Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • The "Great Resignation" in Big Tech - Better Jobs, More Money

    The "Great Resignation" in Big Tech - Better Jobs, More Money

    There seems to be a worker shortage. And many businesses are finding that, frankly, people involved in technology are resigning; they're calling it a great resignation of workers. We have a lot of problems as business people, filling jobs nowadays.

    [Automated transcript]

    [00:00:20] And one of the things I've thought about doing is maybe even starting a course for people who want to figure out if this whole cybersecurity thing is right for them. I think that might make a lot of sense for some people. And there are some of you listeners. I know, because I've talked to you who have gone out and.

    [00:00:40] Gotten into, is that a word who have changed careers into the cybersecurity realm? So does it make sense for you? I don't know. Do you think it would make sense for me to offer something? A cybersecurity course to give you guys the basics and help you understand it and see if it might be good for you.

    [00:01:00] Only, you know that, and if you're interested, make sure you drop me a note just to me, M E Craig peterson.com, and let me know what you think. Still, the big tech is suffering from this great resignation of workers and workers in the technology field right now. So it's a good time to leave. Now, this isn't the same as many workers who, for instance, were in the restaurant business for many years, were in food service.

    [00:01:31] You make money. Maybe you don't make money. Who knows those. And, of course, those jobs pretty much disappeared during the lockup. Big tech, it's different from big tech. Most of these people, most of us, frankly, retained our jobs. We were still able to work, still able to do the stuff we'd always been doing. Still, we were doing it from home, and many employees looked at the situation and said, I am not going to leave.

    [00:02:05] Because I don't know if I'll be able to get a new job. Does that make sense to you? So we have a bit of pent-up demand in the tech field of people who maybe didn't like the boss, didn't really like what they were doing but kept the job because at least it was a job. It paid some bills. And from the bottom-line standpoint, it didn't make sense to.

    [00:02:29] Now we see something else going on; people are leaving like crazy Facebook here. There's a quote in an article in MarketWatch. Lost this guy named Raymond Andres. Who's now the chief technology officer at the air table. Now I've used air table before I was a client of theirs for a while. It's really something.

    [00:02:52] If you need to do some essential project management or have a process for doing something. That needs to be tracked, and maybe something handed over to another person when it meets a particular stage. Check it out, air table.com online. Still, he left Facebook, and he said there's been a burst of activity of people leaving.

    [00:03:15] If anything. The lockdown delayed decisions. And that's exactly what I was saying. I've been saying that for a very long time, but there's another factor involved when it comes to technology. And that is the funding, which is just amazing. You might remember a couple of years ago we had this. Brakes on IPO's on initial public offerings.

    [00:03:40] These tech companies just were not going to go public at all. And because of that, many angel investors and venture capitalists said, forget about it. I'm not going to go ahead and make any sort of investment. So that is when many of these small companies just failed, and of course, incomes the lockdown, and even more of them died.

    [00:04:03] But now. But the investors are a spinner spending a lot of money so far this year. There have been 84 initial public offerings in the US alone. Isn't that amazing? 50 plus billion dollars in IPO's. Now that's up from about 38 billion. Last year. So there's obviously money in the IPO world. So that gets the venture capitalists interested.

    [00:04:36] So VC money is also at record highs. This year's track is to be the best year yet. According to PitchBook through June. This year 2021, $150 billion has been raised among about 7,000 deals. Now that's ahead of last year's record, a total of $164 billion for the year. So we're looking at some significant money going in.

    [00:05:10] And we have many people leaving from Google and Facebook and Amazon and Apple, maybe your company as well, who are saying, wow there's some real opportunity now I could get in on the ground floor. The VC money is a record high, so I can take at least some salary enough to make it heck I haven't had to pay rent for a year.

    [00:05:33] So I can afford to do that, to try and. Something with some of my friends, and that's precisely what they're doing. Robert half, a company I've had on my show before Robert half international, did a survey. They found that about one-third of the almost 3000 information technology professionals.

    [00:05:57] They surveyed said they planned to look for a new job in the next few months. They're also saying Robert half is that while employers posted more than 365,000 job openings in June alone, they're not getting filled; that's, by the way, the highest monthly. In about since September 2019, according to CompTIA, which is an industry trade group.

    [00:06:25] I'm a member of that. My company is a member of comp Tia as well. So there are a lot of things happening that are really driving people to startups. And there's a lot of advantages to that. So here's another guy. This is an engineering manager who left Facebook last year. And he quickly returned.

    [00:06:46] He said working at a startup, you have much more connection with employees, and things moved faster. So tiger graph, by the way, also hired ex-Googlers. And they're increasing the workforce this year too, about 300 from 90. So think about what they're doing. So that's not, yeah, technically, it's probably still a startup, but it's 300 employees.

    [00:07:10] That's not us. That is a lot of employees, and they've got a lot of money behind them. Here's another guy. And she's saying, I thought I would be a lifer at Amazon. But this was a tremendous opportunity. I can have a far more significant impact and more influence on the company's trajectory, which quite frankly was harder at Amazon.

    [00:07:33] And we're seeing more and more of particularly the younger employees looking at that. Her name's Anna fag fabric. Sorry about the names butchering here, but she's now at freshly. Officer. So many people are saying in this survey from Robert half international that having a chance to impact a smaller company was a significant reason for leaving.

    [00:08:01] And that's after years of massive growth at big tech companies. So again, IBM in the 1970s. They were the ruler; they were the king. It was impossible. If you work for IBM, man, they're going to be around forever. And, of course, they still are. And they have excellent products, especially the Z series mainframe, but they're not the company they were.

    [00:08:24] And I think we now are seeing. The next step in these big high-tech, but is no longer being the companies that they were innovation is going to leave with these employees, and they're going to really be hurt and hurt quite a bit. All right. So coming up, we're going to talk, of course, more about some of the more critical tech stuff you've got to. If you haven't already get on my email list, I'll send you a couple of special reports that we.

    [00:08:54] As well as, of course, every week, one or two newsletters, not sales documents, newsletters, Craig peterson.com.

    10 min
  • Windows 11 Will Require a New Piece of Hardware

    1126-01-windows_11_and_tpm

    [00:00:00] Microsoft has had some incredibly successful operating systems and some significant failures. Think of windows millennial edition. While now they're coming up with windows 11, and frankly, things just aren't looking that good.

    [00:00:16] If you know me, you know how I have had some issues with Microsoft here over the years; they are a company that has been, in my opinion, very dishonest have been doing all kinds of immoral things for a very long time by destroying.

    [00:00:36] Parts of the market that they considered being competitors of theirs, so they have used their position at the top of the market with billions of dollars in cash to really nail anybody that tries to challenge them. And it's incredible to me what has happened over the years. But, of course, you might know Microsoft did.

    [00:00:57] Putting an investment into Apple. And many people say that investment that bill gates authorized really saved apple from total collapse. And I can see how is this a reasonable audience or argument? But the bottom line, when we get down to it, is that Microsoft Windows has never been a great operating system.

    [00:01:21] It's always had issues. It's always had glitches, and we could go into a lot of reasons for that. But I think one of the main ones is that it has really tried to stay compatible with everything, all of the. When you were a kid, you certainly rode a bicycle. But, still, the bike you might be riding when you're in your thirties or forties will probably not have three wheels.

    [00:01:46] And it's probably not going to have a pedal connected to the front wheel. It will be a whole lot different, and Microsoft, over the years, has tried to make their more modern operating systems as time has gone on. Compatible with older operating systems of theirs. And that inevitably leads to problems.

    [00:02:06] If you're trying to fix a problem, Einstein said this, right? If you're trying to fix a problem, you cannot use the thinking that created the problem in that first place. So to fix a problem, you have to think at a different level. And when it comes to software and operating systems, you actually. To program at a different level.

    [00:02:29] And the entire structure of the programs has to be different than it is when you're starting. Microsoft has been doing that a little bit. And with Windows 11, they are really trying, they've gotten such black eyes over the years for security problems, and I think they deserve them for the most part.

    [00:02:50] Now they're forcing you to use what's called a TPM. Now, these TPMS have been around for quite a while. You see them built into your Macs, and they've been built into your apple Macs now for years, built-in frankly to your iOS devices for your iPhone also for years. But this is a trusted platform module TPM.

    [00:03:17] And the idea behind a TPM is that your computer hardware is locking. All of this information and the senior TPM. Now there are a lot of complicated implementations of TPMS. The implementation that apple uses stores, all kinds of stuff that makes sure you're booting properly, security, keys, et cetera. What Microsoft is doing now is for windows 11.

    [00:03:47] If you're going to. Your machine has to have a TPM and not just an older TPM 2.0. Now there are alpha images available right now for developers of Windows 11. And I have to absolutely encourage you if you are a software developer to get an alpha version of windows so that you can double-check, is my software is still going to be able to run in this.

    [00:04:13] And I also want to encourage you if you are relying on particular applications. Maybe they're a little older, perhaps they're not, but if your business requires you to use a piece of software, you really should get windows 11. Right now, get the alpha code, follow it through beta and test your software.

    [00:04:36] Make sure it works. If it isn't working, then talk to your software vendors, warn them that it's. Because Windows 11 requiring TPM support, although it doesn't need it right now in this alpha version that they're releasing, it does require it. Supposedly when they finally release Windows 11, the computers you have today probably don't have this chip.

    [00:05:07] We have a client who decided they would go out and buy their own server against our judgment. And what we told them they should be doing. So they went out, and they purchased an HP server from HP enterprise, and they did. And it did not have most of the security staff they needed, including it did not have a TPM.

    [00:05:27] It did not have one of these trusted platform modules on it. Now, in their case with this HP server, they could buy one after the fact and install it. Although the entire machine had to be destroyed entirely and reloaded, that's a minor price to pay versus purchasing a whole new server.

    [00:05:48] The TBM is not necessarily going to be compatible with the new version of windows. In fact, Microsoft surface tablets. I look this up to their highest-end surface tablets, Microsoft branding all over it. Microsoft certified $6,000 almost to buy this top-end surface tablet with all the bells and whistles you can get on it.

    [00:06:15] It will not work with windows 11. How's that? So the reason Microsoft is doing this, I think, is a good reason. They really want to lock down this system to no longer have as many security problems. And we're not going to get into all of the different types of security problems that TPM is not going to solve a lot of them, but it's going to solve.

    [00:06:40] Some of them, but the program manager over Microsoft, her name is Al area. I guess it is Carly. She said that the hardware floor of TPM 2.0 support will be in place for the final version. We'll see. I think a lot of people are going to push back. However, Microsoft really does and legitimately does want to make sure that everything is safe.

    [00:07:07] So keep that in mind. There are a lot of people complaining about it, the alpha version. And that is why you have an alpha version. They're complaining about it because of the TPM, but also because of some of the other things that are going on with windows 11, at least right now, some of the things Microsoft has announced they've got, for instance, group policy will not let you get around hardware enforcement for windows 11.

    [00:07:34] Microsoft is still going to block you from upgrading your device. To make sure your devices stay supported and secure. So that's good news, and it's good news because many times in the past, how many of us we've upgraded our machines and a new version of the operating system. And I use "upgrade" with air quotes around it, but we've upgraded our machines, and they won't work with the new version.

    [00:08:00] The audience here for her short statement, which was part of this, a Microsoft tech community user questions, was agitated. They did not like the answers that she was giving. And this is according to windows central, the videos, top comment, read, quote, a lot of these answers come off as super Tone Deaf.

    [00:08:22] It is looking like Windows 11 will be another problem. So for those of us, that know, yeah. Windows eight was really quite the flop member. They very quickly came out with windows eight one, and Microsoft is the only tone-deaf company out there. I've got to say, I think Apple has been remarkably tone-deaf in many different ways.

    [00:08:44] Now they seem to be waking up doing some things a little bit better, so kudos to them for that. But a lot of companies, really. Tone, deaf to what users want. And there's a lot of blog posts here. We'll have to see if what they're saying ultimately ends up in windows 11. If it does, things will be a bit of a problem.

    [00:09:08] But part of the reason we don't know. Because Microsoft disabled any more comments on the video, they were getting so many of them. And of course, there are trolls people who hate Microsoft. I'm certainly not one of them. They also, by the way, deleted all existing comments on the video here about windows 11 with their program manager in response to the negativity. The voting is still open on this video, and 2,700 dislikes and only 146 likes as of this last week. It's interesting. Microsofts are really rushing to these new hardware requirements. They're being very aggressive, and I think they're handling it. Sound familiar. We've heard these sorts of things before, but now we'll see here into the legitimacy of this. How much is it going to benefit is limited because where are we solving our biggest problems?

    [00:10:09] People cooking, links, things get installed, et cetera, that nothing to TPM will be able to handle. The TPM is going to make sure that you have a secure boot that's it's missing. The goal in life. So how was it? We will help with a lot of this other stuff we will see, and I'll definitely keep you up to date on this?

    [00:10:28] It's real. Hey, I want to remind you guys, go to Craig peterson.com. Hopefully, you got my newsletter last week. I gave you a private link to a webinar that I did about VPN because there's a lot of people selling VPNs. Unfortunately, most of them are misrepresenting what they can. And in fact, most of them make you less safe.

    [00:10:53] So don't miss another thing. Go to Craig peterson.com right now. And subscribe

    11 min
  • Weekly - Microsoft is planning on making you buy a new computer

    [Automated transcript]

    Weekly - Microsoft is planning on making you buy a new computer

    [00:00:00] Microsoft has had some incredibly successful operating systems and some significant failures. Think of windows millennial edition. While now they're coming up with windows 11, and frankly, things just aren't looking that good.

    [00:00:16] If you know me, you know how I have had some issues with Microsoft here over the years. They are a company that has been, in my opinion, very dishonest have been doing all kinds of immoral things for a very long time by destroying.

    [00:00:36] Parts of the market that they considered being competitors of theirs, so they have used their position at the top of the market with billions of dollars in cash to really nail anybody that tries to challenge them. And it's incredible to me what has happened over the years. But, of course, you might know Microsoft did.

    [00:00:57] Putting investment into Apple. And many people say that investment that bill gates authorized really saved apple from total collapse. And I can see how is this a reasonable audience or argument? But the bottom line is that Microsoft Windows has never been a great operating system when we get down to it.

    [00:01:21] It's always had issues. It's always had glitches, and we could go into a lot of reasons for that. But I think one of the main ones is that it has really tried to stay compatible with everything, all of the. When you were a kid, you certainly rode a bicycle. But, still, the bike that you might be riding when you're in your thirties or forties is probably not going to have three wheels.

    [00:01:46] And it's probably not going to have a pedal connected to the front wheel. It is going to be a whole lot different, and Microsoft, over the years, has tried to make their more modern operating systems as time has gone on. Compatible with older operating systems of theirs. And that inevitably leads to problems.

    [00:02:06] If you're trying to fix a problem, Einstein said this, right? If you're trying to fix a problem, you cannot use the thinking that created the problem in that first place, in order to fix a problem, you have to think at a different level. And when it comes to software and operating systems, you actually. To program at a different level.

    [00:02:29] And the entire structure of the programs has to be different than it is when you're starting. Microsoft has been doing that a little bit. And with Windows 11, they are really trying, they've gotten such black eyes over the years for security problems, and I think they deserve them for the most part.

    [00:02:50] Now they're forcing you to use, what's called a TPM. Now these TPMS have been around for quite a while. You see them built into your Macs, and they've been built into your apple Macs now for years built-in frankly to your iOS devices for your iPhone also for years. But this is a trusted platform module TPM.

    [00:03:17] And the idea behind a TPM is that your computer hardware is locking. All of this information and the senior TPM. Now there are a lot of difficult implementations of TPMS. The implementation that apple uses stores, all kinds of stuff that makes sure you're booting properly security, keys, et cetera. What Microsoft is doing now is for windows 11.

    [00:03:47] If you're going to. Your machine has to have a TPM and not just a older TPM 2.0, now there are alpha images available right now for developers of Windows 11. And I have to absolutely encourage you if you are a software developer to get an alpha version of windows so that you can double-check, is my software still going to be able to run in this.

    [00:04:13] And I also want to encourage you if you are relying on certain applications and maybe they're a little bit older, maybe they're not, but if your business requires you to use a piece of software, you really should get windows 11. Right now, get the alpha code, follow it through beta and test your software.

    [00:04:36] Make sure it works. If it isn't working, then talk to your software vendors, warn them that it's. Because Windows 11 requiring TPM support, although it doesn't require right now in this alpha version that they're releasing, but it does require it. Supposedly when they finally release windows 11, your computers that you have today probably don't have this chip.

    [00:05:07] We have a client that decided they were going to go out and buy their own server against our judgment. And what we told them they should be doing. So they went out and they bought we're going to get an HP server from HP enterprise and they did. And it did not have most of the security staff that they needed, including it did not have a TPM.

    [00:05:27] It did not have one of these trusted platform modules on it. Now, in their case with this HP server, they could buy one after the fact and install it. Although the entire machine had to be completely destroyed and reloaded, that's a minor price to pay versus buying a whole new server.

    [00:05:48] The TBM is not necessarily going to be compatible with the new version of windows. In fact, Microsoft surface tablets. I look this up their highest end surface tablets, Microsoft branding all over it. Microsoft certified $6,000 almost to buy this, or, top end surface tablet with all of the bells and whistles you can get on it.

    [00:06:15] It will not work with windows 11. How's that? So the reason Microsoft is doing this, I think is a good reason. They really want to lock down this system so that we're no longer having as many security problems. And we're not going to get into all of the different types of security problems that TPM is not going to solve a lot of them, but it's going to solve.

    [00:06:40] Some of them, but the program manager over Microsoft, her name is Al area. I guess it is Carly. She said that the hardware floor of TPM 2.0 support is going to be in place for the final version. We'll see. I think a lot of people are going to push back. However, Microsoft really does and legitimately does want to make sure that everything is safe.

    [00:07:07] So keep that in mind. There are a lot of people complaining about it, the alpha version. And that is why you have an alpha version, they're complaining about it because of the TPM, but also because of some of the other things that are going on with windows 11, at least right now, some of the things Microsoft has announced they've got, for instance group policy will not let you get around hardware enforcement for windows 11.

    [00:07:34] Microsoft is still going to block you from upgrading your device. To make sure your devices stay supported and secure. So that's good news and it's good news because many times in the past, how many of us we've upgraded our machines and to a new version of the operating system. And I use upgrade with air quotes around it, but we've upgraded our machines and they won't work with the new version of it.

    [00:08:00] The audience here for her little statement, which was part of this, a Microsoft tech community user questions was very upset. They did not like the answers that she was giving. And this is according to windows central, the videos, top comment, read, quote, a lot of these answers come off as super tone.

    [00:08:22] Deaf is looking like Windows 11 will be another windows. So for those of us that know yeah. Windows eight was really quite the flop member. They very quickly came out with windows eight one and the Microsoft is, and the only tone-deaf company out there, I've got to say, I think Apple has been very tone-deaf in a lot of different ways.

    [00:08:44] Now they seem to be waking up doing some things a little bit better, so kudos to them for that. But a lot of companies really. Tone, deaf to what users want. And there's a lot of blog posts here. We'll have to see if what they're saying ultimately ends up in windows 11. If it does, things will be a bit of a problem.

    [00:09:08] But part of the reason we don't know. Is because Microsoft disabled, any more comments on the video, they were getting so many of them. And of course there's trolls people who hate Microsoft. I'm certainly not one of them. They also, by the way, deleted all existing comments on the video here about windows 11 with their program manager in response to the negativity, the voting is still upon this video and.

    [00:09:37] 2,700 dislikes and only 146 likes as of this last week. It's interesting. Microsofts are really rushing to these new hardware requirements. They're being very aggressive, and I think they're handling it. Sound familiar. We've heard these sorts of things before, but now we'll see here into the legitimacy of this, how much is it going to benefit is limited as well because where are we having our biggest problems?

    [00:10:09] People cooking, links, things get installed et cetera, that nothing to TPM is going to be able to handle. The TPM is going to make sure that you have a secure boot that's it's missing. Goal in life. So how was it we're going to help with a lot of this other stuff we will see, and I'll definitely keep you up to date on this.

    [00:10:28] It's a real. Hey, I want to remind you guys, go to Craig peterson.com. Hopefully you got my newsletter last week. I gave you a private link to a webinar that I did about VPN, because there's a lot of people selling VPNs. Most of them are misrepresenting what they can. And in fact, most of them make you less safe.

    [00:10:53] So don't miss another thing. Go to Craig peterson.com right now. And subscribe

    [00:10:59] There seems to be a worker shortage. And a lot of businesses are finding that frankly, people who are involved in technology are resigning, they're calling it a great resignation of workers. We have a lot of problems as business people, filling jobs nowadays.

    [00:11:20] And one of the things I've thought about doing is maybe even starting a course for people who want to figure out if this whole cybersecurity thing is right for them. I think that might make a lot of sense for some people. And there are some of you listeners. I know, because I've talked to you who have gone out and.

    [00:11:40] Gotten into, is that a word who have changed careers into the cybersecurity realm? So does it make sense for you? I don't know. Do you think it would make sense for me to offer something? A cybersecurity course to give you guys the basics and help you to understand it, to see if it might be good for you.

    [00:12:00] Only, you know that, and if you're interested, make sure you drop me a note just to me, M E Craig peterson.com and let me know what you think, but the big tech is suffering from this great resignation of workers and workers in the technology field right now. It's a good time to leave. Now, this isn't the same as many workers who, for instance, were in the restaurant business for many years, were in food service.

    [00:12:31] You make money. Maybe you don't make money. Who knows those. And of course, those jobs pretty much disappeared during the lockup. Big tech, it's different in big tech. Most of these people, most of us, frankly, we retained our jobs. We were still able to work, still able to do the stuff we'd always been doing, but we were doing it from home, and many employees looked at the situation and said, I am not going to leave.

    [00:13:04] Because I don't know if I'll be able to get a new job. Does that make sense to you? So we have a bit of a pent up demand in the tech field of people who maybe didn't like the boss didn't really like what they were doing, but kept the job because at least it was a job. It paid some bills. And from the bottom-line standpoint, it didn't make sense to.

    [00:13:28] Now we see something else going on, people are leaving like crazy Facebook here. There's a quote in an article in MarketWatch. Lost this guy named Raymond Andres. Who's now the chief technology officer at air table. Now I've used air table before I was a client of theirs for a while. It's really something.

    [00:13:51] If you need to do some basic project management, or if you have a process for doing something. That needs to be tracked and maybe something handed over to another person when it meets a certain stage, check it out, air table.com online, but he left Facebook and he said, there's been a burst of activity of people leaving.

    [00:14:15] If anything. The lockdown delayed decisions. And that's exactly what I was saying. I've been saying that for a very long time, but there's another factor involved when it comes to technology. And that is the funding, which is just amazing. You might remember a couple of years ago we had this. Brakes on IPO's on initial public offerings.

    [00:14:40] These tech companies just were not going to go public at all. And because of that, many angel investors and venture capitalists said, forget about it. I'm not going to go ahead and make any sort of investment. That is the time when a lot of these small companies just failed and of course, incomes the lockdown and even more of them failed.

    [00:15:03] But now. But the investors are a spinner spending a lot of money so far this year, there have been 84 initial public offerings in the U S alone. Isn't that amazing? 50 plus billion dollars in IPO's. Now that's up from about 38 billion. Last year. So there's obviously money in the IPO world. So that gets the venture capitalists interested.

    [00:15:36] So VC money is also a record hives. This year's track to be the best year yet. According to PitchBook through June. This year 2021, $150 billion has been raised among about 7,000 deals. Now that's ahead of last year's record, a total of $164 billion for the year. So we're looking at some major money going in.

    [00:16:09] And we're have a lot of people that are leaving from Google and Facebook and Amazon and Apple, maybe your company as well, who are saying, wow there's some real opportunity now I could get in on the ground floor. The VC money is a record high, so I can take at least some salary enough to make it heck I haven't had to pay rent for a year.

    [00:16:32] So I can afford to do that, to try and. Something with some of my friends and that's exactly what they're doing. Robert half, which is a company I've had on my show before Robert half international, they did a survey and they found that about one third of the almost 3000 information technology professionals.

    [00:16:56] They surveyed said they planned to look for a new job in the next few months. They're also saying Robert half is that while employers posted more than 365,000 job openings in June alone, they're not getting filled that's by the way, the highest monthly. In about since September, 2019, and that's according to comp Tia, which is a, an industry trade group.

    [00:17:24] I'm a member of that. My company is a member of comp Tia as well. So there are a lot of things happening that are really driving people to startups. And there's a lot of advantages to that. So here's another guy. This is an engineering manager who left Facebook last year. And he quickly returned.

    [00:17:45] He said working at a startup, you have much more connection with employees and things moved faster. So tiger graph, by the way, also hired ex-Googlers. And they're increasing the workforce this year too, about 300 from 90. So think about what they're doing. That's not, yeah, technically it's probably still a startup, but it's 300 employees.

    [00:18:10] That's not us. That is a lot of employees, and they've got a lot of money behind them. Here's another guy. And she's saying, I thought I would be a lifer at Amazon. But this was a tremendous opportunity. I can have a far greater impact and more influence on the company's trajectory, which quite frankly was harder at Amazon.

    [00:18:32] And we're seeing more and more of particularly the younger employees looking at that. Her name's Anna fag fabric, sorry about the names butchering here, but she's now at freshly she's their chief criminals commercialization. Officer. So a lot of people are saying in this survey from Robert half international that having a chance to have an impact at a smaller company was a major reason for leaving.

    [00:19:00] And that's after years of massive growth at big tech companies. So again, IBM in the 1970s. They were the ruler, they were the king. They was impossible. If you work for IBM, man, they're going to be around forever. And of course, they still are. And they have amazing products, especially the Z series mainframe, but they're not the company they were.

    [00:19:24] And I think we now are seeing. The next step in these big high-tech, but is no longer being the companies that they were innovation is going to leave with these employees, and they're going to really be hurt and hurt quite a bit. All right. So coming up, we're going to talk, of course, more about some of the more important tech stuff, you've got to, if you haven't already get on my email list, I'll send you a couple of special reports that we.

    [00:19:54] As well as of course, every week, one or two newsletters, not sales documents, newsletters, Craig peterson.com.

    [00:20:04] Bitcoin is all of the rage. In fact, these cryptocurrencies or something, a lot of people have considered investing in of course, many have invested in it. I played around with them about a decade ago, and the IRS seized 1.2 billion worth of it.

    [00:20:19] You might remember, we talked years ago about the IRS trying to tax things in the virtual world. So if you were in one of these real life type things and you owned property, as it were inside this virtual world, they wanted to tax it. Of course, if you sold something with real hard money and. You sold it inside that real world with real hard money, you would end up having to pay taxes.

    [00:20:47] Just if you sold a hammer to someone, that's the way it works. A lot of people have decided that, for some reason, cryptocurrency is completely untracked. Now we know about cases. I've talked about them here where some of these coins in this particular case, we're talking about Bitcoin or has been used online.

    [00:21:15] And in fact, the government has found out who was using it and really stepped in, in a big way. Silk road is the biggest example. This was an online black market for everything you can think of, from illegal drugs to firearms, to all kinds of illegal commodities that were for sale online.

    [00:21:40] This was back in 2013, they were using Bitcoin to buy and sell things on this free trade zone. I think they called themselves and silk growed was just thriving. On comes the federal government and federal agents in the United States really cut their teeth in crypto search and seizure. With taking down the silk road, you might remember this was very unprecedented.

    [00:22:10] People had no idea. What they could do. How could the federal government monitor this? Can I buy and sell these Bitcoins? All of that sort of thing. And 20 years as the chief of money laundering and asset forfeiture in. Yeah, us attorney's office for the Southern District of New York. Sharon Levin said that this whole takedown or silk road was completely unprecedented and it was new technology.

    [00:22:41] What do you do well because people. Here cryptocurrency and crypto, of course, being short for cryptography, they figure that okay. While obviously it is absolutely untraceable untrackable. Tell that to the people that this year have tried to ransom money out of enough. US corporation, some of the major consider for instance, colonial pipeline and what happened with them and how at least half of their cryptocurrency was returned to them.

    [00:23:15] So don't think that this stuff is a way that you can get away with breaking in the law or not paying taxes. It is not the whole. Business, if you will, of crypto seizure and sale is growing incredibly fast. In fact, the federal government just enlisted the help of the private sector to manage and store these crypto tokens that have been seized from.

    [00:23:47] Now I mentioned that the IRS has seized about $1.2 billion worth of cryptocurrency this fiscal year. That is a whole lot of cryptocurrency. And what are they doing with it while it's the same thing? Remember the drug dealers back in the day. Miami, what was happening? I used to love Miami vice TV show. What happened there while they seize boats, they seized cars.

    [00:24:13] They seized cash. Obviously, they can just put back into circulation, but everything else, what do they do? Cores, they go ahead and they sell it at auction. And that's what they've been doing. Then in June, they started auctioning off light coin and Bitcoin cash. They had 11 different lots on offer.

    [00:24:38] It was a four day auction and it included 150.2, 2 5 6 7 1 5 3 light coin. You like that. Remember cryptocurrency is not necessarily a whole coin. It's like having a gold coin. That's worth 500 bucks. How are you going to use that to buy a loaf? But what happens with these cryptocurrencies is you can buy and sell fractions of a coin.

    [00:25:04] So that's why you get into the millions of a piece of a coin. So they sold 150 ish like coin and. Above 0.00022 a Bitcoin cash worth more than 21 grand. So that's one of the 11 lots that was out there. And this crypto property is what they're calling. It had been confiscated as part of a tax noncompliance case.

    [00:25:34] I'm looking right now at the public auction sale notice. And where it was, where you could go online. It was a GS, a auctions.gov. If you want to check these things out, as in the general services administration, auctions.gov, GSA, auctions.gov, and they were selling it, and it was a taxpayer, it tells you all kinds of information about them.

    [00:25:56] It's a. Crazy here, but you have to pay by cash to certified cashiers or treasures check drawn on different whatever banks. And it's really cool to look at some of these things, but you can find them online. If you're interested in buying them might be a good way to buy them, to buy these various cryptocurrencies if you want to get into there.

    [00:26:20] But a lot can refer to almost anything could be, as I said, boats or cars like it was on Miami vice. It could be some number of crypto coins that are being auctioned. So they're going to be doing more and more of that. Then, apparently, the feds are saying that they have no plans to step back from being basically a crypto broker.

    [00:26:46] Here is the bottom line here because they're seizing and selling all of these assets. So keep an eye out for that. Remember what is going on? The silk road site that I mentioned had been shut down or operating on the dark web. It used Bitcoin exclusively nowadays are using various either types of coins.

    [00:27:09] Most of them are ultimately traceable, and we're not going to get into all of the details behind it, but the bottom line is so what do they do now? Think about this. Silk road had 30,000 Bitcoin that they were able to identify in CS. And it was probably the biggest Bitcoin seizure ever. And it sold for about $19 million.

    [00:27:37] So that was quite a few years ago. Somebody just pull up a calculator here, say 30,000 times, and what's Bitcoin nowadays. I'm not quite sure. Let's say it's $15,000. So in today's money, it had a half, a billion dollars. Today's value, a half, a billion dollars worth of Bitcoin in there isn't that something, and that was all seized and it was all auctioned off.

    [00:28:03] So keep an eye on that. They're following the money is the technique they're using. You can find out a lot more at us, marshals.gov, and that is how they found it. If you've got pictures. You're going to have to sell it. You're going to have to transfer. You have to do something with it. And that's where they're getting.

    [00:28:24] Bottom line, particularly if you take the Bitcoin and turn it into something else, but this would take a while to explain. And I was very happy to be able to sit in on a presentation that was done by the treasury department on how they handle all of this. It's frankly very fascinating. Hey, make sure you spend a couple of minutes and join me online.

    [00:28:49] Craig peterson.com. You can sign up for my newsletter. You can listen to my podcasts, and you can get some free, special reports just for signing up.

    [00:28:59] This is a tough one. Apple has decided that they are going to build in to the next release of the iPhone and iPad operating system. Something that monitors for child porn.

    [00:29:12] Apple has now explained that they are going to be looking for child abuse images in specific ones. And I just am so uncomfortable talking about this, but the whole idea behind it is something we need to discuss. Apple said, they're going to start scanning for these images and confirmed the plan. In fact, when people said, are you sure you're going to be doing that?

    [00:29:43] Here's what. IOS 15, which is the next major release of Apple's operating system for I-phones. And for I pad is going to use a tie to something called the national center for missing and exploited children. And the idea behind this is to help stop some of this child abuse and there's people who traffic in children, and it's just unimaginable.

    [00:30:13] What happens out there really is some people it's just such evil. I, it I just don't get it. Here's what they're going to be doing. There are ways of taking checksums of pictures and videos, so that if there is a minor change in something that might occur, because it was copied that it does not mess it up.

    [00:30:39] It still can give the valid checksum and. Iman, that technology is detailed, but basically just think of it as a checksum. So if you have a credit card number, there is a checksum digit on that bank accounts have checked some digits so that if you mess it up a little bit, okay, it's an invalid checksum, so that number's obviously wrong in this case.

    [00:31:03] What we're talking about is a checksum of a pitcher or oven. And these various child safety organizations have pictures of children who are abused or who are being abused, who are being exploited. And they have these checksums, which are also called hashes. That is now going to be stored on your iOS device.

    [00:31:33] And yes, it's going to take some space on the device. I don't think it's going to take an enormous amount of space considering how much space is on most of our iPhones and iPads that are out there. Apple gave this detection system is called C Sam, a real thorough technical summary. It is available online, and I've got a, to this article in this week's newsletter, but they released this in just this month, August of 2021.

    [00:32:06] And they're saying that they're using a threshold that is. Quote set to provide an extremely high level of accuracy and ensures the less than one in 1 trillion chance per year of incorrectly flagging a given account. Now I can say with some certainty in having had a basic look through some of the CSM detection documentation, that they're probably right about that, that the odds are very good.

    [00:32:39] Small that someone that might have a picture of their kids in a bathtub, the odds are like almost so close to zero. It is zero that it will be flagged as some sort of child abuse, because it's not looking at the content of the picture. It's not saying that this picture, maybe it is a picture of child exploitation or a video of her child being exploited.

    [00:33:01] If it is not one that has been seen before by the national center for missing exploited. It will not be flagged. So I don't want you guys to get worried that a picture at the beach of your little boy running around and just boxer trunks, but a lot of skin showing is going to get flagged. It's not going to happen.

    [00:33:24] However, a pitcher that is known to this national center for missing and exploited children is in fact going to be flagged and your account will be flagged. Now it's hard to say exactly what they're going to do. I haven't seen anything about it, of the apples. Only say. That that they're going to deploy software.

    [00:33:50] That's going to analyze images in the messages application for new system that will warn children and their parents from receiving or sending sexually explicit photos. So that's different. And that is where again, a child, you put parental settings on their iPhone. If they're taking these. Pictures, selfies, et cetera.

    [00:34:13] Girls sending it to a boyfriend, sending it to his girlfriend, whatever it might be. The parents are going to be warned, as are the children that is looking for things that might be of a sexual content. Okay. It really is. It's really concerning. Now let's move on to the part that I'm concerned about, because I think everyone can agree that both of those features are something good that are ultimately going to be very good, but here's a quote.

    [00:34:40] Apple is replacing it's industry standard end to end encrypted messaging system with an infrastructure for surveillance and censorship. Now, this is a guy who's co-director for the center for democracy and technology security and surveillance product project, I should say. He's Greg, no, him, no Chaim, is saying this, and he said apple should abandon these changes and restore its users, faith in the security and integrity of their data on apple devices and services.

    [00:35:14] And this is from an article over an tech. So this is now where we're getting. Because what are they doing? How far are they going? Are they going to break the end encryption in something like I messages? I don't think they are going to break it there. They're not setting up necessarily an infrastructure for surveillance and censorship, but apple has been called on as has every other manufacturer of software.

    [00:35:44] I remember during the Clinton administration, this whole thing with eclipse. Where the federal government was going to require anyone that had any sort of security to use this chip that was developed by the federal government. And it turns out, of course, the NSA had an very big backdoor in it, and it was a real problem.

    [00:36:04] Look at the Jupiter. That was another encryption chip and it was being used by Saddam Hussein and his family in order to communicate. And it turns out yeah, there's a back door there too. This was a British project and chip that was being used. So with apple, having resisted pressure. To break into phones by the US government.

    [00:36:27] But some of these other governments worldwide that have been very nasty, who've been spying on their citizens who torture people who don't do what apple are not happy, what the government wants them to do have been trying to pressure Apple into revealing this. Now I have to say, I have been very disappointed in all of these major companies, including apple, when it comes to China, they're just drooling at the opportunity to be there.

    [00:36:56] Apple does sell stuff there. All of these companies do. Yeah, Google move their artificial intelligence lab to China, which just, I cannot believe they would do something like that. AI machine learning, those or technologies that are going to give the United States a real leg up technology wise to our competitors worldwide.

    [00:37:17] And they move to China, but they have complied with this great firewall of China thing where the Chinese people are being censored. They're being monitored. What's going to happen now because they've had pressure from these governments worldwide to install back doors in the encryption systems.

    [00:37:38] And apple said, no, we can't do that because that's going to undermine the security for all users, which is absolutely true. If there is a door with a lock, eventually that lock will get picked. And in this case, if there's a key, if there's a backdoor of some sort, the bad guys are going to fight. Now Apple has been praised by security experts for saying, Hey, listen, we don't want to undermine security for everybody, but this plan to do ploy, some software that uses the capabilities of your iPhone to scan.

    [00:38:15] Your pictures, your photos, things that videos that you're sharing with other people and sharing selected results with the authorities. Apple is really close to coming across that line to going across it. Apple is dangerously close to acting as a tool for government surveillance. And that's what John Hopkins university cryptography professor Matthew Greene said on.

    [00:38:46] This is really a key ingredient to adding surveillance, to encrypted messages. This is again, according to our professor over John Hopkins, green professor green, he's saying that would be a key in Greece and then adding surveillance, encrypted messaging, the ability to add scanning systems like this to end encrypted messaging systems has been a major ask by law enforcement, the world.

    [00:39:14] So they have it for detecting stuff about missing and exploited children. That's totally wonderful. And I'm fine with that. No problem. But that now means that Apple's platform has the ability to add other types of scanning. All right. We'll see what ends up happening these the next thing, which is warning children and their parents about sexually explicit photos is also a bit of a problem here.

    [00:39:46] Apples. Yeah on this is messages uses on-device machine learning to analyze image attachments, and determine if a photo is sexually explicit. The feature is designed so that Apple does not get access to the messages it's saying, if it detects it, they're going to blur the photo. The child will be warned, presented with helpful resources and reassured it is okay if they do not want to view them.

    [00:40:16] And the system will let parents get a message. If children do view a flagged photo and similar protections are available for child attempts to send sexually explicit photos. Interesting. Isn't it. Interesting world. So I think what they're doing now is, okay, they're really close to that line, going over.

    [00:40:38] It could mean the loss of lives in many countries that really totally abuse their citizens or subjects, depending on how they look at them. Hey, make sure you check me out online. Craig peterson.com. Hey, sorry about having to talk about this, but man, this isn't.

    [00:40:57] It's time for a little bit of good news. We now have satellite internet performance. That's pretty much on par with fixed broadband, and it isn't just in the us. We're going to talk about that right now. What are the options?

    [00:41:13] You might remember the whole Sputnik thing and what happened there really drove the space race forward very rapidly, but we're using much fancier satellites than Sputnik, which of course, all it was doing was sending out a beep.

    [00:41:30] It was alive. And I remember I went over to a friend's house. I have an advanced class amateur radio license, and I went over to a friend's house, and he had some satellite equipment. He was also a ham, and we were able to tune his satellite in his satellite dish into a couple of the satellites up there.

    [00:41:52] Now the amateur radio community has one or more satellites. I'm not sure. We were really impressed with all of the stuff that's up there in the sky. There are satellites, of course, that we don't even know what they're doing because they're top-secret government satellites. And they're probably a decade ahead of the rest of the industry.

    [00:42:15] But he was pulling down images from some of these satellites that were open-source of what's happening on the earth and just all kinds of things back before heavy encryption. It was very cool to think that these satellites were miles up in space. No, I'm [email protected].

    [00:42:37] I don't know if you've ever tried it. You should try and go to speed. Test one word.net on your web browser. And it'll open up a little window. It's a company called Uber. And that window will allow you to start a test. And the first thing it does is it tries to find, okay, where are you located? And who has the closest reflector that we can use for speed testing?

    [00:43:02] Usually there's something not too far away from you. If you are out in the Netherlands and of course, many of you listening, kind of our Netherlands, when it comes to internet access, you have pretty slow internet and speed test dot nettle. I'll put there's three numbers, you, or maybe four, you really have to pay attention to.

    [00:43:25] You've got the download number and that's telling you how fast the data comes down to your browser from that particular spot, which is typically, as I said, close to you, although nowadays something that's far away on the internet, isn't going to be that much. So download matters and then probably what matters the most for most people.

    [00:43:48] The next thing to look at is upload most of the time. If you have a regular consumer internet link, your upload speed is about 10, maybe as much as 20% of your download speed. So if you're getting megabit down, It's going to be 10% of that megabit down, maybe as much as 20%. So you're going to get about a hundred K up versus the megabit down it again, it varies.

    [00:44:21] A lot of places will have 50 megabits down and 10 megabits up so it can vary. Now the up speed, the uplink speed is what's going to affect you when you are trying to upload a file. So maybe you're trying to upload something to work, or you are trying to stream a video cause you're trying to run a webinar.

    [00:44:45] That's what that is. The next number that you have to pay attention to is the round trip time. So that's the time it takes from a packet to get from your computer to the server that you're connected to. And then back again. Usually that's measured in milliseconds. And I remember the very first time I was using the ethernet, it was thick wire, ethernet, and 10 megabits.

    [00:45:16] And wow. I was just so fast and very expensive to use. And the delay pinging another machine. In other words, sending a packet from my machine to another machine on the network. And then having that packet returned to me was anywhere from if it was like lightning fast, 10 milliseconds, and more likely it was 30, 40, 50, even a hundred milliseconds on the same day.

    [00:45:44] Nowadays, if you're [email protected], you are probably seen speeds that just blow away what I was using back then because things have just gotten so much faster. You've probably seen a few milliseconds in speed round trip, speed time again, depending on how good your link is. And then the fourth one you have to pay attention to is.

    [00:46:11] And jitter is where you are seeing inconsistent speeds in those round trip times. And that's going to affect live stuff, particularly live audio, which we'll notice a lot to that. Hey, the audio is just terrible. It's dropping out at me. Maybe sounds digitized. Usually. Parts dropout gamers care a lot about the jitter because that's going to affect their game and how they play their game.

    [00:46:42] So I just ran it here on my studio computer. Now we have fiber optics. We have a business line that goes directly to Comcast backbone and I'm seeing. From where I am to a server that's about 90 miles away, I would say my ping time round trip is three milliseconds. It's just, I'm still blown away by that.

    [00:47:08] Cause I remember using dial up modems that were 110 bits per second, 110. And that was just absolutely amazing. And then 300, can you believers? 300 bod and it's changed a lot, right? So three milliseconds round trip time for me. And I'm trying to brag or make you feel bad. I'm just telling you what it can be.

    [00:47:30] My download speed is 720. Megabits per second. And that's because right now we're downloading a few different things and my upload speed is a gigabit per second. So you can see in a commercial link, typically your download and your upload speeds are the same. It is not, it is in 10% obviously is exactly the same.

    [00:47:54] So those are the numbers you should look at. I don't see on my results. The jitter, maybe there's not reporting that anymore, or maybe they only reported on bad lines. I'm not sure, but again, speed test.net. So they have released this [email protected], some stats on the satellite companies, because our friends over at startling, that's Elon Musk's company think Tesla and SpaceX, they are showing.

    [00:48:28] Amazing download speeds. They're showing 97 megabits a second download. Now that doesn't of course, I really approach the gigabit that I'm seeing, but this is from a satellite. It's just amazing. And they're going to see if more now all fixed all speeds of everyone. One in the United States that has gone to speed test.net and ran speed tests.

    [00:48:56] All speeds averaged out in the United States come to 115 megabits. So Starlink is almost as fast as the average broadband connection in the United States. Now here's a little, here's where they really shine to upload speed of about 14 megabits a second. So that's not bad that still fits within our model that we talked about latency.

    [00:49:24] 45 milliseconds. Now compare that with what I had, which was what three milliseconds it's slow, but it's again, remember it's a satellite. So it's going from the earth station while it's actually going from your computer to their satellite dish at your location is going up to the satellite is coming back down to an earth station is picking up the signals from the satellite, and then it's going to the server.

    [00:49:53] So 45 milliseconds is pretty good. I want to put that in perspective, though. The two biggest competitors right now, satellite internet are Hughes net and ViaSat Hughes net. This is again, according to speed, test.net. Download speed is averaging a little less than 20 megabits a second. So it's 20% of the speed of startling.

    [00:50:20] Yeah, pretty bad. A and star links latency. Remember, and this matters a lot. If you're trying to do live video or you're trying to run your phone over it, latency is 724 milliseconds. So that's three quarters of a second. From the time a packet goes out until it comes back. So that will affect any sort of phone calls that you're making on HughesNet and then ViaSat none, much better download speed of 18 megabits a second, which is worse, but the upload is slightly better than HughesNet and their latency is slightly.

    [00:50:56] What I'm saying is Starlink is really starting to shine. And Elon Musk is saying they are going to be even better. They're going to be much better. Give them a little bit of time. The reason that Charlene has the faster latency. Much, much faster latency than our friends at HughesNet or ViaSat is that they have low earth orbit satellite.

    [00:51:23] So they are sitting up there. They do have some drag from our atmosphere, so they will come down. There's things in place to take care of all of that sort of stuff. But Starlink it's going to be available pretty much everywhere. The country. India is very excited about this because they've had real problems with the internet in some of the rural areas.

    [00:51:48] But Hey, if you are out in the middle of nowhere in the United States, there is hope check out, Starlink online, lots of great stuff. Hey, stick around. We will be right back. You're listening to Craig Peterson.

    [00:52:05] The hackers are still going after with ransomware, they're still doing just blanket attacks. They're still doing massive fishing, but they have glommed on to something that is being much more effective. That's what we're going to be talking about.

    [00:52:21] This is a huge problem. We have seen some very high profile ransomware lately. Think of what happened with colonial pipeline, the whole solar winds attack, and much more the bad guys are trying to figure out a way to more inexpensive. Ransom money from us to more inexpensively, get all of our confidential information.

    [00:52:48] I have a client that before he was my client, all of his data was stolen and they run right to the Chinese. I have another client who's operating account was completely emptied. And the problem in both of these cases, Was really the client not doing what they should be doing, but supply chain problems, supply chains, the software, you have the hardware you have that you're relying on it.

    [00:53:19] One of the major types of businesses that are being attacked right now are our managed security services, company, security researchers who are trying to do, with all the effort they can maybe keep ourselves safe. But they're not doing what they should be doing. You've heard me complain for many years about programmers.

    [00:53:43] I'm saying that in air quotes, people who have learned how to do Microsoft C sharp or visual basic, whatever it might be. At a very high level in share. Yeah, they can put stuff together. It reminds me of when the spreadsheets first started hitting the boardrooms, all of a sudden, business people, managers all the way on up through the board were saying I don't need the it department anymore.

    [00:54:09] In order to get these numbers, I can just gather them in myself and put together a spreadsheet. I'll be safe. Everything will be great. I'm going to get that information now instead of having to wait for it, to get some programmers involved and get it done. The problem in all of these cases is exactly this.

    [00:54:29] These are non-professionals that are trying to do the job. Those spreadsheets, many of them had bad data on them. They compiled into even worse data because there were in many cases. Problems with the spreadsheet. I remember when I was a professor at Pepperdine University and I was teaching management information systems out there in the west coast and beautiful campus, by the way, if you've never been there out at Pepperdine, right on the coast.

    [00:54:59] But when I was working with those students, who were, it was his MIS 4 22 last year undergraduate. I ended up emphasizing spreadsheet. Because I realized most of them didn't really know how to do it. Yeah. Okay. They could go ahead and put a little thing in there that says, add up all of these columns and this row and multiply by that and cut out.

    [00:55:25] I've got a number coming out, but is that number correct? It's like a county. And that's why accountants use double entries in the accounting systems to make sure everything zeroes out. Make sure everything is correct. And by having someone who's a manager using this spreadsheet, you might get some great information and might get it quickly.

    [00:55:46] It might be absolutely correct, but it's very possible that it won't be. And from my experience and programmers are the worst of the worst, because many of them started when they were kids, very bright kids who were working on stuff and hacking it things. That's where the term hacker comes from.

    [00:56:05] Hacker wasn't necessarily a bad thing. They certainly. Bad guys. They were just hacking it. The computer's trying to figure out how to program, and if something went wrong, they would hack at the code a little bit more to try and fix it and figure it out. Non-professional they were just hacking that stuff.

    [00:56:23] And that's what we called them hackers. And so it was a derogatory term for someone that didn't really know what they were doing, but they were hacking their programming or hacking it. Some other part of it. Versus having people who are actually trained and experienced Microsoft got sued because of how bad windows millennial edition was and windows Vista.

    [00:56:49] And they found that the majority of the code had been written by interns, by kids, right out of school without the experience. What does that mean? Why am I really bashing the younger generations? It has to do with the ability to foresee problems and the best way to be able to foresee a problem is to have seen it before, for instance, that you've gotta be careful when you're allocating right.

    [00:57:15] And that it's not necessarily going to be cleared properly, or if at all, and that the return points can be changed in programs. That's one of the things that hackers do most nowadays. So if you have software that's written by people that don't realize all of the implications of what they're doing, you could be in trouble.

    [00:57:38] I like to use the analogy of a car. Back in the day, many of us are turned a wrench and we tinkered with the older cars. We had a whole lot of fun with them trying to figure out how can I improve this? And we'll do this to the carb and we'll change this and look at this airflow problem, pretty basic stuff.

    [00:57:56] But today, what we're dealing with is a car that is a whole bunch of major components. We went to replace an air intake because of a bad sensor in a Ford Crown Vic. And it was one of the last model years. And back in the day, you could pretty easily fix that. You just buy the little sensor and put it in there.

    [00:58:20] And you're all set. We had to buy the whole component, which included the air intake, manifold all the way on back to the sensor and everything that was behind it. It was absolutely crazy and cost a lot of money. So think of someone who is trying to build a car today, we might equate this to you by a transmitter.

    [00:58:43] You buy an engine, hopefully they fit together. If all right, have you ever tried to match a transmission to an engine and it's not right. Do you have to get a converter or make a converter that goes in the middle, or do you have to drill it out in order to make it Mount properly? All of those sorts of problems.

    [00:59:00] And then you've got all of the other components in the vehicle as well that are mix and match. That's what programmers are doing nowadays. Nowadays, a programmer grabs this library that does something. So, for instance, Apple has a library you can use that identifies faces, but you don't know how it works.

    [00:59:22] You don't know that transmission, how it works. Is it really going to work for you? It wasn't smart to combine that 600 horsepower engine with a Vega Chevy Vega transmission. For those of you old enough to remember what that is. But it didn't stop you from doing that either. And that's what we're seeing.

    [00:59:42] That's what these supply chain attacks are all based on that. So much software is written by people that have not had the experience to think through the potential problems. And Microsoft is to blame for making it really easy for anyone to write a program, just like you could blame VisiCalc back in the day for making it really easy for anyone to make a spread.

    [01:00:07] But those spreadsheets weren't accurate. The software that we're getting from our suppliers, which include Microsoft. This latest, huge hack came right through Microsoft exchange. It was a zero day bug. The same types of problems that we've had with some of the other software that's out there. Think about how we got the solar winds attack.

    [01:00:31] Think about some of these other ones that we've had that are just absolutely massive. It can kill us and kill us in a very big, when we're talking of course, about all of our systems and software. Hey, I want to remind you guys, just spend a couple of minutes. If you would go online, Craig peterson.com.

    [01:00:51] You're going to get the sort of thing. Last weekend. I sent out a video that I chaired with some friends, and I shared it with anybody on my list. Last weekend, it was just part of the newsletter on VPNs, who you can tell. Who you can't trust and the best ways and times to use a VPN. All right. Stick around.

    [01:01:12] We'll be right back. You're listening to Craig Peterson [email protected].

    [01:01:20] So now, a little bit about what supply chain attacks are. We're going to get into that a little bit more now, what can you do about it? And this European union-funded study that came in the wake of these two major cyber attacks.

    [01:01:36] The European Union has now forecasted that there's going to be four times more software supply chain attacks in 2021 than there were in 2010. That, my friend, is a very big deal. These cybercriminals are now shifting to larger cross border targets.

    [01:01:59] This is just an amazing report. You can look at it. It's called threat landscape for supply chain attacks. And they looked at 24 supply chain incidents that have occurred between January 20, 20 and July, 2021. The basics here are a supply chain attack is where a software provider or some sort of a trusted provider is hacked.

    [01:02:25] Usually they're are hacked in a way that they don't realize they've been hacked and then they pass off. The hacked software to you. I can remember a Microsoft product back when they used to ship them on DVDs or CDs. And we got that thing. One of the first steps was always to scan it for viruses, and we did.

    [01:02:48] And sure enough, Microsoft was shipping out software with a virus on it all. The same sorts of things have been happening with thumb drives some of these ones, particularly cheap ones that you buy online often have built right into them. Malware. Now with some of the reason for the malware is legitimately purposeful.

    [01:03:12] Okay. What they're trying to do is get you to have their little ransomware work for them so they can make some money off of you. In other cases, you have a thumb drive that a friend gave to you, and you're now using a little thumb drive and guests. Yeah, you are a little thumb drive has some nastiness on it.

    [01:03:32] Same, thing's true with Microsoft word documents that might have macro viruses, if you will, that are built into them. These little Trojans do the same thing with the Excel spreadsheets and on. But what they're finding right now is that these hackers are trying to get to the companies that provide services for the bigger companies.

    [01:03:55] And that's where it can hurt you and hurt you in a big way. I was just talking about how many programmers just aren't terribly professional. And some of that has to do with their lack of experience and those programmers might be using a library. So, for instance, get hub, which I use, and it's very common to be used out there online.

    [01:04:18] It has all kinds of source code called open-source code. So you can use it. You can model. That some of that software has been infected. And then there are people who are using languages that are nice and simple, like Python and others. And you write in this scripting language and pull in libraries that come from public sources that do things for you.

    [01:04:41] So they might do something like display something on this screen. They might go out and grab something from a URL online or connect to a database. And what the bad guys have found out is we're not, double-checking all of the sources of all of this software, and that is causing some huge security holes.

    [01:05:04] And what ends up happening is companies like solar wind are using some of this soft. And they then might be including it in the software they're providing you now, in the case of solar winds, it's a little bit different, but it's the same concept. Solar wind software was being used by a large number of companies in the U S.

    [01:05:29] Agencies were using solar wind software. And so we're regular old, small businesses because what happens is you hire a managed services provider and they don't have time to look at all of your computers all of the time. So they have software that they're using called a Ryan in this particular case. And I'll Ryan is installed on all of your computers.

    [01:05:55] So probably unbeknownst to you there's software on your computers. That is not being written by that managed services provider. But in this case was being written and provided by solar winds. Solar winds got hacked and the hackers put into solar wind software. Code that would eventually end up on your computer and your computer getting hacked.

    [01:06:18] So you just see how complicated this gets, right? You guys are the best and brightest, but you've probably got your eyes spinning a little bit here because we're talking about multiple layers of like again, direction, right? So these attacks, which mode, it looks like it began maybe in March 20, 20.

    [01:06:38] We're only detected in December last year, and they have been linked to this Russian organization called cozy bear, but we'll see what happens. We've got the more recent ones, which is the reveal. Ransomware got gang, this R E V I L reveal. And they exploited vulnerability. In Casias VSA, which again is another management platform that's used by many of these companies out there that are providing managed services.

    [01:07:09] Now I've got to say by means of full exposure here. We had to use both of these pieces of software before. And when we looked into them, we found that they. Insecure. In fact, it sounds like some of these companies had been warned by their own employees, that the entire architecture of their software was insecure.

    [01:07:33] Okay. So we ditched them all. We're using Cisco's software, they're advanced malware protection. The real high-end firewalls with special software, the backend that's running. So we're not getting into all of these crazy acronyms and names right now. So just so you know, that's what we use. That's what we use for our customers.

    [01:07:56] I even have that at my house. Okay. So a little bit more expensive, but it's a lot cheaper than having to hire a whole bunch of it. People to keep track of everything else now, because say. I had gotten, I had this ransomware that was distributed to Casa, his client. And potentially to kiss his clients, and this reveal gang demanded a $70 million ransomware payment say is denied that it paid it.

    [01:08:28] They may or may not have paid it. You might remember in the Trump years, they said, absolutely. Don't pay ransoms, or we may come after you because that is illegal to pay a ransom by. Because you are supporting a terrorist organization. So you gotta be careful with stuff like that. Don't pay ransoms, right?

    [01:08:48] Because it also tells them that you are a company that pays ransoms. So guess who they're going to come after again, you, because they know you'll pay. So a lot of incidents, I'm looking at a timeline of the attacks that were studied in this report coming out of the European. Yeah. And it is amazing here.

    [01:09:06] The unit max beans. That's one of those libraries. I was talking about the able desktop as Sydney. Was Vera excelling on VC or excuse me, VG, solar winds, big knocks, Mon pass Ukraine, SEI, click studios cast private stock investment manager goes on Fujitsu ledger. So this is a huge problem. And this is the sad part.

    [01:09:34] European union's predicting. It'll go up four fold this year. So what do you do? You have to audit your vendors. And that usually means you have to have an agreement plays. They accept the responsibility if you are hacked. So keep it up. Yeah. Let me know if you'd like more help with that. You can always email me M [email protected].

    [01:09:59] I think I got a couple of those contracts kicking around these vendor contracts. If you'd, I'll send one to, but you have to reach out to me. M E. At Craig peterson.com. All right, stick around. We've got one more segment today, and I want to make sure you spend a couple of minutes online. Craig peterson.com.

    [01:10:20] And go ahead and sign up. Sign up for my weekly newsletter.

    [01:10:28] We're going to do a little bit of wrap up right now, including talking about I message some of the changes that have come in Apple's messenger application, that many people are saying it shocking, and you should stop using it right now.

    [01:10:44] This is an article in Forbes by Zach Dorfman, where he's talking about why you should stop using iMessage after what he's calling the shock iPhone app.

    [01:10:58] Has had a number of major problems here recently that have been in the news. Of course they have about half of the smartphones in the country, right there. But things have become a little worse for apple here recently. And what we're worried about is, for instance, this whole Pegasus that we talked about a couple of weeks ago, where it is, what's called a zero-click piece of metal.

    [01:11:25] Where they can send you a text message, even if they're not a friend of yours and take over your phone. And we've seen things like that before. In fact, I think it was in Saudi Arabia, where was it? The crown prince received a video from somebody. He played it, and it exploited some vulnerabilities in the video player and allowed them to have full access to his phone.

    [01:11:49] And don't remember all of the details, but that part, I do remember. So the big question is, have all of these major security issues being fixed by apple is I messaged say for not, apple is saying it is encrypted end to end. They don't keep messages. There's some question about that because of a major incident back in 2018, where Apple was going to make sure it encrypted all of your backups and then.

    [01:12:18] FBI apparently spoke to apple and got them to change their opinion on the whole thing, which is another interesting problem. Isn't it. So what do you do, what do you do with that? And what do you do? Very good question. Earlier this year we had WhatsApp make a major change. They had course also said we've got end to end encryption with WhatsApp or wonderful.

    [01:12:41] And then people really questioned it because it was now owned by our friends over at Facebook. Is there privacy thereon WhatsApp? Is it legitimate? Is it just a bad PR move? What's going on WhatsApp, by the way, with 2 billion users worldwide and WhatsApp Facebook said, Hey, listen, we're gonna start giving you ads.

    [01:13:05] And basically people were worried about them examining the content of their messages in order to give them targeted ads, et cetera. So now apples just confirmed what Forbes is calling the most shocking and controversial update in the platforms. History. And here's what's going on. Pegasus, of course, as I mentioned, this click attack, Apple's got his new update now, right?

    [01:13:32] That is using machine learning. In order to see if a minor child might be sending a picture pornographic or otherwise they should not be sending or receiving. And we also have built into it. Now, this child sexual abuse. Check some set of people. That looks on your devices to see, do you have any photos that match, just check some part of the problem with this isn't that I'm not worried about these children that are being exploited.

    [01:14:06] Cause I am, I'm absolutely against that. But the bigger question here is, okay, so what's next is apple going to capitulate to the government and let them know if you have a certain picture of something rather the government doesn't like, where is this going to end? So in other words, Apple's phones being a lockbox.

    [01:14:30] The Apple iPad is being a lockbox is really. No longer going to be true. It is no longer going to be that encrypted lockbox that has been promised to us the electronic frontier foundation. As a little comment here, they say Apple's compromise on end to end encryption may appease government agencies in the U S and abroad, but it is a shocking about phase four users who have relied on the company's leadership in privacy.

    [01:15:00] And security, which is absolutely true. Now there's not much controversy, frankly, about limiting the spread of child sexual abuse material, but where we go on from there, that's where it starts getting a little more questioning here. Here's a, this is a Jake Moore over at east set. You said the initial.

    [01:15:21] Potential concern is that this new technology could drive CSM further underground. See Sam being this child abuse material, but at least it is likely to catch those at the early stages of their offending. The secondary concern, however, is that it highlights the power in which apple holds with the ability to read what is on devices and match any images to those known on a database.

    [01:15:47] This intrusion is grown with intensity and often packaged in a way that is for the greater good, right? Isn't that always the case. So we're doing it for the children. I talked about this extensively earlier. You can find it in my podcast, go to Craig peterson.com/podcast. Right now you can listen to it there.

    [01:16:08] Take a look in your emails from the newsletter. Pretty good about trying to send those out the last few weeks. I haven't been that great because of issues here, family issues and others. So it's been a little tough. So I apologize for that, but we all want to see technology develop. That's going to help tackle abuse.

    [01:16:27] It's going to stop the real bad guys that are out there. But what happens when China says we want access to this? We want to know when there's any pictures of a weaker symbol, for instance, or something else. What's Apple going to do they get, they can no longer say, oh, that's not taught. We don't have that technology.

    [01:16:45] There's nothing we can do. Just like Apple has done with the iPhones in the past, saying we don't have a back door. There is no backdoor key. We can't crack into that. That doesn't stand up when they say, okay, China comes to them or Iran or Saudi Arabia, or you name the country and says, Hey, we don't want people to see these particular messages.

    [01:17:08] Absolutely amazing. So timing on this dreadful. Okay. Part of iOS 15, apparently Pegasus raised two serious concerns that Apple's ecosystem, including I message has still got some dangerous vulnerabilities and that Apple's opaque communications in the kind of a black box security really were an unhealthy man.

    [01:17:32] Now Apple has in the last few months, opened up that black box, a bit to security researchers, but it's still not that open. Now we add a third, which is what happens on your iPhone. No longer stays on your iPhone. Now I get asked by a lot of people. What should I do? Where should I go? What's a safe place. I still say Apple's your best bet in general, but the next problem is so what's next after that?

    [01:18:02] I can still say Android sure is not the platform you want to use. The guidance. Google has snuck stuff in time and time. Again, even going so far as to sneak a microphone. Into the nest thermostats without telling a soul and without it being on any of the datasheets. So Google's definitely not to be trusted.

    [01:18:24] There are other distributions for certain phones that are based on various types of Unix. They may be good. That may not be good. One of the companies I really liked a few years ago, discontinued it's secure and it was based on Android, but they were cleaning it up a little bit. So we'll see. These attacks that came against apple to give them some credit.

    [01:18:47] They were very sophisticated. They cost millions of dollars to develop. They didn't last long because apple released patches. Once I found out what had happened, and they're typically used to target an individual, think of that journalist. Who went to the Saudi embassy. I'm trying to remember his name.

    [01:19:07] Cause saggy, I think was his name, but this is a real problem. Okay. We think by the way that it was fixed in 1471, but these new security child abuse things are being added in the next release. So I'm keeping an eye out. I'll keep an eye on all of this. So keep listening and not I'll let you know how things go.

    [01:19:31] Apple is likely done veil the next generation I phones in September. So we've got trend force out there, outlining what it expects for the next iPhone. Now I have an iPhone. And it is about to go out of support. As soon as this new phone comes out, my eight is going to be too old to get support, but it's going to be called the iPhone 13, which is going to be formally announced by apple.

    [01:19:59] So the exterior design, I'm looking at a picture of it right now. That little notch is smaller than before. They're also using some smaller silicone smaller chips inside so they can put an even bigger battery. These new iPhones are going to have support for 5g millimeter wave. And that's going to be available for sale in more countries after the release of the iPhone 13, because it's covering more bands, which is a really good thing.

    [01:20:30] The circuit boards are moving from the stuff that we've seen for decades. These rigid printed circuit boards to new design that has a flex. Printed circuit board, which is quite nice because if you've ever been to phone before, you know how painful that can end up being, and they're saying this should have the increased battery because of it.

    [01:20:53] There's some more stuff that should be in that phone that I've read a few articles about new features that'll be in there. China, by the way, is decreasing in its purchases of iPhone. The revenue went from 19% in 2017, down to 16 in 2020 coming from China, but they still are big players, 16.7% of global smartphone marketplace.

    [01:21:20] They're also expecting by the way that these new iPhones are going to have the new processor in them as well, the a 15, and also there's going to be brand new. Mac book's coming out too. That should have some neat stuff in them. By the way, the number one app this last year was Tik TOK. It surged from fourth place to first place, knocking Facebook out of the top spot.

    [01:21:48] But the top five is made up of the main Facebook apps. Yeah. WhatsApp, Instagram, and messenger. And then of course would tick talk at the top. And then the next two places go to Snapchat and telegram with another short video app from China in eighth spot. So Pinterest and Twitter, by the way. The top 10.

    [01:22:10] Hey everybody. Thanks for being with me today. Make sure you keep up on it. No, the latest you can help your friends. You can help your family. You guys are the best and brightest. You guys are the guys that people rely on for technology. I know it because you tell them. Any questions, comments, just email me M [email protected] and visit the website.

    [01:22:34] Listen to the podcast and please subscribe. Take care everybody. Bye-bye.

    1 hr 23 min
  • Are You One of More Than 700,000 On U.S. "Watch-Lists"?

    Are You One of More Than 700,000 On U.S. "Watch-Lists"?

    Craig Peterson: You've heard about the no-fly list, right? Yeah. How about the terrorist and other watch lists? It's impossible to get your name off, even when there was no reason to be there in the first place?

    Well, I got some news.

    The Department of Homeland security has been criticized for many things over the years. One of the things that they have been criticized quite a bit about is this watch list that they maintain. They have a watch list for no-fly. People get put on that watch list. It was initially intended to be, we know this guy's a terrorist, so we're going to put them on, right.

    [00:00:45] It's not always the way it goes. It starts out almost innocuous, and before you know it, there are all kinds of people getting caught in this big, big net.

    [00:00:55] That's what's been happening lately. But, unfortunately, it's going to worsen because the Department of Homeland security has decided to hire regular old companies to help develop this no-fly list and this terrorist watch list.

    [00:01:14]Apparently, these companies will be looking through all kinds of public data, maybe some private data, social media to provide information for this new domestic terror watch list.

    [00:01:28] So you look at that and say, okay, I can see that.

    [00:01:32] We've talked before the problem, man, 20 years ago. I think I was talking about these data aggregators and the issues they create. They're taking public records; they're putting them all together. They're figuring out how it all meshes together, and they come up with a pretty accurate picture of who you are.

    [00:01:53] Now, I've got to say when I've had them on my show here before, I was talking to them and said, okay, I want to look up my own records. So I looked them up on their platforms. I did not see a single one that was more than about 30% correct about me.

    This was again, some years ago. I think it's probably been almost a decade since I last spoke with the data aggregators. They really are trying to blend into the background,

    [00:02:21] Nowadays, this data that's put together by these artificial intelligence systems is not necessarily that accurate, and that gets to be a real problem.

    [00:02:33] So who is DHS gonna hire? Well, from the description reported here by the Conservative Tree House, it is going to be big tech, specifically, Google, Facebook, YouTube, Instagram, Snapchat, Twitter, and more.

    [00:02:54] The DHS will put them under contracts to hire and organize internal monitoring teams to assist the government by sending information on citizens they deem dangerous. Again, what could go wrong?

    [00:03:10] Our government is not allowed to spy on us. How many times have we talked about this? You have, of course, the five eyes, and then they added more and more. These are governments that spy on each other's citizens for each other.

    [00:03:26] So, for instance, the US cannot spy on US citizens. So we have an arrangement with the United Kingdom, New Zealand, Australia, Canada to spy on the US citizens for us that makes sense to you.

    [00:03:44] Can you believe that?

    [00:03:46]We spy on their citizens for them, and they spy on our citizens for us. All is good.

    [00:03:57]What's happening here is The Department of Homeland security realizes it cannot spy on us directly. This is what they've been doing for a very long time, they go to the data aggregators, and they pull up the data that they want.

    [00:04:12]They want to see if this guy is maybe selling illicit drugs, and they pull up public records.

    [00:04:19]What cars does he have? How many homes do they own? Who's he dating? Has she all of a sudden been buying diamonds and mink coats? What's going on here?

    [00:04:31]Now we're seeing that the US intelligence apparatus. It's really going live quickly to put together lists of Americans who could be potential threats to the government and need to be watched.

    [00:04:49] Now it's all well and good. It's just like president Biden this week saying, Oh, we're going to have these red flag laws. We're going to stop the sale of certain types of firearms and things. It all sounds good.

    [00:05:04] The reality is we have known about some of these people before, right? So this is all just a red herring that the federal government is doing right now because the real problem is these terrorists, the domestic and otherwise that have shot up schools, have almost always been reported to law enforcement as dangerous people. Some have even been on lists that say they cannot buy firearms, yet they get guns. Bad guys.

    [00:05:39] It's like here in the US. Where does our fentanyl come from? We're not making a domestically. Our fentanyl is coming from China often through Mexico. It is killing people here in the US.

    [00:05:54]The whole George Floyd incident, and what's happening with fentanyl in his system, right. The question is, did the police operate properly? What killed him? According to the coroner's report? It was the fentanyl that killed him.

    [00:06:09]One way or the other that fentanyl got here from China and is being used on the streets, and people are dying from it. Fentanyl's illegal. How could they possibly get it?

    [00:06:24] It's illegal for a felon to be in possession of a firearm. So how did a criminal get the gun?

    [00:06:32] The police were warned about people in San Bernardino, California. They were warned. The people in that business told the police. We were calling. We're apprehensive about this guy, and nothing happened.

    [00:06:48] So now what are we going to do? We're going to cast an even wider net. We cannot take care of the reports that come in right now. We're going to get even more reports, and they're going to be coming from these AI systems. Again, what could possibly go wrong here? It's absolutely incredible.

    [00:07:12]They look at these reports. They try and determine these are actionable, the FBI or other law enforcement agencies. They've been deciding no, it's not actionable. They've been right sometimes, and they've been wrong other times. This is a real problem.

    [00:07:29]What shocked me is NBC news with Andrea Mitchell, NBC news. Not a centrist news organization, very far left. NBC News is even reporting on this. They realize the consequences. Here's a quote from NBC. "DHS planning to expand relationships with companies that scour public data for intelligent and to better harness the vast trove of data it already collects on Americans." "The department is also contemplating changes to its terrorist. Watch listing process." Absolutely amazing.

    [00:08:16] Two senior Biden administrative administration officials told NBC News that Homeland security whose intelligence division did not publish a warning of potential violence before the January sixth Capitol riots are seeking to improve its ability to collect and analyze data about domestic terrorism, including the sorts of public social media posts that threatened a potential attack on the Capitol."

    [00:08:44] "DHS is expanding its relationships with other companies that scour public data for intelligence. One of the senior officials said, and also to better harness the vast trove of data it already collects on Americans, including travel and commercial data through customs and border protection, immigration, customs enforcement, the coast guard, secret service, and other DHS components". There you go from NBC news.

    [00:09:11] So remind yourself what the FBI contractors with access to the NSA database already did in their quest for political opposition, research, and surveillance, and then get everything we were just talking about.

    [00:09:28]The director of national intelligence declassified a FISA judge's ruling. This is judge James Boasberg, 2018 ruling, where the FBI conducted tens of thousands of unauthorized NSA database queries. Do you remember that story? Very, very big deal. This judge is obviously passing these things out like candy and the FBI misusing its power and authority. Again, what could possibly go wrong?

    [00:10:00]By the way, President Obama apparently has been telling us that we should use the no-fly list to keep people from owning guns.

    [00:10:08]There's already a database maintained by the FBI. So this whole thing is, as I said, a red herring. Things are going to get really bad if law enforcement does this. Frankly, they're going to do it. There are no two ways about it.

    [00:10:25]We have to be more careful about keeping our information, our data private.

    [00:10:32] That's what my whole course: "Improving Your Windows Privacy and Security," is all about. Locking it down because the way Microsoft ships windows and how it installs and configures itself by default does not keep your data private. That's a problem. So that's what we're going through.

    [00:10:54]Remind yourself of this and just keep chanting, "nothing bad could happen here," right? Ah, the joys of all of these computers and databases and the way they work nowadays.

    [00:11:07] By the way, if your information is out there at all, even if you use fake names and numbers and addresses and things like I do when it's not required. Right.

    [00:11:20] I don't lie to the bank. I don't lie to the IRS. Nobody else needs to know the truth. Even if you have been, trying to keep it private. Good chance that they know who you are and where you are. Crazy. Crazy.

    [00:11:36] Hey, visit me online. Craig peterson.com. Make sure you subscribe to my weekly newsletter.

    12 min
  • Have Your Healthcare Records Have Been Stolen?

    Have Your Healthcare Records Have Been Stolen? What can you do about it?

    Craig Peterson: We're talking about ransomware and what's the Conti gang and others doing nowadays.

    Hello everybody. Craig Peterson here. Thanks for joining us today. I appreciate you spending a little bit of time, and I enjoy helping bring you guys up to speed on what is happening. There's just so much of it. You wouldn't believe what I have to filter out.

    [00:00:23] The Conti gang has been very successful. Still, their money started to dry up recently when people figured out if they had a decent backup, they could just go ahead and ignore the ransom demand. So instead of paying that ransom, just go ahead and restore from backup. So they had to do something different.

    [00:00:47]What the Conti gang did, as well as pretty much everybody else in the ransomware business, is okay; what we're going to do now is we're going to find all of the other machines we can find on the network. Then we're even going to have real people get onto these computers remotely that they've compromised and had a poke about. See if there is patient healthcare information? Are the bank account numbers on this machine? Are there plans on what to do? Where to go? What's the business going to do next week?

    [00:01:25] But mainly stuff they can sell right away. If you take credit cards, you know that the payment card industry is all over you if credit card numbers are stolen. Those are nowhere near as valuable as patient health record information. As I mentioned a little bit earlier, we're talking about 2000% more than 20 times more value to your healthcare records.

    [00:01:55]Now what happens is Conti gang says, "Oh, looky. We've got patient information here. It has names, addresses, social security numbers. It has birth dates. It has diagnostic information," and then they upload it.

    [00:02:11]We had something like this happened with one of our clients. It wasn't a ransomware attack; ultimately, it may have been. They came in through an unsecured VPN and that they would not let us shut down.

    [00:02:25]We told them to shut it down, and they didn't. In come the bad guys, they actually were coming up via Mexico in this case. Although I doubt they were located in Mexico.

    They took that VPN connection; they used it to get on to the computer and found something interesting. So they started to exfiltrate the data. In other words, Take that data and send it out.

    [00:02:52] That's precisely what the Conti gang and others are doing now.

    [00:02:55]We noticed, wait a minute, this is all automatic. Why is data going out from this host at that speed to this address at this time of day? It wasn't a typical pattern. So our hardware-software that's sitting there in their network automatically shut it down hard.

    [00:03:19]They were able to exfiltrate just a tad bit of data, and then it was stopped instantly.

    [00:03:26] The Conti gang gets your data, and then they try and say pay up from an extortion standpoint. Instead of just holding your data ransom, they're extorting you. Saying, if you do not pay us, we will release this data.

    [00:03:45]The Conti ransomware gang has its own website out there. It's called a leak site. There are many of them out there.

    [00:03:53]I'm not going to give you the URL; it's right there. There's their logo. Conti gang has a logo, and it says Conti news. It's talking about how you can make your payments to them and what data was released and that this person paid up, but it was too late. We don't have the data anymore, which means it was released and too bad. So sad.

    [00:04:18] I wouldn't want to be you.

    [00:04:19] Here's another ransomware gang, the Avedon ransomware gang. So again, they had stolen personal information. They had health information, and they had the ransom side and the extortion side built into it. This was about an attack on the Capitol medical center in Olympia, Washington.

    [00:04:42]They have leaked some of it they're threatening to reveal even more. If Washington Olympia capital medical center doesn't pay up.

    [00:04:52] First of all, ransomware results in data exfiltration 70% of the time now. In other words, 70% of the time, your data is stolen before the file encryption.

    Pretty bad. Pretty bad.

    [00:05:08]Things can get particularly harmful because these ransomware attacks are a growing concern. They're disrupting patient care and healthcare, right?

    [00:05:17] Disabling critical systems because they have been even holding ransom some of the diagnostic equipment.

    [00:05:25] MRI machines that were connected to the network were running Windows. So who would use Windows in the machine that's healthcare critical?

    [00:05:36] Obviously interrupt revenue flow, and they had to now go get involved with real expensive remedies. So it really puts him in a horrible spot, very bad.

    [00:05:47]We've had almost double the number of healthcare institutions attacked this year versus last year.

    [00:05:53] I'm not going to go through all of these things here. I explained the difference between some of these real sites and fake sites and how you can get access to it.

    [00:06:04]By the way, if you're interested, I did record this. I'd be glad to send it out to just let me know; just email [email protected], and I can send you some of this healthcare stuff, the slide deck, or whatever you might like.

    [00:06:16]Phishing campaigns, way up. You probably heard about that. I gave some examples of that emailing patient information without encrypting it.

    [00:06:25] Wireless infusion pumps that are, of course, compromised because they're running an operating system that hasn't been patched. Usually Windows. Think of that there are Windows in that infusion pump, but it could be a version of Linux. It's not fixed. It's crazy. Vital sign equipment. Oh my gosh.

    [00:06:46]We're also seeing that this patient health information being stolen now is being used to create fake insurance claims.

    [00:06:55]I was talking about how much this is worth, and it's worth a lot while this is one of the reasons it's worth a lot, your personal, private patient health information.

    [00:07:08] If you have a diagnosis and that diagnosis has been stolen, and then they can file a health insurance claim. Yeah. You see where I'm going with your information, as though you received some treatment or some care for the diagnosis in your healthcare records. It's just that simple.

    [00:07:33] Average cost of a data breach right now, by the way, if you are a regular business, it's $158 per record for non-healthcare, and it's $408 per record.

    [00:07:47] If you are in healthcare at all. That's a doctor's office. That's not just hospitals; it's anybody. And by the way, mobile breaches are massive 43% of healthcare organizations who reported a mobile breach said the mobile breach caused long lasting repercussions.

    [00:08:09] Now, think about this. If you're a patient. How well are your records protected? I can tell you based on what I've seen and talked with healthcare people, seeing statistics. They're not protected very well at all.

    [00:08:25]People will start going to jail over this. People in the healthcare industry, that is.

    9 min
  • Have Your Healthcare Records Have Been Stolen, too?

    Have Your Healthcare Records Have Been Stolen, too?

    Craig Peterson: We all have healthcare records, and they have some of our most personal information. That's what we're talking about today in follow-up to a webinar I did for the healthcare industry. So we're going to chat right now a little bit more about your privacy.

    Craig Peterson here.

    The actual hard stats on our healthcare records, a lot of them have been stolen. It's just crazy to think about because, in reality, we have had millions of records stolen, 300 million healthcare records stolen to be exact since 2015; that is pretty bad.

    [00:00:38] I'm looking at a chart right now that I showed to this healthcare industry group that is showing that the hacking event has almost doubled over the last three years, year to year, every year. So in 2018, 164 powerful hacks 2019, 312. That's a good double. 2020, 430, which isn't quite a double. So we are seeing a lot of data being stolen. But, of course, stolen data means misused data, which is a huge problem.

    [00:01:14] Now, in the healthcare industry, they've got a different problem. That is these HIPAA rules. Now HIPAA has been in place for quite a while. It's supposed to have been provided Portability of our records. Does anybody have any real luck with that? I know there are some I haven't.

    [00:01:30] Portability, I don't even know where my health records have ended up. Frankly, cause my doctor ended up closing up shop, and I just have no idea. But it's supposed to be Portability and privacy. Well, the most common violations of these HIPAA regulations revolve around professional hackers.

    [00:01:50] Then you've got business associate disclosure. Remember I mentioned that. The cloud is not an excuse for not protecting your data. You cannot hand that off to a third party. There are many more that I go into in the presentation.

    [00:02:05]Then here's the next thing I wanted to talk with you guys about that is the amount of ransomware out there. I'm going to have a little bit of a ransomware offering.

    [00:02:15]If you're not a subscriber right now, go to craig peterson.com/subscribe. You'll actually see it on the site @craigpeterson.com. If you scroll around, do a few things on the site, it should pop up automatically for you.

    [00:02:31]Now we're just talking about healthcare, and of course, this is every business and every person out there.

    [00:02:37] I talked about this Conti gang. I don't know if you've heard of them. C ON T I.

    [00:02:42] Now, remember what I've said before about ransomware. It used to be that you'd get ransomware. Your computer would now have its data encrypted. Then it would pop up this big red screen up that said you've got ransomware to get to all of your data back because what the ransomware did was encrypt it. You need to go to this website. You need to pay this amount of Bitcoin to this Bitcoin wallet, and off it goes, right? That's the idea.

    [00:03:13]According to the FBI, you'll get all your data back half the time. That's even if you pay the ransom. Now, too, the state department and the FBI might come after you if you pay a ransom -- because now you are supporting terrorist organizations, not just criminal enterprises. Huge deal.

    [00:03:34] Now, the other side of ransomware, and this is what just hit with a few different medical providers here. I talked about the Rehobeth McKinney Christian health center services, New Mexico because now it's much more advanced instead of just getting on your computer, encrypting your files, demanding a ransom to get the decryption key. They even pre-install the decryptor for you. Isn't that handy?

    What they are doing is they get onto a computer, and then they start East-West spreading. Now we've seen that for years.

    [00:04:08] I remember one of our clients, a car dealer, and this was five-seven years ago. They got some ransomware. Somebody clicked on something that they shouldn't have, and suddenly their machine gets ransomware. The device, of course, is hooked up to the network. It is, in fact, mounting drives from their file server. So his machine has access to all of these files. This guy was a manager over there at this car dealership. So he had access to all of the files.

    [00:04:47] Think about that for a minute. What his machine did back then is it said, Oh great, here are some network drives. So it started encrypting the S drive and the H drive, and the K drive. All of these different letters for these SMB mounted drives from the file server.

    [00:05:03]We were in there beforehand, and we installed our security stuff.

    [00:05:08]When his machine got this brand new strain of ransomware, and of course, he didn't want us looking at what was on his device. So we couldn't install all of the antivirus software because then we would have access to it.

    [00:05:22]We've got another client that's like that too, where the owner of the business doesn't want us installing software to really keep his machine clean.

    [00:05:29] I don't know why people do that. Are they just trying to play their cards close to the chest? Is that what they're trying to do? Are they looking at something they shouldn't be looking at at work?

    [00:05:43] Why do people do that? If you've got hints, let me know. Cause I would love to know [email protected]. Why do people do that?

    [00:05:52]Anyhow, his machine got the ransomware. It tried to start spreading to the file server. Now, we had special hardware and software installed. So we saw that spread start. We immediately shut down. It was all automatic. It was just shut down because our systems shut down his network port.

    [00:06:13] His computer had the ransomware. We were able to just go ahead and restore from backup. The bad guys know that if all they're doing is encrypting your data, then who cares? You restore from backup.

    [00:06:29] Now, hopefully, you're following a three-two-one backup scheme. Most places don't.

    [00:06:36] Hopefully, you're testing it as well. We try every backup that we make for our customers every day. About once a week, we will spin up the servers in a virtual environment and make sure that it can boot to know we have a good backup.

    I got to tell you guys that the backups are not working most of the time, and it gets to be a real problem.

    [00:06:57]What these guys have figured, including this Conti gang, is we're not going to be able to get as much money out of them by just encrypting their discs. We need to do something else. So while they're trying to spread East-West inside, what they're doing is okay, so they got a hold of this manager's computer. They start scanning for other computers and scanning for vulnerabilities scanning for ways it can gain access.

    [00:07:26] Unfortunately, the statistics show us that most of us have file shares turned on our windows machines.

    [00:07:34] That's one of the things I talk about in my Improving Windows Security course, what to do, how to do, how to turn that off because that is the second target of ransomware. Once it gets onto your machine.

    [00:07:49] You've got to turn off those file-sharing services.

    8 min
  • Are You Getting Dragged Into Dealing With Cybersecurity?

    Are You Getting Dragged Into Dealing With Cybersecurity?

    Craig Peterson: You probably know I've been doing cybersecurity now for 30 years in the online world. Yeah, that long. I'm afraid I have some confessions to make about our relationships here, cybersecurity people, and employees.

    I got pulled into this whole business of cybersecurity quite literally, kicking and screaming. I had already been involved in the development of the internet and internet protocols for a decade before. In fact, one of the contracts that I had was with a major manufacturer of computer systems.

    [00:00:39]What I did there was design for Unix systems a way to check for malware and manage them remotely. Yes, indeed, I made one of the first RMM systems, as we call them nowadays. We also tied that RMM system, of course, into Windows and a few other operating systems. Unix was where I was working at the time.

    [00:01:05] I am what they called an OG in the industry. My gosh, my first job with computer networks was back in 75. Believe it or not, a long time ago. Back then, of course, it was mainframe to mainframe basically and some of the basic protocols, the RJE, and stuff. I know I've got many older people who are listening saying, yeah, I remember that. It brings back memories.

    [00:01:32] In fact, I got a note just this week from a listener who was saying his first computer was a Sinclair. Do you remember those things? Oh my gosh. It brought back so many memories for us older guys. But it was just such a great little device with the keys and much different than I'd ever seen before. The XZ81. I just looked it up online so I can remember what the model number was. Timex made that. Suppose you can believe that too. It's just. Wow. It had a Z 80 CPU, which of course, was like an 8080, which was Intel's big chip at the time, running at 3.25 megahertz. Yes, indeed. Very cool. I love that computer anyways. I digress.

    [00:02:22]The whole industry at the time was non-existent, yeah. You had antivirus software. We started seeing that in the eighties. We had some terrible operating systems that many people were running like Windows, just absolutely horrific.

    [00:02:40] Remember windows three-point 11 and XP and millennial edition just some of the most terrible software ever. That's what happens when you have interns? A lot of the code came out in one of the lawsuits for one of these versions of Windows.

    [00:02:55]It was a different world, and I had to figure out what was going on because I had some servers that were Unix servers. This was the early nineties, and I hosted email for companies and websites and filtered things with some precursor to SpamAssassin. It was really something. I had some DECservers, Digital Equipment Corporation. Remember those guys, and suddenly, customers started calling me because the email wasn't working. It turned out it was working, but it was extremely slow, and I had to figure out why.

    [00:03:37]I telneted to my server. I got on, started poking around the servers.

    [00:03:43] I had a computer room and the first floor of the building I owned, and I was on the second floor. So off we go looking around, trying to figure out what is going on. It was me, actually. I said we, but it was really me. Cause I knew the most about this stuff.

    [00:03:59] These processes just continued to fork, and I was trying to figure out why it is creating all these new processes. What's going on? What has happened here? Back then, The internet was a much different place. We trusted everybody. We had fun online. We would spam people who broke our almost unwritten internet rules about being kind to other people. What spam was, where the whole term comes from is you would send the script from Monty Python spam and eggs, spam and ham spam, spam, spam routine.

    [00:04:37]You send it to somebody that was breaking these unwritten rules, like trying to sell something on the internet. Absolutely verboten. What a change to today.

    [00:04:48]I saw some of this stuff going on. I was trying to figure out what it was, but we trusted everybody. So my mail server, which was Sendmail, at the time. We still maintain some instances of Sendmail for customers that need that.

    [00:05:04] Nowadays. It's usually more something like postfix in the backend. You might have Zimbra or something out front, but postfix in the backend. We allowed anybody on the internet to get on to our mail server and fix some configuration problems. They didn't have full access to everything. Firewalls weren't, then, what they are today.

    [00:05:29] In fact, one of our engineers just had to run out to a client who did something we told them not to do. They were using the SonicWall firewall on their network, as well as they had our stuff. So we had an excellent Cisco firepower firewall sitting there. So then they have this SonicWall so that they're people, remotely could connect to the SonicWall firewall because it's good enough. SonicWall says it's compliant. So the SonicWall firewall was being used to scan the network and load stuff. Does that sound familiar? Much to our chagrin.

    [00:06:08] So he had to run out and take care of that today. It sounds like we might have to do a rip and replace over there restore from backups. You have no idea what these bad guys might've done. We've seen Chinese into these networks before, Chinese malware. It's not been very good.

    [00:06:23]Boy, am I wandering all over the place?

    [00:06:24]Back to this, we would allow people to get onto our network to fix things. If something was wrong, if we were misconfigured, they could help us and get on and do it because the Sendmail configuration was not for the faint-hearted.

    [00:06:42]In the days before Google, right? Eventually, we had Archie and Veronica, and Jughead. They did basic searches across FTP servers. That's my kicking and screaming story.

    [00:06:56]I was trying to run a business where we hosted email for companies, which we still do to this day, and where we had some, back then we didn't have websites. The web didn't come in into play until a couple of years later, but we did host FTP sites for businesses so that they could share files back and forth.

    [00:07:22]That's what I wanted to do. That was my business.

    [00:07:26] Later on, I ended up helping 80% of my clients find the other web hosts after these $8 Gator hosting things. We just got a call on that this week. Somebody who'd been a client of ours 20 years ago went with a guy that charges $5 a month for web hosting. They have personally identifiable information on that site if you can believe it. He was complaining because it wasn't working. He was getting a C-panel error anytime he went to the site. We said, Hey, listen, this problem is the guy that you're hosting from. We did a little research, and we checked the IP address and how many sites we're at that IP address. This guy that was charging them $5 a month had 150 different websites at that one IP address. Now that's not bad. He hosted all of these 150 at a site that charges the eight to $10 a month for Webhosting.

    [00:08:29] He had all of these sites on top of a server that already split up hundreds of ways. It's just amazing what people do.

    [00:08:38]Man alive.

    We got rid of 80% of those customers, the ones that wanted cheap, that's fine, get greedy, and see what happens to you. But, some of them still maintain a good relationship with us, so we help them out from time to time, right?

    [00:08:52] What am I going to do? So somebody calls me, I gotta help them. That's precisely what we do now with this malware problem.

    [00:09:01] What's going on here? We talked already about the Great Suspender and how Google has said, Hey, this now has malware in it, so we're removing it from your web browsers. That, to me, makes a ton of sense. Why not do that?

    [00:09:18]This is another example of what happened with SolarWinds. This is an example of a supply chain infection. What happened with that? Somebody bought Great Suspender from the developer and then added this basic malware to the Great Suspender. Just it's a terrible thing. Very surprising, but one of the most significant exploits used by the bad guys right now is the security team's poor relationship with other employees within the organization.

    [00:09:56]What's going on, and it goes back to this customer that we just had to run out to.

    [00:10:01] Why did they do what we told them not to do?

    11 min
  • App Tracking Traps a Catholic Priest. How It Can Affect You, Too

    App Tracking Traps a Catholic Priest. How It Can Affect You, Too

    Craig Peterson: I've got two hot topics for you this morning. One about this Catholic priest that ended up resigning and how that happened to tie into this Grindr account. And how it affects you because this type of technology used to convict him in the court of public opinion is something that. It could also easily be used against you.

    [00:00:25] And, by the way, it probably is. Now the next thing is this chip shortage. I've got a quote here from the Intel CEO. When is the chip shortage going to go away? When can we get out? Play stations and our new cars. So here we go.

    [00:00:43] Matt Gagnon: I'm going to start. With a story that I think I covered maybe a week or two ago, and I went on a pre prolonged grant. I know you may or may not have heard me do it, but it was about this Catholic priest issue. I know you know about this in some depth and detail, as I said before. But there is this issue here.

    [00:01:00] He was essentially outed as having visited gay bars and had done several other things. We'll just say using Grindr, right? All these types of things. And of course, being a high-ranking Catholic official, the accusations of hypocrisy and whatnot come and blah, blah, blah, et cetera.

    [00:01:18] What's interesting about the story, though, to me, Craig is, the media covered it as a hypocrite priest has been found out. But how that information was discovered is not only creepy but really scary. So I want you to tell me exactly how this happened and what implications do you think it has for our privacy going forward?

    [00:01:39] Because this is about a heck of a lot more than one Catholic priest. This is about Greg Peterson and what he's up to when I don't know. What does it do?

    [00:01:46] Craig Peterson: Yeah, it absolutely is everyone. Every one of you guys that are listening right now could affect you. Here are the basics of what happened. As Matt just explained, he was outed here because he was using an app.

    [00:02:00] Now it wasn't just because of this one. That was being used. And then, again, how many times do I know Matt? You said this. I've heard from you many times. "You are the product." There's something free. It's not free. So behind the scenes, what happened is some people thought that maybe. Bishop was doing something that you weren't supposed to be doing.

    [00:02:22] They figured they would look into it a little more, trying to figure out some more details. And so they went to some of these apps and bought information. Now Grindr is one of these hookup apps, and they went to Grindr and bought location data. And it's anonymized, right? That's what we're always telling everybody.

    [00:02:44] Oh yeah. Yeah. I

    [00:02:45] Matt Gagnon: [00:02:45] don't have your name, right? They don't. Yeah. They may give you some information to people who asked for that data, but it doesn't have things that would identify you.

    [00:02:52] Craig Peterson: [00:02:52] Like the NSA. Don't worry. It's just anonymized. They say this stuff all of the time. However, there are many studies you can find online on how to de-anonymize data.

    [00:03:05] One of the easiest ways, for instance, to find out where Matt lives is, if you know an app or you suspect a few apps you might be using, you just buy the data from those apps about their users. You can now narrow it down because this phone tends to sleep at the same place every day. And that's true for you too.

    [00:03:24] And in this particular case, this clergyman was using this app in various places. So at least the app went to some of these capital meetings, high-level meetings, et cetera. And so they put all of this data together and added two and two together and then confronted him saying, Hey, listen, we know it's you.

    [00:03:47] There was no indisputable evidence of it. There was evidence that he went to all of these different meetings, and he was in all of them, and he was the only person that was all of them. And then his, this must be there for his phone, and it must be him. So this is all legal data. Now I want to add one more layer to the top of this.

    [00:04:06] It's legal. You can buy it. I can buy it. And the federal government is buying it because they're not allowed to track it as supposedly helpful. But, still, there's a lot of evidence that they are. And because the feds, advertisers, and others have been buying all of this data and putting it together, they also track and de-anonymize them.

    [00:04:28] Matt Gagnon: That's, I think, an excellent explanation. Thank you for doing that, Craig, because it's such a technical thing. I think that's what many of these companies rely on because it's difficult to understand how this even works. So the public getting fired up about it is pretty tricky, right?

    [00:04:42]You got to understand it, to know what to be, even opposed to, and ultimately the selling of your data anonymized or not is occurring, and it's a problem. And The inevitable question really comes here. Craig, if you don't like this, what do you do about it? Is there any way to fight against this in some fashion?

    [00:05:01]There's certainly, I suppose, political changes that could be made, and maybe law is different, but maybe there are things in your life you could do right now that. Would Lakey make you less susceptible to this?

    [00:05:12]Craig Peterson: [00:05:12] This is really big. And the data also is being bought by advertisers, obviously roadside services.

    [00:05:21] And one of the creepiest things too is you go to a specific type of a clinic and all of a sudden you start seeing ads about a competitor or maybe how, what you shouldn't be doing there. So what do you do about it? Here's another problem. Our phone carriers were caught about two, three years ago selling your real-time location data to these data brokers.

    [00:05:45] And I've had a few of them on my show before, in years past, but it's just. Don't put apps on your phone that you don't need. The iOS, Apple phones, and Android phones can turn off tracking and turn it off on an individual app basis. Now that doesn't mean that your phone can't.

    [00:06:10] Because they can. All right. But what it does mean is that a specific app might not have access to your location just because you're playing Tetris. So apple has even gone further now. It has made it so that the apps cannot find out what other apps are on the phone and even go to a website on your computer or phone, even though you might have cookies turned off.

    [00:06:35] And you've done that. Some of the other things that I've advised people to do. Yeah. The computer can still report which apps are installed and to a website, to any website the same thing with your phone. Apple's taken some fundamental, extra steps to try and block all of that. So far in the Google ecosystem. It's still more open.

    [00:06:56] Yeah. Delete the apps you don't need. Turn off tracking in your settings for pretty much everything. Obviously, you need it for maps. And if you are using Google maps, talking about selling your data,

    [00:07:11] Matt Gagnon: [00:07:11] indeed. All right. Kirk Peterson, I have a couple other questions for you here. I'm not sure if we'll get a time for all of them.

    [00:07:16] However, I did want to talk a bit about the chip shortage here because I continually get frustrated by my inability to buy a PlayStation, which is now a. Five month-long problem for me that trying to buy one of these things. But it's so much more than that. I was talking to somebody else. Maybe last week it was talking about trying to buy a car and you can't even, they don't even have stock.

    [00:07:36] Like they don't even have the car at all. And manufacturers are now starting to make their cars differently. So that they don't require the chips that there's a shortage of so that they can actually produce the vehicles. Again, I'm hearing things about crank windows in cars, like just crazy stuff here because of this chip shortage.

    [00:07:51] And it might last into 2023. Is that

    [00:07:55] Craig Peterson: [00:07:55] right? Yeah. Yeah. And that's what the CEO over at Intel is saying. Now, this is going to last a while. Everybody made mistakes here during the lockdown. We had never had this before, where the government forced businesses to shut down. If you are in business, you are an important business, or you'd be out of it, of business.

    [00:08:14] That's just the way it goes. And that's true for the whole chip supplier, right? So we have a long way to go as well. He's saying right now, and they are rebuilding manufacturing capability. Now here's part of the problem with the capacity is the. As they're made up, the newer trips keep getting smaller and require different ship fabrication techniques and fabrication plants.

    [00:08:39] That's a huge deal when you get right down to it. And what it means is look at the apple with their M1 chip, and they have just this high-speed chip of Apple's, making its own fabrication, plants, et cetera. So the chips that they're wanting today cannot be made with older fabrication plants.

    [00:08:59] Now, some of them have been brought online, and some of those fabrication plants are making older chips. You are right about cars. I drive a 1980 Mercedes-Benz diesel. There, there are no electronics to speak of in this car. And my kids said, Hey, do you know your car's worth like $10,000? It was I. It was just amazing.

    [00:09:21] You're absolutely right. The car manufacturers are dropping things, and they are lowering the prices supposedly. But, still, they're lowering the prices based on what that costs them. So, for instance, in some of these higher-end cars where you might have a smart charger that you just put your phone on, you don't have to plug anything in, and it charges up.

    [00:09:42]They'll give you a $40 credit. But how are you going to install that later on? How are you going to install electric ones? That was when they put in 10 old ranks. So this is really a big problem. It's hitting everybody. It's tremendously hurting my business. I'm not getting compensated for it because it's taken us forever. We ordered a box of desks for our clients in November.

    [00:10:07] They showed up this last month. So we're going to have to live with this. Probably into 20, 23, and maybe even longer. It should start letting up sometime next year. But your PlayStation Matt is still a way off.

    [00:10:24] Matt Gagnon: Wonderful. Thanks a lot. Craig Peterson, our tech guru, joins us at this time every week. We will talk to you again, sir, next week.

    11 min
  • Intel Tells Us How Long the Shortage Will Last & Explosive Spyware Report

    Intel Tells Us How Long the Shortage Will Last

    [automated transcript]

    We're looking at a big chip shortage. You probably heard a little bit about it, but how long is it going to last? And we've got this explosive report out right now about spyware and some of the cyber hacking and what's happening with Android versus iOS. What should you be using, 50% of Americans are using Android, and the rest is split up mostly with Apple. iOS. So what's going on there? This is a research group that says, my goodness. The media outlets just aren't reporting the truth. So here we go with Mr. Chris Ryan.

    [00:00:40] Chris Ryan: A couple of things we're going to get today with Craig Peterson are the host of tech talk first design, the chip shortage, and how long that may last.

    [00:00:47] The second is a fascinating report on spies where I think a lot of us feel that our phones, and even to a large extent, our laptops are safe because we maybe haven't experienced any overt issues with cybersecurity whether or not that's true. We'll talk about it in a second. Craig Peterson joins us right now. Craig, how are you?

    [00:01:08] Craig Peterson: Good morning. I'm doing great this morning.

    [00:01:11] Chris Ryan: So we get into a couple of not great stories, though. As into the Intel, CEO says the chip shortage could last until 2023, as we continue to hear about supply chain issues and how they lead to the inflation of consumer costs. What do you think of this particular story, and how do you think it will affect those issues that we see with various shortages.

    [00:01:36] Craig Peterson: Yeah, this is a huge deal because, of course, when we're talking about chip shortages, we're talking about affecting everything. It's harder to get a car. For instance, that's driven up the price of used cars, as well as new cars. I mean your computers. We're trying to order them for some of our clients.

    [00:01:54] And we have seen some of the delivery times out six months, we just about two or three weeks ago. We just got it. Some discount in that we had ordered in November last year. So think about how long it is. And now we've got the wall street journal reporting after the Intel company posted second-quarter earnings on Thursday and the Intel CEO saying we have a long way to go yet.

    [00:02:22] And what they're trying to do. Rebuild infrastructure and build new infrastructure capacity. We have to remember that this is partially due to the lockdown, but the other side of this is competition. These chips keep getting faster at an order. Yeah. Faster. They have to get smaller internally. That's that nanometers thing that you keep hearing about with chip sizes and densities.

    [00:02:49] So these older fabrication plans that they couldn't bring back online and that they are, in some cases, bringing back online cannot make the newest chip. So it's a constant gain. So one of the biggest problems we have is. Building brand new chip fabrication plans over the whole lockdown thing. And most of them are in Taiwan.

    [00:03:11] So this could go until 2023, frankly.

    [00:03:15] Chris Ryan: And it also shows how tied our productivity and our consumption-based economy are into what's taking place in other countries as well. We've talked a lot about COVID in this country, but there are. Countries that are out there where we see some meager rates of vaccination, China.

    [00:03:35] We obviously don't know much about them, but Japan, Taiwan vaccination rates are meager there. So we talk obviously a lot about the US side of things, but many of these supply chain issues are driven by the economic and health environments in a foreign country.

    [00:03:56] Craig Peterson: Sure, we have a worldwide economy.

    [00:03:59] We've got Australia now completely locked down. There are parts from Australia that we need as well as all of these other countries. For example, India's vaccination rate is less than 3% right now. And we require a lot of support from India as well as part. So as we move forward continually the worldwide.

    [00:04:20] Source and really the source of everything I can know I can dock is going to be worldwide, and more and more of these countries are going to be playing a bigger part. That's Craig

    [00:04:28] Chris Ryan: Peterson, he's the host of tech talk on news radio six, 10, and 96, 7 Saturdays and Sundays at 11:30 AM. Interesting reports on Android and iOS.

    [00:04:39] Security. And, I think that many individuals who have not experienced identity theft have not experienced significant cyber attacks against them, they feel that they're safe, and they're not really. That's safe. So I want to get your thoughts on that and B what leads to even if you are vulnerable, what leads to that way, an extended period of time, which you don't experience anything, and the kind of that complacency set.

    [00:05:10]Craig Peterson: Many of our devices have been hacked. So if you think it hasn't been you by not know, they're doing everything from not ransoming your phone or random your computer, but using your computer to mine. Coin. And that can be a real problem when it says mark phone and all of a sudden your battery keeps dying after half an hour.

    [00:05:33] It just keeps getting on. It might be used right now for Bitcoin mining, all the ways through, of course, some of the ransoms that are visible so much. Mean now; there is happening in the background. Your computer could be used for one of these botnets to attack others and do other major things. Now, what we're concerned about on the security or cybersecurity researcher side is being able to get into these devices and get into the systems to examine them.

    [00:06:07] We've got this Pegasus malware, right? Which apparently has been used against some 50,000 journalists and government people, agencies, and others. And they, all you had to do was open your phone, open a message, no cocaine involved. And your phone has been. IOS, which is Apple's operating system, has been relatively closed.

    [00:06:30] That's a pro in some ways, and it's a con and others, and we've had all kinds of security researchers over the years here complaining about that while apple made some major changes and has now provided security researchers—access to absolutely everything and also great logging Android.

    [00:06:51] Unfortunately, the assumption is if it's Android, anti-virus can not protect it because Android is really a hodgepodge that was thrown together. It's thrown on to thousands of different models of phones that are out there. So we are. Better than one with an apple, people assume an apple is going to be more secure.

    [00:07:13] So they're being held to a higher standard, and they are stepping up frankly, to the plate here, Chris,

    [00:07:20] Chris Ryan: [00:07:20] you, if you are a business owner, a public official, a person that holds a government position, something that is, would be very intriguing too. Packer or to an organization. And you have questions about your security and whether you are secure, and how do you go about creating an environment where you feel comfortable?

    [00:07:43]Particularly if you are not all that knowledgeable on the topic of cybersecurity.

    [00:07:49] Craig Peterson: I read a great article yesterday. And it was talking about how we, as a whole, pretty much everyone thinks that you can't do anything about it. So we're just going to give up and

    [00:08:03] Chris Ryan: yeah, if I were to get targeted, I get targeted.

    [00:08:04] But I think that even when you think about somebody like throw Brad Pitt out there, right? Brad Pitt has to be the target of just about every single hacking organization imaginable. You would assume to want to get information, access to capital, ransomware, whatever. If you are the higher, you move up the food chain as a public official or a celebrity that you would be accustomed to being hacked by.

    [00:08:27] Everyone. What do you do if you are concerned about that?

    [00:08:31]Craig Peterson: some things can be done, but you cannot use the standard software. We already know that the Norton antivirus and all these other basic antiviruses do not work. They don't protect you against modern threats. In fact, more than 70%.

    [00:08:48] Of the threats this year on cannot be stopped by the wonderful little antivirus software we've had for years. So you have to move up to the next level. We're working right now with a small bank. Who's trying to really secure everything because of these sorts of problems. But I, If you are in a position where you are bigger targets than usual, you have to take extra steps.

    [00:09:15] You have to use advanced malware protection. In all of these years, I've been securing computers out for 30 years. We have never, ever, I had a client that had ransomware, and we're talking about multinational clients all the way on, down through your local dentist. So it can. Done, but you can't just rely on the technology that was invented 20 years ago.

    [00:09:39] Just top ad guys, but it is there, but you're going to have to Lord and get the right people involved. Craig. Thank you so much. Take care.

    10 min
  • Google's Being Sued by the States -- And it doesn't look good for them

    Google's Being Sued by the States -- And it doesn't look good for them Craig Peterson: We talked earlier about Amazon and how much trouble they're in right now, Google apparently is in a similar boat. We had just this week, dozens of state attorneys, general suing Google on antitrust grounds.

    [00:00:16] You can reach me online. Just me. M E Craig peterson.com or what most people do is they just hit reply to my newsletter.

    [00:00:25] Hopefully you're on my newsletter, right? That goes out every week. If you're on that newsletter you can just hit reply and ask me questions. Any questions you want? I'm more than glad to answer them. I know most of you guys, you're not business people. I am still glad to answer your questions for you to keep you on the right track.

    [00:00:42] The whole idea here is it's to keep you going. Safer. And if you're a business person, what the heck, maybe I can help you out as well while the here is a problem. And it's a very big problem. We have these absolutely huge companies that are using their market position in order to really control the entire world.

    [00:01:09] Now it's a very big problem because you have companies that are sitting on billions of dollars in cash who can and do keep their competition out of the market. Now, one of the ways that keep them out, and I've mentioned this before, Microsoft has done this multiple times as lost lawsuits about it, particularly over in Europe, but they find somebody who might be a competitor and they basically squeeze them out of them.

    [00:01:39] Even though they're not necessarily even a direct competitor. One of the things Facebook does is they buy companies for 10, a hundred times sometimes more. Then they're actually worth, would you take 50 million for your company? That's worth 50 million? You might not.

    [00:01:56] Would you take 500 million for the company? How about a billion dollars? That's where it starts becoming very questionable about what they're doing. One of the things that Google is allegedly doing right now is preemptively squashing com competing app stores. When you look at Google and the Google Android ecosystem, who sells the most Android devices out there, right?

    [00:02:24] The high-end devices, the number one seller of Android phones is of course, Sam. And Samsung started to put a store too. An app store. So you could buy Samsung, Sam sung apps now, apple and Google, both charge about the same rates as a general rule. It's 30% for these bigger companies that they have to pay the app store, okay. I'm okay with that. They both spent the time to build the platform, to monitor it, to try and keep the app store clean and guides. That's definitely worth something. But what if Samsung came along and said, okay, we're only going to charge 10% royalty. In our app store and the apps will run on all of our Samsung Android phones.

    [00:03:13] So it's still using the Google operating system. It's still Android. It will probably run on other than Samsung phones as well. That's the whole nature of, but that hasn't happened. And why hasn't it happened? These state attorneys general are saying that what has happened is the Samsung galaxy store got squashed by Google.

    [00:03:41] So it could maintain its monopoly on Android app distribution. So it says that Google engaged in a bunch of different anti-competitive practices. They offered large app developers, profit share, and agree. In exchange for exclusive exclusivity. Okay. I can see that the apple iPhone came out. Do you remember this exclusively on ATN T's network?

    [00:04:08] Is that a problem? They're saying also the Google created unnecessary hurdles for what's called sideloading. So sideloading is where you might go to another app store in order to install something. Or maybe it's something that you want to put on your site. It's not fully approved by the Google play store.

    [00:04:29] So that's the basics of what the side loaning is all about. So saying that they made that even harder. Okay. From Google standpoint, do we really want to. Allow anything to run on our phones. And here's the question, here's why, right? What do I do for living cyber security? What is one of the things you have to do for cybersecurity?

    [00:04:51]You've got to put in special routers, special firewalls and software on servers and computers. Whoever touches a computer last owns the next problem. That's been my mantra forever. So if we installed some software on a computer or we had the customer installed some software on a computer, and there's a problem who they get.

    [00:05:14] They're going to call me, right? Because I was the last one to touch their computer. And at that point now I have to show, okay, it wasn't me. It was this other piece of software. QuickBooks is a piece of junk, you know what, whatever it is, I'm going to have to justify it. And frankly, I'm probably going to have to fix it.

    [00:05:33] So Google is saying. We don't want all of these app stores that might have apps that are not secure apps, that crash apps that might cause problems with the Android ecosystem. I think that's perfectly legitimate. Apparently these state attorneys general don't think it is. And here's the last one. This is a.

    [00:05:56] Attempting to buy off Samsung to limit competition from the Samsung galaxy app store. Now, Google is saying that this lawsuit is merit lesson. I can see a whole bunch of legitimate argument on their part. They also said, quote, and this is an article from ARS Technica. It's a strange, it's strange that a group of state attorneys general.

    [00:06:21] Chose to file a lawsuit, attacking a system that provides more openness and choice than the others. In other words, are taking a jab at apple because apple is very closed for the reasons I just decided to hear that Google I'm sure is going to argue as to why they are closed. Okay. Apparently the state attorneys general are saying, quote, Google promised repeatedly that Android would be the basis for an open ecosystem in which industry participants could freely compete.

    [00:06:56] Google has not kept its word. Instead. Google has taken steps to close the ecosystem from competition and insert itself as the middleman between app developers. Consumers. Okay. Can, so can you see that they're also complaining this 30% commission. It's a monopoly rent that unfairly burdens consumers and developers, and K-12, you could argue that I don't fall for that one personally.

    [00:07:24] Now the buy-off is where I think that there's a lot. Yep. Teeth in this particular lawsuit. Cause they're saying that we've got the commission rate argument, right? We've got those. It's not as open as you said, it would be. But these attorneys general have spent a lot of time dissecting Google's alleged efforts to keep competing app stores at bay by, and they said Google was willing to offer Samsung myriad benefits and concessions in order to prevent Samsung's galaxy store from being built out.

    [00:08:00]Again, Is that a huge problem. If you've got a big customer or a potential partner coming to you and saying, okay, I want a few concessions here. I'm not going to pay 30%, or I want to have some of you, my developers in house with your people so that they can short circuit some of the problems that always develop those are.

    [00:08:25] In the business in business period. And when it comes to software development, right? People, businesses have we'll use apple again as an example jam, which is a really great set of software to help manage your devices. Jan PF, you might want to check it out. So jam had their engineers camp out at Apple's headquarters, apparently four months while they were working on.

    [00:08:52] Some of the, their software for the next release of Apple's iOS and Mac iOS. Is that unfair? Yeah, in a way it is right because here I am little Mr. Small developer and I'm not gaining access to Apple's top engineers and able to send mine out there to live with apple engineers and ask questions and help them debug my software.

    [00:09:18] But it happens every day. Makes sense. So it says though the galaxy store was not nearly as popular as the play store. Google feared that Samsung would develop into a strong competitor, especially since the company sells a majority of high-end Android phones in the us ARS Technica says Google was particularly concerned that Samsung would get an exclusive game.

    [00:09:43] For the store to attract more users, which Samsung did do in 2018, when it partnered with epic to launch fortnight exclusively on the galaxy store. And that one, move that one game. That one app. Costs Google millions of dollars in revenue. So we'll see what happens here. They make other claims in there. Apparently it even offered a Google offered to white label, the play stores, the galaxy store, so that Samsung could maintain its branding, all kinds of negotiations, the types of things I've seen before, the types of things that are.

    [00:10:23] Particularly uncommon, but a European commission is also going after them with an antitrust investigation. They've done that a few years ago with this is a problem. These companies are huge and we don't let them fail. Look at what happened. GM and Chrysler, both got bail and the federal government Chrysler got bailouts twice.

    [00:10:45] The free market. You never would have had that happen. The best part of Chrysler would still exist and those weak parts would have been gone. That's what bankruptcy law is all about GM. The same thing, the best parts of GM would have remained. We would have probably had better cars today. Then we have, if DM GM had been allowed to go bankrupt and yeah, it's going to hurt people, but guess what?

    [00:11:11] It's hurting people right now from the other side. And when I see this happening as well at Google and Amazon, of course they haven't gone bankrupt, but they both along with Facebook and a few others, they're both huge. Huge and they control so much of the market. So what's the best way forward. What do you think I'd love to hear from you?

    [00:11:32] Just drop me an email. [email protected]. What is the solution to this? Hey, make sure you get my newsletter. We got all of this information, of course, a whole lot more comes out every week. May be semi-weekly here fairly soon. See how it goes, but go to Craig, Peter sohn.com/subscribe. You'll get my free newsletter and you'll keep up to date on what you need to do to keep yourself safe.

    [00:12:02] Craig peterson.com.

    13 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…