with application security experience are expected to be in greater demand with a five-year growth rate of 164%.
[01:09:29] Okay. Yeah. And they're talking about 115% growth as well. Hey, visit me online, get all of this information and more put in a little bit of training right at Craig. Peter saw. Calm go there right now at the very top, you can sign up, get my newsletters and get my special reports. Craig peterson.com.
[01:09:54] So we know already hackers went wild. So what are the things we should be doing to help keep ourselves safe? Five things. We're going to go through. Right now how to stay safe.
[01:10:09] This whole thing with hackers is it's just so annoying. I got hacked back in. I'm trying to remember.
[01:10:19] 91 92, something like that. And I, it. It really sent me for a loop to go about three days to figure out what was going on. So I had a couple of deck servers. You might remember those digital equipment corporation. I was working for them as a contractor. So I had purchased those systems and I had them in my data center that I had built in the building that I bought.
[01:10:44] And it was down on the ground floor. It was something I was really proud of. Cool. It was so neat. So I was down there in the computer room trying to figure out what had happened because my customers were calling and complaining that the email wasn't working, it wasn't going through what was the. I had banked some dial up modems.
[01:11:07] I had my T1 lines going to the internet, which costs a pretty penny and all in all, just trying to figure out what's what, and how did this happen? And it turned out it was a back door that was purposely built into the male applicant. So with the mail application and was send mail. I was using at the time, still a great mail program, but I tend to use postfix now.
[01:11:33] And then of, I use again, Cisco's advanced mail filters and I often will use Microsoft email for businesses and then put the additional mail filters in front of that. Send mail had this feature so that you could get onto someone else's mail server that was misconfigured and reconfigured. Which was really a cool idea.
[01:11:57] It worked great for years when the internet was a safe place when it was just us online, a bunch of wonderful people, libertarians trying to spread the word and the gospel of libertarianism and sending jokes back and forth and using Usenet and everything. This is before websites even existed.
[01:12:21] And. It was a shock to me to see what had happened. And it was something called the Morris worm. And one of these days where we should probably talk about that whole worm thing, but it nailed me and my machine was spreading it to other machines on the internet. And the reason it all slowed down in the mail stop was it was so busy, spinning off new processes to find other machines to infect.
[01:12:49] But the machine just ran out of gas. So it was very frustrating. And although my business was a technology business at the time, I've always almost always had technology businesses. But it was not an internet security business. Who was dealing with that then, nobody, because it was barely legal to do business on the internet.
[01:13:10] I think I was doing it before. It was actually. To do business on the internet. There was just Al gore in me back then. At that problem really got to me. And none of my customers understood what had happened. And there was no reason to even try and explain what a worm was and stuff. I just said, some hacker got in and of course, Back then hacker was a term disused for people that were not professional computer programmers, a hacker where somebody that sat there and hacked code and tried to figure it out and trying to put it together.
[01:13:44] That was a. What do you do? You'd tell them the basics of what happened and you continue on your way. So I almost lost the business, frankly. I ended up losing some customers over the next few months, but not very many. So it worked out okay. But then in talking to friends of mine, I found out even more of them that had been hacked and that it was a a serious problem for.
[01:14:09] What do they do? They turn to me cause I knew I'd been hacked before I was a techie guy and I went on and I built some big. Systems. I built the largest website in the world at the time. And it was, you might be familiar with it, big yellow or yellow pages.com. Any of those sorts of platforms.
[01:14:33] The first one of those and got that up online, built the whole data center and even had to make our own routers at the time and firewalls. We actually designed one of the world's first firewalls, and that was my design. And I had a couple of guys that helped to implement it with me. We had to do everything back.
[01:14:53] And ever since then, I've had a focus on this because one of my clients had a million dollar, a day lottery system down in New York city. You got to keep that safe. And they were sending out millions of emails. So I had to learn about the email security, all of that stuff. So I mentioned all of that to you guys, because think about the position you're in now.
[01:15:16] I don't think it's much. And then the position I was in 30 years ago, but you don't want to spend all of the time that I've had to spend the last 30 years to understand this better and to learn how to protect it better. So that's why I do what I do. I try and get this information out to you. Here's this another article from our friends at dark reading and it's a Leche, I think they invite people to come on and write things for them, but he's talking okay. He's the product strategy manager over at UConn to can canonical they've been around quite a while. Been to was a Linux distribution. What's happening. We know about the colonial pipeline, right? We know the hack that happened and how bad that hack was.
[01:16:08] They was absolutely huge. And it affected all of the east coast for fuel. Every kind of fuel you can think of a real big problem. Russian linked. The hackers that broke into this. Okay. Probably the largest hack ever on a U S utility system. I'm pretty sure it was solar winds, another big hack. They hacked companies that were providing.
[01:16:34] Services to businesses, including security services, right? That's why we don't use them. And we reported serious security problems to them a year and a half before they were hacked. Did they fix them? No, they did not. So this article goes on to talk about how through September in 2021, there were about 1300 breaches in the U S.
[01:16:59] These are reported breaches and K and they're broke the all-time record last year. No two ways about it. And then president Biden in 2021. With an executive order that is forcing now the federal government to eventually become secure and department of defense and the department of defense contractors.
[01:17:24] Okay. Very big problem. He's trying to fix it. Of course, Trump tried to fix it. And president Obama tried to fix it. Everybody's tried to fix it. And so far it just hasn't happened. And our typical, I teach teams really are struggling, trying to stop some of these intrusions, including the more sophisticated ones, which are the intrusions that tend to be coming from nation states.
[01:17:50] The intrusions that are coming from China, Russia, North Korea, and Iran, those are the main. That are coming after us. So what are the things you can do? And I'm going to explain these kind of briefly you can, of course, look this article up yourself, but it is on dark reading. And if you're watching this on video, you can follow along.
[01:18:13] Zero trust is the first thing that is the new, if you will kid on the block or new, where, when it comes to cybersecurity, because what it does now is it assumes all traffic on your network needs to be monitored closely because it could be. So at the very least you're monitoring all the traffic. We do that for our clients as well.
[01:18:39] And you can get into very sophisticated firewall rules, which again, we have to stop certain applications from being reachable from machines. They should not be reachable from. Okay. So there's no silver bullet to. Put zero trust in place, or even to make it work, but you need to do it. So if you're responsible for cyber security in your business, to some degree, checkout, zero trust, next one.
[01:19:07] What data assets do you have because you need to protect them. This particular article is calling them a software bill of materials. But you need to know what you have to protect. What software are you running? What data do you have? What data is controlled by regulations, federal regulations, et cetera.
[01:19:29] You have to know all of that. You have to secure it properly. You need automated vulnerability management. That's why we tie into. Fingers real time, database of hacks going on in the world. And we use that in real time, again, to protect endpoints and to protect network points, secure configuration. That's another thing we do.
[01:19:54] I'm going to probably have this as part of a webinar, if you will, or at least a course, there's about 250. Yeah, that many changes you have to make to windows to try and secure. In fact, I have behind me, this book is probably about five inches thick. It's a binder on how to secure windows 10 and it has gotten even bigger with windows 11.
[01:20:19] Okay. And you have to be aware of the regulations you have to comply with now at the very least. Every last business out there needs to comply, which is called the NIST CSF. I'm helping another company right now, gain compliance with this. This is the national Institute of standards and technology, consumer security, not consumer computer security framework, NIST CSF.
[01:20:50] It is the basics out there. There's others that get more complicated. The CMMC the PCI DSS HIPAA. Hi-tech right. We can go on and on, but those are the five things. Zero trust. No, what data you have, what software you have to protect of my automatic vulnerability management. I'm telling you're not getting that.
[01:21:12] Buying something from best buy or from a big box retailer, online, secure configuration and regulatory. Hey, thanks for being with us today. It has been fun. I enjoy sharing this and I really realized that this morning, even more, this is a blessing for me. Hopefully it's been a blessing for you.
[01:21:34] Check me out, go online and get my newsletter. Craig peterson.com and have a great week ahead. Take care. Bye-bye.
Is Your Email On The Dark Web? Let's Check Now!
Do you know how to find out if you have had your private information stolen? Well, you know, the odds are probably that you have, but where was it stolen, when, and what has been stolen? How about your password and how safe that password is? We're going to show you real hard evidence.
[The following is an automatic transcript.]
[00:00:16] Knowing whether or not your data has been stolen and what's been stolen is very important.
[00:00:24] And there is a service out there that you can go to. They don't charge you a thin dime, anything, and you can right there find out which of your account has been compromised. And. Out on the dark web. Now the dark web is the place that the criminals go. That's where they exchange information they've stolen.
[00:00:49] That's where they sell it. That's where you can buy a tool to do Ransomware hacking all on your own. Far less than 50 bucks. Ransomware as a service is available where they'll do absolutely everything except infect people. So you just go ahead and sign up with them; you pay them a 20% or sometimes more commission.
[00:01:12] You get somebody to download, in fact, to themselves with the Ransomware, and they do everything else. They take the phone call; they find out what it is. The company is doing, and they set the ransom, and they provide tech support for the person that got ransomed to buy Bitcoin or sometimes some of these other cryptocurrencies.
[00:01:38] In fact, we've got another article in the newsletter this week about cryptocurrencies and how they may be falling through. Floor because of Ransomware. We'll talk about that a little later here, but here's the bottom line. You want to know this. You want to know if the bad guys are trading your information on the dark web; you want to know what data they have so that you can keep an eye on it.
[00:02:11] Now you guys are the best and brightest, you know, you have to be cautious, or you wouldn't be listening today. And because, you know, you've been caught, you need to be careful. You have been cautious, but the time you need to be the most cautious is right after one of the websites that you use that hasn't been hacked because the fresher, the information, the more it's worth on the dark web, your identity can be bought on the dark web for.
[00:02:38] Penny's depending on how much information is there. If a bad guy has your name, your email, the password you've used on a few different website, your home address, social security number, basically the whole shooting match. They can sell your personal information for as little as. $2 on the dark web. That is really bad.
[00:03:02] That's sad. In fact, because it takes you a hundred or more hours. A few years ago, they were saying about 300 hours nowadays. It's less in order to get your identity kind of back in control. I suspect it probably is closer to 300, frankly, because you. To call anybody that pops up on your credit report. Oh, and of course you have to get your credit report.
[00:03:29] You have to review them closely. You have to put a freeze on your. Got an email this week from a listener whose wife had her information stolen. He had lost a wallet some years ago and she found because of a letter that came saying, Hey, thanks for opening an account that someone had opened an account in her name.
[00:03:51] Now the good news for her is that it had a zero balance. Caught it on time. And because it was a zero balance, it was easy for her to close the account and he's had some problems as well because of the lost wallet a few years back. So again, some basic tips don't carry things like your social security card in your wallet.
[00:04:17] Now you got to carry your driver's license because if you're driving, the police wanted, okay. Nowadays there's in some ways less and less of a reason to have that, but our driver's license, as you might've noticed on the back, many of them have either a QR code or they've got a kind of a bar code scan on them, but that big QR code contains all kinds of information about.
[00:04:41] You that would normally be in the online database. So maybe you don't want to carry a bunch of cash. Although, you know, cash is king and credit cards can be problematic. It kind of depends. And the same thing is true with any other personal identifiable information. Keep it to a minimum in your wall. But there is a place online that I mentioned just a minute ago that does have the ability to track much of the dark web.
[00:05:13] Now this guy that put it together, his name's Troy hunt, and Troy's an Australian he's been doing this. Public service for forever. He tried to sell his little company, but the qualifications for buying it included, you will keep it free. And there are billions of people, or I shouldn't say people there's billions of requests to his website about people's private information.
[00:05:42] So, how do you deal with this? What do you do? Well, the website is called, have I been poned? Have I been E and poned P w N E D. Ponying is an old term that comes from. Uh, these video games before they were online. And it means that basically I own you, I own all of your properties. You've been postponed and that's what Troy kind of followed here.
[00:06:11] Have I been postponed to.com is a website that you can go to now. They have a whole bunch of other things. They have API calls. For those of you who are programmers and might want to keep an eye out for your company's record. Because it does have that ability as well. And it has a tie ins too, with some of the password managers, like one password to be able to tell is my new password, any good.
[00:06:41] And which websites have been hacked. Does that make sense? And so that is a very good thing, too, because if you know that a website that you use has been hacked, I would like to get an email from them. So the first thing right there in the homepage, you're going to want to do. Is click on notify me. So you ensure in your email address, I'm going to do that right now, while we're talking, they've got a recapture.
[00:07:12] I'm not a robot. So go ahead and click that. And then you click on the button. Notify. a lot of people are concerned nowadays about the security and safety of their information. They may not want to put their email address into a site like this. Let me assure you that Troy. Is on the op and up, he really is trying to help.
[00:07:39] He does not use any of the information that you provide on his website for evil. He is just trying to be very, very helpful. Now his site might get hacked, I suppose, but it has been just a huge target of. Characters and because of that, he has a lot of security stuff in place. So once you've put your email address right into the notify me box, click on notify me of
[00:08:06] Of course you got to click the I'm not a robot. So once you've done that, It sends you a verification email. So all you have to do at that point, it's just like my website. When you sign up for my newsletter, keep an eye out for an email from Troy from have I been poned.com asking you if you signed up for his notification service?
[00:08:31] Obviously it is a very good idea to click on his link in the email. Now I caution people, it costs. And you guys all of the time about clicking on links and emails, because so many of them are malicious, but in the case of like Troy or my website, or maybe another one that you sign up for, if you just signed up for.
[00:08:54] You should expect an email to come to your mailbox within a matter of a couple of minutes, and then you should spend just that minute or so. It takes to click on that email to confirm that you do want to get the emails from the website, because if you don't hit that confirmation, you're not going to get the emails.
[00:09:17] Let me explain a little bit about why that is. Good guys on the internet don't want to spam you. They don't want to overload you with all kinds of emails that may matter may not matter, et cetera. They just want to get you information. So every legitimate, basic a guy out there business, a organization, charity that is legitimate is going to send you a confirmation email.
[00:09:50] The reason is they don't want someone to who doesn't like you let's say to sign you up on a few hundred different emails site. And now all of a sudden you're getting. Well, these emails that you didn't want, I had that happen to me years and years ago, and it wasn't sites that I had signed up for. In fact, some of them were rather pornographic and they kept sending me emails all of the time.
[00:10:19] So Troy is going to send you just like I do another legitimate website, send you an email. The link that you must click. If you do not click his link, you are not going to get the emails. It's really that simple. Now, Troy looking at a site right now has information on 11 billion pond account poned accounts.
[00:10:47] Really? That is huge. It is the largest collection that's publicly available of. To count. So I'm, we're going to talk about that a little bit more. And what information does he have? How does he protect it? What else can you find out from? Have I been poned? This is an important site. One of the most important sites you can visit in order to keep yourself safe.
[00:11:16] Next to mine. Right? Make sure you visit right now. Craig peterson.com/subscribe and sign up for my newsletter and expect that confirmation email to.
[00:11:29] Have you been hit by Ransomware before? Well, it is a terrible thing if you have, but what's the future of Ransomware? Where is it going? We've talked about the past and we'll start with that and then move into what we're expecting to come.
[00:11:46] The future of Ransomware is an interesting one. And we kind of have to look at the past in Ransomware.
[00:11:55] Ransomware was pretty popular in that bad guy. Just loved it. They still do because it is a simple thing to do. And it gives them incredible amounts of flexibility in going after whoever they want to go. After initially they were sending out Ransomware to anybody's email address. They could find and hoping people would click on it.
[00:12:24] And unfortunately, many people did click. But back then the ransoms were maybe a couple hundred dollars and you paid the ransom and 50% chance you got your data back. Isn't that terrible 50% chance. So what do you do? How do you make all of this better? Make your life better? Well, Ransomware really, really drove up the value of Bitcoin.
[00:12:54] Bitcoins Ascension was largely based on Ransomware because the bad guys needed a way that was difficult to trace in order to get paid. They didn't want the bank to just sweep the money back out of your account. They didn't want the FBI or other agencies to know what they were doing and where they were located.
[00:13:20] So, what they did is, uh, they decided, Hey, wait a minute. Now this whole crypto game sounds interesting. And of course talking about crypto currency game, because from their viewpoint, it was anonymous. So they started demanding ransoms instead of dollars, PayPal, even gift certificates that they would receive from you.
[00:13:46] They decided we're going to use some of the cryptocurrencies. And of course the big one that they started using was Bitcoin and Bitcoin has been rather volatile. Hasn't it over the years. And its founding was ethically. Empty, basically what they did and how they did it. It's just disgusting again, how bad some people really are, but they managed to manipulate the cryptocurrency themselves.
[00:14:17] These people that were the early. There's of the cryptocurrency called Bitcoin and they manipulated it. They manipulated people into buying it and accepting it, and then they managed to drive the price up. And then the, the hackers found, oh, there's a great way to do it. We're going to use Bitcoin. And so they demanded ransoms and Bitcoin, and they found that no longer did they have to get like a hundred dollar gifts, different kid for Amazon.
[00:14:46] Now they could charge a thousand dollars, maybe even a million dollars or more, which is what we saw in 2021 and get it paid in Bitcoin. Now Bitcoin is kind of useful, kind of not useful. Most places don't take Bitcoin as payment, some have started to because they see it might be an investment in the future.
[00:15:11] I do not use Bitcoin and I don't promote it at all, but here's what we've been seeing. Uh, and this is from the chief technology officer over tripwire, his name's Dave Meltzer. What we've seen with ransom. Attacks here. And the tie to Bitcoin want to cry back in 2017 was terrible and it destroyed multiple companies.
[00:15:39] One of our clients had us protecting one of their divisions and. We were using really good software. We were keeping an eye on it. In fact, in the 30 years I've been protecting businesses from cyber intrusions. We have never, ever had a successful intrusion. That's how effectively. And I'm very, very proud of that.
[00:16:05] Very proud of that. We've we've seen ransomware attacks come and go. This wanna cry. Ransomware attack destroyed every part of the company, except for. The one division we were protecting, and this is a big company that had professional it, people who really weren't very professional. Right. And how, how do you decide, how do you figure out if someone really knows what they're talking about?
[00:16:32] If all they're doing is throwing around buzzwords, aren't, that's a huge problem for the hiring managers. But anyways, I digress because having a. Particular series of letters after your name representing tests that you might've passed doesn't mean you're actually any good at anything. That's always been one of my little pet peeves over the decades.
[00:16:55] Okay. But another shift in the targeting of Ransomware now is showing a major uptick in attacks. Operational technology. Now that's a real big thing. We've had some huge hits. Uh, we think of what happened with solar winds and how it got into solar wind software, which is used to monitor computers had been.
[00:17:24] And had inserted into it. This one little nice little piece of code that let the bad guys into thousands of networks. Now we've got another operational technology hack in progress. As we speak called vog for J or log for shell. Huge right now, we're seeing 40% of corporate networks are right now being targeted by attackers who are trying to exploit this log for J.
[00:17:53] So in both cases, it's operational software. It's software businesses are using. Part of their operations. So we're, and part of that is because we're seeing this convergence of it, which is of course information technology and operational technology environment. In many times in the past, we've seen, for instance, the sales department going out and getting sales force or, or something else online or off.
[00:18:25] They're not it professionals in the sales department or the marketing department. And with all of these kids now that have grown up and are in these it departments in their thirties and think, wow, you know, I've been using technology my whole life. I understand this stuff. No, you don't. That has really hurt a lot of bigger companies.
[00:18:48] Then that's why some companies have come to me and saying, Hey, we need help. We need some real adult supervision. There's, there's so many people who don't have the decades of experience that you need in order to see the types of holes. So. We've got the it and OT kind of coming together and they've exposed a technology gap and a skills gap.
[00:19:16] The businesses are trying to solve right now in order to protect themselves. They're moving very quickly in order to try and solve it. And there they've been pretty much unable to. And w we use for our clients, some very advanced systems. Hardware software and tools, because again, it goes back to the kind of the one pane of glass.
[00:19:38] Cisco doesn't really only have one pane of glass, but that's where it goes back to. And there's a lot of potential for hackers to get into systems, but having that unified system. That Cisco offers really helps a lot. So that's kinda my, my little inside secret there, but we walk into companies that have Cisco and they're completely misusing them.
[00:20:02] In fact, one of these, uh, what do you, would you call it? Well, it's called a school administrative unit in my state and it's kind of a super school board, super school district where there's multiple school districts. Hold two. And they put out an RFP because they knew we liked Cisco and what some of the advantages were.
[00:20:22] So they put out a request for proposal for Cisco gear and lo and behold, they got Cisco gear, but they didn't get it configured properly, not even close. They would have been better off buying something cheap and being still exposed. Like, you know, uh, I'm not going to name some of this stuff you don't want to buy.
[00:20:42] Don't want to give them any, uh, any airtime as it were. But what we're finding now is law enforcement has gotten better at tracking the digital paper trail from cryptocurrencies because cryptocurrencies do have a. Paper trail and the bad guys didn't realize this. At first, they're starting to now because the secret service and the FBI have been taking down a number of these huge ransomware gangs, which is great.
[00:21:16] Thank you very much for doing that. It has been phenomenal because they've been able to stop much of the Ransomware by taking down these gangs. But criminal activity that's been supported by nation states like North Korea, China, and Russia is much harder to take down. There's not much that our law enforcement can do about it.
[00:21:42] So w how does this tie into Ransomware and cryptocurrency while ultimately. The ability to tr address the trail. That's left behind a ransom payment. There's been a massive shift in the focus from government trying to tackle the underlying problem of these parolees secured curdle Infor critical infrastructure sites.
[00:22:06] And that's what I did training for. The eyes infra guard program on for a couple of years, it has shifted. Now we've got executive orders. As I mentioned earlier, from various presidents to try and tighten it up and increase government regulation mandate. But the big question is, should you pay or not? And I recommend to everyone out there, including the federal government recommends this, by the way, don't pay ransoms because you're just encouraging them.
[00:22:40] Well, as fewer and fewer ransoms are paid, what's going to happen to Bitcoin. What's going to happen to cryptocurrencies while the massive rise we saw in the value of Bitcoins will deteriorate. Because we won't have businesses trying to buy Bitcoin before they're even ransomed in order to mitigate any future compromise.
[00:23:06] So I love this. I think this is great. And I think that getting more sophisticated systems like what, like my company mainstream does for businesses that I've been doing for over 30 years is going to draw. Well, some of these cryptocurrencies like Bitcoin down no longer will the cryptocurrencies be supported by criminals and Ransomware.
[00:23:35] So that's my hope anyways. And that's also the hope of David Meltzer, chief technology officer over at tripwire hope you're having a great year so far. You're listening to Craig Peter sohn.com. Sign up for my. At Craig peterson.com. And hopefully I can help you have a little bit of a better year ahead.
[00:23:57] All of these data breaches that the hackers got are not graded equal. So we're going to go through a few more types of hacks, what they got. And what does it mean to you and what can you do about it?
[00:24:13] Have I been B EEN poned P w N E d.com. And this is a website that has been put together by a guy by the name of Troy hunt. He's an Australian and it goes through the details of various. So that he has found now it's not just him. There are a lot of people who are out there on the dark web, looking for hacks, and there's a few different types of hacks.
[00:24:43] And of course, a lot of different types of information that has been compromised and gathered by the bad guys. And, um, stat just out this week is talking about how businesses are so easy. To compromise. It is crazy. This was a study that was done by a company called positive technologies, and they had a look at businesses.
[00:25:11] Basically they did white hacking of those businesses and found that 93% of tested networks now. 3% of tested networks are vulnerable to breaches. Now that is incredible. And according to them in dark reading, it says the vast majority of businesses can be compromised within one month by a motivated attacker using common tech.
[00:25:42] Such as compromising credentials, exploiting, known vulnerabilities in software and web applications or taking advantage of configuration flaw. Isn't that something in 93% of cases, an external attacker could breach a target company's network and gain access to local devices and systems in 71% of cases, the attacker could affect the business in a way deemed unacceptable.
[00:26:13] For example, every. Bank tested by positive technologies could be attacked in a way, the disrupted business processes and reduced their quality of service. It's a very big deal. And much of this has to do with the fact that we're not taking cyber secure. Seriously as businesses or as government agencies.
[00:26:41] Now, the government agencies have been trying to pull up their socks. I got to give a handout to president Biden. He really started squeezing many of these federal contractors to get security in place. President Trump really pushed it even back to president Obama, who. Pushed this fairly heavily. Now we're starting to see a little bit of movement, but how about the smaller guys?
[00:27:08] How about private businesses? What are you doing? So I'm going through right now. Some of the basic things you can get from, have I been poned and what you can do with all of that data, all of that information, what does it mean to you? So I'm looking right now at my business email address, which [email protected], pretty simple Craig and mainstream gotten that.
[00:27:36] And I found because this email address is about 30 years old. Yeah. I've been using it a long time, about 14 data breaches and. Paste. All right. So what does that mean? What is a paste? Well, pastes are a little bit different than a regular hack. All right. The paste is information that has been pasted to a publicly facing.
[00:28:03] Website. Now there's many of them out there. There've been a lot of breaches of Amazon site of Amazon databases, Azure, all of these types of things. But we're, we're talking about here are these websites that are designed to. People to share whatever they want. So for instance, you might have a real cool program, wants to people, those to try out to you don't have the bandwidth to send it to them.
[00:28:28] You certainly can send it via email because it's much, much, much too big. So sites like Pastebin or out there to allow you to go ahead and paste stuff in and share the link. Pretty simple, fairly straightforward. Well, these pay sites are also used by hackers to make it even easier for them to anonymously share information.
[00:28:55] And many times the first place that a breach appears is on one of these paste sites. So have I been poned searches through these different pastes that are broadcast by a Twitter account called dump Mon, which is a site where again, bad guys are putting information out about dumps had been found as well as good guys.
[00:29:20] All right. And they. Port, uh, on, in the dump mom dump MUN Twitter account. If you're interested, it's at D U M P M O N. They report emails that are potential indicator of a breach. So finding an email address in a paste. Necessarily mean it's been disclosed as a result of a breach, but you should have a look at the paste and determine whether or not your account has been legitimately compromised as part of that breach or not.
[00:29:53] All right. So in my case again, for [email protected] email address, it was involved. In a paste. So let me see what it says. So let me see. It shows it involved in a pace. This is pace title AA from July, 2015. So this is information from published to a publicly facing website. I don't know if I click on that.
[00:30:22] What does it do? Yeah. Okay. So it actually has a link to the paste on AEs to ban. And in this case it's gone, right? It's been deleted. It could have been deleted by the Pastebin staff. Somebody told them to take it down, whatever it is. But again, have I been poned allows you to see all of the information that has been found by the top security.
[00:30:48] Researchers in the world, including various government agencies and allows you to know what's up. So let's have a look here at passwords. So if you click passwords at the very top, this is the other tool you should be looking at. You can safely type in the passwords you use. What have I been poned does is instead of taking the passwords from these hacks in the clear and storing them, it creates a check some of the password.
[00:31:21] So if you type a password into this, I'm going to type in P a S S w Z. Oh, excuse me. Uh, oh, is that, let me use a better password. P at S S w zero RD. One of the most common passwords on the internet, common passwords ever. Okay. So it says, oh no, poned this password has been seen 73,586 times B four. Okay. It says it, the passwords previously.
[00:31:53] Appeared in a data breach and should never be used if you've ever used it anywhere before change it. You see, that's why you need to check your passwords here. Are they even safe to use because what the bad guys have done in order to counter us using. Longer passwords. Cause it's not the complexity of the password that matters so much.
[00:32:16] It's the length of the password. So they don't have enough CPU resources in order to try every possible password from eight characters through 20 characters long, they could never do that. Would take forever or going to try and hack in. So what they do is they use the database of stolen passwords in order to try and get in to your account.
[00:32:42] Hey, I'm going to try and summarize all of this in the newsletter. So keep your eye. For that. And again, the only way you're going to find that out and get my summary today, including the links to all of this stuff is by being on my email list. Craig Peterson.com/subscribe. That's Craig Peterson, S O n.com/subscribe, stick around.
[00:33:09] Did you know, there is a site you can check your password against to see if other people have used it. And if that password has been stolen, it's a really great site called have I been postponed? And we're going to talk about it more right now.
[00:33:26] You know, I've been doing cyber security pretty much as a primary job function here in my career for about, let me see.
[00:33:37] Not since 92. So my goodness, uh, yeah, an anniversary this year. Okay. 30 years. So you're listening to a lot of experience here as I have. Protect some of the biggest companies in the world, the department of defense, defense, and military contractors all the way down through our local dentist's office. So over 5,000 companies over the years, and I helped perform what are called virtual CIS services.
[00:34:11] Which are services to help companies make sure that they have their security all lined up. And we also have kind of a hacker audit whether or not you are vulnerable as a business to being hacked. So we'll go in, we'll look at your systems. We can even do a little bit of white hat hacking in order to let you know what information is out there available about your company.
[00:34:39] And that's really where. Have I been poned comes in. It's a very simple tool to use and it gives you some great information, some really good information about what it is that you should be doing. What is that? I had a meeting with the FBI, one of my client's sites, because they had been hacked and my client said, yeah, go ahead and bring them in.
[00:35:03] And it turned out to be the worst infection that the Boston office of the FBI has ever seen. There were active Chinese backdoors in there stealing their information. Their plans are designed everything from them. Right there. Right. And, oh, it was just incredible to see this thing that it all started because they said they had an email problem.
[00:35:30] We started looking at more closely and we found him indications of compromise, et cetera. So it gets bad. I've been doing this for a long time. But one of the things that you can do, cause I understand not everybody can do what we do. There are some very complicated tools we use and methods, methodologies, but this is something anyone can do.
[00:35:53] Again, this site's called, have I been poned.com? You don't have to be a white hat hacker to use this. This is not a tool for the black hats, for another words, for the bad guys, for the hackers out there. This is a tool for you, whether you're a business person or a home user. And we talked about how you can sign up there to get a notification.
[00:36:18] If your account has been hacked. So I'm going to the site right now. Have I been poned, which is spelled P w N E D. Have I being B E N poned P w N E d.com. And I'm going to type in [email protected], which is my main email address for the radio show and others. So good news. It says. Postage found. In other words, this particular email address has not been found in any of the hacks on the dark web that Troy has access to.
[00:36:56] Now, remember, Troy does not know about every hack that's occurred. He does not know about every data breach that has occurred, but he knows about a whole lot of them. And I mean, a lot. If you look on his site right there in the homepage, you'll see the largest breaches that he knows about drug. For instance, 510 million Facebook accounts that were hacked.
[00:37:24] He has the most recently added breaches. We just got an addition from the United Kingdom, from their police service over there. Some of the more recent ones include Gravatar accounts. Gravatar you might have a, it's a very common, in fact, 114 million Gravatar accounts information were compromised. So me at Craig Peterson is safe.
[00:37:52] Well, let me check. My mainstream email address now, mainstream.net is the website that I've been using for about 30 years now online. And this is the company that I own that is looking at how do we protect businesses? No. And we're a small company, basically a family operation, and we use a lot of different people to help out with specific specialties.
[00:38:21] But let me [email protected], this one's guaranteed to be poned all right, because again, that email [email protected] is close to 30 years old. Uh, okay. So here we go. 14 data breaches. It says my business email address has been involved. Eight tracks back in 2017 and it says compromised data was emails and passwords.
[00:38:48] The Apollo breach in July of 2018. This was a sales engagement startup email address, employer, geographic location, job, title, name, phone number salutation, social media profiles. Now you see this information that they got about me from this Apollo breach. Is the type of information that they need in order to fish you now, we're talking about phishing, P H I S H I N G.
[00:39:17] And the whole idea behind fishing is they trick you into doing something that you probably. Should not do. And boy, do they trick you into it? Okay. So the data left, exposed by a Paulo was used in their revenue acceleration platform and it's data that they had gathered. That's fishing stuff. So for instance, I know my company name, they know where it's located.
[00:39:44] They know what my job title is, uh, phone numbers, uh, how to address me, right. Not my pronouns, but salutations, uh, and social media profile information interest in it. So think about all of that and how they could try and trick me into doing something that really is against my best judgment. My better interest makes sense.
[00:40:09] Co this big collection collection. Number one in January, 2019, they found this massive collection of, of a credential stuffing lists. So that's combinations of email addresses and passwords. It's the, uh, 773 million record collection. So what password stuffing is, is where they have your username. They have your passwords that are used on multiple accounts.
[00:40:40] Now, usually the username is your email address and that's a problem. And it really bothers me when websites require your email address for you to log in, as opposed to just some name that you make up. And I make up a lot of really cool names based on random words. Plus I have 5,000 identities that are completely fabricated that I use on various social media sites or other sites where I don't care if they have my right information.
[00:41:14] Now, obviously the bank's gonna need your information. You can't give it to the, you know, the fake stuff to law enforcement. Too anyways, but that's what credential stuffing is. They will use the email address that you have, that they found online in one of these massive dumps, or maybe one of the smaller ones are long with the passwords.
[00:41:39] They found that you use on those websites and they will stuff them and other. They'll use them on a website. They will continually go ahead and just try different username, different password combinations until they get in. Now, that is a very, very big problem called credential stuffing. And that's why you want to make sure that you change your password when a breach occurs.
[00:42:10] And it isn't a bad idea to change it every six months or so. We'll talk more about this when we get back, but I want you to make sure you go right now because we've got bootcamps and other things starting up with just probably mid to late January. And you only find out about [email protected].
[00:42:32] Make sure you subscribed. .
Are You Ready For the Latest Cyber Attack From Russia? Yet another warning coming out from the federal government about cyber security. And this one is based on what's been happening in Ukraine. So we're going to talk about that situation, the whole cyber security over there, and why it's coming here.
[Automated transcript follows]
CISA is the Cybersecurity and Infrastructure Security Agency. How's that for a name? It's not as bad as what does S.H.I.E.L.D mean? Over from the Marvel universe.
But the cybersecurity and infrastructure security agency is the agency that was created to not just protect federal government systems, although they are providing information for.
[00:00:41] People who protect those systems, but also for businesses and you and me and our homes. So they keep an eye on what's happening, what the various companies out there are finding, because most of the cybersecurity information that we get is from private companies and they. But it altogether, put it in a nice little wrapping paper.
[00:01:06] In fact, you can go onto their website anytime that you'd like to, and find all kinds of stuff that is going to help you out. They've got a ton of documents that you can download for free little steps that you can take. It's at csun.gov, C I S a.gov. And they've got the known exploited vulnerabilities catalog.
[00:01:30] That's something that we keep up to date on to help make sure our clients are staying ahead of the game. They've also got their review board securing public gatherings. They also run the stop ransomware.gov site that you might want to check out. And we'll be talking a little bit more about ransomware and the ways to protect yourself a little later today.
[00:01:53] Now Seesaw is interesting too, because when they are releasing information, most Americans really aren't aware that they even exist. They do. And they've got a big warning for us this week. There's a site that I follow called bleeping computer that you might want to keep an eye on and they have.
[00:02:16] I'll report just out this week that you, crane government agencies and corporate entities were being attacked. This was a coordinated cyber attack last Friday, a week ago, where websites were defaced data wiping malware was deployed and causing all of these systems to become not just a corrupt, but some of these windows devices to be completely.
[00:02:45] Operable now that is a bad thing. The reason for this, this is speculation, but it isn't a whole lot of speculation. Right? Am I getting out of, on a limb here particularly, but the whole idea behind this is a cyber war, that Russia's got, what is it now? 130,000 troops, whatever it is over a hundred thousand.
[00:03:08] On the border of Ukraine, they invaded Ukraine a few years ago. Russians shot down a passenger airline in Ukrainian air space. This that was a few years back. They've been doing all kinds of nastiness to those poor Ukrainians. They also had a massive ransomware attack in Ukraine. That was aimed at their tax software.
[00:03:36] Some countries do the electronic filing thing a lot differently than the us does. A couple of examples are Ukraine. France is another one that comes to mind. We have clients in France that we've had to help with cyber safety. And we're always getting popups about major security problems in the tax software, because they have to use this software that's provided by the French government.
[00:04:04] Ukraine's kind of the same way. The biggest. Company providing and the tax filing software for Ukraine was hacked and they use that hack to then get into the tech software and make it so that when that software was run by these Ukrainian companies, they would get ransomware. It was really rather nasty.
[00:04:30] So the Russians had been playing games over in Ukraine for quite a while. But what's apparently happened now, is that a thing? Those things, same things are coming our way now. It's not just because of the fact that a Ukraine is being threatened, maybe they're going to encroach even more, take more than Crimea, which they did last time.
[00:04:56] We're in the U S and what are we doing? President? Biden's been sending troops to Europe, troops to Poland, Germany, and also advisors to the Ukraine. He's removed the embassy staff, at least the vast majority of it from Ukraine. And I just I think. To what happened with his completely unplanned withdrawal that we did in Afghanistan and how things just got really bad there.
[00:05:28] And I'm not worried about what's going to happen in Ukraine because the Russians aren't particularly fond of the idea that we are sending aid and support to. Yeah, it's a bad thing. President Obama sent them blankets, but Biden is sending them military weapons and ordinance, which is what they'd need to fight.
[00:05:54] So Russia has shown that they will attack a country via electronic means cyber means, right? Cyber attacks. And so what's happening now is the bad guys from. That have been the facing websites and who have been doing more than that, wiping computers and making them completely unusable could well come after us because they're really going to be upset with what's happening now.
[00:06:28] And that was CNN has reported the Ukrainian it services company that helped develop many of these sites was also a big. And of course that means bottom line, that this is what's called a supply chain attack. What I mentioned earlier with the Ukrainian tax software, that's a supply chain attack where you are buying that software, or you're mandated to use the software to file your taxes by the government.
[00:06:58] And what happens while it turns out that software is contaminated, that's called a supply chain attack. Now crane issued a press release about a week ago, saying that the entities were hit by both attacks, leading them to believe that they were coordinated. This is a quote here. Thus, it can be argued with high probability that the interface.
[00:07:24] Of websites have attacked government agencies and destruction of data by Viper are part of a cyber attacking, but causing as much damage to the infrastructure of state electronic resource that's from the Ukrainian government, not the best English, but their English is much better than my Ukrainian or Russian.
[00:07:44] So you, crane is blaming these attacks on Russia, incomes, CS. So you says now urgent. Business people in the us and other organizations to take some specific steps. So quote, here from the Seesaw insights bulletin, the CSO insights is intended to ensure that senior leaders at the top of every organizational where the cyber risks and take urgent near term steps to reduce the likelihood and impact of a potentially damaging compromise.
[00:08:19] All organizations, regardless of the sector or side should immediately implement the steps outlined below. So here's the steps and there are a lot of them. One I'm going to do these, you should find in your newsletter today. Hopefully that all made it in. But three basic things. One reduce the likelihood of a damaging cyber intrusion.
[00:08:47] And we're going to talk about the best way to do backups here a little later on today. Make sure your software is up to date. Make sure your organization's it personnel disabled, all ports and protocols, not essential for business purposes. This is all basic stuff, but I got to say. I bet you, 98% of businesses and organizations, haven't done these things.
[00:09:07] The next major category here, take steps to quickly detect a potential intrusion, and then ultimately maximize the organizations resilient to destructive. Incident. So that means doing things like testing your backup procedure, make sure your data can be restored rapidly, or you have a way to get your business back online quickly.
[00:09:31] What we tend to do is in our backup strategy, depending on how much the company can afford, to be down. To be out of business if they lose all of their stock versus what it costs to do this, but we will put a server on site at the company and that server then does some of the backups, right? It does all of the initial backups.
[00:09:55] And then what happens is it gets relayed to us. It gets pushed to tape and tape is really good. We'll talk about that in just a few minutes, but the other big thing is. The backup that we have local to their business also has what's called a virtual machine infrastructure built on it. So if a machine goes down, If it gets wiped or if it just crashes and can't be recovered easily, we can spin up that machine.
[00:10:28] A copy of it in our little virtual environment in just a matter of minutes. So these are all things you should be considering. If you're interested, you can send an email to [email protected]. I can send you a checklist that a little more extensive than this, or I can help you with any other questions you have.
[00:10:47] I get lots of questions every week from everything for on retirees, wondering what they should do all the way through businesses that we help government contractors and others. This isn't good. Russia is likely coming after us. Based on this. Visit me online. Craig peterson.com or email [email protected] with your questions.
[00:11:14] With all of this talk about hackers, ransomware data, wiping systems. What's the best way to protect yourself, but what do you do to really protect against ransomware? I can tell you, it's not just plugging another hard disk into do backups.
[00:11:31] We have a lot of problems nowadays. We've got so many hackers out there. We're talking about a multi-billion dollar industry to go after us.
[00:11:43] It's just depressing. Really. When you think about it, I think about the old days where security, wasn't a huge concern, right? Physical security. I had one of my first jobs was at a bank and I was, this was back way back in the a G it would have been the mid seventies and I was one of the operators of the main.
[00:12:09] And so as a mainframe operator, we'd load up the tapes and we would ship them places. We'd also go ahead and put them in the vault so that they were in a fireproof vault, and we could recover anything we needed to recover. It worked out pretty darn well, and it was a fun job, but most of the time it was cleaning the tape drive heads and taking those tapes, those big round tapes, you might remember those.
[00:12:38] Nine track tapes and maybe the fancy stuff, 52 50 BPI or 800 BPI of one end or the other, or the spectrum. And we just had to make sure they were physically safe nowadays of course, mainframes are still around and are still absolutely fantastic. They're just phenomenal. Some of the technology IBM has in their mainframes.
[00:13:04] Most of us, aren't using those. Most of us are using a regular computer or I'm sitting in front of a Mac right now that I use for the radio show. We have windows, computers, Linux machines, right? All of those things that we have in our business and that we maintain securely for our clients. But what do you do when we're talking about random?
[00:13:27] You can cross your fingers and hope that you'd hope you don't get ransomed. That sort of a practice doesn't usually work out too well for people, but you can do backups and many people do. So let's talk about the backups. Let's say that you have your computer and you're doing a backup and you have one or two generations worth of backups for your company.
[00:13:52] Ransomware nowadays does not just typically destroy your whole disk. Usually what it does is it encrypts files like doc files, doc X, right? Excel files, all kinds of files that thinks might be useful to you. And then of course, the rest, it pops up says, pay me. And off you go. The reason for that is so your computer still works so that you can enter in the decryption code.
[00:14:22] Once you've paid the ransom, hopefully it works for you give or take 50% of the time. You will get your data back. If you pay the ransom much of the time. But let's go back to that one or two generations of backup. You're using a cloud service, let's say, and your computer gets ransomware. That cloud service backup software will still work.
[00:14:48] What if it's working? So you're now backing up your encrypted files to the backup site in the cloud. Do you see where I'm going with this? Your backups? No. Same thing is true. If you're backing up to a local hard disk, many people do it and it's handy. I recommend that you do that, but it's not all you should do.
[00:15:13] So that disc is attached. We had a. Boy, who was it here? Yeah, we have a client in Maine and they have a really smart system administrator and he designed these disk drives that would physically disconnect themselves from a machine when the backup was not running and would physically connect themselves when the backup.
[00:15:38] Was running. So the idea there was okay, great. We've got a local backup on a local disk and if the bad guys managed to get a hold of the machine, they're not going to be able to encrypt the. And, as long as the backup isn't running, I thought that was a brilliant solution. Doesn't solve some problems, but it certainly takes care of some others.
[00:16:03] So if you are doing a backup, you've got to make sure you've got multi generations. I tend to keep a year's worth. Now there's other considerations. There's the federal rules of. Procedures that say you have to have bad cops. They have to go back years. And there are also other things the payment card industry requires certain types of backups.
[00:16:29] If you are a government contract, We have them as clients and they have certain data retention policies based on the length of the contract. They have keep it for some years afterwards. It goes on and on. So if your data is lost or stolen or encrypted, and your backup is encrypted or deleted, You are in real trouble depending on the type of business you're in.
[00:17:00] So what's the right answer to this. I've talked about 3, 2, 1 backup for a long time, and it's still a very good methodology for doing backups, but nowadays they're talking about 3, 2, 1, 1 backup, which is again, that's a bit of a different methodology. In doing backups, but the idea is you've got multiple copies of your data on multiple types of media in multiple places.
[00:17:34] That's the bottom line. What is the gold standard for this? I it's something that gets to be a little expensive. Again, we have another client that we've had for years, and they are looking for a replacement for the backup system. Now. And so we proposed something that's based on what's called LTO technology, which is a type of a tape drive.
[00:17:59] It's a small cassette, right? It's not those big 12 inch reels of tape that we used to lug around and it's amazingly dance. The new LTO tape drives have space on them for as much as 45. Terabytes of information. It's also great because it's encrypted by hardware, government level encryption automatically, and those tapes can be taken offline.
[00:18:29] You can take the tape. Now we picked up a client who had been doing backups and they were using little USB drives and every day he'd take the drive home and bring in the next drive. So he had five drives, right? So he had the drive for Monday, Tuesday, Wednesday, Thursday, Friday. And he was taking them home, but he missed one of the key things to check the back.
[00:18:57] He hadn't checked the backup and their backup had not been running for more than a year and a half. So that's the other thing you have to do? The LTO tapes are really the gold standard. It goes back to that for one of the first jobs of mine, right? The job I mentioned, where I was mounting tapes and filing them and moving them around and mountain disc packs and pulling them out and everything.
[00:19:24] It still makes sense. They'll last for decades, they cannot be hacked because they are literally offline. You can ship them to places to have them stored. I have a course on backups and if you're really interested, send me a an email to [email protected]. And I'll go ahead and. Send you a link to the course, you can watch it.
[00:19:52] But yeah, I think this is really important. Of course, I'm not going to charge you for that, but magnetic tape it's established. It's understood. It's proven it's been around for many decades and LTO tape is unique. It needs all five best practices for addressing ransomware. Even be able to recover.
[00:20:16] If you want more information, just email [email protected] or sign up for my free newsletter. Craig peterson.com.
[00:20:26] Switching from gasoline powered engines to these new electric cars is no environmental panacea. At least that's what West Virginia university is saying. And the E. Just changed its mind as well.
[00:20:42] Ford of course, about a year ago, unveiled its new electric.
[00:20:47] F-150 the lightning and Ford has stopped taking orders for them because they are going to have to make double what they thought they would have to make. Ford also has a similar problem with yet another electric vehicle. The Mustang GM is doing a few different electric. Coles. And so is everybody else, frankly, Porsche even now has an electric car out.
[00:21:16] That is all well and good. Isn't it. And there's certainly problems, particularly with manufacturing nowadays, trying to get the CPU's and other electronic components you need. They're even having trouble getting electric motors for electric windows in vehicles. Now they're coming. Crank window with a little coupon saying later on, we'll convert it to electric for you all kinds of problems, but there's one that I haven't heard anybody but myself talk about.
[00:21:48] And so I was online looking around, doing some searches, seeing if I was, like the only one there's no way right now, I'm not the smartest person in the world. I don't pay the most attention to everything. And I found that. Virginia university is in total agreement with that with me, it's just amazing.
[00:22:11] They looked at recent trends and they're cautioning as I have been for years, at least a decade. Now they're cautioning about what seems to be a race to put more electric vehicles. On the road. And the problem is that these electric vehicles in their demand for electricity may well out, run what's needed to keep the vehicles on the road.
[00:22:40] So here's a quote from them. The electric grid will struggle to handle the quick charging of very many electric vehicles at the same time. Okay yeah, by the way, like hardly any quick charging is generally what everyone thinks about, like going to the gas station, getting a full charge in 10 to 15 minutes, which would be a tremendous instantaneous load on the local distribution center.
[00:23:07] My concern is the huge power dumps required at quick charging stations along the interstate. It sounds good, but it'll require a lot of new infrastructure to get the power to the charging stations, as well as building those charging stations. So where does the power come from? Power storage is going to be required if we're going to also move towards fixing.
[00:23:32] Power sources such as solar and wind. We do not have power storage capability yet in large enough quantities to do this on a large scale. Solar does not work at night. The wind doesn't blow all the time. Also, we do not have the distribution on the streets to move fast charging into residential neighborhoods on mass.
[00:23:57] Electric vehicles are great, but we have not fully considered the impact it'll have on our electrical grid infrastructure. It will require a lot of expansion of our electrical distribution and charging facilities. Remember, electric power comes from the power company. I heard an interview with a lady the other day, and they asked her, where does the electricity come?
[00:24:19] She said, From the plugin, the wall, right? We must consider this when considering wide-scale electric vehicle adoption, much as there is to gain from electric vehicles. I don't believe we're ready yet as a society for completely electrical vehicle transportation system. With time and infrastructure development, we can be.
[00:24:41] I totally agree. This is Rory Nutter, professor lane, department of computer science, electrical engineering, Benjamin M. Slater, college of engineering and mineral resources. I totally agree with that. We don't have the ability to generate the electricity. We don't have the ability to store the excess electricity.
[00:25:05] So in other words, if we're using solar at nighttime, we don't have the sun, we can't run solar. So we got to store the solar. And in fact, we have to make about twice as much electricity as we need during the day so that if we can store it, we can then use it in. The same thing with wind, right? It's fickle.
[00:25:29] It just doesn't work that well. So what do we need? Basically right now, we need to stop turning off our coal powered plants, our natural gas plans and our nuclear plant. Because we need to still have electricity. Look at what's happened last year. And this year over in Europe with the crazy cutbacks that they've been doing on some of these plants, coal nowadays with the scrubbers that are on our cold powered, flat plant is clean energy.
[00:26:03] It's not like the old days where you lived on the south side of the tracks and you got all of the wind blowing towards you that had all of that nasty cold ass. You ever seen any of those pictures? It was just terrible. All of that nasty sitcom. It's not something we need to worry about nowadays.
[00:26:21] The other big thing that ties into all of this is so how do we generate our electricity cleanly? A hundred percent cleanly? Nothing. Per cent, but just a couple of weeks ago, the European commission presented their 27 members states with new draft rules that classified natural gas and nuclear power as green fuels for electricity generation.
[00:26:52] Listen, if we want electric cars, which as we've talked about before are highly polluting. Yes. Because of the materials in them, because of the materials that go into the batteries, having to mine it, having to ship it, having to process it and then having to change out those battery packs after 80,000 or a hundred thousand miles.
[00:27:13] Did you see this guy? There was a meme in the video about this online a few weeks ago. How to test. His Tesla needed a battery replacement. It would cost him, I can't remember what it was. 20, $30,000. A lot of money. So he decided to just blow up the car. That's all it took. I saw another Tesla that had water damage.
[00:27:38] From, being down in new Orleans or somewhere, the flooding occurred. And the guy bought that Tesla because Tesla won't sell the parts to fix the car after the water damage. And so he ripped out the batteries, ripped out the electric motors and he bought a high power engine. And gasoline and put it into the Tesla and made really, quite a very cool car.
[00:28:05] You can find it online if you want to look for that, it's quite cool. What they ended up doing. It took us quite a while to do it, but they did it. So now that we're seeing. That nuclear is green. Let's talk about why we've been so afraid of nuclear. One of the biggest problems of course is so what do you do with all of the waste?
[00:28:25] And that's a legitimate question, but what you're really talking about when you ask that question are the reactors that went online 50 years ago, or that were approved 50 years ago because of the regulations. There are. These nuclear plants that have been provisioned in the last 20 years that are still using that old technology.
[00:28:47] So when we get back, we're going to talk about this more. What about the waste? What our fourth generation nuclear power plants, how safe are they when they say they're intrinsically safe? What does that mean? And how and why? Because I'm predicting to this point that we're going to have to switch back to nuclear and even the European union, if you can believe it agrees with.
[00:29:17] Hey, make sure you take a minute. Go online. Craig peterson.com. Subscribe to my free newsletter. You can get it right there. I send you out stuff every week. And this week is no exception. We've got a bunch of bullet points that if you are in a business position, you got to protect yourself immediately. So I tell you how Craig peterson.com.
[00:29:42] So what are these new rules for nuclear energy? And why is it absolutely necessary that we do something like this? Get fourth generation nuclear online. If we can even consider electric vehicles on our roads.
[00:29:59] Things have changed in the European union. They've been trying to figure out how they're gonna handle all of these electric vehicles, how they're going to properly handle all of the solar cells and the wind turbines.
[00:30:14] And there's even some work over in the EU. To get the tide to generate electricity, some very cool stuff. Actually, that's been done, I love tech and I'm into all of this stuff, frankly. I think we should be doing a lot of it. What I don't think we should be doing. Is getting ahead of ourselves. And unfortunately that's really what's being going on.
[00:30:40] We don't have a grid that can really use the electricity that we can generate from our windmills, from our solar cells, from anything, frankly. And we cannot. All of that electricity that we might be generating and somehow have that electricity be stored and used distributed appropriately to our charging station.
[00:31:07] And our grid was built and designed to have a few central point where the electricity is made, where it's generated and then distributed to some pretty specific types of things like housing, development, businesses, et cetera. You can't just go ahead and open a big business man. in a residential area.
[00:31:29] And part of the reason for that is the grid isn't set up for it. You don't have three phase power going into residential areas or even more than that, you don't have the high voltage, the high current, et cetera. So how are you going to be able to quick charge electric cars in the regular residential neighborhoods?
[00:31:51] I w how about at a hotel? Yeah. Okay. A hotel is probably. Multiple phases and has a fair amount of power there, but the amount of strain that's put on the grid by trying to just rapid charge a single car is huge. So how can we deal with that as well? The quickest and easiest way to deal with it is just put more large power plants online.
[00:32:17] Some people don't like that. Don't like that idea at all, frankly, but we're not ready. What are we going to do? Look at what happened in Texas with a fairly minor reliability or re reliance, I should say, on these windmills last winter and things with this winter, as cold as it's been, that could really cause some just incredible problems.
[00:32:44] Nuclear is being reconsidered, particularly fourth generation nuclear power plants. The greenhouse gas emissions from nuclear power are one 700th of those of coal. The nuclear power plants produce one, 400th greenhouse gas emissions of a gas plant, and they produce a quarter of the greenhouse gas emissions from solar.
[00:33:13] Now you're saying, Hey Craig, come on, I get it. Wait a minute. How can solar produce greenhouse gas? It does. And it produces greenhouse gases because of the manufacturing processes, as well as of course it off gases. So how do we make all of this stuff work? We all saw the China syndrome and we heard from experts like Jane Fonda, how we would all die.
[00:33:38] If we put a nuclear power plant. These are intrinsically safe, power plants much different than they used to be. Nuclear power frankly is a much safer business than most people think it is. They no longer these new plants produce. The the nastiest what's called high level nuclear waste.
[00:34:04] They can reprocess it right there in the plant. They can start in fact where some of the nuclear waste though has been generated from the older nuclear plants and get rid of that. It's amazing. So people are asking okay. Plutonium might have a half-life of 24,000 years, but it doesn't emit much radiation.
[00:34:28] We get that. How about the higher levels of radiation? Because some of it can last for hundreds of thousands of years. According to the U S radiation expert, Robert Gale for every terawatt hour of electricity produced nuclear energy is 10. To 100 times safer than coal or gas. What it does emit are alpha particles, which do not even penetrate human skin.
[00:34:58] They've done all kinds of risk assessments and tried to figure out what's going to happen. What can we do? And I'm not going get into all the details here, but it is intrinsically safe because. What really happens is that the, these new plants he's fourth generation, a newer plant are instead of using water, for instance, that can do reactors out of Canada, use heavy water in order to cool those rods.
[00:35:29] It was same sort of thing we've had in the meltdowns before they're using a liquid silica inside. They're set up in such a way that they do not need to have pumps running. So the Fukushima reactor that you might remember in Japan that failed because of the tsunami and the fact that one fact, this is what was their killer that their electrical generation from the diesel generators went offline.
[00:36:00] Why did it go offline? Oh, I can see the grid going offline, but how about a diesel generator? If you have a below sealer, And the water comes in. You're in big trouble now. They didn't have it like below, permanently below sea level and Fukushima. But when that tsunami wave came in, it was below sea level.
[00:36:20] They just, man, we could talk for a long time about the problems that they had over there. The nepotism, the line on the forums. They fact they did not do the upgrades that the manufacturer has suggested on and on. So these new reactors can lose all power and you won't have a China store. They won't go through a meltdown and they're even designed in such a way using physics things called the law of gravity, who would have thought, right?
[00:36:55] So that what happens in the worst case scenario is no one gets hurt. It just eats in on itself and then stops runs out of. So we've got to remember all of this stuff. Okay. The nuclear power of yesteryear is not the nuclear power of today. And the nuclear power of today is so green and so safe that even the European commission presented new draft rules that said to the natural gas, nuclear power, our agreement.
[00:37:33] Fuels for electricity generation. So assuming the rules are approved and Francis in favor, Germany isn't as into nuclear power. In fact, they plan on having all of their plants shut off by the end of 2025, which is crazy because they're already having serious problems with their solar and wind.
[00:37:57] And that's why they're buying so much natural gas now for. Yeah, American influence dropping over there. Thank you again, president Biden for allowing that pipeline to go through. All right. Anyhow. They're assuming they're approved Germany. Apparently isn't likely to try and block these rules. It means that nuclear, the new nuclear force generation or newer is going to be right there alongside renewables, like wind and solar on the list of the EUS technology that are approved for financial support.
[00:38:34] Now, this is very good news because as I mentioned earlier, What happens when it comes to solar at nighttime doesn't work solar. When it's raining, doesn't work solar. When it's snowing, doesn't work solar. When it's cloudy, doesn't work. Ryan, how about the windmills? When the wind is. They don't work when they break down, which happens a lot due to mechanical failures, they don't work.
[00:39:07] So having the. New nuclear plants that are intrinsically safe, that don't generate this really nasty radiation, and stuff that we have to store for a thousand years, et cetera. The high level nuclear waste makes a lot of sense because unlike the. Solar plants or other things that might be on someone's house that cannot be easily controlled by the central grid.
[00:39:37] In other words, Hey, stop generating electricity because I got enough right now. And what Germany has been doing is putting it into heat sinks, heating up lakes and other things, to get rid of that extra solar energy people are generating on their homes and businesses. What you can do is, Hey, we are at the point where we don't have enough sun.
[00:39:58] It's really cold. People are trying to heat their homes, or it's really hot. People are trying to cool to their homes. And yet it's raining heavily or there's a lot of clouds. So all you have to do at that point is turn off. That nuclear power plant or multiple plants. You see the way it's going.
[00:40:16] You're not going to have some massive plant with a bunch of reactors. No. Where they're going with this is to have community reactors in the multi megawatt range that can be put into communities and the power distributed directly. Into the community and these power plants are good for 20 years and these new ones, they are typically going to be buried in the.
[00:40:46] And then every 20 years they get dug up, put onto a truck, shipped off, they get recharged, brought back and you're off and running again, a whole different concept. And I love it. We're starting to do this in the United States. We've got some early approvals for some of these, and I was shocked and amazed and happy that the Biden administration has decided.
[00:41:10] To approve the new nuclear here in the United States. So there'll be some test plants going online relatively soon. That just makes so much sense. These 50 year old nuclear red regulations and plants, they just don't work. Make sure you visit me online. Craig peterson.com. I'm going to have a lot of stuff for you every week.
[00:41:36] Craig peterson.com.
[00:41:42] I hope weekend's going well for you. There's lots of fun stuff to do. And it's fun getting out of the house. Isn't it getting out, going out, going around. There's a, an outlet store close by where I live and it's one of these outdoor. Outlet things. And it was fun. Just walking around, enjoying the little bit of fresh air, no matter what the weather has.
[00:42:07] I even enjoy going up there when there's some snow on the ground. Because again, it's a little bit of a it's fun. It's a little bit of a change, which is not. Part of what I love about living in the Northeast. You really get all four seasons and they can be really nice. Black Friday of course came and went.
[00:42:26] It was not a bad black Friday, but one of the questions I am been asked all week long, all month long, frankly, has to do. When should I buy, what should I buy? What are the deals? And it is weird this year. Let me tell you really weird. And the reason I say that is I didn't my show prep. And I spent some hours just looking on different websites and looking at opinion pieces, looking at news sources, just trying to find, okay, what's going on?
[00:43:01] What's the real word out there. Our items, as rare as everybody seems to be saying they are, or is it easy enough to find. That's what we're going to talk about right now. Really. We've had a very turbulent two years for retail, every branch of retail, whatever it is, it's been terrible. So many people have lost their businesses.
[00:43:24] So many small businesses, small retail restaurants, some restaurants that I, I enjoy and just haven't been to in years, really. Completely gone, which is such a crying shame. And a lot of people have put a lot of the blame for the general retail malaise on Amazon and Walmart. Because again, I had a discussion just this last weekend with.
[00:43:56] Oh, a friend's father. And he was saying, wow, I've been a biologist in pharmacology for years. And th this is just as just a science, it's all science talking about the lockdown. And so I pointed out how let me see. I got family from Canada. They cannot drive across the border because of the lockdown, but in, in the states, they won't let us, we won't let them fly.
[00:44:21] But they are drive in, I should say, but they will let them fly in. How does that science, there's coronavirus not survive at 30,000 feet. Is that what it is? No, come on. People it's politics and part of the politics was. Walmart got to stay open and all of these other small businesses couldn't so what are they supposed to do?
[00:44:46] How are they supposed to compete? And, yeah. Hey, I understand you need clothes, right? And you need food. Most Walmarts have both. You might need medicine in order to even survive. So that kind of makes sense, but why. Walmart. Why did the government choose Walmart and target are going to survive all of you, little mom and pops stores, that maybe you've been multi-generational where it's your parents.
[00:45:16] And maybe even your grandparents that started the store, started the restaurant. And now all of a sudden there's a lockout and you cannot be over. It just, it entirely political. And I understand the science behind all of this. I have spent a lot of time studying it and you might remember if you've listened to me even.
[00:45:40] Dean or 20 years ago, I'm trying to remember when it was, I started talking with scientists about RNI, RNA interference and the coolest stuff that was happening with African violets and getting the purple flowers to change to white and all of the stuff they were doing. It's exciting. It's fun. But why.
[00:46:01] Did we use politics here. And so many people lost their livelihood. So many people lost their businesses. It's absolutely incredible. And just pain companies basically to stay closed. It doesn't make sense either. Because now you're pumping more money into the economy and that's causing inflation because there are not more products or not more vendors.
[00:46:23] There's not enough competition. So the prices go up. And when there's inflation, how about people who are retired, who have saved something. And now their money is worth what the inflation rates are. Again, it's a hidden tax, but it's really hard on retirees because their money that they've saved, they're getting the pitons, you put it in a savings account and you're making a fraction of 1%.
[00:46:51] And yet we're seeing inflation rates on things like fuel being almost a hundred percent. Think about what it was like in 2019, what the gas prices were. It is insane. So small businesses have to be supported. They are the backbone. They are the innovators. Walmart didn't start as a big company. They started very small.
[00:47:18] He innovated his claim to fame. That old Sam Walton was let's go ahead and have the best prices and anywhere. And so they got the best prices by beating up their suppliers, et cetera, but it all worked. And Walmart increased, raised its it's demonstrable again through real science, but they raised the standard of living in every community.
[00:47:47] They opened a store. It's absolutely funneling. But Walmart stopped innovating a long time ago. Now again, the innovations come just like they do in the tech world. Typically not from the existing companies, facebook isn't innovating, they bought WhatsApp, they bought so much of the technology they're using to drive their company.
[00:48:10] Oculus. You look at it, right? That's their future. According to of course Mr. Mark. What did it come from? What was the cost? They by their competition. So I want to encourage everybody to really try and go out of your way, try and shop at these small places. There are. And so many of these malls nowadays local stores where they've got together and they're running their co-op or where someone's managing a buying product from local craftsman, really that they, everything from these women that are knitting doilies all the way on out, through very cool black iron work things that you can find there.
[00:48:59] That maybe you can find on Amazon, maybe they come from China. Maybe they're locally sourced. Not very likely, but it's been a very tough time here for so many of these industries. One of the things that I did talk about this week, I, one of my radio appearances is. Tik TOK live shopping. If you haven't heard of tick tock is this short form video site.
[00:49:25] And it started by people saying, okay, with this song use that song to make a funny little 32nd. And 22nd and that's what people did. And it was really quite cool to see they there's some innovative people out there. Tick talk has a lot of, I share nowadays way more popular amongst the younger people than Facebook is become something for the older people.
[00:49:51] But what tech talk is now doing is providing live shop. And this is an innovation that really started in China, which of course is where tick-tock is located. But in 2020, there was a survey done that found that two thirds of Chinese consumers said that they bought products via live stream in the past year.
[00:50:15] So what's live stream. I want you to think about QVC online share or a television shop. Those channels, those infomercials that come on at night, but particularly the channels that are constantly selling stuff like micro did a little bit of that at one point in time, right? His interview was, he came in and the, he, the guy who was interviewing him, held up a pen.
[00:50:39] Is that okay, you sell me this pencil. And so micro went on and on for 10 minutes or more just talking about the pencil and everything related to the pencil and what a great quality was. All he course, she didn't know anything about it. And that's part of what bothers me about some of these things, right?
[00:50:56] These people are just making stuff up, but Tech-Talk live now is allowing you to go ahead and make funny little thing. Gain an audience. Maybe they're not funny. Maybe they're just informative. Have them inserted into people's streams and then sell it right there. In fact, instant purchasing of a featured product during a live stream.
[00:51:24] And then obviously audience participation, they got chat functions, reaction buttons. This is what's coming our way. And so all of you, small businesses out there, I really want to encourage you pay attention to social media. This is the sort of thing that you can do. You can target your local area, which is where most small businesses operate, right?
[00:51:50] It's in, in your town. It's maybe a 10, 20 mile radius, depending on what you're doing, what you're selling. And you can micro target nowadays. That's the joy. That's the beauty of the online world. Micro-targeting Hey, and if you're interested, let me know. We can talk a lot more about this because I have studied this for years now.
[00:52:13] Hey, stick around Craig peterson.com online.
[00:52:21] So while you're shopping online, what are some of the things you should do or look out for? I've got a few ideas. I'm going to tell you what I do, and it has worked wonders for me. So here we go.
[00:52:36] When you're shopping online, there are some obvious tips, just run through them very quickly because I don't, I think you guys being the best and the brightest really know these things.
[00:52:51] So just very quickly, make sure your security. Today, make sure that everything is patched up the way that it should be, that you have some really great anti-malware hopefully advanced anti-malware, but apply any updates before you start doing shopping, because this is a bad time of year to lose all of your personal information and to have your money stolen.
[00:53:18] Number two. If you're seeing an email or you're seeing a deal that really looks too good to be true. Take caution here. Do you see a place? Oh, I got five brand new Sony PlayStation fives for sale. You might not want. To buy those, right? The minister, Jeff Foxworthy hears your sign. So be careful about that.
[00:53:45] Criminals are really taking advantage of consumers who life's been tough, money's been tight. You're trying to find a deal. So be careful about that. Okay. Coupons or other way, the bad guys have been trying to get consumers. To compromise their own cyber security. Okay. 12% of emails out there are considered to be spam emails.
[00:54:12] I think it's more like 80% or 90%, but then I've had the same email address for 30 years. Okay. So don't click on link. Be sure you shop on the real website and apply coupons there by manually typing out the code. So for instance if let's say you use duck, go for your search engine, which you should be using for most cases, most searches a duck go says, okay, let me see where coupons here you go.
[00:54:41] Here's a site that has a lot of coupons be careful about those sites, because some of them are trying to lure you in. Are the websites you're going to the real ones, the legit one. Are you clicking a link in your email in order to get to that sale site? Double check, because what they're doing is using some of these URLs that aren't.
[00:55:08] And we see those all of the time. They'll have a misspelling of the business name or they'll do something else. So they might have Amazon Dodd bad guys.com. Oh, okay. Amazon. Okay. Is Amazon obviously they wouldn't say bad guys, but yeah. That's what they're doing. So be careful. So once you're on a website, look for that little padlock that's to the side, click on it and double.
[00:55:35] To make sure that it is legit because they might have us. What's called a secure, sir. And they might have a certificate that's valid for the site that you just went to, but it's not, there's a different kit for Amazon or Walmart or target or w whatever Joe's clothing.com. It might be something entirely different.
[00:55:58] So be careful, okay. Is what you're looking at on the ad. Because there are a lot of fake advertisements out there that looked like they got great deals. And even though black Friday has come and gone, they're going to continue to do this through the end of the year and be on. Okay. So rather than clicking on the ad, just type in the retailer.
[00:56:26] Information, because some of these ads that are showing up are in fact, almost every last one of them is coming from what's called an ad network. So that ad network is where people go and buy ads and they say, Hey, I want to retarget people that were at this site or clicked on this link, et cetera, et cetera.
[00:56:46] And now. If you are a bad guy, all you have to do is sneak into one of those big ad networks. And all of a sudden your bad guy ads are showing up everywhere. So you see a great ad for a Chromebook. For instance, we've talked about those before you can just go ahead. Okay. Chromebook. No problem. Wow. Yeah.
[00:57:05] Yeah. Type it in. If the ads for a Chromebook from Walmart, just type in walmart.com. Okay. Avoid clicking on ads. Isn't it terrible how bad it's gotten, man. I liked the internet better back in the 1980s and nineties. How should you pay? We're going to talk about that in a minute. Public why fi is a potential problem.
[00:57:31] The bad guys will often create fake hot spots and you are now using their hot spot. Now this isn't as much of a problem as a used to be because your visits to most websites nowadays are encrypted. Do you remember that lock? I mentioned in the URL. That means it is using SSL or TLS, which is a secure communications pro protocol.
[00:57:56] So if you're seeing that, you know that you basically have a VPN, you don't have to buy a VPM service. You don't have to use a VPN service. You have a VPN that's being provided by the website, your. And that's really what that lock means. So the public wifi is less of an issue for the monitoring, what you're doing, although yeah, they can still do some monitoring.
[00:58:22] They might play with DNS and things, but they can also scan you, which is the biggest problem from my perspective about using public wifi and never. Share your personal data. If you can avoid it, one of the things we're going to be covering in the upcoming boot camps and workshops is using fake or alternate email addresses.
[00:58:46] I do it all of the time. That's why I have 3000, 3000. Yes. You heard it right different log-ins right now in use active use on. In my password manager, at least over the last decade. So I've accumulated a lot of them. So I use a different email address pretty much all of the time. And I'll, I explain how to do that in the boot camps and workshops that are coming up.
[00:59:13] So keep an eye on. On my weekly emails again, Craig peterson.com/subscribe. So you can find out about them, these, the free ones. I really want to give you guys all of the basics, right? So that's what I'm going to be doing anyways. How should I pay? This is maybe the even bigger side of things. It is very rare that I actually put my credit card number in on a website at least.
[00:59:41] Real credit card number. There's a number of options that are available to you now that weren't before, even if it's not a credit card, even if it's a debit card and generically, this is known as single use credit cards. So we've got a few. I use typically capital one's email E N O. If you have a capital one card of any sort, this is a little browser plugin that you can put on.
[01:00:11] Now, the downside of this is they will by default, try and look. Every webpage you visit. So from their perspective, it's worth it because now they get that data from you. However, in all modern browsers, you can restrict when it runs. But what happens is I go to a website, it wants a credit card and I can pop up that little Eno browser plugin.
[01:00:40] And now. Todd I can generate a virtual credit card number that's tied in behind the scenes to my real credit card number. I can even put an expiration date on that credit card number. So it can't be used after a certain. Some of these virtual credit card options, even allow you to say, Hey, it really is only single use.
[01:01:04] It can only ever be used once. And that way the bad guys can't run up your credit card. Bill Citibank, American express, JP Morgan, and the more have these types of options and basically any visa or MasterCard. Look for virtual credit cards. From your bank or whoever's providing your credit card. Hey, stick around.
[01:01:28] You're listening to Craig Peterson and I'll be right back.
[01:01:33] We're going to talk a little bit now, since it's getting near the end of the year, about what kind of technology do we think is going to be big next year. And I've got to mention this project. My daughter has been working on it. Finally hit the ocean.
[01:01:49] My daughter has been busy. You might know she's been in the maritime industry for quite a while now.
[01:01:58] And a man, she went to, she graduated 2008. I think it was this daughter. And you probably already know I have five daughters, right? Three sons too. So it was a mix, but she has been working on a ship called the Yarra Burkland it's over in Norway. And what the ship is doing here is hauling fertilizer, anything.
[01:02:24] Oh, wow. Isn't that exciting? Wow. Craig, I'm so excited for you. It is the world's first autonomous electric ship period. Okay, cargo ship and what it is doing ultimately, is it to eliminating the need for about 40,000 truck round trips a year. See what's happening over there in Norway is there's a factory that's right.
[01:02:52] Located right next to a mine. That's making all of this fertilizer and it needs to be hauled down through some fjords. To get to the main shipping Depot where it can be loaded onto the big ocean ship. So these trucks are going up and over the mountains alongside the fjords. And this is a ship that's going to take a trip that's about seven and a half nautical mile.
[01:03:19] So give or take eight miles and on the water. And now Norway is doing this in its own waterways. So there's no problem with international rules and regulations about ships here. This is just local and it loads itself. It drives itself and it unloads itself. I think that's really cool. And what it does is it plugs itself.
[01:03:47] When it is on either port w now we've seen this with some ships, right? You might've been on some of these ferries that are electric. They work pretty well for electric ferries. Cause they're usually short haul. They connect up to shore power and they do a rapid charge and they're ready for. The next leg of their ship while they are busy taking all of their load in right.
[01:04:11] Makes sense. And you might've done it, but this is different. And a lot of the incidents that happen in shipping are due to human error. Think about all of the problems we've had with Navy ships, even running into things, human error, and a lot of that's due to fatigue. On the ships. I don't know if you know it.
[01:04:32] I have two kids that three actually that have been in the maritime industry the big maritime industry and they take four hour shifts. So four on four off four on four off every day. So fatigue is a very big deal for a lot of the shipping industry. And for the first few years, they're planning on having this ship be.
[01:04:58] They're going to be up, of course, on the bridge monitoring everything, because you got a problem with artificial intelligence machine learning. If a big ship is coming along and there's a kayak in the way, it's actually the kayaks job to get out of the way. But if you run over a kayaker things, aren't going to go very well for you, frankly.
[01:05:20] But how does a computer recognize that kayak? Maybe Marine life or even some sort of a swell that's out there. So they think they've got most of this solved. And this is the project that my daughter's been working on for a few years here. She's a Mariner. She has her captain's license unlimited. Tonnage unlimited vessels on unlimited waterways anywhere in the world is just incredible.
[01:05:49] All of the stuff she's done. So the wheelhouse could disappear all together, but they've got to make sure that everything is working pretty darn well. Okay. Large vessels. Do anything about the kayak? All they can do is warn, but they definitely can't maneuver. And that's why the deep draft vessels have priority over sailboats or pretty much anything else that's out there.
[01:06:14] But, and what that brings up is the fact that we don't have the regulations yet for these autonomous ship. We don't have the regulations yet for the autonomous cars, right? This is normal. The technology tends to proceed the regulations, and we have regulations in place right now for autonomous vehicles in certain areas.
[01:06:39] But they're nowhere near mature. It's going to take a while before everything is all frigging. And now that is leading us into our friends at Ford. Ford's done a couple of interesting announcements over the last couple of weeks. So I have to bring the. And an effort really to deal with this ongoing chip shortage.
[01:07:02] Ford has made a deal with global founders. Global foundries is a chip maker and they have a non-binding agreement. Now that makes it interesting. If it's non-binding. Why even bother, but the press release says opening the door for global foundries, deliver more chips to Ford in the short term, but what's happening right now because of the chip shortages.
[01:07:30] Companies are designing their own. Purpose built chips rather than relying on the general purpose chips made by Intel or AMD Qualcomm, Samsung and video media tech, depending on what kind of chips we're talking about. This is fascinating because it is hurting Intel. No question about it. And AMD. So what does Intel done?
[01:07:55] Intel is moving its stance to being more of a contracted chip manufacturer. So you can go to Intel and say, here's my chip design. Go ahead and make that forest. And off they'll go and they will manufacture it and then probably even help you with some of the design things. Fascinating. Now, the other thing that's been happening for a while is if you look at apple, for instance, they have been using their own chips in their I phones and eye pads.
[01:08:32] Now they also are using their own chips in the laptops and various desktop computers. So apple is the highest profile example I can think of offhand. That have replaced Intel's chips. That's absolutely amazing. Google has also created its own chip for the latest pixel phone. So if you buy the latest flagship pixel, which I would not do, because this is the first time they're really using their own chip, but they've got their own chip now in.
[01:09:09] Amazon has been deploying its own chips in its internal servers to improve performance as well as to make it better for the Alexa voice assistant. You see how long tail that's a marketing term, but really how special purpose designed purpose built chips are. So it's huge. Intel's changing course.
[01:09:35] They've never been a great chip designer. If he asked me and a few know my history, I've been down at the chip level. I was down there for many years in the kernel of operating systems and dealing directly with all. From chips, when you're thinking about drivers and the low end and the operating system, that's what I did for a lot of years.
[01:09:57] So I'm glad to see this happen. It's going to be better for you because the devices can be cheaper because they don't use a general purpose chip. The chip is built and designed. For what it's being used for. So good news there for four, because Ford is going to be doing the same sort of thing.
[01:10:18] I bet mark my words. Okay. I didn't get to the predictions for this year, but I will, when we get back this upcoming year, stick around, of course you listening to Craig, Peter Sohn, you can get all kinds of information. And in fact, if you sign up for my email list, which is not a heavy marketing.
[01:10:39] Believe me, you'll get a bunch of different special reports. So ones I think are going to help you out the most. Craig peterson.com.
[01:10:50] We just talked about the future when it comes to chips and our computers, we're going to continue that discuss discussion right now on artificial intelligence and machine learning. What else is going to be important next?
[01:11:06] You just got my basic predictions about what's going to happen with chip manufacturing. These various vendors of various devices are going to continue to move away from Intel AMD, et cetera, these general purpose chips and move more to special purpose chips.
[01:11:29] Now there's a number of special purpose type designs that have been out there for a very long time. For instance, a six OCB in industry. No, those I programmed some way back when. I have gotten much more complicated, but for instance, when we're putting in systems for a business, we will typically use Cisco systems that have a basics so that everything is extremely fast.
[01:11:56] You don't notice any delay and yet it can do very heavy duty filtering. Packet examination, stream examination, because it's being done in hardware. That's the advantage to it. So we're going to see more and more that since Apple's already moved to their own chips, Google has already moved to their own chips, Amazon, their own chips, et cetera.
[01:12:20] And there'll always be a need for general purpose chips. In fact, you can say that the apple chips for instance, are fairly. Purpose they're being used in your iOS devices, your iPhone, your iPad, but they're also being used in desktop applications. But if you look more closely at what Apple's done, it has a couple of different types.
[01:12:43] Of CPU's inside the chip. So it has the high performance CPU's that are only engaged when it needs some serious computing going on. It has the low power, lower performance CPU's that are also built into that same chip that now handle background tasks, things. Dated the don't need a whole lot of CPU or don't need to be really fast.
[01:13:09] And then it also has graphics processing units that will handle things like screen updates, moving stuff around on the screens. There is a lot of technology in that chip in reality, it's it would use to take three. Completely different sets of chips to do what the one apple chip can do. So it is an example of a special purpose CPU.
[01:13:38] We're going to be seeing more and more of those now as a consumer, you're not really going to notice other than, wow, this thing's fast or wow. This battery lasts forever. You're going to have some great functionality. And I think we are seeing, because they're spinning. $2 billion a week right now in the industry, you're going to be seeing more of these fabs come online, chip fabrication plants, and they take a long time to build and put up online, but they're going to be making more specialized chips, which I really.
[01:14:12] There's an article that came out based on a survey from the I Tripoli. And this is called the impact of technology in 2022. And beyond of these are some global technology leaders. Of course I Tripoli was all about electrical engineering back in the day today, it's more about general technology. But here's the results.
[01:14:37] What is important for next year? Now, remember, I don't give investment advice. So don't look at this as things you should be putting your money into. This is just stuff that is good to know and probably should be considered, but this is not again, investment advice. Technologies will be the most important in 2022.
[01:14:57] While according to this kind of little brain trust, if you will, amongst the respondents more than one in five, say that AI and machine learning are going to be very important. What's the difference between artificial intelligence and machine learning. The lines are blurred nowadays. They used to be a lot more clear machine learning used to be the machine, the computer learns it.
[01:15:24] Let's say it's working on a factory floor and it has to do some welding on a joint. And the, it has sensors and it learns, oh, okay. This part, when it comes into me may be here, but I might be there and I might be here. So I got move around a little bit. That's basic machine. Artificial intelligence, which I think is a super set of machine learning, but other people argue the other way, they don't know what they're talking about.
[01:15:50] There is artificial intelligence is where it doesn't even have to be taught how to learn. It. Just figures things out. So it's. When it's built, talk to learn where that piece that it needs to weld is likely going to be and how to find it. It just knows. Okay I'm supposed to weld. So how do I do that?
[01:16:16] That's much more of an artificial intelligence. So that's number one, artificial intelligence next. Cloud computing 20%. Now my opinion on cloud computing is not very high, frankly, because cloud is just the name for somebody else's computer cloud computing does not mean it's safer. It does not mean that it requires less work on your part where I think cloud computing can help a business is where.
[01:16:50] Push over flow to the cloud. The many businesses that have moved technology to the cloud have moved it back now because frankly, the cloud did not provide them with what they thought they'd get, which is cheaper, better computing. And a lot of the breaches that we're getting nowadays are in the cloud.
[01:17:13] People's databases being exposed, applications, being exposed. It's great for hackers because they know, okay, let me see. Amazon has the majority of all cloud computing in the world. So let's just scan Amazon computers and see what we can find. And they're going to find that this bank has this opener, that company has that database available, et cetera, et cetera.
[01:17:37] So be careful with that, but they think cloud's number two, five G. 17% that I am very excited about it. And here's why five G is a generic term for the high speed room wireless data. So think cell phone basically, but why it really matters is it's designed to handle billions of devices. So that you can have a lot of people sharing data and getting to data, sharing a network connection in a densely populated area.
[01:18:16] That's where it really shined. And then it also has a faster data rate than the older technology. One of the things you'll find as you compare, if you really dig into the technology compare, the various cell companies is that for instance, T mobile, which is who I use has a lower frequency spectrum.
[01:18:41] Lower frequencies can not carry as much data for, but what they can do, I'm really oversimplifying. But what they can do is more readily peers, glass, and brick and walls. So T-Mobile's frequencies are lower than Verizon, for instance. So Verizon can get you faster data. But can't get it into as many places and not as well as T-Mobile just really putting this quite simply.
[01:19:14] And in fact, just what was it? Two weeks ago, we had a court order stopping the deployment of these higher frequency, 5g networks. Because of complaints from some people particularly in the avionics, in the airline industry where they're saying they could be squashing some of our critical systems because they're using some of the old satellite frequencies for 5g up in the upper bands.
[01:19:42] Anyhow, one of the things that 5g. Which has already been used for is what I was involved with. I was involved with emergency medicine for a long time and I was an EMT I P D back in the day. So almost a paramedic. And think about what could happen now, you're in the back of an ambulance that you could be the hands for the doctor who can be seeing the patient as you're driving down the highway, bringing that person in, because historically I remember this one woman.
[01:20:16] Placenta previa and had just soaked through some towels with blood. She was in really bad shape and we were squeezing IVs to get fluid into her. It was incredible. It was something else. And we brought her right in on the gurney, in emergency room and right up to the operating room and put her on the table, right from her ambulance gurney while with five G.
[01:20:42] They can be doing that now, not just in an ambulance, but in, in more rural areas, doctors can be operating remotely on someone. It's very cool. This whole tele medicine, including remote surgery. It's huge. So these technology leaders agreed with me on that 24% is the number one most benefit for or five G telemedicine.
[01:21:08] Number two, remote learning and education 20%. Personal and professional day-to-day communications. Think of all of the stuff we're doing now, how much better that's going to get entertainment, sports, live streaming, manufacturing, and assembly transportation, traffic control. Now we're down to 7% and by the way, that's where the cars are talking to each other.
[01:21:31] If you have five G. You don't need a mesh because you can use 5g, carbon footprint reduction in energy efficiency. That's 5% and 2% farming and agriculture. Our farming equipment is already using GPS in order to plow fields, planned fields, harvest fields. It's amazing. So there you go. Those are the top pieces of technology that are predicted to influence us next year.
[01:22:01] I think it's absolutely correct. And I've got to give you a bit of good news here again. 97% of these people polled agree that their teams are working more closely than ever before. Because of these working from home workplace technologies and apps for office check-in, et cetera. Good news. All around.
[01:22:26] Hey, if you want more good news. If you want to know what's happening, even some bad news, I got the right place for you to go. I have five minute little trainings in my emails every week. I have bootcamps again, all of this is the freeze stuff. You imagine what the paid stuff is but I want you to understand this.
Have You Been Phished? Email Spoofing is in full swing!
In this video, I review what's happening right now. The how, why, and and you can do about it!
From the publisher's feed