
Sign up to save your podcasts
Or


[Following is an automated transcript of Week 1115 podcast aired 2021-05-29]
Craig Peterson: [00:00:00] We've got these semiconductor shortages. What that means is various types of chips are just not available and it's been hurting us all the way across our economy. And that's where we're going to start the day with today. Semiconductors.
[00:00:15] Man, this has been so bad, these semiconductor shortages, because what it means is we just cannot get the types of devices that we want because those raw components just aren't available. I was talking with a gentleman earlier this week and he was telling me how he has a special little app that tells him when there is a Sony PS five available for sale anywhere online.
[00:00:45] It's gotten that bad. First of all, Why does he want a PS five so bad? I've never owned one or an X-Box or any of those gaming consoles? Since the original Nintendo, we had a we as well. Cause we had all the exercise stuff that went along with the week. But anyways, that's a different story entirely.
[00:01:04] I'm sure a lot of you guys play a lot of video games, but. There really are not Sony available. And we're finding much the same problem in even the car industry where some of these major manufacturers here in the U S have had to shut down lines. They've had, gone from three shifts down to a single shift every day.
[00:01:30] And in some cases it's gotten even worse where vehicle manufacturers are only. Making vehicles of few times a week. It is incredible. What's been happening and there a number of reasons for it. This isn't just one reason, but it does bring up the real problem we could have with our critical infrastructure.
[00:01:53] How critical is it that we have computers that can run our businesses, drive our cars, and fly our airplanes. I think it's pretty darn critical when you get right down to it. Yeah. You can probably get an extra year out of that computer, if you really need to many times that computer's just plain broken, you just can't use it.
[00:02:15] So you do need to replace it. But in reality, we've gotten a little bit soft. We are not making most of the chips here in the U S anymore. Yes, it's us technology. But most of this is in Southeast Asia, particularly in Taiwan. And do you remember what's happening with Taiwan with the threats from China?
[00:02:38] China is flying over Taiwan right now with military jets in Taiwanese air space, because China has never officially recognized that Taiwan is independent from the people's Republic of China. And do you know how socialists are? They're just going to go ahead and take that land. What would happen if they did.
[00:03:00] Remember China really wants to get their hands on our top chip technology because that helps them in the military. It helps them with all of these facial recognition systems they have in China, the social credit systems that they have in China, by the way, all built primarily by us companies and sold to China to track their people.
[00:03:23] Including the nasty things have been happening with the Wiggers over there. It's just absolutely incredible as well as Christian communities and others in China. So all of this tech has stuff they want to get their hands on. If they were to invade Taiwan, what would happen? The Biden administration.
[00:03:40] There they've been a little soft on this. Unlike president Trump, who said, yeah, the Trump administration, we're not going to tolerate any of this. And the Trump administration shipped all kinds of military systems to Taiwan, so they could potentially defend themselves because we don't really want to get drawn into a hot war, but.
[00:04:00] Oh, if they had taken over Taiwan, they would now have access to the U S technology on chip making. Now let me explain what that means from a technology standpoint, the chips that we have are. into a wafer of silicone. I'm going to try and keep this pretty simple. And then, and that silicone is grown. Cause you think of a crystal or maybe think of a still-life tight or it's like titers to leg might that you'd find in a cave.
[00:04:34] Those crystals are grown. They're humanly grown, and obviously you don't want any defects in them. So it's very hard to do to grow them. And we need those crystals for all kinds of things, including these solar panels that some people are so hot to trot about. I, Hey, I love the idea. Don't get me wrong.
[00:04:52] It's just right now, again, with solar panels, like so many other things, don't think you're green because you. Are or putting up solar panels. You're not right. There's certainly other advantages to it, but you're not being green by doing that. But what really matters is how much power does that chip use in order to do a certain number of computations?
[00:05:17] And how much heat is given off by the chip. Think again about the old Edison light bulbs that we've had and still have in some places and those Edison light bulbs, by the way, one of the original ones still burning in New York city and the fire department after over a hundred years, that one light bulb just incredible.
[00:05:37] But think about that Edison light bulb, it gives off light. Sure. But it also gives off heat. And the same thing is true with. Anything electronic the movement of the electricity through that conductor or semiconductor create heat. Heat is a waste. That's part of the problem with Edison bulbs. It'd be one thing if they were giving off just straight light, the, but so much of that energy is used to generate heat that we don't want.
[00:06:06] And then we have to dissipate that heat somehow, but that's another story. The same thing is true. When we're talking about these chips, the chips have a resistance to them. In fact, that's what a semiconductor does. It provide some resistance, so that resistance is going to. Do what create heat. So you feel your laptop when you're running it and so hot to get over time, the laptops have gotten faster and have actually created less heat, certainly poorer computational unit.
[00:06:44] They created a lot less heat. What we're looking at now is if we can make these chips even smaller. We can decrease the amount of electricity they need, because it doesn't have electricity. It doesn't have to flow as far through the conductors or semiconductors inside these chips. So that's what the race has been over the years.
[00:07:09] The race has been how small can we make them? And by making them smaller, You're doing a couple of things. You're making them faster because electricity has to travel less distance. Even though electricity is really fast. When you're talking about a billion transistors inside one of these chips or more, you are traveling through a whole lot of conductor and semiconductor.
[00:07:32] So you can make that chip faster by making it smaller and you can reduce the amount of power it needs, because you're not going to be giving off as much power via heat and heat generation. And that's important for everything, but particularly important for our mobile devices. Look at your apple watch or your iPhone or your laptop or your desktop.
[00:07:56] All of them need to consume less and less electricity as time goes on. So what we're talking about now are just teeny tiny measurement. We're talking about nanometers. So if you go online, you look up nano meter. Which is a foul. Yeah, there you go. 10 to the negative nine meters. It's a billionth of a meter.
[00:08:21] Isn't that something looking it up right now, sell it a 1E-9.000000000. Give or take, and it's a unit of measurement that is being used now in chips and chip designs. And we're seeing these faster and faster chips getting down into the five nanometer process that is incredibly small, incredibly.
[00:08:49] Fast potentially, but likely incredibly fast and uses a lot less electricity right now. We're seeing seven nanometers out of Taiwan and we're working on five nanometer, but we have such a shortage of chips right now that they're bringing some of these old 15 nanometer. Chip fabs online, even 22 nanometer.
[00:09:14] I'm looking right now online at some of these old chip fabricators that are being brought online and China really wants to get their hands on some of this technology, because at this point anyways, they really can't get to the seven nanoliter chips. China right now. I think is pretty much limited to 14 nanometer.
[00:09:39] So we're still, I had in that race, but because they're being made in Taiwan, these chips that we're using here in the us using us technology, and because we had the lockdown in Taiwan and pretty much worldwide, the whole supply chain got interrupted and these big car manufacturers just. Shut off the orders.
[00:10:01] So there's no reason for the manufacturers to continue to make these things are a little reason for them to make them for the car industry in the current street, he thought we can just turn it back on and we'll have the chips. And of course they didn't, but it's also been compounded by the conditions in Taiwan right now.
[00:10:19] Because the Taiwanese centers for disease control this week raised it's epidemic warning level and is strengthening their containment measures and making things even worse. Taiwan is in the midst of a severe drought. So they are. Rationing water in Taiwan. They're looking at cutoffs of two days a week.
[00:10:42] And water reduction plans are expected to decrease supply to all major manufacturers by as much as 15%. So there you go. In a nutshell, that's why we care. Nanometers and we're talking about chips. That's why we need to start making them back here in the U S. And the good news, apple and others are doing exactly that.
[00:11:03] Starting to bring some of this technology back from Taiwan, into the U S and I think that's going to help keep us safer in the long run
[00:11:12]All electric vehicles are I think very cool. And some people give me a hard time because I am not a fan of it.
[00:11:20] If you think you're being green, because you're not. And I went through the whole science behind that the life cycle of an electric vehicle is much more. Dangerous and hazardous and polluting in the environment. Then even a diesel truck is just to give you an idea of small truck. So that's, let's put that aside, but in reality, these things I think are potentially the future.
[00:11:50] Now there's a lot of things we've got to take care of, for instance. Our electric grid is not set up for electric cars. Our electric grid is not set up for us to have windmills in our backyard or to have solar panels on our roofs. It's set up to have a main power station of some sort, whether it's nuclear, which by the way is green or whether it might be.
[00:12:17] Be coal or natural gas or wood or trash. That's what the grid is set up for. So we have some problems there and there's another big problem. And that has to do with how much power one of these vehicles can hold, because I don't know about you, but having a, what is it? The brand new car that came out a Fiat or somebody and his electric vehicle and its range is 78 miles.
[00:12:46]In some places that might be okay, but progress. The problem is I'll write, let's say I'll put up with stopping every hour to recharge these cars, unless it's a rapid recharger, you're going to be there for an hour and a half or more. And even with the rapid recharger, you're going to be there for a least 20 minutes.
[00:13:07] Now Tesla had some innovative ideas on how to deal with that. Like the, I don't know if you ever saw it a battery pack, so you'd pull into the station and it would just trade battery packs for you. The idea was it's right in the center. GM has this concept of the roller skate, where the entire car really is built into this frame.
[00:13:29] That kind of looks like roller skate. And then on top of that, Goes your car and there's some thinking maybe we can make it so that you can just swap out your rollerskate. Make it nice and simple and hopefully relatively inexpensive, but we still don't see the range on the vehicles. And as of yet, we haven't seen any huge forays by any of the big auto makers.
[00:13:54] Of course, Nissan had it to leaf, which. Pretty well accepted GM had their entry. And I chuckled because it was in a lot of ways. It was a joke. And of course they're up with better stuff here in the future, but I want to play a little bit here. I'm going to play about 25 seconds worth of an ad.
[00:14:12] And then we're going to talk about it a bit.
[00:14:16] Unknown: [00:14:16] It's got a targeted 775 pound feet of torque. It's targeted to go from zero to 60 in the mid four second range. It's a driving experience. That's pure unfiltered exhilaration from the moment you hit the accelerator. Oh, and it's an F-150 introducing the all electric F-150
[00:14:40] Craig Peterson: [00:14:40] lightning.
[00:14:41] So you noticed there were no mentions in there of no birds were harmed in January generating electricity here. And of course, a little tongue in cheek because of course birds are harmed in generate electricity, particularly windmill, but anyways, they're not going for the eco greeny. They're not going for the Prius driver.
[00:15:01] You remember the stats on the Prius where they surveyed the drivers of Prius's. This was probably five. Maybe a little more years ago. And the number one reason they found people drove a Prius. 70% of the time in fact, was they drove a Prius because of what they thought other people would think of them.
[00:15:23] So there they are driving this car that they're driving it for one reason, because they, I think it's going to make other people think that they're just fantastic people. I obviously I disagree with that. I think that's little bit of a problem, but what is what they're doing here with that Ford commercial is they are working on mainstreaming.
[00:15:46] Yes. Electric vehicles. Can you imagine this a 700 plus foot point foot pound torque in a sub $40,000 truck? It's just amazing. And you can even use the batteries that are in this truck. Of course, there's a lot of batteries in that truck to run power tools while you're out at a work site. Which I think is a great idea.
[00:16:12] And you can even use it to power your house. They have a special adapter you can use to hook up to your house so that you can get up to three days. They say of electricity in your house. If the power goes out, No mention in here of, any of these greeny things, right? Oh, none of oases talking points are in that ad.
[00:16:37] At least I didn't hear him on, did you guys hear them, but this is going to be amazing. This of course is Ford's best-selling vehicle, the F-150 and I drove one for years. It was very handy with the horses and chickens and everything here. And I'm looking forward to this thing coming out. I don't think I'm going to buy one, by the way.
[00:16:58] They've also got this Mustang mark II, which is this electric Mustang thingy. And then they have an electric transit van. And the reason I don't think I'm going to buy one is it just doesn't have the range. Now you can get better equipped lightening trucks in that sub $40,000 one. You can also go ahead and get bigger batteries.
[00:17:22] You can do a whole bunch of things, but this range is a combined output here, a 426 horsepower estimated range of 230 miles. And the extended range of this F-150 lightning is going to get an even. Bigger horsepower rating, 563 horsepower and an estimated range of 300 miles. And 775 foot pounds of torque, which is just stump polling.
[00:17:56] It's absolutely amazing. So I don't know about you. I'm not in the mode for pain, 60 ish grand for an electric truck that is only going to take me 230 miles. That, but maybe that's me. And then looking further into the stats on this thing, it can do a bunch of towing. It can have a 77, a hundred pounds of towing.
[00:18:22] You can get Reduce cargo, excuse me, reduce cargo course. If you're getting the bigger battery and looking at an illustration of the F-150 lightening, what they're doing is similar to what GM had proposed way back with the roller skate. The entire drive train is underneath the truck. And it's just like an old frame.
[00:18:44] You remember, trucks used to have frames now? The F-150 is, I think still do have frames underneath, but the whole bottom of the truck is one piece. If you will, obviously there's little pieces to it, but one major component and then the cab and bed and everything else just sits right on top of it.
[00:19:03] It's amazing. Now with this truck, if you connected to 150 kilowatt fast charger, you're going to get 41 miles in 10 minutes. So how long does it take you fill up with gas? Probably about 10 minutes. How long is it good for? It was my car 400, 500 miles in this case that 10 minute stop. At the fuel station is going to get you 41 miles.
[00:19:29] And if you can find the, just the 50 kilowatt fast charger, it's going to take you 91 minutes to get 41 miles of range. It's not there yet, but it's very obvious that Ford is aiming for the truck driver. And more particularly if I was a construction guy and I was taking my truck out and I needed to plug in tools and I don't have to drive very far.
[00:19:56] I look seriously at that new F-150 lightning.
[00:20:00]President Biden . I've got an article in my newsletter this week about what he's been doing when it comes to the hackers, China, is it Russia? What's going on? He's been blaming. It looks like. Russia for some of the hacks that China has actually been carrying out, but no matter what the bottom line is, we are getting hacked and this is a very big problem.
[00:20:28] We have to modernize our technology strategy. Because this ideological divide between these authoritan or authoritarians, whether it's a dictatorship like the socialists have in China, where you have chairman Mao, who is chairman for life now, or Putin. President Putin, who is president for life over in Russia.
[00:20:53]It's absolutely amazing. They are coming after us. And so is North Korea, of course, again, socialist dictator for life over there as well, Iran not so socialist, but a very fascist in many ways, which is typically a form of socialism anyways. We need to be able to protect ourselves. It's a real problem, frankly.
[00:21:18] 1947 world war two was over and George Kennan, R yeah. Kennan introduced this concept of containment and that containment concept was used throughout the entire cold war. And of course you probably know what that is. At least, excuse me. I hope you do. But today we don't have that cold war anymore.
[00:21:45] What is it that we have? Why would China be attacking this? We know, for instance, a China comes after our intellectual property and they w they come after it because it helps them militarily. If they know what we're doing, what we're ordering. What's going on that we know they come after us as well, because they want to cause some havoc.
[00:22:11] There's no question about that. Some of these other smaller countries come after us because they need the hard currency. Ultimately they want to trade in those Bitcoin for us dollars, which of course can be spent here. But. This whole system that we have right now is really on the brink of a new economy.
[00:22:34] Look at the technology we've been using. Look at the number of people that have been working from home. We're sitting on the edge of three simultaneous bubbles. Right now we have the housing bubble. We have the stock market bubble and we have the cryptocurrency bubble and we've seen downs in all of those just over the last week or so.
[00:22:56]We'll see what happens, but there's no denying that they're bubbles are home values adjusted for inflation, have not been higher than the last 100 years as an example. So there's a lot for us to look at. And when these bad guys are under the same types of financial pressures we are under, because, collapses tend to be worldwide.
[00:23:21] What are they going to do? What's ultimately going to happen? Here is what president Biden thinks should happen with these two executive orders that came out really It, it has to do with federal government supply chains. And that is people who obviously are selling to the feds. And I want you to think mostly about department of defense here, and we deal with the department of defense contractors and tightening them up.
[00:23:50] But in getting them to the point they should be at. And there's a lot to be concerned about it from that standpoint, but they have been releasing some details over the last few months, really. They started in April this year, and they're saying that because of the supply chain problem that we had with solar winds, they are now.
[00:24:15] Pushing out some rules that require the people who sell to the federal government to keep a certain level of cybersecurity. We've talked a little bit before about CMMC, which is. Again, it's a cyber security maturity model that's out there and they are requiring certain federal contractors to meet that.
[00:24:40] We've also talked about some of the NIST standards, which is the national Institute of science and technology. In fact, we talked about their password standard and how a year and a half or so ago, they changed the way we need to do passwords. And if you don't know what that is, have a look at my. A special report on passwords.
[00:25:02] And I go through that in some detail, but there's an executive order on American supply chains that came out in February and it's leaning pretty heavily on these newer emerging technologies, including secure access to semiconductors. And we talked about them earlier in the show today, the high capacity batteries.
[00:25:24] Because again, if we're not innovating. In the, you name it. But in end in the automotive field, we're going to fall behind what's important automotive. We just talked about it. Last segment here. Batteries. So it's covering batteries and materials that are used to create them. So they both of these orders address the need for us to really work closely together with our allies economically, as well as national security.
[00:25:55] But that's exactly what we've been doing. Isn't it? What it really boils down to in my mind is democracy versus authoritarianism. It was so funny that they called president Trump and authoritarian a decade, her right. He was liking to Hitler constantly. I thought if you brought him up, you automatically lost the argument.
[00:26:18] But in reality, now we're seeing more of a hands-on from the federal government more authoritarianism. And I got a question whether or not that's what we really want. Do we need a digital politic. This guiding doctrine, that places digital considerations at the forefront of our national strategy. Is this something that should be handled by the state or the businesses involved?
[00:26:47]We've seen all kinds of mixed. Pros and cons to each one of those strategies over the years, we know government controls, centralized government control, ultimately causes serious problems serious as in the deaths of over a hundred million people in the last century alone. So I'm not sure that's the best idea.
[00:27:09] And I have to say work. I With defense contractors, even not really a defense contractor, someone that makes something that's sold to a defense contractor. Having a one size fits all cybersecurity policy, a cybersecurity czar, and these executive orders pushing everything down does not make sense. It doesn't make sense for a real small company that makes a wiring harness to have to meet the same.
[00:27:38]Cyber security requirements as a big BAE systems, they don't have the time. They don't have the money. It can cost a million dollars over the course of three years for even a small company to meet these federal standards that are required. If you take a contract from the federal government or from one of these contractors.
[00:28:04] So you are a subcontractor, all of those requirements that are put on that huge military contractor, all of those requirements get pushed down to you. So this just doesn't make a whole lot of sense to me. I'm very concerned about it. There's a bipartisan bill. That's moving right now called the democracy technology partnership act.
[00:28:26] And they're trying to get some collaboration and innovation amongst democracies. I think it's good now that there are rules in place that have changed, that allows competitors to talk with each other when it comes to cyber security.
[00:28:43]Internet Explorer was Microsoft's first major foray into the internet browsing world internet browsing didn't really take off until almost the mid nineties. And it was really cool. I remember when I first started using. Web browsing and websites and building them with NCSA mosaic. Oh my gosh. Those were the days heady days back then.
[00:29:09] And we were just thinking about everything that could happen, how great it would be. And there were no hackers to speak of online. You didn't have to worry about drive by downloads or so many of the other problems that we have today. And Microsoft took that NCSA mosaic browser code base and created something.
[00:29:33] They called internet Explorer. Now the history of internet Explorer, frankly. Is rather interesting when you get right down to it. Internet Explorer. Yeah. It's been around for a long time, but in genetics, Explorer was one of the worst browsers out there for a very long time. It was just terrible.
[00:29:57] And one of the things that Microsoft did that really got. With the whole internet community upset with them is they built it right into their operating system. Absolutely. They used the code here from again, mosaic, which was this early commercial web browser back in 2003. It, the whole project started in 1994.
[00:30:25]I'm looking right now, Wikipedia. I remember these things happening. It's just nuts to think about how far it's gone, but they took internet Explorer and they bolted it into the operating system. So the operating system now supposedly was dependent on internet Explorer. Now it's an interesting concept to think about if all they have to do is maintain a user interface.
[00:30:51] That's web based for the operating system. That's really cool. Microsoft internet Explorer is some 5 million lines of code that is a lot of programming to maintain. And then on top of that, of course you have all of the user interface code that's sitting there in the operating system. So I think this is my suspicion.
[00:31:12] What Microsoft is trying to do is make their life a little bit easier. But by doing that by hard wiring in internet Explorer, into the operating system, they ended up making it so that other companies like the Firefox guys, Mozilla, they could not run independently on inch, on a windows. And a third party, like Dell could not decide, Hey, I don't want to use internet Explorer because Google's paying me to install Google Chrome.
[00:31:43] So I want to put Chrome on windows. So you just couldn't do any of that. So they got a whole bunch of flack. The industry came after them and because of that, so did the department of justice. And the United States versus Microsoft case, very fundamental. And it was absolutely, it was essential, I think because Microsoft never would have done anything about this, but they developed Microsoft this thing called ActiveX technology, which is a security nightmare and remains one to this very day where you could effectively as a website.
[00:32:25] Tell the internet Explorer to do almost anything you wanted to do. And there were bugs after bugs. I don't have a count. It might be interesting to see what the actual count would be, but it was, it had to be in the thousands of bugs that were fixed security bugs that were fixed and internet Explorer because of active X and because of some of these other things.
[00:32:48] So it's just been absolutely terrible. One of the questions I get asked most often to this day. What do we do when we don't want to use internet Explorer or more commonly, what is the best browser to use while I'm online? And the answer to that kind of varies. It depends, right? That's the answer, but as a general rule using Firefox is a good idea.
[00:33:20] Now, one of the things I like about Firefox for an individual or for a, an extremely small business, like a small office home office, where you're not tying into a corporate network at all. One of the things that's really good is Firefox. Uses a version of DNS, which is the main name, service. It's what your computer uses in order to find websites online, Firefox uses a version of DNS that is.
[00:33:50] Encrypted and protected so that your internet service provider cannot see the website names you're looking up and cannot intercept it. And that's the bigger thing. You don't want it to be intercepted because one of the major hacks, and this is affected millions of people. Homed and businesses.
[00:34:10] One of the major hacks is let's just go in. We can hack the router and then we'll change the router DNS settings so that it uses our DNS and our DNS by the way is great because it redirects you. If you think you want to go to bank of America, it takes you to bank of America dot China. Okay. A fake site, not a real site.
[00:34:31] And you may not even know. You may not even be able to tell unless you look really closely. So that is a big plus for Firefox as well as it has all kinds of anti-trafficking technology. Anti-malware technology built right in, they've just done a bang up job. The reason I do not like it for bigger businesses is that same.
[00:34:54] Feature that DNS feature because what we do when we go into a business, and one of the things we do is we change their DNS servers to use some commercial DNS servers that we have from Cisco that get updated minute by minute for the sole purpose of trying to stop the bad guys. And they're very good at it.
[00:35:16] It stopped being ransomware just by DNS. If you're using Firefox inside one of these networks, the problem is Firefox is going to try and hide the DNS request. So it was not so much as I care that they're being hidden, except that might be going to a malicious site. It said, I can't see any of them.
[00:35:36] And I cannot tell your web browser or your computer not to go to that website because that particular site or that particular internet server is actually malicious. So there's the two sides for Firefox. So if you're a regular little home user, get Firefox, it's free. It's a great little browser. If you are a business, you can still use Firefox with things like Cisco's umbrella.
[00:36:04] But what you need to do is turn off the DNS over HTTPS or TLS in which gets a little advanced. You can probably find it. If you'd duck, duck, go search it online. And that'll get you the answers you need. So turn that off so that all of your DNS requests are going through the filter, whatever it might be.
[00:36:24] A Barracuda has a DNS filter. I don't like Barracuda. Don't think I'm endorsing them, but it's better to use the Barracuda DNS filter. If that's all you have, then nothing. Let me tell ya. And then there are also free DNS servers that are going to be fantastic for you to check them out. I talked about them this last week.
[00:36:44] I got a lot of emails, open dns.com open ope, N D N S the letters, DNS domain name service, or. Dynamic name server or whatever you want. How are you going to remember it? Open dns.com and there it's easy enough. You just set it up on your ad drought or, and you're off and running. So that's my general favorite.
[00:37:10] If you want something that's more secure, you can take a look at our friend, the epic browser, epi C. It has been very good in the past, and I assume it's going to continue to be pretty good in the future. Microsoft's newest ed edge browser. I think there's been three different browsers. They call ed just under what Microsoft, they call them all the same thing, even though it's entirely different code basis. And what were there? Seven different versions of windows that were entirely different? I was just, ah, drives me crazy. The current version of the edge browser from Microsoft is based on Google's Chrome browser. So keep that in mind, if you're using edge, Microsoft is looking over your shoulder.
[00:37:55] Google may be looking over your shoulder as well. A little bit. The edge browser also uses Google chromium base, but they've gone through and Labatt itemized it pretty seriously. If you're on a Mac, you can even do this on a windows computer. The fastest browser, generally speaking is safari, which is an apple product and it's available for free S a F a R.
[00:38:18] I. And it also like most apple products doesn't like you being tracked. And so it has a lot of anti-trafficking stuff. Built-in. And it also not this too. The safari browser has a whole bunch of anti-malware stuff built in. So whether you're using iOS on your iPhone or I panned or Mac iOS or windows, you can get safari.
[00:38:46] And I had recommended that. So Fari frankly, is the browser I use for a little bit more secure stuff. And then I also use opera, the opera O P E R a browser. You might want to have a look at it as well, but if you're looking for ease of use and compatibility, I think you're probably about right. Sticking with the Firefox browser.
[00:39:09] I do use that. So I actually use all of these browsers in different circumstances. I also use the brave browser and others. I just don't want to confuse you guys. Firefox stick with Firefox and you're probably going to be pretty well off on rare occasions. Firefox is not going to work for you. And in that case, you might consider a Google Chrome or the edge browser.
[00:39:34] If you're using a cloud-based to service a website that is obviously a website for something you're doing. And it does not work with Firefox. It might not even work with the default on the Microsoft edge browser. And that's because that website might've been poorly coded, had not written right. And requires the old Microsoft engineer Explorer.
[00:40:04] If so you can turn on compatibility mode so that the edge browser will act just like the insecure bug ridden internet Explorer, but try and force the vendor to upgrade their site so that it works with modern browsers rather than having to stick with that old piece of software. That's dangerous as can be internet Explorer.
[00:40:29]I have always been fascinated by it ever since I saw people who were communicating, using computers and it, I always thought it just. It would be so wonderful if we could help people out, particularly people who are locked in who have a brain that's functioning fully, and yet their body isn't cooperating, they can't communicate, or they can't communicate well.
[00:40:54] And of course, that comes to mind. Of course, one of the greatest scientific minds of our generation, Stephen Hawkins, who was in a wheelchair, he was unable to move. And later in life, other than just a little bit with his face and mouth, and he used that to communicate. And it's just an incredible thing. I can't imagine being in a position like that.
[00:41:19] So when I see these technological advances that help people out, even in a minor way, I am just overjoyed, really overjoyed. So we've got to, I want to talk about right now. One is a brain implant that ARS Technica is John Timmer was talking about here about a week ago. And he was talking about robotic arms.
[00:41:42] Now you might've seen them before. There's various types of robotic arms and they have different types of functionality depending. Right. Well, one of the problems that we've had with robotic arms is how much force can you put on them? I, again, I remember the first time I saw someone who had lost, uh, the forearm and of course the hand and he had on one of those kind of captain hook things, appliances with a rubber band on it to close it.
[00:42:13] And he was able to pull one of the muscles in his arms in order to open it and close it. I thought, well, that's really cool. Those have advanced now, and there are projects with 3d printers. I forget the name of the company. I had them on my radio show. Maybe a decade ago now been awhile and they were selling 3d printers.
[00:42:34] And when you bought their printer, they would give you the plans to make a specific artificial prosthesis for. Child that couldn't afford one. So it might be for a leg or an arm or so I guess something else. And you bought the printer, they would provide you with the material that you needed as well as the design specifically for that person.
[00:43:01] And that you could print it up. It might take a couple of days and you ship it off. And many of these kids were in Africa. There are some here in the us, and of course in Russia, and this was, I thought an amazing project. It was just so cool again, because they're helping these kids get a little bit of mobility.
[00:43:21] Then we came out with some of these robotic arms that can be controlled through your brain. I don't know if you've seen these. Arms, there's been also some major advancement in just thinking about moving a cursor on a computer screen and the computer can track your brain enough to be able to move that cursor around.
[00:43:46] And basically what you're doing is you've lost a limb or you've lost mobility. You think about moving your hand or a leg, and usually it's your arm and your hand. And that can be picked up. Of course, that's per person, that's programmable per person. Then they figure out what the pattern is in your brain.
[00:44:06] And then they tie it all in so that now you can control a cursor on a computer, which means you can communicate. Robotic arms a little bit different because what you have now is something that can reach out. These things have all of the joint and the flexibility and functionality of a regular hand, except for.
[00:44:30] The feedback loop and that's been really important. How do you know if you are actually touching something? How do you know if you're squeezing it too hard? Like that egg and early robotic arms? It was very visual. So you watch that arm and you'd see, okay. It now has a grip on that ball or that pencil or whatever you pick it up and you all visual.
[00:44:58] And so you're able to pick it up and you know that you've got it. Maybe you don't know how hard you're holding it, but that's okay. You had to track the arm visually as you moved it around and estimate really when you had that grip, that was strong enough on the object by looking at it. And obviously that's just an incredible improvement over a missing limb or potentially paralysis, but it's not very intuitive.
[00:45:25] And the question is how do you make things intuitive for the brain when they're obviously foreign? We're going to talk about an extra thumb here in a minute too, but this is just absolutely phenomenal. It's called propyl. Yeah. Prope re O ception proprioception. And it's a sense that we have, this has been difficult to reconstruct that ties the sense of touch and pressure and.
[00:45:55] Knowing where something is. So you can close your eyes. And on the side of the road, when the police offers is there and close your eyes, hold your arm out and touch your nose. Right. Hopefully you can do that. I'm doing that right now, here in the studio. I'm touching my notes with my eyes closed with my arm, starting out fully extended.
[00:46:16] That's the sense we're talking about. That's very, very difficult. How do you build that in? Because we've been able to build in a little bit of sense of touch feedback for these arms, a little bit of pressure feedback, but we haven't been able to really understand how the brain processes, all this information that's sent by these sensory nerve cells in the hand, in order to let you know where it is.
[00:46:42] And what it's doing. So for this new research at team and planted two electrode arrays into the part of the brain that specifically handles information coming from the skin, and they're able to activate these electrode and produce the sensation of something, interacting with the Palm of the hand, as well as the finger.
[00:47:04] So they've made a whole lot of progress here, and this is very cool. They were able to tie it into a robotic arm. They got a study together, got some funding for it. And they got a participant who had been paralyzed from the neck down. And this doesn't save as male or female, but. Default gender right in English.
[00:47:29] As he sold, say, he'd been controlling this robotic arm for about two years by using brain implant in the motor control region of the brain. And he could successfully use the arm even without sensation. He'd gotten pretty good at it. Uh, so for these experiments, they had some different tests because they wanted additional, tactile feedback.
[00:47:53] They wanted to be able to somehow tie into this perception that your body has, of where your body parts are. Have you ever tried to tickle yourself? Usually it doesn't work. Right. But a third person or a second person tickling you may, it's definitely going to work. That's all party, these same systems. So they come up with a whole bunch of tests.
[00:48:16] I'm not going to go into a lot of detail on the tests, but they did say that having a sense of. Touch and the ability to understand where that arm and hand were in space, dramatically improve performance. And that makes sense. Hold on a sense to me, it w it really increased or decreased actually the time it took to pick up something to move something, to drop it in every case.
[00:48:43] So. I am pretty darn excited about this, and I hope it's going to be able to help a lot of people very, very soon. This is the university of Pittsburgh medical center, by the way, that's been conducting these experiments. Now there's another one I want to talk about. And I thought this was really cool. I saw this about a couple of weeks ago.
[00:49:02] I think it was, and this is a robotic extra thumb. What they did is they placed a robotic thumb on a hand underneath the little finger. So if you're looking at your hand right now, I got my left hand out in front of me. I've got my thumb here on the far left side. I've got my four fingers pointing up and on the right hand side opposite where your real thumb is, they put.
[00:49:30] An extra thumb, like a robotic thumb that can, can bend up and down and a little other lateral movements. This study, I think was phenomenal. And there were 36 people that were part of the experiment. This was at Danielle Clode, university, college, London, and her colleagues. Uh, and it's, it's phenomenal. So when we get back, I'm going to play a little bit of audio.
[00:49:57] That is from a story over there in the UK about this. I'm going to tell you a little bit more about this thumb and the. Impact to the hat on the brain. One of the things I think it was fascinating to me anyways, was it did change the brain in unexpected ways, basically the brains of these people. And this was determined by cat scans and watching the activity when they were moving their hand, the brains were changed.
[00:50:27] Two, if you will, uh, look at the hands and as more of a single unit than individual units. I thought that was really fascinating and that extra thumb became part of the brains understanding of the hand. So this is the kind of thing we can be looking forward to. Now, this one is it's kind of cool. It's kind of fun.
[00:50:53] We're going to find a lot of different uses for, and it's part of what's fun is what they did in the experiments. So we'll talk about that as well. Hey, I want to point out if you have questions about cyber security, I might have the answers for you and you'll get those answers in the form of some stuff.
[00:51:13] Special reports. I wrote, if you subscribed to my email list, just go to Craig peterson.com/subscribe, and I'll make sure I send them all to you and get you on the right track.
[00:51:25]this is augmenting a human and I think this is the future. We are going to be augmented. And how many movies have been made about that movies where they're saying model? Yeah, we'll just tie basically Google into your brain and have Google site into your brain.
[00:51:41] That have as a thought. And you'll get a response from Google, which I think is scary. Look at Google now and how they're tracking you. Imagine if they get a copy of every one of your thoughts, but things like this that make us super human. I think are going to become more mainstream. So Google, for instance, had the Google glass, you might remember that these glasses type things that you wore, Apple's done some work on something similar.
[00:52:11] And the idea is they can project in front of you an artificial reality. Maybe that our official reality is just telling you to turn left, to get to grandma's house or where the best food in town is. Or maybe you're playing a game. All of which are cool. This that's going to happen. This is really something that is going to happen.
[00:52:30] And it's going to talk to you with a set of speakers that are right on those glasses. And it's going to be, I think, potentially amazing not reading your brain, but helping you to navigate a, read an audio book to you, do all kinds of things, and you can already get Alexa. Which is, of course Amazon's digital assistant in a lot of different configurations from your car all the way on out through these little mobile devices.
[00:52:59] In this case, we're talking about a third thumb and that third or second thumb, I should say, it's really a third one because you have two hands, right? Two thumbs, but a second thumb on one hand. And the pictures I'm looking at from the experiment had it on the right hand. I don't think it really matters, but it's opposite your normal thumb.
[00:53:20] It's not a fancy thing. It doesn't look human. It's close to the wrist. W on your hand, but it still is on your hand and you control this thumb and how it moves based on why our wireless sensors that are on your big toes. So you wiggle the toe and you can move the thumb in different directions and also have it clench the grip.
[00:53:49] And these experimenters gave the thumb to people for about five days and the participants were. Told to use the thumb in regular, old things in the world. So they use it in the labs, of course, and they wanted the participants to really push the envelope about what was possible. And they didn't want the lab to just think of all of the different experiments they wanted the participants to think of things.
[00:54:17] Maybe they hadn't thought of. So I'm looking at a video that's really cool people think of this guys. You can hold a cup of coffee and stir it all with the same hand, because you use that third thumb to grab onto the coffee and then your right thumb and forefinger. In order to stir the coffee. I think that's cool.
[00:54:42] There were other people did things like bloom bubbles, right? You hold the little bottle of the bubble soap, water. And in the fake thumb. And then again, use your fingers to hold the little thing that you are blowing into. So it's really cool. And it did change the brain. What this showed us, I think more than anything else was our brains are capable of controlling limbs and dependence pended, GS dependencies.
[00:55:14] Yeah, appendages. There you go. That, that you don't normally have, and it leads him into think about cats here in the Northeast. I don't know if you've ever noticed cats with a thumb. Have you ever noticed that it's really a Northeast phenomenon? And apparently the captains of these old boats loved these cats because they could go on the ship and chase the rats and kill the rat and hold on really well in the heavy weather and even climb up on the ropes because I had a thumb, we had a cat like that.
[00:55:52] And it wasn't the brightest cat one, a Fox caught it when it was in our yard one time, but that cat could pick things up off the floor and using the thumb. Now, cats don't normally have a thumb, but some of these cats here in the Northeast, they have a thumb. It's a real thumb. They really can pick things up.
[00:56:12] So they, this experiment proved that we can, as humans control an appendage, like an extra thumb. So let's play a little bit here about what happened a little bit of the report. The
[00:56:26] Unknown: [00:56:26] additional thumb could cradle a cup of coffee while the same hands, four fingers held a spoon to stare in milk. While some participants use the thumb to peel a banana, blow bubbles, or even play the guitar to understand how the extra thumb effected people's brains.
[00:56:40] The researchers gave them an MRI scan before and after the experiments.
[00:56:45] Craig Peterson: [00:56:45] Is that cool or what. And you can find more online. I duck goat it, you can just duck, duck go a robotic extra thumb, and you'll be able to find the video and more reports on it, but we will see what ends up happening. With our appendages what are we going to be attaching to our bodies in the future?
[00:57:07] We know we are going to be using those glasses like Google glass. We'll see what it ends up looking is it going to project right? Enjoy your eyes. What's going to happen here. We're seeing heads up displays in our cars where the speed you're going, the maps, et cetera, are projected right on.
[00:57:25] The windshield. So you don't have to move your head a big direction, in order to see what's going on. So lots of stuff. And we're starting to understand the brain a little bit better when it comes to some of this stuff, dark side. My gosh a little bit of, a little bit about the dark web, because you guys are the best and brightest, right?
[00:57:47] So the dark web of course, is that part of the internet that was created to keep things secret. No, not totally secret, but the identities of people posting things on the dark web are hard to determine. And it is in fact, something that is maintained by our military and was developed in order to allow people in other countries to communicate effectively with the CIA, with the military, et cetera, without.
[00:58:19] Being caught by their government. So the dark web is a pretty secure place, but because of that, it's a place where people go to conduct illicit transactions. This is the place where the. The major site that was out there that it's called silk road was man, I can't remember how many billions of dollars they say went through the silk road website, but they were selling everything you can think of for drugs or drug running, a gun running some of these military weapons.
[00:58:58] you name it? I don't even want to talk about some of the stuff that was being sold there on that website. Now there's other websites and taken over, but we caught that guy by the way. And all the transactions were in between. Coin. So those people that think that Bitcoin is somehow impossible to track you are wrong.
[00:59:19] And those who think that the dark web is a place where you can go and really be anonymous. Again, you are wrong. More technically we're talking about something called the onion network, the Tor browser, and it is an interesting thing. So when we get back. We're going to talk about a court case, a really weird court case involving the dark web.
[00:59:47] You've heard before about trust amongst thieves, this kind of throws it entirely out the window, shall we say
[00:59:56]You might've heard of DarkSide. I mentioned them here on the show before. DarkSide is a bad guy, right? It's a group of people that got together who had been experts at ransomware. And so what they ended up doing is deciding, Hey, we want to make a business. We're going to do ransomware. And because we're so good at it, we're going to sell ransomware as a service.
[01:00:28] And this ransomware is a service. All they did was they would take a cut of what you made off of their ransomware. They do things like provide tech support. So you ran some poor guy, some poor, small business, and that small business now is, a really hurting and you say Pay up sucker.
[01:00:50] It's going to be whatever it is. I think most of the time for very small businesses, about $40,000 and you need to buy Bitcoin and you can't how to have a lot. I don't know. Why do I buy Bitcoin? So you contact. To the DarkSide, a webs support site, and guess what they do at that point? They can help you.
[01:01:13] Okay. So go to this site. This is what you're going to see. Click on this. They have little user guides. They will help you when you're encrypted. Do you just give them the key and they'll tell you, okay. So use this key and this software to decrypt it. Just like a real business bottom line. They disappeared.
[01:01:32] You might've heard about this. Of course, DarkSide attacked the colonial pipeline. And if you live in the Southeast United States, you were hit perk too. Darn hard by this, because that shut down over a thousand gas stations, they ran out of gasoline because it was not getting shipped via the pipeline. So off they went and a DarkSide said there, I think there's a little too much heat here.
[01:02:03] At least that's what we were thinking. Initially DarkSide was trying to avoid prosecution. And so they shut down their website. Where was the website? Obviously? Wasn't out there for you on DarkSide.com. No, it was on the dark web while they shut down. And apparently they were not paying out these people that they were providing ransomware services to.
[01:02:32] Isn't that kind of interesting. So Russian speaking person, you use the handle darks up for DarkSide support had XSS dot IIS. Guess what that is. Yeah, a recruiting site for these bad guys. Now, you're not going to be able to get there. If you're not on the dark web, you shouldn't be able to get there just in general, but he was trying to recruit him affiliates for DarkSide and DarkSide was the new ransomware as a service kid in town.
[01:03:05]And it was looking for business partners until a partner could come along and say I have a hundred million email addresses or. I'm going to go after a company X like colonial pipeline. And so they become an affiliate of DarkSide. And as an affiliate, now they can send out the ransomware, try and get somebody at colonial to click on it.
[01:03:29] And then once inside then DarkSide takes over and they go ahead and download important files from the machines that are compromised. That's part of the one-two punch that they were doing. And the punch that we saw that happened on Metro PD down in Washington, DC, where the bad guys got in down there and threatened to not decrypt stuff unless a paid up.
[01:03:57]And then secondarily, you said. Since you're not paying that ransom, pay us this ransom and you have so many days, or we're going to start releasing information from the private police records. And they actually did end up releasing some of that information. All of that sort of stuff is part of the ransomware as a service.
[01:04:16]This is interesting and DarkSide has made a bunch of money. There's some newly released figures from a company called chain analysis and they track cryptocurrency. Trading. Yeah. Guess what? It's not completely private. So chain analysis said the DarkSide netted at least $60 million in its first seven months.
[01:04:44] That's a small fortune. Actually that's a pretty big fortune 46 million of it. Came in the first three months of 2021 and Darkseid made another $10 million this month with about 5 million coming from colonial pipeline. You probably heard about that. Colonial paid the ransom. And I saw an interview with the CEO of colonial, who said we didn't know if we'd be able to recover.
[01:05:13] And it's basically, it's a small business, my words, small price to pay to know we can get back in business. So they made the 5 million from colonial and 4.4 million from the chemical distribution company known as Brenntag. And then last week, DarkSide went dark. And I mentioned that on the show as well.
[01:05:37] And this guy, dark sub said that his group had lost control of the infrastructure and it Bitcoin. Does that mean that maybe Interpol the S somebody shut them down because. We have verified that there was a huge transaction where all of the money was taken out of their bit coin account. Okay, so the servers can the access to anymore the hosting panels to see panels been blocked and the hosting support service isn't providing any information, except quote, you ready for this at the request of law enforcement authorities.
[01:06:25] Okay. Yeah. And within a couple hours of the seizure funds from the payment server were withdrawn to an unknown account. And Darkseid hasn't been heard from since now DarkSide is supposed to be paying affiliates 75% of ransoms that are less than $500,000. And that cut rises to 90% for ransoms higher than $5 million.
[01:06:55] So DarkSide gets the money, right? Cause they're doing this whole thing. It's a service it's service provided to the bad guys out there, but apparently these affiliates have not been paid. Apparently the ransomware as a service provider of did not honor its commitment and the affiliates, these bad guys, I feel so sorry for them.
[01:07:22] Not they've been asking to be reimbursed from a deposit about a million dollars. The DarkSide was required to make with this website X access, which is one of these sites on the dark web, where they are setting up these deals. Okay. So there's three posts on the site. Where there are plaintiffs who have filed charges against the defendant against DarkSide.
[01:07:53] So here you go, honor. Amongst thieves, DarkSide did not honor its financial commitments. It did not pay the bad guys. The ransomed people. Like they were supposed to they've disappeared and apparently their servers have been seized and all have DarkSides, holdings have been taken. All right. Interesting.
[01:08:19] That's what you get DarkSide disrupted gasoline supply for the huge swaths of the U S about two weeks ago. And no doubt, the FBI brought full force of its might onto DarkSide. And I also know personally that historically the secret service has gotten involved too.
[01:08:40]Electric vehicles. We've talked about a lot. I had a lot of fun talking about, of course, that great Ford electric vehicle in the first hour of today's show.
[01:08:52] And they've got some cool looking cars, but they're coming out of everywhere. Now. You've got Italy with a few manufacturers that are now right. Pushing out the cars GM of course has had them for quite a while. The volt Nissan has had theirs. Ford has a couple, including the Mustang, the new electronic Mustang.
[01:09:14] There is some good things to say about them. I love the technology myself. I prefer to have something that can go a long distance. I can't really have two or three cars right now. And they might make a nice little car. If I was commuting just a few miles or maybe if it was cheap enough, I would use it to run to the grocery store.
[01:09:37] But looking at the cost of these vehicles like that, that Ford pickup truck fully maxed out, fully loaded. I looked it up. During the break it's $90,000. That's crazy money. And even though it starts at 40,000, well $39,999 95 cents. Even though it's a $40,000 start. That's a lot of money to pay for a car is especially with these batteries, there's next generation stuff coming out.
[01:10:09] That's going to be just phenomenal. That's what I'm waiting for, but here's part of the problem. We're looking at electric vehicles and there's so many things to talk about, but electric vehicles do not pay the taxes that are used to construct our roads and maintain our bridges and our roads.
[01:10:30] There is a per mile tax that is added on by the federal government and by the state governments. But it isn't computed as a per mile tax. It's computed as an add on to the price of gasoline and the price of diesel. What they're doing is they figure okay your fuel mileage may vary. And they had a big hit, of course, when fuel injectors came into cars, because they basically doubled the fuel mileage, but they say, okay, so the average car is getting 20 or maybe 25 miles a gallon and his pain anywhere from about 50 cents to a buck, a gallon in.
[01:11:14] Road taxes and those road taxes are supposed to be used to build new roads, maintain existing roads and bridges by the states and by the feds. And again, that's a topic for another conversation. So how about electric cars? They're not buying gasoline, they're not buying diesel. So those vehicles are really putting a major dent in the road budget for the feds and the state government.
[01:11:46] We've got states like California, Massachusetts, and New York who want to completely phase out any fossil fuel vehicles by 2035 and Washington state plans to follow the California rules and phase out sale of gas powered cars by 2035. But there's a huge hitch in those plans. How do you have these electric vehicles, including that Ford F-150 lightning hit the road?
[01:12:18] Because gas sales will continue to decline along with the revenue from taxing them. It's a very big deal. So what do you do while there are some bills that have been moving in? All of those states had just named, including Massachusetts, where they're saying we need to charge people. Per mile when they're driving within our state, how do you do that?
[01:12:48] Charging per mile means, how many miles they're traveling? You could certainly set up something like easy pass that covers the major highways, but the major highways are not where everyone's always driving. Think of the state routes we're on all of the time that have no toll ability. And of course, all of the side roads, how do you tax it while there are things that say maybe we use an easy pass type thing only on the bigger roads and we're charging by the mile.
[01:13:21] That's just going to drive people off of those bigger roads that are meant for traffic onto the side streets. I've seen that happen before in my own town. There are other things that are being proposed that include having the car report on miles driven within a state. So the car would have to have GPS information would know when it has crossed state lines and then keep.
[01:13:51] Tabs on how many miles it drove in the state and
[01:13:55] then
[01:13:56] Craig Peterson: [01:13:56] report that to the tax authority for you to be charged. How would that be to have at the end of the year, right? This additional tax burden based on how many miles you drove. Yeah, that would be a lot of fun. And then there are other proposals while we'll just look at all of the vehicles that are registered in our state.
[01:14:16] So again, in mass it would be when you go in for that mandatory vehicle check every year at your birthday, we will read. Your car's mileage every year and we'll discharge you by the mile. They don't care if you drove up and down to Florida most of the year or out to Texas, or most of the year back and forth to California from mass.
[01:14:40]All of that would be charged against you. So there are a lot of debates going on to try and figure it out. How can we make this work? The feds have a gas tax that hasn't changed since 1993. So the federal gas tax is 18. 0.40 cents per gallon. And then you have the state taxes and most states have increased their fuel taxes since 2010 to beginning to, to bring in more money and fix the roads.
[01:15:15] But this is going to be difficult. Some states, including California, Hawaii, Minnesota, Oregon, Utah, and Virginia have implemented road, user fees. A lot of questions there. It's so easy to collect a gas tax. It's hidden away in the price of the gasoline. Are they just going to put an extra tax on electricity and say, the average home is using so many kilowatts for their cars and do it that way.
[01:15:43] We really don't know. We just don't know. And our roads I think, are going to suffer until we figure that whole thing out. We've talked about some of these big hacks. And I was talking with a client this week about the whole solar winds hack. And where did it come from and what did they do? The solar winds hack.
[01:16:07] It looks like came in through Microsoft exchange server. There are a lot of patches out there for exchange server. If you don't have it. Pay close attention, try and figure that whole thing out. Okay. It this is a very big deal, but these reasons, cyber security instances in incident are really a reminder to all of us that public and private sector entities are being attacked from nation state actors and these big cybercriminals, like what we were just talking about.
[01:16:44] Here's our big question, who was behind the solar winds hack. Remember we talked about it here. The reports coming out of the federal government in the U S were, that was Russian intelligence was to be hunted it's Poot and blame Puente. Oh no. It's a Russian. Hacker gang, nothing to do with Putin.
[01:17:06]Maybe Putin was, giving them a little bit of a nod, it was a Russian hacker guy, gang. Things have changed a little bit. They announced here, but Microsoft being there. Microsoft announced in March that a detected multiple zero day exploits being used to attack the exchange server and a hacker group that they dug half a numb, which operates primarily from least virtual private servers in the U S so think about that.
[01:17:37] And what does that mean least. Virtual private servers. That's everybody from GoDaddy through Amazon all the way on out. Everybody now has these virtual private servers and they also installed additional malware so they could get long-term access to these victims networks. Where do they come from?
[01:18:00]Microsoft wrote in March that half of them operates from China. And this is the first time we're discussing its activity. And he called the Chinese hacker group, Microsoft here, a highly skilled and sophisticated actor that primarily targets entities in the United States. For the purpose of exfiltrating information from a number of industry sectors, including infectious disease, law firms, higher education institutions, defense contractors, policy think tanks and NGOs non-government organizations.
[01:18:37] Now, cause I've talked about it before that we've been called into organizations and D found indications of compromise that were coming from China. And that's what it looks like. It came from a huge attack. It, it hit pretty much every one of our lives in one way or another through the companies we deal with.
[01:18:59] But the Biden administration has been silent on attributing the attack to China. They won't say the China was doing this at all. And they are completely blowing it off. Yeah. All of the questions about it. So it looks like it was China that did this. The Biden administration is unwilling to say it was China for whatever reason.
[01:19:25] They are very willing to attribute it to Russia. And I don't know, maybe this is another, yeah. Russia, like we've seen before. Hey, everybody, I want to invite you. Make sure you get my newsletter. When you sign up, I'm going to be sending you some special reports on passwords and what to do with your cybersecurity.
[As heard on WTAG, WHYN, WHJJ 2021-05-25 - Automated Transcript]
Craig Peterson: [00:00:00] On with Mr. Polito this morning, and we gave a little bit of a eulogy to Microsoft internet Explorer. Finally, almost gone. And I don't know if it will ever be completely gone. So here we go with Mr. Polito,
[00:00:17] Jim Polito: [00:00:17] Our good friend, Craig Peterson, nothing like a little rage against the machine. To introduce our tech talk guru, the master of all machines, right?
[00:00:33] He is our tech talk guru here to talk about the death of Microsoft Explorer. What is that? Joining us now? Craig Peterson. Good morning, Craig.
[00:00:48] Craig Peterson: [00:00:48] Hey, good morning. Microsoft Explorer of course had been used for years by Microsoft in order to let you go online. And it was the source of a major lawsuit against Microsoft.
[00:01:02]Right now you're talking about what's happening with this whole apple lawsuit and what directions is going to go what's happening? Microsoft had this major problem years ago, and that is. It did not have anything to do with the internet at all. Microsoft was a very much a late comer to the internet and to all of the connectivity that comes from it.
[00:01:26] And so what they did is they stole, borrowed some software from NCSA, this lab over in Europe. And use that as a basis to create a web browser. And since of course, Microsoft didn't really care so much about the internet as they never put much thought or work into it. However, Many of these kids that are doing programming thought internet Explorer is the way to go.
[00:01:54] And the people who were running the businesses who had windows on their desks, they looked at it and said in genetics blowers, what we need to do. So a large percentage of businesses over 50% of businesses designed their website. To work with internet Explorer and never bothered checking any other web browsers out there to see if they were compatible.
[00:02:19] Yeah. So Microsoft got even more and more into this and Microsoft added things to internet Explorer made it the most dangerous browser on the internet. It allows a website to take control of your computer. It allowed websites to download malicious software and start running with it. It might be Microsoft.
[00:02:41] It just sometimes drives me crazy.
[00:02:44] Jim Polito: [00:02:44] Let's roll it. You've just put a lot out there. So let's just go back and take a look at it. First of all, Dan and I were laughing earlier and you just said it. Oh, Microsoft didn't think this internet was going to be a big deal. Yeah. So bill gates is our real genius.
[00:02:59]Something comes along like the internet. Eh, so Netscape was really the big browser in the beginning. Am I correct?
[00:03:07] Craig Peterson: [00:03:07] It was one of the early Browns. Yeah, very popular one. The internet didn't really start really going anywhere until the browsers came out. NCSA mosaic was really the first one.
[00:03:22] Wow. I used that one extensively way back when and yeah. Firefox has been around. Yeah, Microsoft. Yeah. As part of an incredible internal arrogance decided that it would wire internet Explorer into the operating system, for lack of a better term, you could argue that Microsoft has never had a true operating system until the latest ones, but it hardwired the men.
[00:03:51] So now. You had places like Firefox Mozilla project and some of these other like Google, et cetera. Say, wait a minute wait. We have browsers. And there is no way to delete internet Exploder off of your computer. Oh, I forgot about
[00:04:09] Jim Polito: [00:04:09] that. Nickname, internet Exploder. Greg you're, we're talking with our tech dog guru, Craig Peterson.
[00:04:15] We're having a little bit of a way care. He's performing the eulogy for internet Explorer. So they get rid of it. Does that mean that Microsoft is out of the browsing business?
[00:04:27] Craig Peterson: [00:04:27] Oh, I never very big way. See Microsoft decided that people fought that Microsoft was it, they're the go-to people.
[00:04:35] And so they said we've got to get rid of, first of all, we've got to get out of the operating system because the courts ordered it. And so they finally did. And so now there's some competition in the browser space and then they came up with. The edge browser, you could still use internet Explorer on your windows, computer, and still came with it because so many websites were so poorly programmed.
[00:05:02] They would only ever work with this one browser. So they came up with the edge browser, which was their answer to everything. And of course it didn't work so good and it didn't work with most websites that had any complexity to them. And so they came up with another edge. Browser and they called it an edge because it was a completely different browser.
[00:05:23] And then they went and said, okay this just isn't working so well. So nowadays Microsoft edge browser is, do you have a drum roll? Oh yeah. Hold on. Hold on a second. I got it. Ready. Alright. Here Microsoft edge is actually Google Chrome. Are you kidding? There you go. No it's based on what Microsoft did is Google had open source.
[00:05:55] In other words, it made available the source code, the program, and they call the chromium and chromium is the base for for the Chrome web browser, Google Chrome web browser. Wow. So now Microsoft edge, the latest versions of edge, they have completely benched all of them. Terrible software or web browsers anyway, still got plenty left.
[00:06:19]And they are now, if you're running Microsoft edge, you are actually running Google Chrome and Microsoft of course has made changes to it and is tracking you in different ways. And Jen number one question I have from listeners really is. What browser should I use? And
[00:06:38]Jim Polito: [00:06:38] Your answer to the question?
[00:06:41] Craig Peterson: [00:06:41] Sure. It depends but Firefox. Wow.
[00:06:47] Jim Polito: [00:06:47] I haven't been I haven't been using it. Here at work, I use Chrome. I didn't use it on my home laptop Firefox. But I hardly use my laptop at home. Anymore, because I use my smartphone or my tablet to do most things when I'm at home. So that's all very interesting now let's move on to something that came up earlier and you made the recommendation, is that Jim start using duck go.
[00:07:20] For your searching because they don't track you and they have a better rhythms. They don't get political with their algorithms. You said, Jim, if you're going shopping, yes, Google is still the best place to go. But if you want information, it's duck go. This came up earlier because we've been discussing the power.
[00:07:44] That Google exerts in politics. And, there's real evidence that if you search for a liberal candidate for office versus a conservative, you're going to get. Better results of the liberal or the liberals results are going to be at the top of results, as opposed to a conservative and Google will say it's the algorithm, it's based on hits and bologna, people make out algorithms.
[00:08:12] The algorithms don't drop from the sky, right?
[00:08:15] Craig Peterson: [00:08:15] Yeah. You're absolutely right. Yeah. And there is no such thing as artificial intelligence, at least not in this day and age, but here's the, I, I mentioned this to you before I think, but here's that quote from a study that was done in a top on this is student news daily.
[00:08:32] But he was talking about a study that I read. We found significant pro liberal bias on Google enough, quite easily to have flipped all three congressional districts in orange county, California for Republican to Democrat. Okay. Very big deal. And that the study looked at the 2016 looked at 2018 as well.
[00:08:57] I haven't seen any good studies out yet about 2020, but Google and in you. And I saw this Google goes in and. Purposely makes changes to the recommendations, their search results. So you can look for a story and hardly find any evidence of it. And yet that story was covered by all of the major news agencies, NBC, CBS, MSNBC, CNN, you name it, they all discuss it.
[00:09:28] And yet you look forward on Google and it just doesn't show up. So you're right. And now the rhythm of a computer program is written by a person. Computers are not writing the code and there are biases in everything you and I would agree. We're bias, right? Thousands of articles, of course, thousands of articles.
[00:09:51] And I put together six to 10 of them every week that I think are important. That's showing some bias why you thought they were important. And that's the reason you're talking about things today, George foil, and then other things, right? Because you think they're important. And so that bias leaks out.
[00:10:09] And when it comes to Google and almost all of these big tech, not only does it leaked out, they enforce their bias on. You, which is why I recommend duck go. And then for browsers, Firefox Mozilla Firefox is a good general browser. There are some reasons not to use it. And I still recommend epic API C if you want very private browsing, if not, quite as good as it used to be, but it's also okay.
[00:10:39] Based on chromium. It's basically Google Chrome that they ripped. All of the tracking code out of epic browser.com is where you can find it online. Oh, this has been
[00:10:49] Jim Polito: [00:10:49] fantastic. Very helpful as usual and Firefox and duck go. And that is Craig's opinion, his well-educated opinion, but that's his opinion.
[00:11:02] Look. Greg, I've got an example for you, and then I've got to let you go, Kathy and I went to a museum. With the boys in New York city this past weekend and the museum, the it's called the Frick museum. It's right near the met and their location is undergoing renovations. They're actually in an old mansion.
[00:11:23] And so they're in a temporary location where they couldn't show their entire collection. So they picked from their collection. What they thought was best, the curator. Came up with what they thought was best in their opinion, in their collection. And that's exactly what Google people are doing, except it involves politics, not art.
[00:11:51] Yeah. Politics. And that's the issue I have with it. I'll take the opinion of a curator who will say, this is what we think is the finest in our collection, but not Google. No, not it comes to politics.
[00:12:06] Craig Peterson: [00:12:06] Yeah, absolutely. Yeah. And you're right, doing that doctor go by the way, you can set it as your default search engine on your Android device, on your iOS device, on your computers.
[00:12:18] You can, it's integrated everywhere. It's just not the default. Yeah. I think
[00:12:22] Jim Polito: [00:12:22] it's great. Craig, how is your lovely wife doing? How is her recovery going from her fall?
[00:12:27]Craig Peterson: [00:12:27] I am totally amazing. You saw the doctor yesterday. And she is only three weeks now, post-op emergency surgery and she's doing better than most of the patients had six months.
[00:12:40] Wow. So amazing. Yeah. She's, I'm doing amazing. That's great.
[00:12:45]Jim Polito: [00:12:45] The center. Our best. And then how do people get in touch with you so that you can send them while your best?
[00:12:52]Craig Peterson: [00:12:52] If you'd go to Craig peterson.com/subscribe, you can subscribe, get the newsletter. I'm going to send you a bunch of little special reports there, five to 10 pages telling you what to do to help make your life safer. All it's all free. Okay. I'm going to try to squeeze you for anything, but you do have to sign up and I'll send those to you all automatically. You'll get my, not quite weekly with Karen down newsletter as well. And you can also get links right there to the podcast, so you can listen to my whole shows on the weekend.
[00:13:27] Great.
[00:13:27] Jim Polito: [00:13:27] Craig Peterson everybody, our tech talk guru, Craig, I look forward to it talking with you next week.
[00:13:33] Craig Peterson: [00:13:33] You too, Jim. Take care. Thanks.
[Following is an automated transcript of show #1114 aired on weekend of 2021-05-22]
Craig Peterson: Hi everybody.Craig Peterson here. We're going to start out with a couple of Tesla articles in the news this week. These things are really not self-driving. I don't care what Tesla calls them and some problems people got themselves into.
[00:00:21]Tesla has had all kinds of news. And sometimes I wonder what is happening here?
[00:00:28] Is this Elon Musk, just trying to get a little bit more notoriety? I don't think so. Because there have been so many negative articles out there. One of the reasons I would be extremely hesitant to buy a Tesla has to do with the door handles. Something as simple as the door handles, you probably know for a decade, I was a volunteer in our emergency medical squad here and was doing paramedic work for anybody that needed it.
[00:00:59]No charge. I wasn't charging the town wise, but. It was something where I got to see a lot of accidents and sometimes I was first on the scene, beat the fire department there sometimes even beat the police department there, although there were normally their first because they're out on the road and I'm at home in bed asleep in the middle of the night.
[00:01:19]I saw, as you can imagine some horrific things and all of you guys that are first responders listening, you've seen some just terrible things as well. And one of the things that really bothers me about the Tesla are the handles. The door handles the outside. Door handles to be a little more specific.
[00:01:38] Tesla has had some amazing crash tests. I don't know if you've seen them, but these Tesla cars broke the testing gear over the national highway transportation safety board. They had to come up with new tests because these Tesla cars just. Took those crashes and did extremely well. And seeing what Elon Musk's company space X has been able to do with these rocket ships, they have mastered the art of having a computer kind of predicted.
[00:02:10] What is going to happen in various circumstances. So it wasn't a huge surprise for me to see that they said, Hey, yeah, you're in a car accident. One of these things that these cars were scoring at 11, a 12 out of 10, they were just that good. But the problem I have with that handle is exemplified by an attorney.
[00:02:33] I think he was out in Los Angeles, who was in an accident. And I remember in the Tesla cars and all of these electric cars, there are batteries. And the batteries are typically some form of lithium ion, and there's a lithium glass. That's under development, all kinds of cool stuff going on with those batteries.
[00:02:51] But the reason they're using them is that they hold a huge charge because you don't want to just go 79 miles on a charge. Most of the time you don't. One of the reasons I'm not real fond of electric cars is when I'm going for a drive, I'm going for a drive, right? We'll drive to Florida.
[00:03:10] We'll drive to the middle of the country. We'll go up to Montana to British Columbia. So a lot of people are saying, okay, so you just go ahead and you get a gas powered vehicle for that type of driving, and then you can use an electric car for most of your driving. So if most of the driving that they're talking about is the number of times I get into the car.
[00:03:31]Then that would work, cause most of the time or money into the grocery store or running an errand here or there. So an electric car probably would be okay for that now. I have gotten many times before into the science behind electric cars and how they are nowhere near as green as even diesel vehicles are nowhere near.
[00:03:53] When you consider the entire life cycle, the manufacturing all the way through how many miles you can get out of these things. But the concern with this attorneys' crash was that the batteries were damaged in the crash. And you can imagine what that means, right? You get rear-ended, you get hit in a certain way that battery pack is impacted.
[00:04:17] Things can happen. And our friends over at MythBusters back when they were still on TV, did a little test on this. They built a rig in the back of a garbage truck, because there were stories about these garbage trucks getting caught on fire and catching on fire. And the theory was while it's lithium batteries.
[00:04:39] And we're talking about small ones, they're the type that you have in a small cell phone. So they built a rig in the back of the truck, the garbage truck. And the strapped a lithium-ion battery to the front of this rig, which was a wedge, right? Cause they wanted to make sure that it bent and bending that battery now, cause day short, remember these batteries are designed to hold as much power as they possibly can.
[00:05:07]If you have a short circuit inside of battery, what's going to happen. Think about a, an old light bulb, the Edison bulbs that we had for over a hundred years, and those bulbs had a filament inside. And that filament, when it was heated up, what did it do? It. God gave us light and it also gave us heat.
[00:05:28] The heat is the problem here because our MythBusters friends were able to get that battery to ignite in that rig. And of course it ignites inside a trash truck. Remember trash trucks are always compacting everything. If it goes ahead and ignites inside that maybe you catch the trash on fire. In fact, they were able to get it.
[00:05:49] To catch on fire. And this attorney's Tesla caught on fire in the accident. Now, when you have passers by who see an accident, usually they'll stop and they'll try and help. We're that kind of thing. People were all good Samaritans, at least almost all of us. And I have no remember remembrance at all of it, a single car accident where I got there.
[00:06:13] And there was no one there. Sometimes it was just the police officer, but there's always someone who tries to stop. So these people who stopped to try and help this guy who was in his Tesla could not open the doors. And the reason was that the Tesla has these recessed handles. Yeah. They look cool. GM.
[00:06:34] A lot of the GM vehicles have had those handles over the years. And again, it's not something I would drive because of that. There's nothing to grab onto because sometimes in an accident you need to pry that door open and by prying it open, grab a handle a good solid handle and pull hard on that handle.
[00:06:57] And if you can pull hard on that handle, you can open that door sometimes if it's just that the frame's bent a little bit and you can get that person out. And in this case, that attorney was not able to get out of that car. That battery was damaged and the battery heated up and caught on fire. And we'll leave it at that.
[00:07:19] You can imagine what happened. So the Teslas have done very well in crash tests, but. They have not done well when the batteries are damaged in a certain way. And that's why I have a bit of an issue with it. But we got two articles in the news this week. This first one's from Reuters and that'll be in the newsletter that comes out on Saturday, but a Tesla driver was killed in an accident out in California.
[00:07:46] And this guy was one of these tick tock people, tick tock, that's that website where you can put up these short videos. And oftentimes there's a theme. There's a whole series of themes. People, post videos using the same music or whatever it might be. And he had posted videos on what a beard to be his Tik TOK account in which he was driving with this hand off the route, the wheel.
[00:08:14] Now you can obviously take your hands off for a second or two and almost any car. And I don't know that I would consider that safe, it, it happens and it's happened before, but he was posting these pictures and praising Tesla's self driving. In fact, he said full self-driving features. May 5th and Tesla model three crashed into an overturned truck on a highway in Fontana, California, if Southern California, nowhere Fontana is there.
[00:08:46] You might anyways. And that crash, of course, as I mentioned, killed the Tesla driver, injured the truck driver and a motorist who had stopped to help him. So again, we're seeing the problem with these self-driving features. And you might remember a few months ago, I was talking about a little study that was done.
[00:09:09] They made police cars out of a balloon. It was just a big blow up car. That was a balloon. And they put it part way in a lane, just like a police officer might stop someone and being partially in the lane. And then they had different self-driving cars or cars that had, the autonomous semi-autonomous mode the follow behind mode, et cetera, go down that road and see what happens.
[00:09:34] And they kept hitting the cop. In this case, we're talking about an overturned truck on a highway. And apparently Tesla got it wrong. The associated press was citing. The police saying preliminary investigation determined that the Tesla's driver assistance system autopilot was engaged prior to the crash.
[00:09:58] And. I've got a problem with them calling it an autopilot because it isn't, it's not like an airplane where you engage the autopilot and then you just keep a basic eye on things. People are treating it like it's an autopilot as in you can go to sleep. And when we come back here in just a minute, I'm going to talk about something just like that with another Tesla driver.
[00:10:21] So there's no final determination as to what driving mode the Tesla was in. But there's a couple of videos of him driving with his hands off the wheel, posted on his alleged Tik TOK account, 35 year old, Stephen Hendrickson running Springs in California, and a couple of quotes from him. What would I do without my cell driving?
[00:10:43] Excuse me, full self-driving tests. After a long day at work, he said, I messaged them. One of them coming home from LA after work. Thank God. Self-drive best car ever. So when we get back, we're going to talk about this a little bit more. What are people doing with Teslas and what should we be doing? Where are we going?
[00:11:05]Frankly, I think we're jumping the gun here. Hey, you're listening to Craig Peterson. You'll find me [email protected].
[00:11:13]And we were just talking about Tesla, my biggest fear with Tesla, the biggest problem as I see it, the reason number one reason I won't buy a Tesla. Which has to do with the door handles and not being able to use them to easily pry out a door and occupant of the vehicle because yeah, they're supposed to pop open.
[00:11:38] Yeah. They're supposed to open, but in this particular case I'm talking about, they just did not do it, which is a real problem. Very problem. The national highway traffic safety administration has been investigating. This is according again to Reuters, more than two dozen crashes of Tesla vehicles, including this Fontana crash and a high profile crash in Texas last month that killed two men.
[00:12:06] Since 2016, at least three Tesla vehicles operating on autopilot have been in fatal crashes. Two involving a Tesla car driving beneath a semi-truck in Florida. The U S transport safety board said Tesla's autopilot system failed to properly detect a truck as it crossed the car's path, contributing to the accident.
[00:12:29] Also caused by a lack of driver attention and an adequate driver monitoring system. Now you can't say three or four crashes of a Tesla where there was a death involved represent much without knowing how many miles are being driven. It's like people saying yeah, it's way safer to fly in an airplane than it is for you to drive your car.
[00:12:57] And yeah, if you're talking about miles driven, that's very true. The airplane is safer than the car and yeah, at this point it actually looks like these Tesla cars might well be safe for then a car operated by human. It is borderline. You could argue some of the statistics I've seen them argued both ways, but it's not a bad vehicle from, from the general safety standpoint.
[00:13:27] But as I said, we've got another Tesla story this week, and this is from a guy his name's param Sharma 25 years old lives out in middle California and in the Bay area. And he has been arrested twice and he was booked into the Santa Rita jail on counts of reckless driving and disobeying an officer. So what was happening?
[00:13:55] What was he doing? He apparently was driving his Tesla the back seat. Yeah. Yeah, absolutely. It's absolutely incredible. So this is an interesting one, too. This is a KTV you Fox two reporting. You said perineum Sharma met KTV use Jesse Gary in San Francisco, Wednesday afternoon. Not far from his mother's high rise apartment.
[00:14:24] After getting out of jail on two counts of reckless driving, he pulled up sitting in the back seat of a Tesla with no one. In the driver's seat when asked to be purchased a new Tesla after the previous one was impounded, he said, yeah, I'm rich as beep. I'm very rich. I feel safer back here than I do up there.
[00:14:46] And that was him sitting in the right rear passenger seat of his Tesla being interviewed by the Fox affiliate TV station there in San Francisco. It's absolutely amazing to me. And he's saying how he's been brake checked before, which of course is something way more in California than you would out here in Northeast where I live.
[00:15:11] And that's where somebody slams on their brakes. Who's in front of you. Cause they don't like what you're doing. And he says, Oh, my Tesla came to a complete stop. Tesla's CEO really knows what he's doing. I think people are tripping and they're scared. It's incredible. The police officer that had arrested him said that he was sitting in the rear seat driving quote unquote, the Tesla. And when the police officer pulled him over, he climbed up into the driver's seat in order to stop the car, the guy even posted a video. Saying, I just got out of jail already got another Tesla. You feel me? I'm rich like that. It came out of the pandemic, a beeping millionaire and some more swear words that I won't repeat here.
[00:16:01] So the CHP California highway patrol spokesman told Vice's motherboard. It's just a website covers a lot of tech. That it's recommending charges to the district's attorney's office and conducted a thorough investigation that will consider the possibility of previous incidents and pop, obviously his social media.
[00:16:21] So here's your problem. According to Tesla, autopilot is a hand on driver assistance system. It's intended to be used only with a fully attentive driver. And I mentioned some of the problems that Tesla has been known to have consumer reports has also reported. This is just last month that Tesla's driver monitoring system not only failed to make sure the driver was paying attention, but it also couldn't tell if there was a driver there at all.
[00:16:57] Obviously if it could tell there is a driver there, it wouldn't have been able to be driven, quote unquote from the back seat. Tesla's full self-driving system has more capabilities, but again, this is from Tesla, both autopilot and full self-driving capability are intended for use with a fully attentive driver who has their hands on the wheel and is prepared to take over at any moment.
[00:17:24] Cadillac came out with a system. I liked this idea where it vibrates. If it notices that you're not paying attention, it'll vibrate, your seat. Some of these vehicles will vibrate your steering wheel. Just wake you up. Hey, wake up. There's various levels of autonomy.
[00:17:42] Level five is. You don't need a driver at all. And Elon Musk says that he expects Teslas will be available at the end of this year, perhaps in 2022, that we'll have full what's called level five automation, which means they can drive without any human attention. The California DMV says the Tesla's director of autopilot software told regulators that Musk's predict and timeline does not match engineering reality.
[00:18:16] Okay. So again, the it's somebody on the marketing side, that's overselling things a little bit, or maybe a lot a bit. I don't, I really don't know, but. They do have permits in California to operate these vehicles in full autonomous mode, as long as there's human backup drivers. And I think it's good.
[00:18:36] I think we're moving forward and the investigations into these crashes are going to make us, I think, ultimately a lot safer. So let's say that there's a crash where the human at a wheel of a normal car they'll then investigate, they'll say it was at a human's fault. And then insurance companies kick in and payments are made maybe a driver's license is suspended or removed from that.
[00:19:03] Person, but when we're talking about an autonomous vehicle, like a Tesla, when they do the investigation and they find a flaw in the assumptions made by the programmers, their software, that's in the computer, that flaw. Is probably fixable, which means that type of accident will probably not happen again.
[00:19:27] And that's where I'm looking at it and saying these ultimately are going to make our roads safer. Cause hairy men make a mistake and Harry May not make that mistake again. But Mary May make that mistake when she's out driving. But if the slow car has an accident, they fix the problem. Teslas are probably not going to have that accent again.
[00:19:50] So I'm looking forward to this in the future on not sure it's going to be this year, maybe next. Make sure you're on my newsletter. Craig peterson.com/subscribe.
[00:20:01]I've been talking about this Tesla driver, and I just absolutely loved this. Cause I, I did a little searching on him. I went to duck, go and poked around a little bit to find out who is the sky, this Sharma guy who's driving from the back seat. And remember he says, he's rich as bleep.
[00:20:20] And so he doesn't care that his car was impounded. He just went out and bought another one. His money apparently comes from his parents who apparently were in the banking business. And then he Rose to fame during the whole lockdown because he was posting videos of him driving his Tesla. From the back seat and making all kinds of outlandish statements.
[00:20:48] That's how he got rich. And the rest of us, what are we doing? We're busting ourselves, trying to get everything done that we can possibly get done and hoping people notice, oh man. I guess frustrating. Sometimes every year. Verizon publishes some cybersecurity stats. And I absolutely love these.
[00:21:09] I pay attention to them. I read them from cover to cover because they are absolutely. Correct. This is their 2021 data breach investigations report. And it helps me to understand what's happening out there in the world. And of course I follow the news stories every week and it also lets me know information about the surveys that they have done with business owners and it executives and everything else.
[00:21:41] So they came out with some new stats I would expect. That there was a change because so many people were working from home. And to me it would seem obvious that with people working from home on computers, that probably are not properly secured, they're probably in properly using VPNs that we would see an increase in ransoms.
[00:22:08] Now we know that we did right. 300% increase last year because of people working from home and businesses, just not having things set up properly. And that makes sense. Cause most businesses, they, it's not their business to do cybersecurity. They're just trying to stay in business. I had a meeting this week with one of my clients, a longterm client he's been climbed for, I don't know, 25, 30 years.
[00:22:34] And it was interesting to me to get his perspective. In fact, it was very informative because I live and breathe this cyber security stuff. He doesn't, and he has. Concern about cybersecurity. It would be inconvenient to have ransomware in his mind because he has a lot of stuff on paper and I could maybe use the backups.
[00:23:01] Now we were keeping reminding him, Hey, you're doing the backups yourself. You don't have us doing them where we automatically, at least once them once a month. We start your systems from backups. We do that in the cloud. We have our own little cloud. We don't do this up on like Amazon or anything, but we do it locally.
[00:23:22] And that way we know the backups. Good. Because if we can start your machines up in our little cloud, we know that we got a good backup. He has never tested his backup. We had, we had another client like that. And when we picked them up as a client, we went in and they were taking home hard desks every day, religiously, just like this guy is.
[00:23:45] And so he they would take the desks, bring in Monday's desk, plug it in Monday morning and leave it plugged in all day. So the backup would go on to that desk. And then Monday night he would take that disc home and then Tuesday he'd bring in Tuesday's desk. Now there's a lot of problems here. One is they never tested it ever.
[00:24:12] And they'd been doing this for least 18 months prior to us getting there, because that was the advice or somebody, somebody said, yeah, all you have to do install the backup software and. Plug in your disc every week. So number one, it had never been tested, right? You got to test these things end to end.
[00:24:29] You have to do full restores, which they weren't doing. The other thing that is a problem with these USB drives is you plug them in. Are they really working? How many errors are on that drive? Are you even checking the logs from the backup software? So they had a server, in fact, in both cases and all that, I think of it, they had a server and it had a raid array.
[00:24:54] It had three drives and a raid five configuration. For those of you who know what that means. And basically what that means is you could lose one drive and you'd still be okay. So the idea is that drive goes bad. You replace that drive, you re silver the whole thing and then you're off and running again, so you can lose another drive and you'd be okay.
[00:25:18] But in both cases, both of these businesses had a bad drive in the raid array. And they didn't notice it. They didn't know. And at least in this other customer they had never ever checked to see if their backup was working and in the second customer. So in both of them, they never checked.
[00:25:39]And they said, so how much would you charge us to. Verify it. And we said we'd want to spin it up. And that means you have to copy everything. We'd have a bunch of bench time, so it'd be 500 bucks and we'll make sure your backups are working. Oh no, we can't. We can't do that. We can't pay them 500 bucks, so who knows still, we don't know if the backups working. They think that they could recover from paper, that ransomware isn't going to be so bad and extortion doesn't matter. My head just spins with this stuff. It really does. It just spins. So looking at the variety doesn't report that comes out the data breach investigations report, they are seeing that ransomware, phishing and web application attacks all increased during this last year.
[00:26:27] And they also found that 85% of the data breaches involved. Human interaction. So what that means is you and I doing some stuff that maybe we shouldn't be doing, and some of this human interaction is installing malware, right? From fishing activity, where they're sending out these emails. A day, doesn't go by where I don't get an email every day.
[00:26:56] I get emails that are saying what's the biggest one right now. I've been getting Oh, it has to do with some signature software. I'm not going to name them because I don't want them to get in trouble. Cause I got a decent software, but it's a big deal. Okay. A very big deal. So they're saying that the median financial impact or so do you know what median is mean?
[00:27:18] Median and mode? Median and financial income pact of a breach last year was about $21,000 95% of the incidences incident. Costs the businesses somewhere between $826 and $653,000. Okay. So many breaches they say did not cause losses. And those that did cause losses. This is where it really gets big.
[00:27:50] Okay. 95% of the computer data breaches led to losses as much of 1.6 million. So it's getting expensive. So what do we do? How do we deal with this? I talked about this before you need to improve your windows, privacy and security. You need to harden your windows. You need to get good firewalls. And I talked about it this week.
[00:28:14] Again, you need to use something like open DNS, which is, it has a free version. There are paid versions, but this is going to get you. A long way towards being safe, open dns.com. That's where you find them online. If you can't remember you can't run it down. Just email me M [email protected]. Ask your question and I'll be glad to point you in the right direction.
[00:28:41]I was just talking a little bit about the Verizon data breach, their incident incidents report. And I wanted to just bring up one other bit of data. And that is that the attacks that are going on are actually simpler. They're not as complex as the old ones and phishing attacks are now going hand in hand with the use of stolen credentials.
[00:29:09] What are stolen credentials while it is information that has been stolen from another website, typically? Now might be as stolen from your business. And so they know what your password is because they have all of the passwords in the business you're working for. But more often they're doing something called credential stuffing.
[00:29:32] So they're going to the dark web and let's say they want to attack colonial pipeline, which of course just happened. And colonial pipeline has their URL that all of their email is sent to. What they end up doing is they go to the dark web and they find. Credentials for people that have a colonial pipeline, email address, and those credentials are going to include things like your password on that website.
[00:30:04] Now, what happens is. They stuff that username and that password in as many sites as they can. So let's say they found that you're using Microsoft remote desktop, and maybe there's a zero day bug as there are many bugs in that software that people haven't patched yet. So they'll just use that to get on, but if they can, let's say you patched it and they found your email address and use over on website X.
[00:30:35] That has nothing to do with colonial pipeline. What they can then do is take that username, which is that email address and that password and try it at colonial pipeline. And guess what? It works more than 60% of the breaches involved, credentialed data. And 95% of organizations that we're experiencing this credential stuffing attack had to between 637 and 3.3 billion malicious login attempts throughout the past year.
[00:31:14] We see them all the time. We have a couple of internet facing servers and those servers we log when someone tries to log in and if they try and log in more than four times immediately, they are blocked at the firewall. So they can't even connect to the server anymore, period at all. And that stops this type of attack.
[00:31:39] So I'm sitting here. I'm actually, I was literally scratching my head because I cannot figure out how can you have 3.3 billion malicious log in attempts at one business over the course of a year and not do something about it. Not have them automatically blocked. This is just crazy because credentials are the key that the bad guys can use to get into the network.
[00:32:13] And they're not just using them to do ransomware into somewhere like colonial pipeline. They're using those credentials to go to your bank account. Yeah. So you, most people are using the same email I'll address as a credentials, which is ridiculous. I can't believe businesses are letting people use an email address as their login username, but most people using that same email address and those same passwords at multiple websites.
[00:32:46] So I want you to do something now, and I've asked you guys to do it before on the show. You may not have had a chance before you may not have known about it, but I want you to go. If you're not in front of your computer, go there right now, or grab something. You can write this down with, or send me an email just [email protected].
[00:33:06] What I want you to do is go to have I been poned.com. So that's like it sound have HIV. E I, the letter I been B E N P w N E d.com and put in your email address right there. And that will tell you what information of yours is widely available on the dark web. Now it doesn't have everything that's on the dark web.
[00:33:37] By any stretch, but it has all of the major stuff. And I can guarantee you if you've had an email address for any time at all, that email address is going to show up. It's going to show up all a lot. Okay. So check it out. Have I been poned.com and then trend, according to Verizon is towards simplicity.
[00:33:59] They're using passwords stuffing. They're using social engineering fifth. Dean X spike in misrepresentation, which is a type of integrity, breach business, email compromised, doubled last year, and a gain this year. It doubled again, 60% of business, email compromise attacks that successfully stole money. It's crazy here.
[00:34:27] Median lost $30,000. That's email coming in, pretending to be someone that they're not. And again, I've helped companies that this has happened to and help them tighten things up. That is the problem. Okay. There's huge medium was 30,000. And 95% of them cost somewhere between $250 and a million dollars.
[00:34:53]It's just amazing. So we've got to pull up our socks. We have to be careful. I have some free info that you'll get. If you sign up from an email newsletter, you're automatically going to get a few of the special reports that I put together. You're going to get my weekly emails. It's all for free.
[00:35:12] This newsletter. Most people can't believe they don't have to pay. I had someone just this last week say. Are you sure I'm not supposed to pay for this because a lot of newsletters out there, of course you have to pay for, but I send out all of this type of information for free and I have free little trainings and free guides, and I'm more than glad to offer them all to you guys.
[00:35:37] So check them out. Go right now. Craig peterson.com/subscribe. Now have I been poned is again a website juke should go to, but the other thing you need to do is make sure you're using a password manager. Now a password manager is something like one password. I wouldn't no longer use the last pass. I have pulled that off of my list of recommended password managers because of a major problem that they had.
[00:36:07] And it showed, they really didn't know what they were doing. Everybody makes mistakes. Nothing's a hundred percent secure. Believe me. I know that, but they really lost all. Of my trust with this huge hack that they had. So one password is the only one I'm recommending nowadays. That's a digit one in the word password.
[00:36:28] Use that. If you can use something other than your email address to log in. Do that change your account name to something out, something completely unrelated call it the human element or something. Use a login. That's not your name. That is not your email address in is not something that's easily guessed.
[00:36:50] And then use a fairly randomly generated password. Now, what I'm recommending now is the latest NIST guidance, and this does the national institutes of standards and technology, and the latest NIST guidance says. You do use some random stuff, but I'm not talking about random letters, numbers, special characters.
[00:37:13] I'm talking about taking three or four randomly chosen words, or even a phrase that are separated using maybe a digit or a special character, making sure there's a little bit of upper lowercase stuff going on, but it's something that can be remembered if you need to. And one password will generate these for you automatically, which is absolutely amazing.
[00:37:41] Okay. It's such a godsend. I was surprised when I looked the other day, I have 1400 different accounts in my one password. Yeah. That's how many I have that's a lot. And it'll also keep your notes in there. So you can put in bank account information, et cetera. It keeps it encrypted. It keeps it in their own little secure cloud.
[00:38:05] So knock on wood should be pretty darn safe. Now want to point out one more thing about these statistics here? Nearly all email servers, 96%. 96% of email servers that were compromised in these attacks or cloud-based once they've gotten into your email. They have control of you. I just got a call again.
[00:38:36] This is a friend of a friend who called me up because their email account had been compromised almost certainly because again, credential, stuffing there's password information out on the dark web, et cetera. Cause I ha I looked it up for him and sent him the link. Here's what have I been poned says. But once they have control of that email address, they probably have something that you're using for password recovery.
[00:39:05] So you go to the bank. So the right way to do this for the bad guys is they go to like bank of America. They try and put in your email address and say, I forgot my password. So where are they going to send your password? They're going to send it to your compromised email account. If they're, they'll try all of the major banks and they'll see what they can find.
[00:39:27] 96%. So it's just crazy. And people are using this. They, the cloud is just the name for someone else's computer and you don't know how all protected it is. And you still have ability if it's broken into, and in this case, Verizon saying that this led to the compromise of personal information, internal business information.
[00:39:54] Medical information, bank, account information. This is part of the challenge of moving a business to the cloud. It's incredible. All right. And not flip that make sure you do get all this info. You'll get all of my free, special reports by signing up. If you're not already on the list. If you have any questions, Craig peterson.com.
[00:40:17] Feel free to reach out me at CraigPeterson.com. That's my meal at that's my email address, and I don't use it to log into anything [email protected].
[The following is an automated transcript.]
Craig Peterson: [00:00:00] The lies and misinformation that are going on right now over in Israel, between Hamas and of course the Israeli government. This Tesla owner got bulled over sent to jail because he was driving the Tesla from a back seat. And a little bit more about the colonial pipeline with Mr. Matt Gagnon. We joined him of course, this morning.
[00:00:27] Here we go.
[00:00:28] Matt Gagnon: [00:00:28] Good to have you with us. 7:36 on a Wednesday means it's time to talk to Craig Peterson, our tech guru. He joins us at this time every single week. Craig, how are you this week?
[00:00:38]Craig Peterson: [00:00:38] Hey, I am doing quite well. I had a couple of my hives swarm. It's just been such a great day; over winter and a great spring.
[00:00:47] And so I was able to capture them. So I'm up two more hives. I cut two swarms.
[00:00:53] Matt Gagnon: [00:00:53] So I'm what are you talking about? Are you a bee person?
[00:00:56] Craig Peterson: [00:00:56] My honey bees. Yeah. You didn't know that?
[00:00:58] Matt Gagnon: [00:00:58] Well, yeah. Okay. I sort of remember that a little bit, but you wouldn't mean you caught a swarm. I mean, they like you, you go out there with a net, I mean, yeah,
[00:01:06] Craig Peterson: [00:01:06] Well,, the way it works is bees multiply by dividing. So if they're, if they're really, really healthy, they will go ahead and make some new Queens. And then when that queen emerges, the old queen will take about half of the workers and we'll go to try and find a new hive. So she'll go out and she'll just sit on a branch.
[00:01:28] And of course, all of these other workers that had 10 to 15,000 bees will swarm right around her. So they'll all be resting on this poor branch, which is almost always just sagging. So if you can touch them. So what you do is if you can get that queen particularly, and get her into another little hive or a box to begin with, then now you've got a whole new hive. So that's how they have new colonies. That's how the honeybees is started expanding. And I, I often just let them go because it helps with the whole diversity thing and they become wild honey bees, which we need because this year, about half of all of the colonies in the U S died. So that's how it works.
[00:02:14] There's a bigger than a football, but kind of shaped like it. And if you see one call a beekeeper in your area, so they can either go and grab them and help them make sure they're healthy because unfortunately our wild bees are dying at very high rates, but they can make sure they're healthy. They can capture them and they'll be happy.
[00:02:34] And hopefully they won't end up in somebody's Eve's over there that they then have to try and get those beat colony out of.
[00:02:43] Matt Gagnon: [00:02:43] Well, I learned something about bees today. Ladies and gentlemen, Craig Peterson joins us at this time. He also joins the program where we're joins the station, excuse me, on Saturdays at one o'clock where he hosts the show where he goes into many of these topics in more detail.
[00:02:54] I don't know if you're going to hear about bees, but I guess you're probably going to hear about the colonial pipeline. I know that we talked a little bit about this last week, but Craig, they paid a $5 million ransom. And from what I understand, they basically, I mean, what they got back for a key, they didn't even really use any way.
[00:03:09] And they ended up like using a, sort of a backup, uh, uh, of theirs to restore things. Anyway. I mean, first of all, tell me about what actually happened with that payment ransom. And second of all, what's the impact of this? I mean, does this not just incentivize more of this garbage happening? Yeah,
[00:03:24] Craig Peterson: [00:03:24] it really does.
[00:03:25] And that not only incentivizes it generally, but it incentivizes them to go after colonial dam, just like they've done with the city of Atlanta, where they paid a ransom. And of course they got hit again just weeks later. Another ransom. Right? They got hit again. So this is really bad. Under the Trump administration, the department of justice said you are supporting terrorism.
[00:03:51] If you pay ransoms. And we consider that to be a legal. Now under the Biden administration, they said, no, you know, whatever, do whatever you want. It's kind of, you know, up to you. Uh, they paid $5 million. The bad guys gave them the decryption key. And, and in fact, tried to help them decrypt to their data that wasn't successful.
[00:04:14] What colonial ended up doing is two things. One, they switched their pipeline over to manual. Control away from computer control. So they actually had to have people all the way up and down the coast. How long does that? It's like two, 3000 mile pipeline and all of the valves turn them on and off. That's how they had to deal with it.
[00:04:36] But pain, your ransom is a bad thing to do. Having a backup is a good thing to do, but you gotta remember. And I cover this in my backup. Of course that when we're talking about backups, something that's attached to your machine is also going to be encrypted as part of the ransom. So make sure your backups are remote and the bad guys can't get it them, but that's the easiest way to get them.
[00:05:01] Pass that first part of the ransom. The second part is what's going to be interesting here mind, because what they will do this group is they'll steal your data and then they will threaten to release the data. And, uh, when Zach shoe going to drop, and then also there are claims out there that the reason they shut the pipeline down, Matt was because their billing systems were offline.
[00:05:28] That was the part of their network that was attached, attacked by ransomware. And they wanted to be paid for the fuel. So they shut it down because they didn't want it to deliver fuel that they couldn't bill for.
[00:05:45] Matt Gagnon: [00:05:45] It's quite a mess, obviously, correct. Peter Sohn joins us at this time, uh, every Wednesday to go over what's happening in the world of technology or the big story besides this colonial pipeline issue, which is really more of a last week thing is what's going on in Israel with, uh, you know, obviously the, uh, the, the rockets being watched back and forth, the potential of a ground invasion, the conflict.
[00:06:04] At its worst point for the last probably eight years or so. Uh, social media has been a part of this story here. And one of the things that's interesting about that is that misinformation lies a bunch of garbage has been skewed around on social media. And there seems to be no stopping it. Craig Peterson.
[00:06:21] Craig Peterson: [00:06:21] Yeah. Yeah, exactly. And what we're finding now is really something that's been going on for a long time, all over the world. And that is, they are showing at official press conferences on basically on both sides of this conflict. There's showing videos. Of other past conflicts and representing it as it's happening right now.
[00:06:48] So this is a real big problem, frankly, these, this is a different world. Many of our news organizations are not investigating. They find a video, they use the video, even though it misrepresents it. And of course, a lot of people are familiar. With that at our U S border where they were showing pictures of kids in cages, when they were, those bridges are taken cherry, the Obama administration.
[00:07:15] And yet it is the Trump administration. They're complaining about same thing here. So we are able to do research online, please do the research, and it's disgusting to see the state of Israel. Using videos that are not particularly relevant and misrepresenting them in the same thing on the other side with
[00:07:37] Matt Gagnon: [00:07:37] Tomas.
[00:07:38] Yeah. That's not the first time that's ever happened. We're talking with Craig Peterson, our tech guru who joins us this time every single week. Lastly, just want to ask a little bit about Tesla. Uh, a Tesla owner who drives from the back seat got arrested recently.
[00:07:53] Craig Peterson: [00:07:53] Yeah. You said he apparently told the police officer that, uh, and this was in California highway patrol that he felt safer in the back seat.
[00:08:05] Matt Gagnon: [00:08:05] This is, this is the self-driving car revolution about to happen to us. Right? Do we are going to get a lot more stories like this
[00:08:11] Craig Peterson: [00:08:11] happening soon? It absolutely is traveling eastbound on the IAT or across the San Francisco Oakland Bay bridge. Uh, if you're familiar with it.
[00:08:21] Matt Gagnon: [00:08:21] Oh my God. He drove on that bridge.
[00:08:24] Seriously. Yeah, I know I've spent an awful lot of time out there and I've driven on that bridge more than once. And that's the last place I would be in the backseat, not driving my car. I guess. It's just my I'm terrified of Heights, but now that's insane. Yeah.
[00:08:37] Craig Peterson: [00:08:37] So people were reporting it to the police.
[00:08:40] The police pulled him over. You apparently climbed into the front seat and in order to stop the car and he actually got arrested, put in jail. He was released as is the norm in California. And so what does he do? He does it again. And he's caught again and arrested again. He says, I just feel safer back here than I do.
[00:09:02] Uh, there, uh, this is, yeah, this is what we're in for here. Remember, even though Tesla calls it full self-driving, it is not with autonomous,
[00:09:14] Matt Gagnon: [00:09:14] right. It's meant to be an autopilot while you're sitting there. Behind the wheel, just in case and, and directing things still really. I mean, it's not a full self-driving for real right now, Craig Peterson.
[00:09:25] Thanks for joining us as always good luck on Saturday on this very program one, o'clock make sure you tune in for that. And we'll talk again next week. Hey, take care. All right, we're going to take a quick break here. When we come back.
[A quick, automated transcript of my conversation with Jim Polito on WTAG, WHYN, and WHJJ on 2021-05-18]
Good morning, everybody. Craig Peterson here. I was on with Mr. Polito this morning, and we went through the colonial pipeline and why you don't want to pay a ransom. And then I went into the things you can do for free. That'll give you 90%, maybe a little higher protection. So some websites to go to some things to do on a windows computer.
So it went a little deeper, I think, than I usually. Go into, but I think a lot of great info. So here we go with Mr. Polito.
If I ever got hacked, ransomware, whatever there's one guy had called, not the Ghostbusters. I would call our tech talk guru and good friend, Craig Peterson, who joins us every week at this time.
Good morning, sir.
Hey, good morning, Mr. Jim.
Craig, why don't you just say, I told you so because they, it looks like colonial paid the $5 million ransom, the stories I'm reading say that then the Russian hackers gave them the key to fix the encryption, and it didn't work. And then they eventually figured it out themselves.
Am I correct? Yeah.
Yeah. That's pretty much what happened.
Brilliant guy because that's called colonial pipeline. So you said, and you have said many times before, the easiest way to get yourself in the crosshairs of a cyber hacker, ransomware criminal is to pay the ransom. Then you have painted a bullseye on your back.
Why don't you tell us about that?
Yeah, we have a whole country thing. You might remember. There was an organization called the United States Navy. And the United States Marine Corps. And you remember, the Marine Corps Anthem, right?
Oh yeah. From the halls of Montezuma to the shores of Tripoli, the barber.
Okay. And why did they form the Marine Corps? Why did the Navy come to be? It came to be in both cases to protect our merchants, our merchant leads; we were having some problems with some alumnus back 250 years ago. And we sent our Marines over. In fact, the whole thing about leather neck comes from that same period.
So they wouldn't get their heads chopped off. I hate to talk about that, but we've been facing thisโtype of thing, extortion as a country forever. And now we've got president and Biden out there. Know I'm trying to do a hairy imitation. There might've been the Russians, but it wasn't the Russians; it wasn't Putin.
At this point, it seems very obvious that because of dark by the way, who shut themselves down over the weekend, along with two other major ransomware operations, it looks like they were at the very least under the protection of the Russian government. So they go out, and who do they want to target?
It used to just go out there, spray and pray. See who you can find now it's, let's go after the people with the bigger pockets, as much as we can, at least these professional groups of which of course are present, colonial or act by. But these professional groups now go after people.
Now, who are they going to go after? They want somebody with the big. Wallet, a big deep pocket. And they also want to have somebody that they know is going to pay. So let's take the city of Atlanta, for instance. This is a small city in the south, and Atlanta went ahead and got around somewhere and paid.
And what happened again? A couple of weeks later, they got ransomware and paid. And then what happened about a month later, they got ransomware and they. Multiple times now compare that, for instance, with the metropolitan police department down in Washington, DC. Now in Washington, of course, again, a small town, and they have a metropolitan police department.
And again, They didn't bother putting together the type of security they need. And we just did an audit in fact of a county who will go on named that their cybersecurity was almost completely non-existent, yet you talked to them, and they say it's absolutely there, but in Washington, DC, they got into the police department computers.
Now, if you are connected to one of these networks, you have what is called the feed, just requirements, which are really aimed at law enforcement. But they got on, and they were able to grab all kinds of data, and they said, okay, pay up. Watching the DC said, no, we're not going to pay. We're just going to restore from backup.
So they said, okay, we'll pay up now. Or we're going to release the names of all of your informants and their phone numbers and their home addresses. And what's ended up happening so far. Is. He still hasn't paid, but they did release the identities of the police officers within the department. At least some of them in this is a real problem.
We are, as a nation, allowing these foreign countries to get. Bitcoin typically, which by the way, has been the major motivator, driving up the price of Bitcoin and getting away with it. We are funding North Korean operations. This is one of their major sources of currency attacking us in the United States.
We're talking with Craig Peterson, our tech talker right now, generally, we're talking about things that are to protect your new gadgets, all this stuff, software, and that's generally what we discussed, but there comes a time when we have to open it up globally. And Craig Peterson is the man to do it two weeks.
Stand what's going on. The bigger picture, Greg Bitcoin, is the way. That they can fund themselves because you can't trace it. If I have money, I've got to have some way. If I'm asking for ransom and dollars, there's gotta be some way to get those dollars to me. And, financial institutions can say, we're not doing business with you.
Credit card companies can say we're not doing business with you. And so they get Bitcoin. It's like the wild west. It's like robbing the stagecoach and getting the pieces of gold.
It is. I had a briefing by the secret service and went through the takedown of one of these dark web operations that were only using.
Bitcoin. And a lot of people have the con the idea that somehow cryptocurrency, because it has crypto in the name as in cryptography, they have the impression that somehow it's secure, they're never going to get caught. And yet, in fact, that's exactly what happened. So there is some speculation right now that because we can track many Bitcoin.
Transactions that these three major ransomware operations shut down over the weekend because of somebody getting a little bit too close. Okay. I don't think it was the call from president Biden that lasted what, three minutes?
Yeah.
Please gimme a break, gimme a bread.
Yeah. So there are some things that we should do as home users. And as a business, as small businesses, you can get better than 90%, probably close to 95% protection by doing just a full of things 90%, I'd say, but they're both free. Okay. If you have windows use windows defender, it's free.
It's part of your windows 10 installation. Make sure you keep everything up to date and use windows defender. All right. Don't bother with so many of these other antivirus packages that really aren't going to do you any good? So that's number one. Number two, what I teach in my courses and show you exactly how to do it is there's a professional version, but I'm going to tell you right now, get your pencils out.
I'm going to tell you right now the version that it doesn't do anywhere near as much the commercial, but this is going to get you way closer. This is going to get you on the higher side of the 90% range. There is a website out there called OpenDNS. No Cisco, who is the company that runs that makes hardware that runs the internet and is a company that we deal with.
When we install firewalls and switches and clean things up, it's always Cisco bought OpenDNS, and then they improved it. They call it an umbrella. But if you go to OpenDNS, it is simple and it is three. All right. They have paid versions. If you can afford them, get the paid versions, they are better.
They've got all of this consumer stuff and basically all you have to do is make a couple of changes in your network. Are you going to connect to your little firewall router or on your PC? You really don't even have to install any software. You see what happens is once the bad guys get their software on your computer.
Then you have your computer call them up. So essentially you're paying for the phone call, but call them up and say, okay, I've got a computer. What do you want me to do? And then they use your computer now to move around within the network and then install ransomware that et cetera. But if they can't call home, They can't do much or do anything.
And almost all modern ramps are more. If it gets on your machine calls home, can't get there. It just sits dormant. So by telling your computer to use OpenDNS instead of Comcast or whoever your local provider is, what happens now is it asks OpenDNS. Hey how do I get to bad guys.com internet bad guys.com.
And I want to challenge you guys right now. Go there on your computer, internet bad guys.com. And this is a demonstration site. All right. And what'll happen is how do I get your internet bad guys.com? Or how do I get to dark sky or whoever it might be. And OpenDNS will say, what, where what?
And so they can't call home gym. So if you can. If you can get to that website, internet, bad guys.com right now on your computer. That means that your internet provider is not blocking DNS appropriately. So you can do this simply OpenDNS.com, install the software. If you want more professional stuff, let me know.
We're starting to do some more cybersecurity health assessment is I want businesses and individual to be able to protect themselves. This is the 90% solution. And sorry, I've been rambling for a while.
Yeah. Oh, this has been great. Now, Craig, if folks want to get in touch with you how do they do it?
Just send me an email just to [email protected]. It might take me a few days to get back to you. My wife, as you might know, at a serious activity, but just email me M E Craig peterson.com in the subject line. Just put what you're interested in. If you wanted to know more about OpenDNS or passwords or whatever, and I'll send your info, I'm not charging for any of this stuff and get you on the right path.
[email protected] and you can sign up of course. On my website, which happens to be right. Peter som.com.
I love that. Make, keep it simple for the stupid anyway. And that's me, me Craig, great segment as usual. And you've been in the forefront of this for quite a while. And and people need to hear more of what you're saying.
Craig, thanks so much. We'll catch up with you next week. All
right. Take care, Jim. Thanks. Bye. Bye. Hey everybody take care. I have been very busy helping out small businesses and individuals to that cyber health assessment stuff I talked about. I've got a self administered. Cyber health assessment as well.
So keep your eyes out for that and make sure on that mailing list. So you can find out more about it. You can just do it yourself. You don't have to talk to me or my texts or anybody else. Craig peterson.com and sign up right there.
As Heard On WGIR - 2021-05-17
Hi, everybody, Craig Peterson here. I'm not quite sure how to describe this interview, but you're going to find out something about me you may not have known and it's not a bad thing. It's just, I've never really disclosed it. Certainly not publicly. Anyhow. So we talked today about the colonial pipeline what's happening with these ransomware groups and there are a number of them and why.
Why is it happening? And then also of course, over the weekend, there's a little bit of discussion with Marco Rubio and others on 60 minutes, I think it was about UFO's. So I guess there's a clue. So here we go with Mr. Chris, Ryan Stanford.
I am Chris Ryan joining us right now is Craig Peterson. He is the host of tech talk.
On Saturdays and Sundays at 11:30 AM on news radio six, 10 and 96 seven Craig area.
Hey, good morning. That's a nice kickoff there with the stones.
Love to hear it. We really do. And there's nothing better. Little Keith Richards riff to get us into the mood here on this Monday morning cross the great state of New Hampshire.
So Craig. It's amazing how our news cycle works. We have the colonial pipeline is one of the biggest and maybe most significant stories that we've had so far this year. And we talked about this actually, Liz Cheney as well. When she joined us on Friday to me, there has to be a priority. And a predominance of focus placed upon cyber warfare and germ warfare and electromagnetic warfare.
We're hearing about, UFO's and that report from 60 minutes, which I think is really important as well. I It's clear now that there are. UFO's used to be. The question was, do they exist? The answer is, yeah, they do, because we have video evidence of them and people have seen him at firsthand accounts.
So those are the two things we're going to get delve into today. And I want to start with your takeaways from the colonial pipeline circumstance.
I talked about it a lot on the radio show this last weekend. Cause it is a change. It really reflects a change in the way ransomware works too. And over the weekend we saw a big change yet.
Again, ransomware used to be just, they got software on your machine. Usually through. Phishing, which is sending you an email, getting on something, and then they'd encrypt all of your files and say, pay up sucker, if you want access to your files again. And then it moved to the next stage, which was people didn't always pay off because they might have backups and say we can just restore from backups for Canada better.
We're not paying you a dime. They decided maybe what we should do then is get a little more. Vance. And before we encrypt your files, we're going to steal all of your important data. And then we're going to hold that data hostage and threatened to release it just like they did with the metropolitan police department down in Washington, Jen DC.
And yes, indeed. They did release home information about the police officers in the metropolitan police department right down there in Washington, DC, because they didn't pay this ransom. Now, what we have is something called dark side, which is a group that's been around for almost a year. And they sell services to other bad guys who want to rent some people.
So dark side, we'll take a 25% cut all the way down to 10%. They have it on their website, depending on how much money you're able to get out of. People twenty-five percent cut on anything under about $5 million and they'll do tech support for you and everything else. So when you take over someone's computer and they are now trying to pay you buy Bitcoin, et cetera, in order to do that dark side, we'll do the tech support.
It turns out the dark side was behind this hack of the colonial pipeline. And ArcSight is now a little bit nervous. They brought their website down. Of course it's on the dark web has two other major operations that are again, ransomware for hire. So we've seen three major groups. Chris go completely dark over the weekend.
What does that mean as well? Are they nervous that what are they nervous about in particular? Are they nervous about the FBI? Are they nervous about, and does the FBI have. No jurisdiction over a cause that's one of the main challenges for whether it's for local police departments or for even an entity like the FBI, where there's a international type of a flavor to these many of these entities, how, who has jurisdiction over them?
How do you. How do you make them accountable? And how does things have to change in order for that to take place?
Part of what drove up the value of Bitcoins so high and continues to our businesses who are buying Bitcoin in case they get ransom. So that obviously supply and demand limited supply of Bitcoin businesses buying right.
Bitcoin by the millions in case they ever get hacked. And look at what just happened with Tesla, buying all kinds of Bitcoin as a quote investment unquote, most of the time, these investments are to protect themselves who has jurisdiction. I have been to a lecture by the secret service where they were able to shut up.
Down a major black market operation that was running on the dark web and they were doing all of their transactions in Bitcoin that's cryptocurrency. And it is not. Safe. They were able to figure out who it was, where they were. Okay. And they were able to get an Interpol involved and get it all shut down and get most of the money back, which is interesting as well.
So here in the us, the FBI does get involved and I've worked with them on a number of cases. And there's the, of course secret service gets involved because they're talking about currency, staffs, international fashion, and then they. In the international community to round these guys up. So I suspect they're either very nervous because someone's getting awfully close to them.
And we've seen a lot of shutdowns lately of these bad guys, or maybe it's just good business. Let's just put up a different shingle and move on. I don't really know what's happening yet. And
why out in the open, the way that they are to begin with, because you're going to draw attention. To yourself and they, as you were referencing, they basically opened up a business and put forward that business and said, here we are, we're going to supply a commission-based environment.
And that, to me says that they're not that fearful of repercussions because of being. Very much a international type of a, of an entity. And there being questions, about how you go about enforcement on this side. And there still are questions in regards to jurisdiction.
There has to be a lot of cooperation for arrests and for investigation and things of that nature to transpire. So why do they have this type of confidence in your own?
So excellent question again. Look at their targets. They've been very careful not to target Eastern European countries, specifically countries or parts of the former Soviet union.
So it does make me wonder Chris about whether or not the Russians are actually involved and are providing them with some protection. And maybe Mako has said, Hey, get your heads down.
Biden said there was no direct relationship. He did not say there was no relationship. He said that he did not believe that Latimer Putin was behind it specifically, but that does not mean that he is not behind the entity or that there is some sort of branch out to them as there are.
Many companies and all oligarchs and individuals who have not necessarily a direct association with Putin, but indirect ones. The final thing is on the UFO's Craig and your thoughts on this and how this also plays into what we're talking about with no technological warfare, as I've said before, based upon the evidence.
I am still not on board with the fact that the UFO's are from outer space. I'm on board with them being Chinese or Russian or another country has developed some sort of a technology that allows for these identified flying objects to get close to our aircraft carriers or be seen off of the coast of Florida.
And in other. Circumstance, as I've said before, I've seen UFO's flying over and as many other people have flying over our airspace here in New Hampshire things that just don't make sense, different colors and so forth. And now we know that they have been we've seen them on video. We know that they exist.
There's no question about that. The question is who is responsible,
right? Yeah, absolutely. Chris, my experience with you at post goes back to 1982, when I had a close encounter. With the UFO, not just the movie back then, but I was driving up the central Valley there in California and I, all of a sudden saw this light that was blasting right into my car.
There was probably about a half a mile ahead of me. And then it came closer and I had my windows open. Didn't have air conditioning and it came right next to me. Now I know that helicopters make a lot of noise. We didn't have anything like drones back then. And it followed me and stayed right next to me as I went up that central Valley and took curves and everything else.
Wow. My mother also had an experience. Where do they come from? That's your right? That's the really big question. We certainly did not have that type of technology in the 82 or so when I saw it and when it followed me and that technology, I doubt existed 20 years before when my mother had an encounter with a UFO.
And it's it's a scary thing. It really scared the living daylights out of me that day, here I am on my twenties, a driving scene that there are some right now, some technologies that we do have that provide on an extremely limited scale. Some of the features that we've seen of many types of UFO's.
And at this point, Chris, I'd have to say again, we really don't know where they are. Come from, it would take an incredible breakthrough in physics in order to be able to have an aircraft or some forum that can hover make almost no noise. If any noise at all and change directions completely without causing enough.
Jeez G-Force to destroy the vessel itself, let alone everything inside. So it is a long way from anything technology wise, that's ever been exposed that we have control of the aliens. That's
what I'm hearing. That's that is that Greg did not go that distance, but it sounds like that is where you want to go with this.
We don't have a lot of time here left, but I do have to follow up on this because you basically just described an alien encounter. Yeah. How did it end? Did the UFO go away? What do, were you abducted? What happened?
No I thank goodness. I wasn't abducted, but that got my interest up. And as I've studied this a lot over the years it followed me along for 15 or 20 minutes or so.
And it, it just, it had this light on me on the car and the whole time I slowed down it load, I sped up it sped up. It was very odd. Let's settle this and put it that way. And yeah, I don't see any way it could have been from made by us or the Chinese at the time or anybody else.
It was, and they, I felt scared, really scared. It wasn't like a peaceful feeling like there's love coming here or something. But I do think that they're either extra dimensional there or, out from outside of this world, Greg,
the amazing story there. Thank you so much. Take care, Greg Peterson, he is the host of tech talk here on news radio, six, 10 and 96, seven on Saturdays and Sundays at 11:30 AM.
Hey I'm going to be a little slow getting back to you guys. I want to schedule these cyber health assessments and get them all done for everybody that asked over the weekend. If you did not get a chance to ask it and make sure you do go on line, just send me an email. [email protected]. Put a like cyber.
In the subject line and just let me know, you're looking for one of these health assessments. I got some that you can do yourself. You don't even have to talk to me or anybody out all the way through very deep ones that we do for businesses and others. So let me know, take care, everybody, and I should be back tomorrow.
Take care. Bye-bye.
2021-05-15 Show 1113 - How the Colonial Pipeline changed Ransomware forever
Craig Peterson: Hey, wherever you are, whatever you're doing right now. I know you're listening, and I appreciate you being with us. Of course, this is Craig Peterson. I've been in cybersecurity now for 30 years, and we're going to talk about what's really happening with this Colonial Pipeline ransom. [00:00:16]This whole hack, if you will, of what's been happening with this Colonial Pipeline. Cyberattack is very upsetting to me. Let's just really briefly because I've talked about it before. Talk about what happened. What is ransomware? Ransomware is software that the bad guys get onto your computers. [00:00:40] Now it's changed over the years. When ransomware first started hitting, I think most people still have this in mind, and the software gets onto your computer. Usually, you click on something. You download a zip file, and you open it up. Maybe it's a Microsoft word document and embedded inside that document. [00:01:00] Is a piece of nastiness, and that nastiness is the ransomware. And what it'll do on your machine is it'll start looking for files that it can encrypt. And those files typically are things like your word documents, your Excel spreadsheets, all that sort of stuff. And. They would encrypt it and then pop up on your screen, a nice little red warning message that all your files have been encrypted. [00:01:31] And if you really want to get those files back, what you're going to have to do is go to this particular website, send some Bitcoin to this specific Bitcoin wallet. And then hopefully, you'll be okay. Now, back in the day, it was crossing your fingers cause you didn't know what was going to happen. [00:01:52] If I send the money while I get the decryption key, will the software work while I get all my files back. And frankly, the answer to most of those questions was no. In most cases, you would not get all your files back in this day and age. It's changed slightly, but we'll get into that and how it's changed and who has changed the ransomware. [00:02:16] Industry. I want to give you some tips on what to do and how to avoid ransomware in the first place. And there are some automated things you can do. You can do some things just as a human being that you should watch out for. And I want to also get into it, so what do you do after the fact? I got a call from a listener this week who had a real problem. [00:02:41] Actually, she sent an email to just [email protected], and I got her phone number called her back, and I had my lead tech and myself on the phone with her for probably about 15 minutes going through. Okay. So here's what you have to do to respond. So I think it's essential for everybody to understand this. [00:03:01] This Colonial Pipeline cyber attack was ransomware, but it wasn't like that original ransomware that I saw all those years ago where you're crossing your fingers, et cetera. It has advanced to the point where this company has now made this cyber attack business an actual commodity for lack of a better term. [00:03:25] Quite literally, it was called the DarkSide. They've been around for about a year. And apparently, the people that are involved with the DarkSide have been doing ransomware for much longer than that. But what they're doing now isn't just, Oh, take a gamble, and maybe you'll get your decryption key. [00:03:44] Maybe the decryption will work. Nowadays, they have turned it into a truly professional organization. There are tech support people that you can talk to. You can call, you can have an interactive chat with them. The ransomware is very careful to make sure that you can still use the online chat features in your windows machine or whatever they might need to communicate with you. [00:04:14] And the tech support people [00:04:15] will [00:04:15] Craig Peterson: say, Oh yeah, some, I'm sorry that happened to you. Let me help you fix it. What you have to do is go to this website and buy Bitcoin. First, you have to set up a wallet. All of this was just so complicated. People weren't able to figure it out. So they now, with their tech support, will help you. [00:04:34] Find a place to buy the Bitcoin help you set up a wallet, help you put your more money into that Bitcoin wallet after you bought some fractional, probably Bitcoin, because they're worth quite a bit right now. And then. They'll help you to send that money from your Bitcoin wallet to their Bitcoin wallet. [00:04:59] And then they'll help you run the software to decrypt your files. This is pretty complicated, and these guys, a DarkSide, understood that. And that's why they did all of this tech support type stuff, but they've taken it. I yet a step further, this gang-like DarkSide in there. They're not the only ones DarkSide. [00:05:23] They're just the guys that we think went ahead and hacked the colonial gas pipeline, but they've taken it to the step now where they are selling ransomware as a service. You can approach to them and pay them. And quite a while, you've been able to buy ransomware that you could use. You had to find the email addresses. [00:05:47] You had to send it out. You had to do this, but now for a down payment and a percentage of your take this gang will go ahead and do everything for you. Including sending it all out. They've really professionalized this whole Industry of crime, of ransomware crime, of course. And we've talked about this on the show before they also will go the next step and what the next step is in this day and age is. [00:06:19] When they get into your machine before they encrypt anything, they have a human being who looks at your machine. So the machine calls home. And I want to tell you how to stop them from calling home. Because that's going to stop most of the ransomware, but it calls home and says okay. I got somebody. [00:06:39] And so the bad guy now, because that connection's opened up to call home. Can now hop on to your computer, unbeknownst to you. It's not as though you're going to see the mouse moving or screens changing. It's all happening behind the scenes. And so they're on your computer. They look for files. They think might be of interest. [00:06:59] Those files get uploaded to them and they try and spread laterally. And a lateral spread means that they see, yeah, here's some machine that we have compromised. This looks interesting. What other computers on the network? Is there an active directory server, some sort of a file server network-attached, storage, other computers what's out there. [00:07:25] They will probe your network, which again, if you've got good network equipment, you're going to see that probe happening and you're gonna be able to stop it. But most people don't write. And including some of these big businesses that just aren't paying enough attention to how the bad guys operate. Now more than they knew. [00:07:45] The Colonial Pipeline huge multi-billion dollar company. Okay. You now know more than they do in what order we eight minutes into their show today. So they will look around the network, spread laterally, take control of other machines. And they try all of the known ways of getting in. And of course, if you haven't patched your machines and haven't kept them up to date lately, it seems like Microsoft is releasing patches a couple of times a week, just like the old days. [00:08:15]Microsoft fixed that problem. So you no longer had to patch once or twice a week? Yeah. How did they fix it? No, not by fixing their software. I know. No, I haven't forbid know what Microsoft fixer software. No, what they did is. They came up with this concept of patch Tuesday. So once a month, they'll just release all of the patches for all of the vulnerabilities that have been found that they know about and that they could patch readily. [00:08:44] Is that insanity or what? So on average, they were leaving. You exposed for one, let's see, half of a month would be about 15 days. So there you go. About 15 days you were completely exposed. It's this whole thing is insanity. I just, I don't know why people aren't paying attention to it. And I talked to small businesses, and basically, they have their fingers crossed, and they don't think it's going to damage the reputation, even if they do get hit. [00:09:14] But these guys are gathering all of this data from all of your machines inside your network, including your home network. Although they're not as interested in this. If it's just a little home network, other than if you are working from home. Okay. Are you silly enough to use a VPN? That's not configured right. [00:09:35] Or the wrong kind of VPN. Okay. Hey. Yeah. So what we'll do now is we will spread laterally. Over to the business computers and all of the other people working from home that are also VPN in, in, properly into the business network. So they can just spread like crazy. It's, it is absolutely amazing that we're not doing more. [00:09:58] I'm not calling for the feds to get involved with this cause they will almost certainly make everything worse. I'm just shaking my head here thinking about all of the potential problems they can't even get. This whole net neutrality thing straightened out, but DarkSide then has your files. And they do what I talked about a couple of weeks ago here in the show, they hold your files ransom by threatening to release them. [00:10:24] Look at what happened to Metro PD, the Metro police department in Washington, DC, just a couple of weeks ago. Yeah, they got into Metro PDs, computers, they spread laterally. Hey, look at what we found. They threatened to release these files. They had found of all of the confidential informants there, phone numbers, addresses names, cases that they're involved with, et cetera. [00:10:52] Yeah. Again, they're not taking it seriously. There's a lot we have to do. [00:10:58]There is a huge problem out there right now. And the problem has to do with these ransomware gangs. And there are quite a few of these gangs out there, frankly. And one of them called DarkSide has nailed the Colonial Pipeline. What happened is the ransomware got into their network. We don't know the details yet. [00:11:21] I've heard a lot of rumors. I'm not sure. And it started spreading inside the network. Again, you don't have a lot of details. I'm sure I'll find them out. And when I do, I will share them with you, but it spread. And the guys over at Colonial Pipeline said we better shut down the pipeline. Because we don't want the ransomware to cause serious problems thinking about what could happen with a pipeline, you could go overpressure, which could cause the pipeline to burst valves might not close that are supposed to be closed. [00:11:56] It's going to really affect the whole flow of everything in the pipeline. And remember too, you have one pipeline that carries multiple different fuels, so they stop it. From carrying gasoline, for instance, it switched to diesel, they switched to jet fuel. They switched to gasoline. They switched to home heating oil. [00:12:16] All of those are carried by Colonial Pipeline. I'm not sure if they're all in one pipeline, that's just send-up. Okay, we're sending gas now type thing. Or if there's actually multiple physical pipelines inside, I'm not really sure, but there is a lot that could go wrong. Either way, just based on the fact that they don't have the computers to control the vows, to control the flow, to monitor everything that needs to be monitored. [00:12:44] Monitored. So DarkSide is at the very least holding their computers hostage. We don't know at this point, if Colonial Pipeline is going to pay the ransom, we don't know if there's going to be a backend ransom. As I explained a little earlier, we're seeing now these. Bad guys. Not only saying pay us now in order to get your files back, but pay us now, or we're going to release all of your data. [00:13:16] I'm not sure Colonial Pipeline has that much data because they. Probably only have a very limited number of customers. So something might not happen there. The obvious data that they'd be concerned about is what I was contacted about just this week bank accounts, what happens if the bank accounts broken into stuff is stolen, what do you do? [00:13:40] And how do you deal with this? So these. Types of attacks are becoming much more frequent and it's very concerning to all of us. For a couple of years, I ran the FBI InfraGard webinar program and we talked a lot about. Protecting our critical infrastructure, but the critical infrastructure is more than just the electric grid or the fuel pipelines. [00:14:09] Frankly. It includes almost every business because if a business isn't critical, how could it possibly stay in business? Okay. You might argue how about the tourism industry? Is that critical? I don't know, ask the people that work in the tourism industry, if it's critical to their jobs or not. [00:14:29] We have to defend everything and ransomware attacks, according to commerce, secretary Gina Raimondo. Are what businesses have to worry about now. So it's a real problem, but they've got a Homeland security involved in investigating this. They've got, of course, the FBI involved investigating it, and they've brought in some third parties. [00:14:56] And w the one that looks to be the prime, I'm concerned about, cause this is not what they do, but they're saying it's an all hands on deck effort right now. She said we're working closely with the companies, state and local officials to make sure they get back up to normal operations as quickly as possible. [00:15:17] And there aren't disruptions in supply. We already know. There have been some disruptions. I think it was South Carolina declared a state of emergency this week. There's a more than 1800 fuel stations, gas stations that are out of fuel. Some of it is attributed to what we're now calling the toilet paper response where people are saying, Oh no, there's not gonna be any gas. [00:15:43] I better go buy gas now. And some people are bringing cans and cans to fill up as always filling up all of their vehicles. So it is a problem. Now, I'm going to talk a little bit more here about how ransomware gets in so that we can then give you some solutions. And if you have to drop out, I understand you can listen to this whole show as a podcast, just go to Craig peterson.com/podcast, and you can get all of the details there. [00:16:19] I even post. These automated transcripts, they're not like an absolute type of transcript, but it's pretty darn close. So again, Craig peterson.com/podcast, and you can listen there if you miss part of it today. Ransomware has to get onto your machine. Now there's a few ways it can get onto your machine. [00:16:42] There are a number of different types of attacks, but the biggest one that's typically used is called a Trojan attack. And a Trojan attack is kinda as the name implies. You think that it is something other than what it is, the Trojan horse. So the software that supposedly your friend sent you by email that you're downloading, it's not really good software. [00:17:08] It's really ransomware disguised as maybe a Microsoft word document macro. There's a lot of things that it could potentially be, but. That's one of the ways and the most common way gets in there are other ways as well. They can exploit vulnerabilities in software that you're running. So if you're not keeping your machines patched up to date, it could get in using either a zero day attack, which. [00:17:38] Yeah, there's nothing much you can do about those other than having a great firewall. So that's why I recommend having a real high end one, a good Cisco firewall. There are some other brands out there that are pretty darn good. And there's reasons that I like the Cisco over some of the other ones and it is what we sell, because I think it's the best out there. [00:18:00] But having a real high-end firewall can talk. Stop these zero day attacks. Zero day attack is where thethe bad guys are using a vulnerability in your computer. That is currently unpatchable. The vendor, Microsoft, whoever it might be, has not come up with a patch for yet. So the bad guys say Hey, day, let's just get into machines and then they can remote control your machines, install the malware, usually the ransomware nowadays and go off on their own. [00:18:34] That's the number one way they get in. Now, if you've been listening to this whole show so far today, that what has happened is once you have the ransomware that ransomware calls home, Now there's a number of different pieces or classifications of software that call home. One of them is ransomware. [00:18:57] So it gets on your machine. It calls the bad guys up and says, Hey, here I am. What do you want me to do? And usually the bad guys. If it looks like a decent target, hop on your machine, poke around, try and spread laterally. As I explained, in some cases, what it does is it just uses your machine, particularly if it's just a home machine and there's nothing particularly valuable on it. [00:19:20] It uses that whole machine now as part of a botnet, and it uses your machine that it's taken over to attack other machines. And unless you're paying a lot of attention, you probably don't even know that it's happened. [00:19:37]What do you do here with ransomware? He gets in, it looks like it's something that it's not most often, it's a Trojan. Sometimes what happens is the bad guys are sending it all in because of a zero-day or more than likely because you haven't applied the patches to all of the software that you need to patch. [00:20:01] So there's a few different things here, right? That, that you gotta be careful of. So do those, you hear it a million times. The next thing you can do to help prevent this from happening is to make sure your usernames, email addresses passwords are unique for every site you go to. Because some of these bad guys just go to the dark web, they can download for free your email, address your password from hundreds of websites. [00:20:35] Yeah, it's available for them. It's been stolen, and it's been released in some cases, they have to pay for it, but, overall it's well worth their money spent to find out your username and password. So if you are working from home, let's say you're a homeworker for, let's say Colonial Pipeline here, making stuff up right now, a nonexisting company, and you're at home. [00:21:01] He was supposed to be monitoring the pipeline, make sure the right valves are open when they're supposed to be open, make sure the fuel is flowing. Make sure all of the bills are getting paid invoices going out. And you're just doing it from home. And in fact, you got a nice little laptop set up in the corner of the bedroom, on a table. [00:21:20]It's, it's the life. And then. All of a sudden you're losing control. Just what I, I know of two water systems where this happened. Yeah. Yeah. All of a sudden somebody finds your username and your password online and that email address. Yeah. Yeah. [00:21:41] [email protected]. Perfect. Okay. So let's look in the dark web. Oh, here's Joe's. Password that he used over on LinkedIn back when we stole all of those LinkedIn usernames and passwords and emails and everything else. So let's just try that because we see that at colonial pipeline. There's this remote desktop server. [00:22:07] And we know that. Yeah, because we scan them in. There it is today, remote desktop server, you know what they eat the named it remote desktop, RDP dot colonial pipeline.com. Of course, we're talking about a fictional company here, but it's only now God, I use their name and email address and a password that has been used by Joe on one or more other websites. [00:22:31] So what do they do? They say. I'm going to try. Let me see. Let me see. I'm going to connect right now to the Microsoft remote desktop server at colonial pipeline. And let's try and log in as [email protected] and let's cut, copy and paste the email address that he was or a password he's using it. [00:22:51] LinkedIn, you know what I just noticed he uses the same. Password even a few years back over at Facebook. So let's just try it. Oh, look at that. I'm in. I'm in. So what's the next step? The next step is, of course, they start to poke around a little, can I take control of this machine? Let's download my ransomware onto the machine. [00:23:13] And of course this fictitious company known as colonial pipeline. They don't have a really great firewall that looks at it. Everything that's being put onto a machine downloaded. So it's not even going to notice that we're installing the most common form of ransomware on the internet today. So let's get that on his machine at work. [00:23:35] Okay. At Tonya's machine at work and off. Okay. We got it. We're the remote controls working. So let's just connect from the remote. Desktop server and okay, so we're in now, let's see what other machines we can find on their network and off they go, this fictional company now because Joe had a username and a password that he has used before on another website, they were able to get into our fictional company. [00:24:06]Does that make sense to you? So now they're inside, they're moving around. They're taking control. They're finding the computers that are used to control the valves, the flow of oil, or whatever's in the pipeline. This. Day and okay, so we're all set. So let's go ahead now because we've got all of their files, including all of their banking information while we were in there and [00:24:31] we [00:24:31] Craig Peterson: grabbed all yeah. [00:24:33] All of the account numbers, all to their customer info. So let's let it loose. And now they start encrypting all of the data. And by the time this fictional pipeline company has figured out that they're on there. Guess what? Yeah. In fact, what happened was they found out that they had been hit with ransomware because the ransom messages came. [00:25:03] So that is how it could happen. And that could happen to almost any company out there. And the reputation damage is enormous. The amount of money that is going to cost them is enormous. It's more than doubled in the last year. The cost on average now is over $1.2 million because of a breach and ransomware. [00:25:29] And so now they're in big trouble. Really big trouble. So how could you have stopped this? That's where life gets interesting. And I have done a number of webinars on that very thing we've delved into in some detail, it's been about a year and I'm thinking what I'm going to do is just put together some little courses that if you're on my email list, you'll find out about just little free things in order to help you guys understand this a little bit better. [00:26:00]So I'll make sure you're on my email list. Craig peterson.com/subscribe, and I'll explain it all. So here's what you can do. First of all, get a various smart, next generation firewall. Now, one thing about cybersecurity that you'll find is there are a lot of criminals out there. A lot of criminals and. [00:26:25] I'm not just talking about the people that put ransomware on your machine. I'm talking about the people that are telling you to buy their VPN product because it's going to make you safe, and they're lying about it. And they're really lawyering their words. So that, that perception that you have is somehow you're going to be safe. [00:26:43] I'm talking about the people that will sell you this. Anti-virus software that not only do not need but could potentially open you up to even more security problems, just like the VPNs can open you up to more security problems. It is full. Of criminals. They just haven't been convicted yet. Okay. So it, it's definitely a problem, a very major problem for so many people and you just don't know. [00:27:14]So that's why I want to make sure you guys understand why it's happening and the how it's happening to can. Then go on to the next step and what do I need to do to keep it out? So a really good next generation firewall, by my definition, means that firewall is going to examine all data coming in and going out. [00:27:40] So it's going to be able to look at anything that's encrypted at websites that are encrypted at data that's being downloaded at zip files that are being downloaded and check the payload to make sure. That it is legitimate traffic. Okay. It sounds easy, but again, there's so many criminals in the cybersecurity business. [00:28:03] You have to look very closely stick around. [00:28:06] So if the bad guys have control of a machine and they are trying to download some malware, in this case, ransomware, the firewall is going to see that and stop it right there. [00:28:20]Most firewalls, all they'll do is block certain ports, or they will stop as someone on the outside from getting. To the inside, but what about you going to a website and downloading accidentally, or maybe purposely downloading some software? That's malicious. Or what about some guy the got onto your computer via your VPN connection or your remote desktop or team viewer, et cetera. [00:28:51] And now has control of your computer. You have to watch all of the data coming in, going out, and it all needs to be checked for. Any sort of malware. So that's one of the first things we always do. Now. The next thing has to do with your computer. I'm going to focus in on windows because that's what most people have. [00:29:14] Nowadays. If you have a Mac, you're relatively safe. If you have a Google Chromebook again, You're relatively safe. Just keep them up to date. All right. But windows, windows is a whole other world and you know how much I love windows. Yeah, not right. And I worked on it way back when in the empty days. [00:29:39] Anyhow. Microsoft Windows has built into it. Now, some very good software that can help protect you. Windows defender, make sure windows defender is turned on and is up to date. If you have windows. And it's a recent version, and you need to be running a recent version of windows. Then you have access to windows defender, turn that on. [00:30:08] And windows defender again, keeps an eye out for malicious software. Oh, really? Who knows windows better than Microsoft? I would argue there are some people, but as a general rule, Microsoft understands what they're doing here. They have kept it up to date, right? They have had major security problems in the past with windows, the vendor itself, but most of those are fixed now. [00:30:33] And to me, the measure of success isn't, Hey, it's a hundred percent secure because you and I both know that's a load of cow stuff, because nothing's a hundred percent secure. And whether it's made by Microsoft or it's made by Cisco. There could potentially be problems. So Microsoft has fixed the known problems anyways, in windows defender. [00:31:00] So make sure that is turned on. That's the first free tool I wanted to mention, and it is huge. The next one is, of course, make sure you're up. Dating your machine. I don't mean just windows, make sure all of the other software in your machine is being updated. If you're using a browser like Firefox or even Google Chrome, I have issues with Google Chrome from a privacy standpoint, but at least both of those browsers and many others that are based on either one of them, the both of those browsers do. [00:31:36] Update themselves automatically. So that's like a huge win. So they'll keep themselves up to date, but most of the Adobe software won't keep itself up to date. Most other third party applications that you might've bought and installed on your computer or downloaded. They're not going to keep themselves up to date. [00:31:56] So keep on top of that. That's the second thing you can do. That's usually free. I would say usually because Microsoft does sometimes charge you for upgrades. I'm not sure they're going to do that anymore. The whole naming scheme and everything else, numbering scheme for windows indicates that maybe they've dropped that idea. [00:32:18] Yeah. But some of these other vendors might charge you for new release. So let's say Microsoft really decides I'm working on our climb down. We're not going to let this malware continue to give us a black eye. And so they changed the way parts of the operating system work. And so that software you're using for your customer management billing, whatever might be requires an upgrade, which of course that vendor's going to call a major upgrade. [00:32:45] And now you've got to do the app. Great. And you've probably got to pay them in order to get your hands on that upgrade. So that's why I said usually free, not always free. Microsoft also comes with a firewall, and I use that term very loosely because it's an old style firewall. It is just protecting data on certain parts. [00:33:10] And Microsoft does a very poor job of configuring that firewall. Basically, Microsoft doesn't want any tech support calls. So they pretty much turned on all of the features that you could possibly have. And when it comes to the firewall, they just leave them all wide open. To me, that's a huge problem. So yeah, the firewall is turned on by default on windows. [00:33:38] It is by the way off by default on your Mac. And both of those companies take much different approaches on the Mac. Nothing is enabled that doesn't, isn't explicitly turned on. So there's not a whole lot of reason for a firewall because you don't have a file server running on your machine. SMB file sharing. [00:34:00] You don't have a way a web browser running on your machine, et cetera, et cetera, all of that stuff you have to turn on manually. So on windows. I've I have a course that I haven't released yet. That talks about how to harden windows. I did my improving windows security course. I released that in April of 21 and a lot of you guys signed up for it and I've had nothing but great feedback, a few legitimate. [00:34:28] Questions people have, but great feedback over the course. So I'm going to have to do one on specifically the firewall on, on windows and maybe the windows defenders as well, but you're going to want to turn off any services you're not using. And I do describe that in the improving windows privacy and security course. [00:34:50] So if you took that. You've Oh, and you did it. You've got really your mission locked down. Noah came anyways. I'm rambling. Next up. Remember I said that the malware calls home, both ransomware malware, calling home to say, Hey, look what I found. You want to have a poke around. And another piece of nastiness called a botnet. [00:35:18] Where the button that will again, call home to the bad guys and say, here I am, let me know what you want me to do. And very frequently they'll use your computer. It might be a home computer might be a business computer. They love business computers because usually they have a better internet connection. [00:35:37] And they'll use your computer. Just send out a hundred million pieces of spam to any email address they can find. And once they've done that, of course, what's attached to that email while ransomware or other nastiness that's out there. So how do you stop them from calling home? Again, the non-paid or the paid, I should say option is a really good next generation firewall. [00:36:05] So we had a client that has an office here and an office that's out of state. And what happened was one of their of state offices had connected in via a VPN that we had warned about. And being in properly set up and configured and protected. So they came in on that VPN, the bad guys did because they had control of these out-of-state computers and they found accounting files, and they started to upload them. [00:36:38] So we had a really good next generation firewall from Cisco in place of firepower firewall. And we've got all kinds of equipment in our data center that, that controls all of that, but it saw, wait a minute. There's data being exfiltrated we're seeing in their account information potentially. So I would shut it right down. [00:37:01] So they got a few megabytes worth of data out and that's it. We shut it right down. It was all automatic. And then it informed us, Hey, look at what we just did. You might want to have a closer look, which of course we did do. So having that next generation firewall that can recognize data coming into your network and going out of your network is crucial. [00:37:27] The other thing that you can do, and you can do it for free or paid, the $50 a month charge that we have for endpoint computers. In other words for desktops is includes a paid version of this. Which is more advanced, but you can get it also for free. And it's obviously it's not as good and as many options, et cetera, et cetera, not men really for business, but checkout open DNS online. [00:37:58] You can go there right now. Just open D N s.com. Open-domain name server.com. And you can find out how to do it there, but it is as simple as setting your name servers to the addresses. You'll find [email protected] homepage. So you'd set it to two Oh eight 67 two two two-dot two, two, two. [00:38:26] And. Let it do its thing. So what happens now, once you've set up your DNS using open DNS, and again, you can get it for free and the low end. And then at the higher end, it's called Cisco umbrella and a lot more features, but when the bad guys trying call home, they need to convert the name of their server. [00:38:48] Into an internet address and open DNS is updated quite frequently. I know the commercial versions that we have are updated instantaneously 24 seven, whenever anything is discovered. And I think the free open DNS is pretty close to that. So put that in place. Do some of these other things I've been telling you about, and you're going to be 95% ish safe. [00:39:17] That's pretty good. Isn't it for nothing plus the firewall, which can cost you some real money. Some of these real fast firewalls can cost over a hundred grand for a very large business, you can start at just a few grand anyways. [00:39:32]Colonial pipeline. Of course it hit the East coast hard. It particularly hit the Southern state, some of whom declared States of emergency because of what was happening, panic buying. I don't know if you saw the pictures of people with a gap, with a gas in. [00:39:51] Trash bags, clear trash bags, people buying every fuel can, they could fill it up with gasoline, somebody dangerous things. I remember back in the sixties, a friend of my dad's had this beautiful Corvette. I'd love to have one of those nowadays, and he needed to get some gas for the lawnmower. So we went down to buy it, and he had a gallon jug that he filled up with gasoline. [00:40:17] Oh, my gosh. And we had this glass one gallon jug in the back with me. This was the Corvette where there was that little, a two piece window in the back. And that's where I was just a little kid. What happens if you're in an accident? It just, these people who are doing this are crazy. Plus the gasoline is almost guaranteed to break down that trash bag. [00:40:43] This it's just not true. What people have been doing. No man, no wonder people have been calling it the latest toilet paper fear, right? Where everybody went out to buy toilet paper, but this is a real. Problem. We've got Saudi you do remember this Aramco. They were probably hacked by Iran about a decade ago, and we've seen hacks against all kinds of other utilities, these public service, if you will utilities that provide us with. [00:41:14] Pretty much everything that we need for our daily lives. And colonial apparently had a cyber health assessment about five years ago, give or take. Now it sounds like it was the same thing that we do for businesses, a paid one versus the free ones. And I've got. A checklist that you can use. [00:41:36]I'll send it to you. All you have to do is ask me for it. And you can use that to get an idea of what are the things you should be doing to prevent this. What are the things you can do as well? And if you listen to the first hour today, show of course, I went through some of the free things you can do as well to help prevent all of this sort of thing. [00:41:56] So they did go through a cybersecurity analysis. Apparently, they did not follow through on all of the recommendations. And as I started out this segment today, one of the things that's really probable, probably behind this is because they didn't know what they needed to do. So many of us are using people who are great people. [00:42:22] They love computers. They've been learning a lot about cybersecurity, but none of the snow, everything. And unfortunately, so many of us just don't know enough. And we're talking about over one, 1 million to 2 million open jobs in cybersecurity. So everybody's hanging up their hat. Everybody's putting out a shingle saying I'm a cybersecurity expert person. [00:42:47] I've got months, even, maybe even years worth of training. That's all well and good, but you still need to have a third party come in and look, and then you have to follow the recommendations. That's the other big problem I found is businesses just not following the recommendations. And then we get calls back in on average. [00:43:08] I think we figured it out a couple of months back. It was like eight months after we do a cyber health assessment for someone they come to us and say yeah, we got hacked. Can you fix this for us? And in some cases, we're able to close things up and help them out. Just like the phone call we had this week. [00:43:25] And they had taken some of the right steps to make sure that they shut down these hackers. But there's a lot of things I just plain didn't do. And that's a problem, right? We have government contractors that are subs, and sometimes these guys have the primary contracts, and they're out there in the front line. [00:43:48] They have potential prison terms. If data is stolen, Now this last week, this week, right this week. Okay. It's Saturday now, president Biden signed an executive order that is starting to put teeth into these laws. If you even sell something to someone that ultimately has a contract with the federal government, you've got some serious liability now. [00:44:18] If data is stolen and we could get into a lot of details because it happens all the time and people have businesses and they say I just make X product, but the only customer for product X is the government. And you just had all of the purchase orders stolen. And think about Hogan's heroes, right? [00:44:40] If you remember that show back in the sixties and early seventies and in the whole Cogans heroes, what ended up happening is they were looking at it all saying what should we do? What can we do? When we're were to get a little bit of information and they do everything they possibly could to get that information back to London. [00:45:00] And sorry about that. A little phone ringing here. So they're trying to get all that information back to London. Some of it, they got back, some of it, they didn't get back, et cetera, et cetera. But just that little bit about wait a minute, now they just bought 50 of these. Therefore we're thinking that the military. [00:45:19] Is now starting to expand and is going to be doing this or doing that in this area, that area, right? Those little bits of information are valuable, not just to someone like Iran or to Russia or to China, it's valuable to competitors. So president Biden's latest little executive order is really starting to. [00:45:44] Bite into all of these contractors that have been, as we call a pencil whipping forms. Now the SPRs forums as the type of form, they have to go online. They have to report about what their compliance is for their cybersecurity maturity. They don't know what they're doing. They don't know what they're filling out. [00:46:01]I'm thinking maybe I should go ahead and. Put one more little trick into this whole thing. And that is have a a service where we help businesses fill out their paperwork and understand it. But the reason I haven't done that is because the businesses that I know that have been lying on these forums, pencil whipping the forums, they don't really want to know. [00:46:29] Cause then they have plausible deniability. So how do we solve this problem? It really bothers me, frankly. When we come back, I'm going to talk about these five urgent actions that are happening right now, where these 65 businesses, nonprofits, and NGOs have formed this ransomware task force. [00:46:51] What this is about, what it's hopefully going to help everybody out with. But I want to really emphasize again, do you guys. Make sure you have a good cybersecurity health assessment. You have to have that. And if you get a cha cybersecurity health assessment, I'm more glad this end of the paperwork, you can do it yourself. [00:47:14] Okay. The basics and you know what else I'm going to do. I'm going to have a training on this. That's available for free. I'll put that up on my website so that you know what each one of those questions really means. It's so that you can now. Have a good look at your cybersecurity. Cause I know a lot of you guys you're retired. [00:47:34] You have some money that you're trying to protect from these bad guys. A ton of you guys are small business owners like me, right? I've owned and run small businesses for decades now. And. We just are focused on our businesses and just don't know everything we need to know. We don't even know what we don't know right. [00:47:56] About cybersecurity. So I'm going to help you with that. But when we get back, we're going to talk about these fights. If you want to reach out to me, if you want a copy of any of these cybersecurity health assessment forms. I'll send them to you. No problem. Just email me. M [email protected] or reply to tomorrow's email. [00:48:17] If you're on my email list, I'll be glad to get that off to you. No problems, no questions asked. I'm not going to be harassing you. If you want us to do a deeper dive, where we look at your systems, we scan them all. We help you prioritize it. We put together a series of steps that you can take to make sure all of the is done in the order that it really should be done in. [00:48:42] Yeah. Be glad to do that, to that, to pay the assessment. There are a number of companies out there that do it. There's about 1200 nationwide. So you should be able to find somebody if you don't trust me, I get it. That's fine. But get one done, get a very good one done and go deep into it. We're also hopefully going to be able to get into some of the other articles, and you'll find all of these, of course, in tomorrow's newsletter. [00:49:09] And you can get that by just going to Craig peterson.com/subscribe by Google, wants people to use two factor authentication, which I think is a great idea. So it's going to start turning it on for you guys. App tracking. Apple has just gone above and beyond yet again in helping to keep our data secure. [00:49:30] Thank goodness, not just secure, but. Private Peloton man. They're hurting again. Total mess up on their part again, cybersecurity, absolutely cybersecurity problems. [00:49:42]Now we've mentioned here in the last hour about DarkSide ransomware, and these are groups. Both bad guys that have been doing ransomware for a long time and more lately, they've gotten together and built a company and this company actually sells ransomware services. Now I don't mean that if you've been hacked to go to the DarkSide and say, Oh my gosh, we got ransomware. [00:50:10] Fix it for us. No, they are selling. Ransomware as a service and the hers there. There's a huge problem with this. It's just absolutely amazing, but there's some security researchers out there who have been trying to find out okay. Who. Is using them. So let's give you a couple of numbers here. So you have an idea of how much money DarkSide is making by selling this as a service. [00:50:40] So they, they do everything. They write the software that holds your stuff ransom. They go ahead on that software, and we'll do tech support, not just for the people that have licensed their software, but tech support for you. The poor ransom me. Okay. All of that stuff, but according to what is in, let me see ZD net. [00:51:05] They went and had some researchers check out the DarkSide, ransomware variants website, and there's some forum posts there that indicate that affiliation with DarkSiderequires 25% of the cut for ransomware payments under 500,000. And it has a sliding scale. So if you can ransom somebody. For more than 5 million, all they want is 10% of the money. [00:51:36] Can you believe this talking about a real business? It's just incredible. So they are out there and they are really rampant now. And they've been doing it since last summer, this whole double extortion tactic and something they've really fine tuned where they say pay us. And we will decrypt your data. At least we'll give you the key and help you decrypt it, or don't pay us now, but pay us later. [00:52:03] So we don't release your data. As I mentioned, that's what's happened with the Metro DC Washington DC police department that got the data out of the police department, and they're threatening to release it. If the DC police don't pay the right money to them. So these guys, these researchers and this particular cases, fire, I said, they have found five groups that are doing rants that are linked with the DarkSide, bad guys. [00:52:36] And they've got these letters, numbers. It's not real names. It's just what they've been labeled. But the, I wanted to go through here. What these. Different affiliated DarkSide, ransomware gangs are doing so there's one where there's was to start with one we'll run through all five and what their tactics are. [00:53:00] But this first one, which is identified as UNC 26, 28 has been active since February this year. Now, remember how I mentioned how they'll get into your network and then they'll start to move. Laterally within the network, they'll try and infect other machines. If they get onto your home machine, they'll go through the VPN that you're using to connect to the office. [00:53:21] And. Once they're there, they'll start spreading between office machines. And there's some thinking that has actually happened in the case of the colonial pipeline. We'll know more details. I hope fairly soon I've been watching what the FBI has been saying. They send me updates, but I haven't seen anything. [00:53:41] That's publicly shareable at this point in time. Anyways. So this lateral movement is where they're really going to kill you. And this first group tends to move quickly from the initial infection where they get the software on your machine. And they're only lurking on your network for two, two to three days before they start the encryption. [00:54:06] That's all the time it takes for them to find all of your machines. Now they use suspicious authentication attempts, brute force attacks. Spray and pray tactics, all common spray and pray means they're just looking for anybody out there. They're not going after a specific target. They'll find your home, the computer and bam they're in and they'll just take bank account information, or they might use your machine for attacking other people, including by the way, attacking governments and governments don't take well to having your computer attack them. [00:54:40] Okay. So they. Apparently, I'm just trying to summarize all of this as we're going, but they get their initial access through legitimate credentials for corporate virtual private networks. What have I been telling you for a long time? VPNs are not the panacea. Most people think they are, and they purchase it from other criminals. [00:55:02] Next group, 26, 28. Is thought to partner with other of these services besides DarkSide and includes revival and net Walker. Another one has been active since at least January, they moved from initial access to ransomware deployment at an average of 10 days. So it used to be about two weeks. And that's where I've been saying for a long time, that most of the time when you get ransomware, They'll be in your network, poking around for a couple of weeks, but it's been so profitable. [00:55:36] They may well hire more people and spread more quickly. So instead of 14 days is now down to three to 10 days. According to this report, I'm looking at right now, from what FireEye has said and fire, I do do investigations of these types of things. And in fact, they got involved in some political stuff, not too long ago as well. [00:55:57] Team viewer home. My gosh, Microsoft team viewer. It's abused to maintain the persistence in connections. That's where they can continue to be on your machine. Get on a compromised machine, and then they exfiltrate your files before they encrypt them. Next one here, dating back for a little over a year. [00:56:20] They use a phishing name. Emails to deliver this DarkSide ransomware, and they use a smoked ham net backdoor. So there go here. This group can wait on your network and lurk for months ahead of when they actually fire up their ransomware and our friends. Over at Sofo said that they've been called in to assist on five different instances of DarkSide ransomware infection. [00:56:52] So there's a lot to know there's a lot to be concerned about, but remember they get in blocking them. The way I told you in the last hour is really going to help. It's going to stop more than 95% of them, and it doesn't have to cost you a dime. Mind you, the paid versions are going to be better, but that's the way that is. [00:57:13] And we also now have these 65 businesses, which includes some nonprofits, government organizations, and formed this ransomware task force. So that's, I think good. News to all of us world economic forums involved in this as well. And they're just trying to really help. Now, what I get concerned about is the government's involvement, and it's one thing for the government to follow up after an attack. [00:57:44] Okay. And it's another thing for the government to provide general information. In fact, you can find it. The small business association has quite a bit of stuff, not as detailed. I don't think it's anywhere near as good as the free cyber health assessment forms that I can send you. But they, we do have it. [00:58:01] A lot of places have it, and it is well worth looking into. I, so yeah, here we go. Average downtime due to ransomware attacks, 21 days, get that thorough cyber health assessment done. Now whether you do it yourself, you hire somebody to come in and do it. Or we did 1100 of these last year for free for listeners and their businesses. [00:58:29] So more than glad to do it as well. Just email [email protected] and I'll get all the info out to you. [00:58:36]Look at what's happening right now with. [00:58:38] The whole colonial pipeline thing, and I am more than glad to help you guys out. And all you have to do is just go ahead and email me M [email protected]. All right. Getting down to it here. Two factor authentication. A lot of people have started using. Text messages as part of two factor authentication. [00:59:02] So for instance, you go to a website, you put in your username, which is usually your email address, which is a bad idea from these people that coded up this terrible software, right? You should be able to choose your own username, so you can have a different username on every website, and then you put in your password. [00:59:19] And of course you guys. Best and brightest, you are using different passwords on every website, and hopefully you're also using a password manager to keep track of it all. I were really surprised. I looked at it. I had 1200, 1200 different. Accounts on different websites. So then you probably have more than you realize, but SMS, text messages are not the best way to do two factor authentication. [00:59:53] The idea behind a secure system, just a regular login security is, do have something, along with something you have. So there's something, is your username and your password. Something you have. That's a lot different, isn't it? And having your phone with you that can receive a text message is not really going to protect you, especially if they are out to get you. [01:00:17] So if you have a fair amount of money in investments, maybe you have some Bitcoin, et cetera, many. Times now there are a lot of examples I can cite of people who have had their phone number hijacked. So the bad guys remember the, all these data, leach data breaches, these leaks, where they've got your username, they've got your password, they've got your phone number. [01:00:42] So if they really want to take over everything, all they have to do is. Grab ahold of your phone number, because most of the time, how do you recover your password on our site? Oh, I just go ahead and have it, send me a text message. What happens if instead of that text message going to you, that text message goes to a bad guy because they've taken control of your phone number. [01:01:07] It happens. It happens every day. So Google has an idea that I think is a pretty reasonable one. And Google has for a long time, had an app called Google authenticator. And I used that when it first came out, and I played around with it a little bit nowadays I've been using duo, and I've got, go do all set up so that. [01:01:27] I can put in a one-time password thing, but that changes every 30 seconds or so. And you might've used those before. Sometimes it's a token, et cetera. But what Google has done for two factor authentication is they have it set up so that when you go to login. If you have a Google program on your smartphone, it will have you open up Google, for instance, the app on your smartphone. [01:01:55] And then you confirm that yes, it is me who is logging in. It's not a bad idea. They do it a little different on Android. Google's prompt is a full screen. Popup is built into every Android device as part of Google play services. So it's really pretty easy. This is going to be, I think, a good game changer because otherwise you're in trouble. [01:02:20] I just got a call. This is just crazy. Yeah. What a week, this week from another listener, who's a church. This particular church had been basically hacked and their main email account was hacked into the bank account. It just goes on and on. And it smells like they may have access to his text messages, which are used for account. [01:02:48] Recovery. So this type of two factor authentication thing that Google is pushing out. Yeah. I think is a very good idea. They're becoming a little more proactive and it's, I think it's going to be good. Yeah. Overall we'll see how this all goes. There are some other ways to do it. I think maybe some better ways, but this is not a bad way. [01:03:14] Now speaking about privacy versus security, we've been talking so far about security. That's what two-factor authentication is all about. And if you want a little privacy, Android slash Google is not the way to go. You know that already. I say every time that you should be using duck, Go, not Google to do searches online, to find stuff well, Apple released their newest version of iOS, which is of course the operating system for the iPhone and for the eye pad. [01:03:48] And I guess the iPod, right? Like the iPod touch and stuff, but this operating system has now code in it that pops up and asks you if you want to allow an app to track your activity across other companies, apps, and websites. This I think is a very good thing. At least, that they're trying to track you, right? [01:04:13] So Facebook has been complaining about this for a long time. The experts said probably 40%, maybe 60%, let's call it. 50% of people will allow the app tracking. It turns out that 96% of users in the us have opted out of app tracking. In this latest version of iOS, which to me makes a lot of sense. In other words, only 4% of people said, yeah, you can track me. [01:04:44] What does this mean? Obviously to you as a consumer, it might be good. It actually might be bad. Again, if I want to buy an F150 pickup truck, I wanna buy an F150 pickup truck. Now, maybe you could try and talk me into buying a Dodger Chevy or something else. I get it, but I want a pickup truck. I don't care about seeing ads for women's pajamas or you name it. [01:05:16] I'm looking for a pickup truck. So I want to see ads that are aimed at me for something that I want. I you're probably the same way you remember those days on the internet, where you were constantly getting these male enhancement. Emails. And they went out to everybody because they had no idea who you were. [01:05:38] They didn't have any information about you. And when Facebook and Google and some of these others came along, all of a sudden you were getting more relevant information. By not allowing them to track you, you are going to be getting ads that maybe aren't as relevant as they used to be. Now on the other side, it's nice not having them track you because it's none of their business. [01:06:04]But it's, I think it's overall a good thing. Reminds me of Tom cruise in minority report where he's walking past those billboards, and they scan his eye. As all that's possible from that distance. And they recognize him as, what was it, Mr. Tadashi or something? Not definitely not him. And they were trying to sell him something that were tied into what Mr. [01:06:29] Tadashi had purchased before. And the machines, just the billboard just thought it was Mr. DACI not the Tom Cruise character. So this is going to change quite a few things. If you are a. Business. You're going to have a little bit of a harder time trying to track people, which also means, by the way, and not distract people, but, find people that are of interest to you. [01:06:53]I want somebody that's a white male in his mid forties who drives an F150 that is 10 years old, which means, okay, he's probably going to buy another one. You're going to have a little bit of a harder time with some of that tracking. So it's going to cost you a little bit more for some of the advertising, but I think it's also going to drive down the cost of ads on some of these platforms, because they're not going to be able to target as closely as they could be for all right. [01:07:20] really we're everywhere. All you have to do is you can find the podcast. You can go to tune-in dot com and of course you can just ask your Amazon Alexa, Alexa, play. W G a N and off she'll go, there are so many articles to talk about this week. [01:07:36] You will find all of them in my newsletter. And what I typically do in the newsletter is not only do I go through hundreds of articles and put together a collection of what I think are the most important ones, the best ones for you guys to be able to follow. But I also send you right to the person's website that put the article out. [01:08:00] So they get a little bit of credit. Maybe they get a little bit of advertising revenue, that revenue we talked about in the last segment today. But I think that's the way it only fair to everybody involved. Although obviously I'm adding a lot of my own commentary. So if you want to hear what I had to say about it, Subscribe to my podcast. [01:08:24] Just go to Craig peterson.com/podcast. You can listen to them there, or if you are a podcast listener, I'd really appreciate a comment. Hopefully I've earned five stars from you. Just go to Craig peterson.com/itunes, and we will. At that point be able to track it a little bit subscribing to the podcast really helps us. [01:08:49] And that's how some of these podcasts are measured and I'm doing this all without any commercial content. On the podcast that I do, obviously here, there's some great companies that are supporting us and trying to get this message out. And I appreciate them for advertising, but on the podcast has used subscribing that really helps Peloton. [01:09:12] You do remember Christmas, was it last year or the year before Peloton running these ads and this guy was going to buy this exercise bike from Peloton for his wife. And it seemed like a great Christmas gift for her. She seemed to be very excited about it. And then all of these snowflakes started saying, Oh, that's just terrible. [01:09:35] I like it. Was you doing saying she's fat. What's going on? Obviously she wanted one of these Peloton bikes cause they are amazing. Peloton has done just a great job in tying it into internet training, and you've got a coach, and you've got some really good hardware. The only in the form of the bike and Peloton has some other things as well. [01:09:57] So they really got nailed over that one and I think a little bit unfairly. And then we also had here within the last week, two weeks. Recall by Peloton on two treadmill models. And this was following the death of a six-year old child who was pulled under one of these treadmills is a terrible, I know I've gotten caught up in them before as well. [01:10:24] And the consumer product safety commission said that the recall decision took some intense negotiation. Because they're, Peloton, they didn't want to get nailed for something and it wasn't really their fault. But the CEO of Peloton did admit that there was a mistake here, but this is just, it's a terrible thing to think of. [01:10:48] In addition to this death, apparently Peloton received at least 72 other reports, according to ARS, Technica of adults, children, pets, and or objects getting dragged under. The tread plus treadmill 29 children suffered injuries. Second and third degree abrasions, broken bones, lacerations pretty bad all the way around, you've got moving. [01:11:13] Parts stuff can happen. I don't know. It's do we really need a label on our lawnmower telling us not to use it, to cut our hair? It's bad. It's terrible in any of these things happen. Oh my gosh. I'm not going to read the details here, but this poor little boy's three-year-old son. [01:11:32] No, I'm the parent involved. I'm sure he felt feels this terrible. So there you go. That's problem. Number one, Peloton had and within the last week obviously a major problem considering what happened, but also. Piling on to what happened at Christmas, with all of the snowflakes complaining. [01:11:54]It's now come to light the Peloton exposed sensitive user data and continued to expose it even after it knew about the leak. So it's no wonder Peloton stock price closed down 15% on Wednesday. Now I've got to add to that, that because of the lockdown, starting to go away. A lot, fewer people I think are going to be exercising indoor on their Peloton, but it's still going to happen. [01:12:23] They've got a lot of stationary bikes got a lot of treadmills, but 3 million members, according to their stockholder report and the data exposed include the user IDs, instructor, IDs, group memberships workout stats, their sex and their age, their weight. If they're in a studio or not There's apparently another piece of personal data exposed that the Peloton still hasn't secured. [01:12:50] And so ours check Nicola where this article was published, said, we're not going to tell you about it because it's still being exposed. It's pretty bad. Apparently again, this is just bad programming. It's the API APIs, these application programming interfaces that are used by programmers. [01:13:09] That are used to connect to cloud services, et cetera required no authentication before providing the information. I was reading an article this week, too. On an API might've actually been theirs, but again, no authentication says, okay, we'll lock it down. We're going to lock it down. So how do they lock it down? [01:13:30]They put a username and password on it. Okay. That sounds reasonable. But if you had a username and password, you could access. Any personal information on any API call? I didn't just restrict it to yours. Oh my gosh. Yeah. Totally barked fixed. In fact that it looks like it was Peloton who botched that fix. [01:13:53] Okay. Move onto the next one. We've got a lot of stuff here I RRS is, has been for a long time. Warning people. Hey, listen. If you have an asset. And you sell that asset. You have to pay taxes, and we've got President Biden now saying, Hey, if you invest in a company and you lose money, it's too bad, so sad. But if you make money, now you've got to pay taxes on it. [01:14:19] And they're saying the same thing about, of course, Bitcoin investments and not just Bitcoin, any cryptocurrency trades. Now they have the IRS been granted permission by federal court in the Northern District of California to issue a John DOE summons. And what they have done is they've sent us summons off to this company called cracking and cracking is a us facing arm of something called pay word ventures, according to ZD Net. [01:14:56] And what they've said is they want information on any us taxpayers who conducted at least $20,000 or the equivalent in cryptocurrency trades between 2016 and 20. 20 now they're not alleging that there's any wrongdoing. Cause we know every last person that did a cryptocurrency trade and made money on it, paid the taxes. [01:15:22] And we already know president Biden is planning on increasing those taxes to over 30% right now. Say lovey. What are you going to do? According to the IRS convertible cryptocurrency. In other words, cur cryptocurrency that you can trade for Fiat currency, your affirms, your dollars such as Bitcoin may have tax liabilities. [01:15:46] All in fact it does. So keep that in mind, everybody. That you sell these things, you owe money on them, just like if you sold anything else, frankly. So apples, I mentioned the last segment here, but Apple's new iPhone, anti-tracking feature. It is being called devastating for Facebook. And I agree with that. [01:16:11] Absolutely agree with it. And this is from bgr.com. They've got a lot of great technical stuff up there. But Apple rolled out this new iOS update, and it's forcing developers to ask for consent before tracking users across your Apple apps, which I think is really great. But what's interesting is that Facebook is looking at a devastating loss in revenue. [01:16:41] Lisa asked her, they're saying at this point, both Facebook and Instagram have come out and said that they might no longer be free. And if you block the tracking there, he might start charging you. So we'll see what happens obviously. Facebook and Instagram can still track you within their application. [01:17:03] Although they're supposed to tell you what they're doing with your data, and if you go into the Apple app store and you pull up, for instance, the Facebook app, it will tell you right there in the app store, you scroll down a little bit. To the privacy section. It'll tell you what it is Facebook is doing with your data right now, that self reported, but we'll see what ends up happening. [01:17:29] I'm looking at these opt-out rates cyst. It's crazy. There's a whole bunch of graphs here showing how people just don't want to be tracked. So it makes a whole lot of sense, frankly, a whole lot of sense. Let's see. And. Our last one here is really, I think the bottom line fought for the day. Ransomware is up dramatically. [01:17:54] We've seen triple the amount of hacks ransomware hacks in the last year we have seen. Doubling of ransomware payments, the average business that gets ransomware, it takes them on average about nine months to get back to normal nine months. So I really want you guys to spend a couple of minutes. If you want me to send you, I'll be glad to a checklist of what you can do. [01:18:27] For a self, some self audited here, cybersecurity assessment. I'd be glad to do that. I can send it to you. If you want to have one done by a third party, by all means, do it and then follow the instructions. That's something that we do as well. But I can send all of this to you. Just email [email protected] please do it. [01:18:50] An individual or a business. This is going to help you out so much. Just me, CraigPeterson.com. I got all kinds of free stuff. That's going to help you out. [01:19:00]
Thanks for downloading Podcast 1111 - May 1, 2021.
Uber and Lyft have both sold their self-driving car divisions. Washington DC Police are in a lot of trouble due to Ransomware. The latest trend in Cloud Computing is hazardous. How to tell if your laptop is sick and how to fix it. Costs of Ransomware have doubled in 12 months. Why I think China is threatening Taiwan. Finally, Emotet has been taken down. SpaceX is winning the Satellite-Internet war.
For more tech tips, news, and updates, visit - CraigPeterson.com.
Articles for this week:
An ambitious plan to tackle ransomware faces long odds
Tile bashes Apple's new AirTag as unfair competition
More US agencies potentially hacked, this time with Pulse Secure exploits
The saga of McDonald's ice cream machines and why they're out of order all the time - Right-to-Repair
Apple agrees to let Parler back on the App Store, citing improved moderation
Hacker hacks the Police hacking tool - and leaves a "bomb" in place
How to Secure Employees' Home Wi-Fi Networks
The Google Offices of the Future Has Privacy Robots, Meeting Tents, and Your Very Own Balloon Wall
---
Automated Machine-Generated Transcript:
Podcast 1111 - May 01, 2021
Craig Peterson: Self-driving cars have been all the rage. Well, at least talking about them for what are the last four or five years. Well, Lyft and Uber both had big projects when it came to self-driving cars, and both of them have changed their minds. We're going to talk about that.
[00:00:21] Good afternoon, everybody. Craig Peterson, here I've been out for the last couple of weeks. Sorry. I've been here on the weekend, and I'm here again today. We're going to talk about a lot of very interesting stuff that's going on. Hopefully, I can explain to you a little bit about the why that helps you understand the how of what's going on. It's just become so crazy complex.
[00:00:48]That also gets into Lyft, this whole self-driving car thing. Uber, you've got every major player kind of in the world getting into this whole game, including, of course, Apple and Google. They both have big projects going on. GM, Ford, and every major manufacturer, Fiat, has an electric car, and of course, they've got aspirations. Hey, by the way, if you really want to cause some problems with Fiat-Chrysler's finances, buy one of their little electric cars, a little E 500. I don't know if you've seen these little Fiats driving around. They're cool little cars, the type of thing you'd expect in a big city or maybe in Europe somewhere. Just these tiny things. Like the smart cars only slightly bigger. Fiat loses $20,000 for every one of these $33,000 little cars you buy. Electric cars. It only goes 87 miles on a charge. That's the killer, right? 87 miles. Are you kidding me?
[00:01:52] We'll talk more about this later on because there's some study information out now that talks about people that bought electric cars. How many went back to gas engines, and why? It's interesting when you get into the numbers, the people that are switching back, by the way. Tend to be women more than men, but anyway, so we'll get into that in a few minutes here.
[00:02:16] Lyft and Uber, both saw themselves as companies that should be in the self-driving car business. I have learned over the years that you have to focus your business on your business. So what is it? Make your business very narrow don't run after every little opportunity that comes up, don't take every potential customer that comes your way because you probably can't deal with it. It requires a focus, a real focus, in order to be very successful. Otherwise, you can't make your business grow. So because of every customer's different, if everything about the customer's different, you're going to have true experts.
[00:03:01] That's the problem I've had over the years because I've always enjoyed a little bit of a change, a little bit of a difference. So, we've helped all kinds of companies from multinationals with their cybersecurity all the way on, down through little guys.
[00:03:15] Now, when you think about that, I've been crazy. For all of these years, to quote Paul Simon and my craziness has to do with the fact that they're entirely different beasts.
[00:03:26]So, now we're putting together some standardized packages based on what we've been using and selling for more than 20 years now, just to make my life a little bit simpler so, we can handle more clients cause there's more and more them that need it.
[00:03:40] So, when we're looking at Uber and Lyft, how does it fit? What is Uber doing? What is Lyft doing? Really? What's the bottom line here. They're getting you from point A to point B. It's really that simple. Isn't it? You want to get to a place. Now, they've added some of these other features like the Uber eats, where you can get Uber to go to a restaurant, pick up a meal, deliver the meal for you. Then you're off and running. That's not bad, but it's still effectively the same business.
[00:04:15] When we're talking about autonomous vehicles, it's a completely different business. You're talking about major software development. Lyft looks like it's been spending about a hundred million dollars a year in order to try and develop self-driving cars.
[00:04:35] That's expensive. It sure is a lot different than managing people coming from point A to point B. I was out of state. I was down in Florida. Down in Florida, it's difficult to find a Lyft or an Uber driver because so many people are staying home. Why would I bother working when I'm making so much money on unemployment right now? Why would they?
[00:05:00]I'm not sure I could particularly blame them for not wanting to work. So Uber and Lyft are now saying, wait a minute. I got go find drivers. I'm going to have people that are going to deliver food that is going to take passengers from point A to point B. That's what they should be focusing on. Isn't it. Making sure the drivers safe. Making sure the passenger safe. I'm not talking about these lockdown-type restrictions. I'm talking about physically safe because we've seen people attacked before. What happens if they're in a car accident? Do we have contact information for the passenger? Do we know they're in a car accident? Can we reasonably get an ambulance there, get treatment, get the police, whatever needs to happen. There's a lot of things you have to worry aboutโbackground checks for the drivers. Maybe background checks for the passengers. You've got to collect the money. Maybe you want to put in an override system where people who refer another Lyft driver are going to be able to get a bit of an override on them, make a few extra bucks, make it worth their while to refer driver.
[00:06:04]Then you've got all of the streets, the street maps in every city, in every town. How far should you be going as a business like Uber or Lyft? Is your business mapping. Is your business autonomous vehicles? No, of course not. So I think they're smart in getting out of this business, but I want to mention a couple of things about why I think they got in the business in the first place.
[00:06:31] GM and Ford probably Chryslers have said that they are thinking the vehicle of the future isn't going to be something you buy. You're not going to go out and buy a car because they're looking at it and saying, let me see, what do you want? I want to get to the train station in the morning, or I want to get to work in the morning, or I might want to have some food delivered to me, or I might want to run to the grocery store. First of all, grocery stores and food delivery can both be done by Uber or Lyft, but getting you from A to B.
[00:07:08] They're looking and saying we make the cars, we make the autonomous systems. Why don't we provide vehicles when people need them? So it can take your kid to school in the morning. It can go in five different directions. Cause you're going to have five different cars. Maybe you need five cars this morning cause you've got four kids, and you and your wife and you're all going different places. Here come the cars. They're all scheduled the day before, the week before. However you do it. On Tuesday, all of the cars show up. They take you to where you want to go. That's the business model that the major car manufacturers are looking at. I think it makes a lot of sense.
[00:07:51] You don't necessarily need a pickup truck all the time, but I sure need one when I gotta get those sheets of plywood and go here, go there, do things. Frankly, Home Depot and Lowe's are both looking at it, saying we have rental trucks. Maybe they will have some of these in their fleet. Maybe autonomous, maybe not autonomous, but that's how they're looking at it. They don't think you're going to buy a car.
[00:08:15] I don't know if you saw the test Cadillac did down in New York City, of course, this was before the lockdown as well. Cadillac had put together this plan, where for now, what was it? $1,500 a month. I think give or take. You could drive a brand new Cadillac, and you'd have that Cadillac for a month. You could, of course keep it for longer, or you could just pay them more. But the idea was why Cadillac buy? Why even go through all of the trouble leasing. Effectively, what you're doing is renting it like you might rent a car from Hertz.
[00:08:51]In the future, they don't even think you're going to do that. It's Hey, I want a black car to pick me up from one, two, three wall street and take me to park Avenue, that I think makes a lot of sense.
[00:09:03] So Uber and Lyft are both looking at this plan and saying, Whoa, Wait a minute here. What's going to happen when GM and Ford both decide that they are actually in the getting people from point A to point B business. Now, they are stepping on Lyft and Uber's toes in a very big way. I think that's why they decided to get into the autonomous vehicle business. Both of them have gotten. Out of it now.
[00:09:37] Lyft sold as a self-driving division to a subsidiary of Toyota called Woven Planet for half a billion dollars. Part of the reason for that, I'm sure, is it takes a lot of money to compete in the self-driving area.
[00:09:53]Frankly, if Uber and Lyft can really focus on their core business, not mess around with all this other stuff. They might be able to beat GM Ford, Chrysler, et cetera at this game.
[00:10:07] Uber, who was Lyft's main competitor, sold its self-driving business to a startup called Aurora back in December last year. Both of them had been working on these projects for four or five, six years; obviously things are going to change.
[00:10:28] The self-driving vehicles are going to be on the roads starting next year. Ish. Ford's made some announcements, so has GM. We'll see ultimately what happens. Waymo, which is Google, of course, alphabet has a small taxi service in the Phoenix area. Nobody else is operating full driverless taxi services in the US yet.
[00:10:54]Congratulations to Lyft and Uber for getting out of the self-driving business that not their business.
[00:11:01] We see that more and more ransomware, not only is it way up but some police departments have gotten hit with it.
[00:11:09] So, we'll tell you what's happening there. You're listening to Craig Peterson. It has been going up and up and hurting more and more people. In this case, we're going to talk about a police department. There's a briefing that the Boston field office of the FBI's giving on ransomware. If you are an infra guard member, FBI Infragard, I ran their training for a couple of years.
[00:11:34] They've got another training. Coming up on ransomware and what's been happening out of the Boston field office, which covers all of New England. And I discovered and disclosed a huge hack. And it was the biggest one that the Boston field office said that they'd seen it. It was just absolutely incredible.
[00:11:57] What had happened and businesses are just not. Paying attention. They're not paying attention; it isn't just businesses. It's also municipalities. It's counties, its state government, and it's the federal government of all of those. I got to say the federal government is trying the hardest, I think, to pay attention to the problem besides cybersecurity; of course, they take more money from us.
[00:12:22] So they and Lee should have a better budget to do it with right. But there's a great little article this week in the newsletter. We usually get that on hold on Sunday morning, but this is by Dan Gordon. Over at ARS Technica. They will always have some great stuff, but some ransomware, bad guys have sand What they're calling stunning ultimatum to Washington.
[00:12:50] DC's Metro Politan police department. The police department that handled the massive insurrection on January 6th. He said with his tongue firmly in his cheek, the guys that really know what they're doing down there, Washington DC. Ah, boy. So here's the ultimatum. Pay these ransomware guys $50 million, or they'll leak the identities of confidential informants to street gangs though, this group is called Bulk Locker, at least that's what they call themselves.
[00:13:29] And they said on Monday that it had obtained 250 gigabytes worth of sensitive data after hacking. The metropolitan police department. Yeah, Washington DCS, metropolitan police department network. And this Babych site over on the dark web. When you go, there has dozens of images of what appeared to be legitimate, sensitive MPD.
[00:13:58] Documents now these have been slightly blocked out so that people don't know what's going on. Exactly. So they've been It's anonymized. Let me put it that way, but it looks like these legit. I'm looking at some of them right now on the ARS Technica site. One screenshot shows a windows directory called disciplinary files.
[00:14:24] Each of the 28 files shown lists a name and a check of four of the name shows. They all belong to Washington DC, metropolitan police department, officer's disciplinary actions, and looking at the dates on these files, they are from, they've all been modified anyways, within less well about the last year.
[00:14:50] Give or take a little bit less. So that was just the first page of them, by the way. It looks like kids, the officers whose names start with a through E and a few apps, other images that are on, again, this Babych ransomware group's website on the dark web seemed to show persons of interests, names, and photos.
[00:15:16] So they, these bad guys put up a screenshot of a folder named gang database, another chief's report lists of arrest and a document listing the name and address of at least one confidential informant. So it's got the date. It was entered, closed. The persons name, position, sex raised. Date of birth, social security number, mailing address, email phone number.
[00:15:46] Yeah, the informant. Okay. So they said we advise now there's spelling errors in this. There are grammatical errors in this, which is expected. We advise you to contact us as soon as possible to prevent leakage. This is again on their dark web website. Quote, if no response is received within three days, we will start to contact gangs in order to drain the informant.
[00:16:16] In other words, still let the gangs know who the squealers are. Her the informant within the gangs. Now this is classic. This next one. Just absolutely classic Washington. DC's. Public. This is again, metropolitan police departments, public information. Officer Hugh Carreyrou wrote in an email. We are aware of unauthorized access on our server while we determine the full impact and continue to review activity.
[00:16:51] We have engaged the FBI to fully investigate this matter. So he didn't answer specific questions about what details, but here's the classic part of this. I bet you dollars per four donuts that they don't have the proper security in place. If you are a city or a County, you have rules which are called CJIS, which is the criminal justice.
[00:17:18] I think information system rules for your securing. Of data and it has to do with the networks, how were they cannot be connected and can only be connected in certain ways and what you have to do. And you have to included in all of this log, everything. What do you want to bet they didn't log everything.
[00:17:40] So they're calling in the FBI and we've done that too. We've done that when, again, we're not mandated reporters. If we see something suspicious, we call up the client, whether it's a city, a County, a state, a business, a DOD contractor or dentist's office. And we say, we found an indication or multiple usually indications of compromise, which means.
[00:18:04] These things make it look like someone got into your systems. We then say this is not what we do here. This is a law enforcement issue, and we think that you should bring in the FBI and then they can talk to the FBI. We can work with the FBI to really figure things out. So the FBI can do the forensic work and make sure they capture everything needed to capture and how needed to be captured, et cetera, et cetera.
[00:18:31]It's amazing. What's happening. But they are looking into this. I'm sure the FBI is involved most recently when we've had. Reports where we brought in law enforcement. We worked directly with the FBI, with their data security information, security team, James, and it's just amazing. People were not maintaining good cyber hygiene in this case, Washington DC, metropolitan police department.
[00:19:03] Almost certainly. Was hacked by these hackers. They admit the MPD that they, something happened. I bet you, they don't know what happened. They probably broke these CJIS rules that every city, state and town and County has to comply with. It's absolutely amazing. And of course you remember now they've got this dual revenue model when it comes to ransomware.
[00:19:32] Pay up now or pay up later, we will extort money from you either way. It's a, it's amazing. Amazing. Apparently this is a Russian group who knows who exactly it is. It's sponsored by the Russian government or not. We really don't know.
[00:19:50]Cloud is a sensitive topic with me and it always has been it's hold, it holds a lot. Of promise. And the biggest promise to most businesses was, Hey, use cloud services, it'll save you money. And of course they have used cloud services and in some cases it's saved the money, frankly.
[00:20:14] It's rare that it saves them money. It really depends on a lot of things, but if you using a service like Amazon's cloud services, and I'm speaking in generalities here, but it's probably going to cost you more than running your own server. Why do a lot of companies use cloud services? When it comes to general computing.
[00:20:35] Now I understand. Why would you use Microsoft's? What does calls Microsoft three 60? It's because Microsoft is going to maintain it. They're going to patch it. I don't have to run a server. I don't have to worry about any of that stuff. Okay. I get that one. How about salesforce.com? I don't use Salesforce.
[00:20:54] I use an alternative, but I can see why you'd want to use that. Unfortunately. In both cases, those services have been hacked and the company's data has been stolen. And you got to remember too, that you still bear responsibility for that lost or stolen data, even though you didn't lose or steal it. So keep that in mind, if you are a business now, when you are moving on to what are called containers, the whole world shifts.
[00:21:25] Here's what's happening and been happening in computers over the last few years. There's something called containers. When I first heard about containers. I was thinking about these data centers that they put into shipping containers. And so you get a 20 foot or 40 foot shipping container, and all you do is plug in power and internet, and it's often running.
[00:21:50] It has racks of computers inside that has all the cooling systems, all the power regulation systems, like while UPS's et cetera, it's got that fans in there to keep the air moving. It's got the tape drives to do the backups, all of this stuff. It's right there. So I that's how I always thought of containers.
[00:22:11] That's not the case so much anymore. Those containers still exist. Some of them are used by Microsoft and Amazon still they'll throw containers into different areas, depending on usage. For instance, with the Olympics coming up, you can bet that there will be shipping containers. With huge data centers in them in order to record all of the video and move it around the world, broadcast it, et cetera, that's going to happen.
[00:22:41] There's another type of container. And this container has changed the way a lot of businesses do computing. It is just absolutely an amazing technology for someone that's been in this business. Now, since the mid seventies, I got to tell you, this is something that just really came to me out of a little bit out of the left.
[00:23:05] Field, because I'd been working with virtual machines since the seventies IBM has had VMs for what, 50 years now that it's not new that concept, but there's something called Kubernetes that is used in the container world. In the idea here. Is rather than having a big machine and that machine has its own operating system.
[00:23:30] And on top of that, you're running multiple programs. We've moved into more of a virtual world. So now even Microsoft has gotten into this game instead of having a Microsoft. Server and people trying to run everything on that one server, which Microsoft advises you not to do. If you have an active directory server, it should only be running active directory.
[00:23:55] Nothing else. If you have an exchange server, it should only. Be running exchange and nothing else. And the same, thing's true for the other major Microsoft servers. But what a lot of companies have done is they have one piece of hardware. And on that, they've got the one Microsoft server operating system.
[00:24:16] And inside that the running exchange and active directory and who knows what else? A whole bunch of other stuff, right? People put QuickBooks on these things, et cetera. Now, nowadays you can get. A virtual machine infrastructure. And this is what we've been using with our clients for 20 years now, more maybe, and there, of course it's advanced over the years.
[00:24:42] Now we use a virtual machine infrastructure called VMware. That's absolutely fantastic. Believe me. We've used them. All, and this is what we've settled on for our client, but the idea here is, okay, you buy one piece of hardware and that piece of hardware has a lot of memory, a lot of disc IO available. And you put on the very bottom of this, right on the machine, you run a virtual machine controller, basically.
[00:25:10] So something like VMware and then that VMware can run multiple operating systems simultaneously. So on that one piece of hardware, you could be running an exchange server, a whole thing. So you've got Microsoft server running and then on top of that, you've got exchange and then you have another.
[00:25:29] Microsoft server running. And on top of that, you have active directory and then you have another Microsoft server and you have something else around top of that one. And maybe you have a Linux server with something else on it. And another Linux server was something else on it. And with VMware, you can also set up virtual networks inside this machine.
[00:25:47] It's just absolutely incredible. So that's something I think most people understand. And if you're an it professional, you've probably worked with that before. Coobernetti's. Brings it to an entirely different level. And what's happening here. Is that again, we're using a virtual machine infrastructure, but the idea is each one of these machines, instead of running this huge Microsoft server software.
[00:26:17] So you got server version, whatever. And that server is software from Microsoft is using up a ton of resources because it's Microsoft and it's not very efficient. And might be causing you some headaches and some problems. There's all kinds of things we could talk about here, but the incentive doing all of that, maybe what you want is a web server.
[00:26:40] And maybe you want to tie the web server into some sort of a database. And that database is taking information from your front-end ordering system, which could be, who knows what, again, it could be a API to salesforce.com. It could be something else that you're using. You, again, name it. There's so many business management systems that could be tied into a lot of ERP stuff, et cetera.
[00:27:06] So instead of having running a big pig line, Microsoft exchange or Microsoft server, and then exchange on top of it or heaven forbid, you're running a Microsoft, a web server, which is in incredibly I would never do that personally. But you want to run a patch, et cetera. What you do is you use Kubernetes and it creates a small machine that does one thing and does one thing.
[00:27:34]And it's well tuned to do that one thing. And then you can tie these together. So on one machine, you can even do this on a workstation on that one workstation, you could have 20, 30, 40 machines, right? Each one of which is dedicated to one task. So one might be doing the web service and another one might be handling your database.
[00:27:57] Another one might be handling the API calls and it's all pushing data back and forth whole new world. Unfortunately there are security problems. So if you are using this stuff, make sure you spend some time considering the security, because Kubernetes is entirely API driven, which means application programming interface.
[00:28:19]I keep an eye open for that. Use a virtual private cloud instead of on the open internet.
[00:28:24]If you have a laptop and you've probably noticed a few things, first of all, that battery life.
[00:28:31] Okay. It's not like it was when it was new, his head, somehow those batteries do wear down. It's much better than it used to be. The nightcap ads and the nickel metal hydride ads. And now we've got various types of lithium batteries based on a few different technologies. There's going to be more stuff coming out.
[00:28:53] And I had a laptop, it was an Apple laptop, a Mac book pro. And on the bottom of it, it had four little legs, just little ones, a little rubber things. So it's a standoff. And one day I noticed that my laptop was teetering. Balanced in the middle. And I had a bit of a closer look and I could tell, wait a minute, and how this laptop is swollen in the middle.
[00:29:17] Now I knew exactly what had happened that battery inside had gone bad. So number one, I've got a one you guys with a lithium ion battery, if it starts to swell, and this is true for most batteries, but it's. Particularly nasty with lithium ion. If that battery begins to swell, what can end up happening is it will short itself out internally.
[00:29:48] Have you ever had that happen? You might be working on a car and you're right there and buy the battery and you put a wrench across the terminal somehow or between the starter. Hot side on the cars engine and the block, and, off it goes, there's a lot of power in that car battery, and there is a lot of power in these lithium-ion batteries.
[00:30:11] They make these hacks now that you can use to jumpstart cars, even small trucks with a little lithium-ion pack. So what happens is. As the swell up in your laptop or your phone, et cetera, we've seen this problem with every manufacturer of cell phones. As they start to swell up, they can and do short out.
[00:30:36] So think about how much power is in that battery, even an older battery, because it can provide your laptop with as much power as it needs. Four hours. And if you're lucky enough to have a brand new laptop with one of these great Apple chips in them that uses very little power, man, you can go better than a day on one charge easily.
[00:31:02] Unless you're like doing heavy graphics, et cetera, et cetera, but that's always been true. So I took my Mac book in and they replaced the battery, no charge. It was still under AppleCare, which I suggest people get. It's just makes life easy. You can always get the support you need and they'll fix things, replace them.
[00:31:23]That's the first step I had to mention that right out of the shoot, because it is very common with laptops to have that happen. I even had it happen with my little what's it called a little, my fi device, which hooks up. To the cell phone data network and then provides wifi to my laptop or other devices.
[00:31:46] And I noticed the battery pack compartment cover was swollen. So I took it off and sure enough, the battery was swollen. I just ordered a new one and. Properly disposed of the old lithium-ion battery. Cause again, it can cause fires right now. I think there's a recall out on some of those mi-fi devices because of the battery.
[00:32:09] So that's a serious problem. You can start your laptop on fire or you phone could start on fire with any of these newer devices. If it starts to swell, if it warps the case warps, then it's not because you're sitting on it. You can indeed cause of fire so we can have, and if you are sitting on it, you might cause of fire because if you bend that battery in the wrong place, you're in trouble.
[00:32:32] There was an episode of MythBusters where they took a lithium-ion battery. And they put it in a trash truck. Now they made this a worst case scenario. They actually built a wedge into the back of the trash truck that compresses all of the trash. It's got that big hydraulic Jack and pulls it and compresses it.
[00:32:53] So they put the battery with this wedge right in the center of the battery so that when the truck compressed it. The battery would get bent. So they bent that battery. Fair enough. The whole trash truck caught on fire, and we've seen that happen in the real world, too, where the whole trash talk truck catches on fire and it can be caused by lithium-ion battery.
[00:33:16] So be very careful with them and be careful of how you dispose of them. So let's get into some. Other things that you probably want to pay some attention to. First of all, there are a couple of programs you might want to have. Look at first off is Microsoft safety scanner, and they've got a. Page online, you can find it [email protected].
[00:33:45] As in documents, docs.microsoft.com. It's called Microsoft safety scan, or they have a 32 bit version on a 64 bit version, depending on which version of windows you have, what you're running, but it goes all the way back to windows seven. It handles the windows servers versions, and all you have to do is download it and open it.
[00:34:09] Tell it, what kind of scan you want to have run and it will go. It has just the one executable file that you can delete if you want to. It writes out its own little log file that you can look at. So that's the things you might want to look at. Microsoft safety. Scanner. And you can find that a docs doc s.microsoft.com.
[00:34:32] The next thing you might want to look at, either on a Mac or on a PC windows is Malwarebytes. And I've used this many times. Neither one of these by the way, is a panacea. Neither one of these is going to find everything or fix any everything. But malware bikes is. Quite good. And it's something you should consider.
[00:34:56] Now we have packages of software. We do not include Malwarebytes because we have some better stuff, but it's a very quick and easy way to do a light scan. Very fast and you can do a few things. So that's the first thing you might, I want to look at. If your computer is sluggish and unresponsive, it's slowing down, it doesn't necessarily mean it's old.
[00:35:22] It might mean you have too much software that you've installed on it. So check your system. To see what is running on it and see if the stuff in the background, see if the stuff that you might want to remove, but it could also be a sign that a hacker has broken into your machine. And they're doing things like mining for crypto currency or using your machine as a launch pad for attacks against other people.
[00:35:51] Okay. So start with a thorough malware scan again on windows. They do have a pretty good little program that you can use that comes with windows, but first off, open the task manager. So you get that by clicking. Right down in the bottom left and the task bar and just type task manager, run it. See what happens, Mac Oh, S you're going to search for it with spotlight and it's called the activity monitor and you'll see all of these active programs next up.
[00:36:23] Persistent error messages. And this is something you can find over at popular science, this little article, obviously I'm adding my own little tips as we go through, but you might find it interesting in you'll also find it in this week's newsletter. That'll come out tomorrow. So make sure in order to get the newsletter, you sign up at Craig peterson.com/subscribe.
[00:36:45] So you'll get a link to this article that goes through all of these things. Computers, they often get error messages. Some of them are really hard to figure out. Many of them are just related to one program and the that's usually pretty easy just remove or uninstalled that program. And re-install it again.
[00:37:07] Some of these error messages are hard to figure out you can go and search for them. Now, I do not recommend Google for most searches, but and I use duck go, but what you might want to do here is use Google type in the exact error message that you're getting and see if they've got a result now.
[00:37:30] Macko Wes. Aye. Aye. Aye, man. It's so rare that you have to re-install Mac last, but you might have to, but windows, the default is Hey or back up and re-install okay. That should fix most of the error messages right there. Cause windows is a mess. If you've got pop-ups on your screen asking, let's say to make changes to settings, make changes for things.
[00:37:57] Be careful. These different types of infections can disable features. They might change your homepage on your browser reset your default search engine. I got an email from a listener this week, talking about that, and it just keeps to keep getting reset back to Google. Tumbled check your extensions in your browser.
[00:38:18] It might just be the browser itself can also be viruses can also be a hack, but roll back the changes, any changes that you've made, puts your browsers homepage back to the original one. Make sure you run again. The built-in tools. They're on windows. Web pop-ups same type of thing. Find a list of browser extensions you've installed.
[00:38:45] So if you're using Chrome, they sit under the more tools entry, have a look at those. See if there's any that it re recommends that you remove and then do it, or just go ahead and remove them all and see if your pop-up problem goes away. There's also the problem of strange noises. And this can be a problem that only the owner of the computer really notices because you're used to what the computer should sound like.
[00:39:16] If you start getting strange noises, have a checked out right away because those noises could be a fan and that fan could be keeping your central processing unit. Cool. And if that CPU fan. Goes, you could have a very expensive repair on your hand. So keep an eye out. It could be your hard desk. It could be a fan.
[00:39:40] There's a few different moving components in, but keep an ear out for those types of sounds that you're not used to hearing from your computer.
[00:39:51]Ransomware has been a huge problem for years now.
[00:39:56] And of course now we've got the whole double whammy where if you don't pay the ransom, then they come after you threatening to release your data. Just like what happened with that police department? I was talking about in the last hour. We've seen according to some statistics I've been reading, including some FBI stuff about a 300% increase in ransomware in just the last year.
[00:40:24] And we have. Also seen a doubling of how much it costs. If you do get hit with ransomware. Now, this is a pretty big deal. And of course these are big numbers and the doubling in cost has nothing to do with inflation. Okay, guys, this is not the sign of inflation. But it is driving up. The value of Bitcoin is people are fleeing to it concerned about the dollar and other currencies.
[00:40:53] We now have a tripling of ransomware payments and ransomware payments are almost always made in Bitcoin. What does it do when you have a scarce, commodity and money chasing it while the value, the price of something goes up. And so just like it, wasn't near the beginning. Ransomware has really been driving the price of Bitcoin.
[00:41:19] I'm not going to say value just because I'm not sure it's value that we're really talking about here, but certainly the price. According to Sofos the. Average total cost to recover from a ransomware attack has more than doubled. Now this is what we're talking about here, businesses. So over the last year, it was on average, about $760,000 for a business to recover from ransomware.
[00:41:48] Now, Nancy, if you could afford the $760,000 loss and we'll get into what. Numbers compose. You add them all up to get that $760,000. But if you are a small enough business that's not something you can even consider doing, odds are good. You will be out of business within months and most smaller businesses just close their door within a week of getting ransomware.
[00:42:19] It's really that bad because there's a lot involved. So last year, about a year ago, it was $761,106 on average. Okay. So now the average cost total for recovering from a ransomware attack is about $1.85 million. Now we're talking about the total cost of recovery. We're not talking about the ransom paid right now on average is about $170,000.
[00:42:56] Again. Can you afford a $170,000 payout? I would say of the small businesses in the world, basically under 20 employees. The answer to that is probably not, but wait, there's more. All right. This is from, Sofo says new survey, the state of ransom 2021, apparently only 8% of organizations managed to get back all of their data.
[00:43:28] After paying a ransom 8%, about five years ago, it was about 50% of organizations that got ransomware. Got, got it back. But now. 8%, only 8% managed to get all the data back. Now that's going to cover not just businesses, but that's going to cover you as an individual as well. If you're a small dentist office, this is going to nail you.
[00:43:52] And I got to say, just having a backup. Most cases is not good enough because of the double whammy, but also because of the fact that most businesses are not doing backups properly. And we could talk about that. I'm going to include that in one of the courses coming up about backups, a three, two, one method, and the best ways to make sure you do have a good backup.
[00:44:18] So 8% got all of their data back after paying the ransom and 29% received no more than half of their data. So it has gotten a lot worse. So these were 5,400. It. Decision makers in the information technology, business mid-size organizations, hence the amount of money involved or right. All the way across Europe, the America is everywhere really worldwide.
[00:44:50] And it found also that the number of organizations that experienced a ransomware attack fell. Now that was interesting at one from 51% of organizations that had knitted in 2020 that they had a ransomware attack. And I added the word admitted in there, right? That wasn't in the original survey results, but admitted because I know most businesses don't admit it and they say it fell from 51% of these organizations had a ransomware attack in 20, 20 and 37% in 2021.
[00:45:28] And few organizations suffered data encryption because of a significant attack. Now that's interesting because interesting when we're talking about significant attacks versus non-significant attacks, do you draw the line? But this Sofo study was focused on the moment, significant attack.
[00:45:49] These various organizations had. So folks researchers are saying that the impact of a ransomware attack is now more damaging and costly, even though there is a decline in overall attacks. We've talked about that before here on the show where we mentioned quite clearly that the ransomware guys are getting more laser focused on their targets.
[00:46:17] They're going after mostly targets with money. Now, there's still those ransomware people out there that are just opportunist. So you made the mistake of downloading some software of installing something and they just took advantage of you. So that's still going to be happening, but. When we're talking about bigger organizations, when we're talking about government agencies, County offices, city offices, and look at what's happened to Atlanta.
[00:46:43] What three times now, I think they've been knocked off the air with ransomware, Washington DC. In the last hour, we were just talking about their metropolitan police department. They're attacking these organizations that can't afford to pay, and they know that they can pay. And if they don't, then they hold it over their heads.
[00:47:05] So I've got this article in this week's newsletter comes out Sunday morning, usually. And it depends on when Karen and I can get it all together. So apologize for the last couple of weeks. Cause I was off at a retreat and just really couldn't handle any of that stuff. But. It really is an increase in these complex targeted attacks much higher.
[00:47:31] And you'll find this article as well as all of the others. Of course, in my newsletter. If you don't get the newsletter right now, make sure you just take a minute and sign up because there's information for you as an employee in a business for you as a business owner, there's information in there for.
[00:47:49] Home users as well, because almost everything we talk about when it comes to businesses also applies to home users. Now I'm going to be doing something different in the weeks to come. I'm hoping to start this next week. We'll see how the week kind of fleshes out. But the idea for this next week is I am going to start doing real releasing soon, but putting together the short training segments.
[00:48:18] And each one of them is going to be on a very narrow topic because most people, they want five to seven minutes worth of content. So I'm going to get very narrow. So for instance, if we're talking about backups, I'm going to get really narrow on one part of backups and I'm going to post them everywhere because we've got to get more people following the podcast.
[00:48:42] I am also, you might've noticed. Putting the podcast together as a one hour, we'll access closer to about 80 minutes podcast every week. And it is going up on my YouTube channel. So you'll find it on YouTube. You'll find it on my Facebook page. I have a Craig Peterson group over there on Facebook. I'm also putting up on LinkedIn.
[00:49:04] It's going in my Craig Peters on Twitter channel. It's going up all over the place. And the idea here is to help you guys understand things better. This is for everyone and everyone, then I'm going to start doing something else as well. And that is all of these little. Classes, I guess you might call them that I've been holding.
[00:49:28] And really, I haven't done anything since March of last year for some of these classes. I've done courses, trainings, but these classes, what I want to do for you guys is if you're online email list, I'll tell you what the next class is about. So for instance, backups, I'd say, and then if you give me a great question, something.
[00:49:51] That you want to learn about backups, then I'm going to give you access to that class for absolutely nothing. All right. So I'll use your questions to help put it together. So I'm coming from the right angle. I will then record it. I'm going to put it up on my navigating cybersecurity website for you guys.
[00:50:12] I'll send you a link to it and you can, at that time, Point watch it, which is really cool. So you'll have access to that class for a few weeks, couple of weeks. I'm not sure how we're going to work that out yet, but yeah.
[00:50:26]One of the big pieces of news that's been out there lately has been the migration away from Intel. We've seen. Our friends at Microsoft move away from Intel with some of their surface tablets. And for years they've been having various versions of windows that run on non-Intel hardware. I helped to way back in the day.
[00:50:51] Get windows running on a DEC alpha chip. You might, if you're a total geek, you might remember that. And I was in the team that was working on some of the kernel stuff for it. And what we ended up with is a 64 bit very fast chip that deck had created. And I think. That Oracle ended up with some of that technology and then they also bought sun for some of their hard work technology.
[00:51:20] But anyhow, it was an incredibly fast chip. I have one, if you look closely on, in my background on the videos, you might see it sitting on when one of the little cubbies behind me, one of these little outfit, chips, they were just absolutely amazing. Great job. Anyhow, DEC digital equipment corporation is no more.
[00:51:42] However, some of the technology that I worked on back then, some of these, what we call risk architectures, where I worked on the kernel, various types of Unix kernels back then. B, this is before Linux. Even these chip sets were designed to be inexpensive, to manufacture and very fast and very easy to use and integrate as well from a hardware standpoint.
[00:52:09] And when Apple came out with its iPhone, they of course used a non-Intel chip for the main processor. And it's a, an Apple chip quote, unquote, based on one of these more or less generic designed. So Apple licensed the core design of the chip and was able to take it and continually improve it. Apple has now released various devices.
[00:52:38] There's an iMac, which they, these things are so cool that you can't buy the latest ones. You all, you might be able to about time you're listening, but they're all different colors. It's a flash back to the old days before Johnny Ives took over in some of the hardware designs, but they've got the new IMAX.
[00:52:57] They've got the Mac box. They have a Mac mini like I have right in front of me right here. It is based on apples am one chip and it is a screamer. It is very fast. And it's, I think it was about 100 bucks, maybe a little bit less then the Intel box. So you can get a Mac mini Intel for a hundred and change dollars more than an Apple based chip set.
[00:53:29] And it's faster, which is just amazing. So it has the main chorusy beause. It has also of course, a GPU's that are built into it. It's very neat. Apparently this Japanese publication called the Nikkei claims that the next generation of Apple's custom designed silicone chips for Mac that are dubbed the M two.
[00:53:53] Entered production this month and how that is fast. They barely released the . So what that might suggest is the new max could be announced at Apple's developer conference on. June seven, at least that's when that conference start. And the sources are saying that this new chip will eventually be used in other Macs and Apple products, besides the Mac books, that M one is also destined to end up in various types of eye pads, et cetera.
[00:54:26] And it's bringing more and more rumors to the front. Then the, I F our iOS apps will run natively on all of these Macs and vice versa. You can run Mac software on the iPad. You can't do all of this yet. Okay. But some of it is almost certainly going to be coming. Now, I had a conversation. With an Intel exec.
[00:54:54] This was a number of years ago and I was teasing her because she worked for Intel. And she was all puffing up about how great Intel was. And I pointed out, Hey, I remember the early days in Intel, Intel was a memory company. And if it hadn't been for IBM looking for cheap, not particularly good processor, Intel probably wouldn't be where they are.
[00:55:19] Today. Oh, certainly they wouldn't be. And I also pointed out how Intel was now AMD compatible MD of course, advanced micro devices and historically AMD and other chip makers made sure their chips were completely compatible with the Intel chip sets. But what we ha, what we ended up with is Intel lagging behind on 64 bit technology.
[00:55:48] And because of that AMD one up them AMD came up with some really great 64 bit extensions to this Intel instruction set and. Intel came out with AMT compatible instructions. I thought that was just hilarious. And she was pretty happy about it, but she admitted. Yeah, you're right. Now we've got a very interesting problem.
[00:56:16] We've had China growing its presence in the South China sea, the South China sea is not part of China. There are various countries, the border that are in it, et cetera. And China has been building islands in the South China sea. So they can then claim up 200 mile territorial limit around those islands as well.
[00:56:43] They want control of it, but I can tell you what they're really after. And this is what's very scary. And there have been a lot of military analysis, people who have been looking at this and trying to decide what to do, and that is Taiwan. Taiwan is according to mainland China. And of course the communist party of China, which is more fascist than communists, socialist party in China it is a part of China.
[00:57:12] And it's just one of these, you have a state that kind of rebels. And so they're going to pull them back in and they've been flying over. China has been flying over time when these air space to make their point. Unfortunately, I don't know how this government's going to respond, that the current administration has been challenged, left, and center by some of these more major powers around the world. And the president Trump was hardly challenged at all. And I think that says something, but here's why they really want Taiwan. It's the technology. And China's had a very hard time with trying to get their chip fabs. In other words, these fabrication plants that make the silicone that make the chips that we use in our devices.
[00:58:05] We have some ability to do it still here in the U S but not much. And the goal then. W, what do you want to call it? The centerpiece the prize of right now of all manufacturing is five nanometre design. You might have heard of that before Intel is having troubles with some of this, but it's incredible.
[00:58:27] And Apple's doing a good job with it. While Taiwan semiconductor manufacturing provides. This five nanometre design technology for making chips to Apple and many others. So if China can get its hands on Taiwan, which are really wants, they are going to be able to manufacture. Chips that we don't want them to have and have a real leg up.
[00:58:56] So man, we may get into a Kinnetic war over Taiwan. And now, you know why, Hey, if you're not on my email list, make sure you get on that newsletter right away.
[00:59:08]Emotet is a huge problem. At least. It was a huge problem. It turns out that this bot was able to harvest 4.3 million email addresses. Now that's not a ton of email addresses in today's language because there are billions of email addresses floating around there in the dark web.
[00:59:34] But Emotet was used. As a basis for ransomware and spreading ransomware. And it was really nasty stuff. AML tech would get onto your machine. And once it was on the machine, it would start trying to brute force, crack your passwords on your machine. It would try and spread to other machines on your network.
[00:59:57] So in a. Business, of course, that means all of the other machines in the business might well get attacked by maybe even compromised by a motet. Same thing is true in your home and the machines that you had at home you're using for the office while they could get cross infected from your kid's machine and all your kid had to do, or you had to do is open a piece of email because amyloid pet also distributed the ransomware via.
[01:00:27] Email fishing. It was sending malware field spam to all of the email addresses. They could get their hands on. This is what your all Paul said was the world most dangerous bot met and been plaguing. The internet, as I mentioned is 2014. A bot net is where someone typically a bad guy has taken control of a number of computers.
[01:00:57] So they took control of your your home computer, right? Some windows, computer, whatever it might be. And now they installed a command and control system on it so that they could command your computer to do things for them. Nowadays, you might see botnets being used to mine cryptocurrency. So your machine gets really slow.
[01:01:21] Like I mentioned, in the first time or today about problems you might be having with your laptop, much the same applies guys to your mobile devices, to your smartphones as well. And particularly the Android has been hit very hard by some of this stuff. Again, Apple's able to keep up on it and we've discussed this enough times in the past.
[01:01:41] But what's happened here now is they have been able to stop it. Yeah. In January, this year, law enforcement in the Netherlands was able to take control of key domains. Again, ammo tat is a bot net among other things. And as a bot net, it had command and control. So it has servers. So it needed to contact the servers to see what to do.
[01:02:12] Hey, do you want me to send email? Who do you want me to send it to? Oh, here's this stuff that I've discovered on this machine. And it sends it all to those servers. So the Netherlands were able to get them. And Germany's federal police agency, the BK, a did some very clever reverse engineering. They looked at the emo type software.
[01:02:35] And they found some interesting things. One of them by the way, was that there was an uninstaller routine built right into AMETEK, which kind of surprised me and many other people, but the German please went through and looked at it thoroughly. If a machine had ammo tat on it, how could we get rid of it now that we have control of the command and control servers?
[01:03:05] So they found this remove routine and that this command that was built into it. And they also found that. Ammo Ted software could self update. I wish most programs would do a self update. Nowadays you see some of the Microsoft software or we'll go ahead and update itself. Firefox does that Google opera?
[01:03:30] Most of the, all of the chromium based browsers will say update, but this is malware that would self update. Okay. They found that since they had control of the command and control servers, and because Emotet could self update, they made a version of Emotet that would be pushed out to any infected machine, any machine that called home.
[01:03:58] And once it called home, they would send this version out. Now they, of course they muted it to you might a virus for a vaccine, but they muted that AMETEK virus. And it was no longer sending out the phishing attacks, et cetera, but it was still setting on everyone's machines because the thinking was, we want to get rid of this Trojan software everywhere at once.
[01:04:25] Just. Bam all at once. And so they put a date into the code that they pushed out saying on this day, at this time course, UTC. Go ahead and remove yourself from the machines. That is incredible. They were able to figure this out or what was happening get emo tap from its base, which is to conduct brute force attacks on accounts, trying to crack passwords, gain access to secure data, send all of that information.
[01:05:01] Out use it as a botnet to also attack other machines and send emails. It just incredible as well, of course has encrypt files and demand ransoms to something that just last week removed itself from any machines, it was on. Absolutely amazing. The FBI collected the email addresses from these AMETEK servers, following this takedown in January, where again, the Netherlands had control of the servers and it's just absolutely amazing here because they were able to take it down worldwide.
[01:05:44] Very dangerous botnet, but once they had those email addresses, they gave them to our friend Troy hunt. Do you remember him? We've talked about him before and it's something I emphasize in most of my courses because Troy hunt has a website called have I been poned. And they gave these email addresses the 4.3 million that they got from Emma and to Troy hunt.
[01:06:14] And he has included them in. Have I been poned now, if you were part of this breach by Emotet and do you registered on, have I been poned.com you now should have already received an email from Troy. So it's important that you do a couple of things. One, make sure you check your email addresses at, have I been poned.com?
[01:06:42] Poned dispelled P w N E D. It's. P O w N E D I, he might actually have it both ways. Let me just have a quick look as we're talking. How have I being, if I say P O w N E d.com, will it no. Okay. There is no such thing which makes sense. It's have I been poned as in P w N E d.com. Check your. Email addresses.
[01:07:10] See if they're there and register for this service. This is a free service. There are a lot of companies that are using it. Mozilla uses it with Firefox to see if your passwords might have been compromised. They've got 11 billion poned accounts. There at, have I been poned this guy knows the stuff. Okay.
[01:07:31] And it's been, this particular one has been tagged sensitive. You can find out more about [email protected], but make sure you do that right now, as you're sitting here listening to me because it's very. Very sensitive information important for you to know. And if you have been powned and it's a business email address, make sure you let your it people know.
[01:07:58]I was fascinated to chat with this guy from Ireland. He had course of pretty heavy accent. He's been living in San Francisco for years, but about the only word that he said that was Americanized was for, he didn't say it like you'd expect someone with a heavy Irish accent to say it quite that way. Then, I am really into accents and placing them.
[01:08:24] And I've pretty much gotten rid of my accent. Some people still pick up a little bit of it, but I was educated in French schools up in Quebec. So there's bound to be a little bit of it left. So I like to listen for those things. And in talking to him, he said that Ireland changed because of wifi. And I had to think about that.
[01:08:48] And he said, yeah, my, my parents, because of what they're just always on the news. And they're just totally freaked out about everything all of the time. And they're always were talking about how horrific Donald Trump was, because that's what CNN was telling them. And these other sites that they were going to.
[01:09:09] And of course, we've talked many times about. The literal censorship that is happening in much of our media. And these all are arcs out in Silicon Valley and how they're controlling the discussions. But that's not what I want to talk about. He was referring to wifi. He was saying, why is what's changed Ireland, wifi?
[01:09:31] And I'm trying to figure out what does he mean? And then I remembered another friend of mine. Who's from Ireland, his name's Dez. And. There's also was continually talking about wifi. And then I finally put two and two together, sometimes a little dense, and tuned to equaled wifi as the internet. So when he was talking about why fi he wasn't really talking about wifi, when I'm thinking about wifi, I'm thinking about why five, five wifi, six, the older protocols, right? G a, some of them, man, it goes way back a, B, G. Anyhow. That's what I think of. I think of the literal in the air, why that choosing radio waves in order to connect right. Beacons and everything else. And maybe that comes from my, having a ham radio background, having an advanced class ham radio license.
[01:10:26] I don't know at any rate, why fine is the intranet, at least in his mind. And also apparently the minds of his parents. I sat all of that because I want to talk about space X space. X has already won a battle. You may not even be aware of. You and I, when we have internet, where are we getting it? Most of us get it from the cable company or from the phone company, almost everybody with five G we're hoping mom, maybe the cost will go down and the speeds are going up and we'll be able to get our internet from the phone company.
[01:11:12] Just like we have cell service. And that is going to happen in some areas, some communities, but how about all of our rural communities and in Maine, New Hampshire, Vermont, North Dakota, South Dakota, Wyoming, Montana, Idaho. And then all the way down South. Yeah. There is a lot of territory that is not covered well by 5g.
[01:11:38] Yeah. Yeah. You see the maps from T-Mobile and from Verizon, but remember maybe you don't know. So I'm like I say, remember, but you have to know that those maps are just based on a mathematical formula. So just because an area is red does not mean that you have coverage there, 5g or otherwise. And you've probably found that before, too.
[01:12:04] I know I did. I looked at a coverage map and sure enough, bam right there in the middle of all of that red was my house. And yet I had no cell signal really upset me and the FCC was trying to fix that out. Pitt who the head of the FCC he had he was appointed by president Trump and he had put some rules in place that made those maps are a lot more reasonable.
[01:12:36] But we're still talking about the majority of the landmass of the United States, vast majority, not being able to get good 5g signals. So my good, in any, in many cases, so space X has been going after those people. I announced it months ago when it was first available, this beta test they were doing for.
[01:13:01] What they call their startling satellite service. Now this is a satellite service, unlike any you've seen before. It isn't putting up a dish for your television and you got to make sure it's aimed in the right direction. And hopefully it's not raining or snowing heavily. Cause you're going to lose your television.
[01:13:22]You guys had those types of problems before they happen. All of the time. And then of course you have summer summertime with the green attenuators, those leaves on the trees and other green things that are absorbed some of those radio frequencies. So your satellite dish works better in the winter than it does a summer.
[01:13:41]That's why you probably have some leaves or other greenery that's in the way space X has already launched a small, pretty large, frankly a whole set of satellites, broadband satellites, and they call these constellations when you have a whole bunch of them together. And then in 2018 space X got FCC approval to launch.
[01:14:06] 4,400 satellites and that permission and that license specifies. Okay. You have to be so far from the earth. It was about 1100 kilometers to 1300 kilometers above the earth. And then the FCC gave space X permission to use a lower altitude for more than 50. 1800 of those satellites. Now the idea behind this is the closer the satellites can be to the ground.
[01:14:37] The last distance, the signal has to travel. So some of the problems people have been having not enough bandwidth, maybe although the majority of them are reporting a hundred megabits down, which is just incredible and also the delay. And that gets to be a problem. When you're speaking to someone, you got a hundred milliseconds up a hundred milliseconds down that is noticeable when you're in the middle of a conversation.
[01:15:06] So the space X guys went ahead and petition the FCC again, and they got an order that granted space X is additional license change requests. So the altitude for all 3000 ish of the satellites. Can now drop their orbit basically in half in about the 550 kilometer range that is going to be. Huge.
[01:15:37] Absolutely huge. And obviously opposition from all of their the companies competing against them via S sat, Hughes, dish network, one web, and Amazon has another one called and they are all saying you can't do that. It's just not fair. But this is fantastic here because it corner the FCC statement.
[01:16:01] They said, based on our review, we agree with space X, that the modification will improve the experience for users of the space X service, including in often underserved polar regions. We conclude that the lower elevation angle of its earth station antennas and lower altitude of its satellites enables a better user experience by improving speeds.
[01:16:26] And latency not, I don't want to go into a whole lot of detail, but man, Oh man, this is huge. Now you may not be aware of it, but part of your telephone bill, some of those fees and taxes that are in that bill have been going into a pot. As though the federal government ever actually saves money, it's a lockbox that doesn't really exist. And there are about, I think it was 16. Billion dollars sitting there in this lockbox. So space X has gone after that money as well. And they've received the majority of that money. I can't remember the exact amount, but it's pretty big. So space X. Remember.
[01:17:18] Controls the whole thing. They're making the satellites themselves. They're launching the satellites on their own reusable rocket. So their cost is way lower than any buddy out and space. X is also seeking permission. For 30,000 more satellites and in about the same range, some of them a little bit lower, it's already received permission in November of 2018 to launch another 7,500 satellites at altitudes of about 340 kilometers.
[01:17:58] This is absolutely incredible because one is going to end up happening is we will get good. Coverage almost anywhere now. You're not going to be able to get the type of speed that I have. For instance, I have fiber coming into my home and it is, I have a gigabit and a three gigabit and it's gigabit up and down.
[01:18:22] A lot of people can get that now, but you're not going to be able to get that in a rural area or a polar region, but they are saying that with this testing there, they're seeing some amazing speed. So space X has already got 1300 plus satellites in orbit. It's in beta. It costs $99 a month. Plus $500 upfront for all of the equipment and the equipment is just amazing, super leading technology.
[01:18:54] It's just amazing what they're doing. And they've been advertising beta service speeds of 50 to 150 megabits latency of 20 to 40 milliseconds. That is very fast. And Elon Musk said in February that the speeds you're going to get, you'd be able to hit 300 megabits later this year. Per second and it'll be available to most of the earth by the end of this year.
[01:19:21] Absolutely amazing. Amazing. All right. Okay. I just found the numbers. They've been granted 885 million, not the billions over 10 years. In rural broadband funding. So there's hope for all of us by the end of this year. Yay. Space X take care of everybody. Make sure you're getting my newsletters. You can get everything today.
[01:19:45] And what we talked about every week. Craig peterson.com/subscribe. Take care, everybody.
Welcome!
For all of my listeners who purchased my course on Improving Windows Security - THANK YOU!
We have a whopper of a warning this week about what the Department of Homeland Security is planning under the Biden Administration -- They are going to let Big Tech and Private Companies create the NO-Fly and Terrorist Watch Lists on their behalf -- Scary beyond measure. Then Apple is doing more to protect your privacy. We have another hack of a Commercial VPN provider and there is more so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
DHS Preparing to Use Private Contractors to "Scour Public Data and Social Media" To Compile Dissident Citizens for Watch List and No-Fly Lists
Another Reason to hate VPNs -- Feds say hackers are likely exploiting critical Fortinet VPN vulnerabilities
Mark Zuckerberg's cell phone number is among leaked personal data from 533 MILLION Facebook users, including two other founders that have been released for FREE by hackers
How scammers siphoned $36B in fraudulent unemployment payments from the US
Are self-driving cars safe? Will they ever be? Fender bender in Arizona illustrates Waymo's commercialization challenge
Apple is enforcing its new privacy standards and rejecting apps - New wave of App Store rejections suggests iOS 14.5, new iPad may be imminent
My biggest complaint about Android? The lack of security updates. Google is trying to solve it -- What we're expecting from Google's custom "Whitechapel" SoC in the Pixel 6
NFTs Weren't Supposed to End Like This
Embracing a Zero Trust Security Model
Turns out Most Manufacturing, Water Supply, and Power Companies Use Controllers with a Security Severity Score of 10 out of 10
Chromebooks outsold Macs worldwide in 2020, cutting into Windows market share
Clubhouse is the New Up-and-Comer but Security and Privacy Lag Behind Its Explosive Growth
New York sues to shut down 'fraudulent' Coinseed crypto platform
Former SolarWinds CEO blames intern for 'solarwinds123' password leak
WhatsApp will basically stop working if you don't accept the new privacy policy
TikTok breaching users' rights "on a massive scale", says European Consumer Group
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] We're going to be talking about a fender bender in Arizona and when will these autonomous cars be safe, at least measured safe.
We've got a new wave of app store rejections from Apple. That means a couple of things, including better privacy for all of us.
Hello, everybody. Craig Peterson here. Thanks for joining us today.
This is an interesting question, because we are looking at a future that we assume anyways is going to be full of autonomous vehicles. Why autonomous? What does it mean? There are various levels of autonomous, degrees, if you will. Everything from what we have today in a lot of cars, which is an assist cruise control, that'll keep you a certain distance from the car in front of you.
We've got assisted braking control, where the car notices, Oh, wait a minute. Someone just hit the brakes right in front of you. I should apply the brakes and it hits the brakes even before your foot is pushing down.
Another way to do this is if you slam your foot on the brake, the car assumes you know something that it doesn't, and it increases the force that you're pushing down with. So even though you might just hit the brake fast and not necessarily hard the car will make it hard.
If you think about these types of braking, for instance, you can start to realize where we're running into a problem when it comes to defining whether or not autonomous vehicles are safe.
Bottom line is autonomous vehicles, which are all the way on the other side of this scale, it started with the brakes and now is hopefully going to end with a car that just drives itself. That's everybody's goal, Ford and GM and Chrysler- Fiat, whatever they're called nowadays of course, these autonomous vehicle companies, such as Tesla. We're going to see a way of measuring them that's different than we've ever seen before.
Right now, if you have a motor vehicle, you have a driver's license, most likely. And do you have insurance. Again, most likely and you have insurance because stuff happens. You don't really mean to hit something. You don't mean to wander out of your lane and end up in the woods. Right?
There's a lot of different things that can happen to you, including having another driver get into your way. My wife has been rear-ended. I was rear-ended. She had a beautiful little car, a little MG, and I can tell to this day that she absolutely loved that little car and she used to drive it around and go down to work. I think it was at Baxter Travenol and she'd be driving down there, just having a great time in Southern California. While she was at a stoplight and somebody rear-ended her and totaled her car. Which is just an absolute shame that wasn't her fault. Was it?
I got rear-ended, I've been ruined it, I think two or three times, never to the point that she was at, where the vehicle had major damage, let alone have to be written off, but it happened right.
People aren't attentive. They misjudged the distance. It might be following too close for the conditions, rain or snow or fog or ice. There's a lots of reasons. So we have insurance and we have a driver's license to prove that we indeed at least understand the basics of driving. We passed a test, right? What is it? 70% pass rate, which frankly, isn't such a great rate if you get right down to it.
Anyway, how do we measure these cars? I mentioned the rear end collisions for a very specific purpose. These autonomous cars are racking up millions of miles on roads out West, really California, Arizona is a very popular place for them to be tested because they don't have a whole lot of weather conditions to worry about. The roads are there and they're not changing very much, particularly in Southern California. They've all been built and there's not another square inch that isn't paved, including people's front lawn, which just absolutely boggled my mind.
Why would you have a cement slab for front lawn anyways? That's California for you. These cars driving millions of miles in California are having accidents. They're not having these types of accidents you and I have.
There is a police report that was obtained by the Phoenix new times this last week that revealed a minor Waymo related crash. Now this crash occurred last October and it isn't the only one. This is, kind of, a pattern, but these have not been publicly reported until now. I'm going to read here just a quick paragraph from what the new times in Phoenix had to say, "a white Waymo minivan" Waymo, of course, Google's little spinoff, to make these autonomous vehicles. "A white Waymo mini-van was traveling westbound in the middle of three westbound lanes on Chandler Boulevard in autonomous mode when it unexpectedly breaked for no reason." "A Waymo backup driver behind the wheel at the time told Chandler police that all of a sudden the vehicle began to stop and gave a code to the effect of stop recommended and came to a sudden stop without warning." A red Chevy Silverado pickup behind the vehicle swerved to the right, but clipped its back panel causing minor damage."
No one was hurt. Overall Waymo has a pretty strong safety record. By the way, that was from an article over at ARS Technica. They have more than 20 million testing miles in the Southwest United States. If you think about it. I was adding these numbers up, 20 million miles. My wife and I, we have put well more than a million miles on cars. That's what happens when you have eight kids, right? Over the years you rack it up, 250,000 this car, 300,000 on that car. Yeah. It adds up. That's a lot of miles.
If you start looking at how many miles the average person drives a year and start doing some comparisons with the accident numbers, you'll see really that the autonomous vehicles are having far fewer accidents. Fewer accidents involving a death, which is actually very good, but the accidents it's having, even though they tend to be minor are usually the fault of the other driver. A large majority, in fact of the accidents where these Waymo vehicles, this is according to Waymo, large majority of those crashes have been the fault of the other driver.
So what is the fault of the other driver? Who was at fault here? If that red Chevy Silverado pickup truck hit that Waymo autonomous car, it's the Chevy's fault.
Why did the Chevy do it? It isn't just because he's driving a Chevy or because it's red or a pickup, he hit that car most likely, I don't know, I'm not talking to the guy, but most likely because the car did something unexpected.
If you read again, that police report it saying that even the driver quote unquote, in, in the Waymo car, this white minivan, who's sitting there to make sure the minivan doesn't run somebody over, that driver said, it was all of a sudden it began to stop. It all of a sudden began to stop and gave this code about a stop recommended and stopped with a warning. Put all of those things in a pot and stirred up and what do you have? You now have a different way of driving.
See that Chevy Silverado, if he's a good driver, he's looking ahead right down the road. If you look too close in front of you, you're going to be over-correcting. You're going to be steering all over the place. You're not going to go in a straight line. So with experience, you're looking down the road, two, three, four minimum car lengths ahead. Depends how fast you're going and that's where you're aiming.
You don't see an obstruction in front of that Waymo minivan. So you're not starting to slow down. It's just like I come up to your traffic light there's cars in front of me, and that light is red. I'm not going to be accelerating and then leaning on the brake, like so many people do. I see, there's a red light ahead. There's cars stopped at the light. I'm just going to coast to a stop. Right? Save some energy. You save some brake pads. Stop global warming by not heating up those brake pads.
It's not something most people expect. I've never been rear-ended by doing that, but I've certainly been given the finger for doing that even though I tend to get to the cars in front of me, right? About the time the light turns green.
It's fascinating to look at, but what's going to happen? What is ultimately the way to determine how safe these cars are?
We cannot use the types of assessments that our insurance companies are using. Rear end collisions, like this, rarely get anyone killed. That's where the real high expenses come in. The driver in the back is usually considered to be at fault.
But, what happens when the self-driving cars suddenly comes to the stop in the middle of the road. It's interesting to think about it, isn't it?
Waymo's vehicles sometime hesitate longer than a human would because they have to do all kinds of computations and consider complex situations that they're not used to.
If you've ever written code, say a hundred lines of code. It's going to be in case with cars millions of lines, but out of a hundred lines of code, about 90% of it is for the edge conditions. In other words, things that are unlikely to happen.
So when something weird happens that car's going to hesitate, and that frankly is a problem, the idiosyncrasies of self driving cars.
We're going to talk about a wave of app store rejections by Apple iOS for your iPhone, iPad, et cetera. We'll tell you why right here.
You're listening to Craig Peterson, online Craig peterson.com.
Apple is making another major change in order to give us more privacy. I just started this, Improving Windows Privacy and Security Course. If you using an Apple iOS device, you're halfway there.
Hello, everybody. Craig Peterson here. Thanks for tuning in . You can always hear me [email protected] slash podcast.
Apple has been really the only major vendor out there in the smartphone industry to really have security as their prime motivation. Okay, you could argue money istheir prime motivation, right?
Apple has always tried to be secure. The hardware is quite secure. They haven't licensed their operating system to third parties and that gives them control. Like you can't have anywhere else.
Think about all of the different Android-based smartphones that are out there. There are thousands of different models. Within each model, sometimes there are dozens of different hardware configurations. So, Google comes out with a security patch and sends it on out to the vendors, well actually makes it available for the vendors to pick up. Then the vendors go and grab it, and they have to test it, and they have to work in their own code, and then they have to work in all of the device drivers stuff, and they have to package it up.
They have to test it on all of the different models. Just think about Samsung, how many models Samsung has, just by itself, a whole lot of models. It is almost impossible for Android phones to get security patches. Any Android phone that's more than two years old is guaranteed to not get security patches.
I talked last weekend about what Samsung is doing to try and solve this. Finally, they must be listening to the show. Samsung had been more or less supporting it's top of the line models for about two years. If you bought a top of the line Galaxy phone from Samsung or another real top hot model, you might get security updates for a couple of years, and that's kind of it. Forget about it beyond that, which is why I said, if you absolutely must use Android, there's only one vendor you can use in that Samsung.
There's only one model phone that you can buy, which is Samsung top of the line phone, and you have to replace it every two years. So Samsung has come out now and said, We're going to provide support security support for our phones for five years.
So they're trying to compete with Apple here. Apple has long provided support for five years. And as we saw just a couple of weeks ago with this big act of zero day attack against Apple iOS devices. They will actually provide security updates for much longer than five years, but it's way easier to provide security updates for 30 models of phones than it is for a few hundred models, which is what Samsung has. Expect Samsung to narrow down their product line and also to only really be providing support for the top models within their product lines.
Now, here's what Apple is doing right now. Apple is starting to reject some of these apps that have been in the app store for a long time, as well as new apps. They're rejecting them for a couple of reasons. The biggest reason is that as of iOS 14.5, Apple is requiring all of the vendors to tell you when you go to the app store, what information of yours they're storing, they're using, and they're selling. Okay. Pretty big deal. Isn't it? It's pretty bad deal, frankly, when you get right down to it for facebook and others. Facebook took out full page ads in major newspapers in the US saying, Oh, Apple can't do this. This is terrible. It's going to destroy a small business. They said, it's going to destroy small business because Facebook can't pry into our lives as much. You know how it is. People say all the time, they're saying, Hey, I, why am I getting these ads? I've never even searched for it and somehow it's coming up.
There's a number of reasons why, but the bottom line is called big data. These apps like Facebook use all kinds of big data to figure out what we might like and part of that is based on what our friends are searching for. So, it puts together this massive mesh and figures it all out. Something that the Obama campaign really pioneered when Facebook gave them all of the data that they had on everyone and anyone.
I'm sitting here shaking my head because somehow that's okay, but having this Cambridge Analytica company do some of it from a paid standpoint and not get wholesale data somehow that was the most evil thing that ever happened.
They forgot about Obama, but you know, I guess that's political. I criticize both sides of the aisle. I am an equal opportunity criticizer. They deserve it.
We've got Apple now telling Facebook and every other app developer, you have to tell the users. In fact, if you go right now to your phone, your iPad or your iPhone, or the iPod touch, you'll see if you go to the app and you scroll up. You can open a little tab and that tab will all of a sudden become a very big part of the screen because it's tell me what this app is doing with my data. If you don't tell it, Apple's going to block you from the store.
Google has, of course, a bunch of apps. You've probably used them things like Google maps, which I try not to use. Use the Apple maps its gotten much, much better than it was, and they're not tracking you and selling your data like Google does.
Google has its own little app for doing searches. Of course, you've got Google Chrome, all these different things from Google. Google stopped updating their apps on the Apple app store because Apple was telling Google, you have to tell people what your doing with their data. Google didn't want to do it. We just want to update the apps, kind of, loophole that was in this whole thing. They can't not update it forever. Now we're seeing rejections of these developers.
Here is a few lines again from ARS Technica, from a rejection letter that some developers received. "We found in our review that your app collects user and device information to create a unique identifier for the users, devices, apps that fingerprint the user's device in this way are in violation of the Apple developer program license agreement and are not appropriate for the app store."
Now, we're not talking about the fingerprint, as in the fingerprint reader, we're saying that they are looking for unique information about the phone, so they know it's you, they can put it all together. That letter goes on specifically, "your app uses algorithmically converted device and usage data to create a unique identifier in order to track the user."
Apple is really making it clear now to developers. To the ire of Facebook and Google and other companies who rely on that type of tracking to maximize the advertising revenue. I can understand that, right. I really can. It's also clear that this app tracking transparency means that apps that are trying to track you by any means without your consent are going to face rejection.
Bravo to Apple, yet again.
Now I'm not so happy about the statement they made this week. Yeah, Georgia. That's another thing entirely.
Stick around everybody. We will be right back talking more about technology. We're going to talk a little bit about what Google's planning to do in order to help with all of these Android developers and people that are selling them. Carriers, et cetera. How's Google is going to help them with their security updates. This is an interesting way to do it. It's exactly what Apple's been doing.
You're listening to Craig Peterson.
Apple's really gotten into the chip business and it isn't just because they wanted a chip for their iPhone that they could control. In fact, Apple has even gone further and looks like Google's going to do the same.
Hello, everybody. Craig Peterson here.
Google has been an interesting beast over the years. Remember they used to say that their motto was don't be evil. Then a few years ago they removed it from the website and evil seems to be their middle name, a little bit.
One of the things Google has been doing is offering an operating system that can be used and is being used to run almost anything. We're talking mostly, however, about smartphones, certainly by number. That's called Android. Android was a little operating system, of sorts, that was developed by a kid actually Google bought it from him. They have continued to develop on it. It's not a bad little platform. The biggest problems with it really have to do with what I talked about a little earlier, the security, right? Getting the updates.
I mentioned how Apple really has a walled garden. They have their own environment where everything is contained so they can control it all. Google cannot control anything other than the Google pixel phone.
It cannot control what Samsung is doing with the operating system, Android can run on pretty much any chip that's manufactured from Intel chips, through all of these, a little fast chips, these snapdragons and many others that have been used over the years. There's a lot of them.
One of the biggest problems, of course, is the chip set. I've mentioned that Google can come out with an operating system release to fix some security problems, and then those are pushed out, but nothing's done by the carrier or maybe the developer of the handset. What Google's decided to do is make their own walled garden.
If you buy an Apple iPhone, you buy an Apple iPad, or you buy a new Apple Mac, they're all using the same basic chip set that's designed by Apple. They have some fabs where they're making some of these components. Apple has done that so again, they can control it even better. They don't have to pay that exorbitant Intel tax.
Also over at Apple trying to figure out how can we avoid the Qualcomm tax. It isn't just a Qualcomm, you know, I say tax, as in you pay way more for Intel than you would for another equivalent or better chip.
In fact, I have an Apple right in front of me here, an Apple Mac. This is a Mac mini M1 based. It is way faster and cheaper than the Intel version.
You can still get the Intel version of the mini $200 more. There's your Intel tax. And it's about half the speed for some of these things.
For instance, Adobe said that this mac with the Apple chip set in it can be twice as fast as the Mac, same Mac with an Intel processor.
Apple is moving away from not just Intel now, but from Qualcomm. Google wants to move away from Qualcomm. In many of these smartphones, including the pixels, they're using a Qualcomm Snapdragon chip.
The Qualcomm makes a lot of different types of chips. They also tend to make the radio chips that are in our smartphones. The radio chips are used to talk to the cell towers, just send data to send our voice. That's what they're used for.
Apple is hiring developers right now to develop their own chip set. It might not be there for 5G. It might be 6G. In fact, that's what the advertisements for those jobs were about as 6G. But they're going to move away from all of these standard devices that are very expensive and hard to control.
Google is saying the biggest problem we have with making sure that users of the Android operating system get updates is Qualcomm. Interesting, isn't it?
Google is coming out with, what's known as a system on a chip, SOC. What that is, think of the motherboards of years past. One of my first computers was an IBM three 60 30 mainframe, and this thing was huge and not much power. It's just amazing to think about, but it really could sling data around even way back then. It was a nice little computer, if you will. Think about how big that motherboard was. Yeah. It had the main processor. You had the memory controllers, the bus controllers, you had everything right that needed to be there to support it. All of your IO stuff. I might have had serial UARTS built into it, et cetera, et cetera.
A system on a chip is basically you got one chip and that's pretty much all you need. Obviously you got to have memory and you're going to have some sort of storage, other more permanent storage devices, but that's the basics of what a system on a chip is. Google reportedly anyways, that the pixel six is expected to ship with Google custom white chapel is what it's going to be called system on a chip internally.
It's referred to as a GS101. And that GS could be for Google silicone. There's all kinds of people speculating that seems to be the kind of the big one. There is a pixel six in the works. We do know that. Nine to five Google, is a website out there and they've done a lot of little spying on what's going on, but apparently it's a, I'm not going to get into all of the details, but basically it's going to have three CPU cores in it and everything. It's going to be really quite nice. A large arm core for single threaded work loads and three medium cores for multi work.
We've had a problem over the years. How do you make your computer faster? And you can use Intel's approach, which is let's just throw more processors at it. That's great if the software you're using can handle multithreaded environments where you have multiple processors. Okay. You got multiple processors, but how about the access to the memory? What if the process is all one access to the same area of memory at the same time? Then you have to start blocking. It gets very complicated, very fast. Intel chips fade very, very fast. You don't have to get to too many CPU's before all of a sudden the addition of one more CPU cuts the performance of that new CPU by 50%. It really doesn't. It really doesn't take much.
They're all trying to get away from Intel. Many of them have, right? Obviously Google Android phones outside of Google as well have been based on non-Intel hardware for awhile, but they're also now trying to get rid of Qualcomm. And I think that's a good thing. Ultimately, it's going to help out a lot. We're going to see more of this thing in the future, and we're all going to benefit from it, right? With the Google having control over their system on a chip, at least their pixel, it's going to make their life easier, which means if you buy a pixel, you're probably going to be able to get the upgrades better.
Thinking in the back of my mind that maybe Samsung is looking to do the same thing. Maybe Samsung's looking to move away from the Qualcomm chips and move to Google's new system on a chip. I have no idea. I have no inside information, but that would seem to make sense for me, particularly if they want to provide support for years.
By the way, Google is in the embarrassing position of offering less support for Android devices than Samsung, which is now up to three years of major updates, which by the way, is Qualcomm's maximum. Samsung has four years of security updates for some of their devices as well.
Stick around.
You're listening to Craig Peterson.
You can find me [email protected]. Don't go anywhere.
You've heard about the no fly list, right? Yeah. How about the terrorist and other watch lists? These lists that people have found it's impossible to get their names off of, even when there was no reason to be there in the first place?
Well, I got some news.
Hi, everybody. Craig Peterson here.
Department of Homeland security has been criticized for many things over the years. One of the things that's been criticized quite a bit about is this watch list that they maintain. They have a watch list for no fly. People get put on that watch list. It was originally intended to be, we know this guy's a terrorist, so we're going to put them on, right.
It's not always the way it goes. It starts out almost innocuous and before you know, it, there's all kinds of people getting caught in this big, big net.
That's what's been happening lately and it's going to get worse because the Department of Homeland security has decided that they are going to hire regular old companies to help develop this no fly list and also this terrorist watch list.
Apparently these companies are going to be looking through all kinds of public data, maybe some private data, social media in order to provide information for this new domestic terror watch list. So you look at that and say, okay, I can see that.
We've talked to before problem, man, 20 years ago, I think I was talking about these data aggregators and the problems they create. Cause they're taking public records, they're putting them all together. They're figuring out how it all meshes together and they come up with a pretty accurate picture of who you are.
Now, I've got to say when I've had them on my show here before I was talking to them and said, okay, I want to look up my own records. So I looked them up on their platforms. I did not see a single one that was more than about 30% correct about me.
Now, this was again, some years ago. I think it's been probably almost a decade since I last spoke with the data aggregators. They really are trying to blend into the background, nowadays. This data that's put together by these artificial intelligence systems is not necessarily that accurate and that gets to be a real problem.
So who is DHS gonna hire? Well, from the description that has been reported on here by the Conservative Tree House, it is going to be big tech, specifically, Google, Facebook, YouTube, Instagram, Snapchat, Twitter, and more.
DHS is going to put them under contracts to hire and organize internal monitoring teams to assist the government by sending information on citizens, they deem dangerous again, what could go wrong?
Our government is not allowed to spy on us. How many times have we talked about this? You have of course the five eyes and then they added more and more. These are governments that spy on each other's citizens for each other.
So for instance, US cannot spy on US citizens. So we have an arrangement with the United Kingdom, New Zealand, Australia, Canada, to spy on the US citizens for us that makes sense to you. Can you believe that?
We spy on their citizens for them and they spy on our citizens for us and all is good.
What's happening here is The Department of Homeland security realizes it cannot spy on us directly. This is what they've been doing for very long time, they go to the data aggregators and they pull up the data that they want.
They want to see if this guy maybe selling illicit drugs and they pull up public records. What cars does he have? How many homesdo they own? Who's he dating? Has she all of a sudden been buying diamonds and mink coats? What's going on here?
So now we're seeing that the US intelligence apparatus. It's really now going live quickly, to put together lists of Americans who could be potential threats to the government and need to be watched.
Now it's all well, and good. It's just like president Biden this week saying, Oh, we're going to have these red flag laws. We're going to stop the sale of certain types of firearms and things. It all sounds good. The reality is we have known about some of these people before, right? This is all just a red herring that the federal government is doing right now because the real problem is these terrorists, the domestic and otherwise that have shot up schools have almost always been reported to law enforcement as dangerous people. Some of them have even been on lists that say they cannot buy firearms, and yet they get firearms. Bad guys.
It's like here in the US. Where does our fentanyl come from? We're not making a domestically. Our fentanyl is coming from China often through Mexico, and it is killing people here in the US. The whole George Floyd incident, and what's happening with fentanyl in his system, right. The question is, did the police operate properly? What killed him? According to the coroner's report? It was the fentanyl. that killed him.
One way or the other that fentanyl got here from China and is being used on the streets and people are dying from it. Fentanyl's illegal. How, how could they possibly get it?
It's illegal for a felon to be in possession of a firearm. How did it felon get the firearm? The police were warned about people in San Bernardino, California, they were warned. The people in that business told the police. We were calling. we're really worried about this guy and nothing happened.
So now what are we going to do? We're going to cast an even wider net, when we cannot take care of the reports that come in right now. We're going to get even more reports and they're going to be coming from these AI systems. Again, what, what could possibly go wrong here? It's absolutely incredible.
They look at these reports, they try and determine are these actionable, the FBI or other law enforcement agencies. They've been deciding no, it's not actionable. They've been right sometimes and they've been wrong other times. This is a real problem.
What shocked me is NBC news with Andrea Mitchell, NBC news. Not a centrist news organization, very far left. NBC news is even reporting on this. They're realizing the consequences. Here's a quote from NBC. "DHS planning to expand relationships with companies that scour public data for intelligent and to better harness the vast trove of data it already collects on Americans."
"The department is also contemplating changes to its terrorist. Watch listing process." Absolutely amazing. "Two senior Biden administrative administration officials told NBC news that Homeland security whose intelligence division did not publish a warning of potential violence before the January sixth Capitol riots, is seeking to improve its ability to collect and analyze data about domestic terrorism, including the sorts of public social media posts that threatened a potential attack on the Capitol."
"DHS is expanding its relationships with other companies that scour public data for intelligence. One of the senior officials said, and also to better harness the vast trove of data it already collects on Americans, including travel and commercial data through customs and border protection, immigration, customs enforcement, the coast guard, secret service, and other DHS components". There you go from NBC news. So remind yourself what the FBI contractors with access to the NSA database already did in their quest for political opposition, research and surveillance, and then get everything we were just talking about.
The director of national intelligence declassified, a FISA judge's ruling. So this is judge James Boasberg, 2018 ruling, where the FBI conducted tens of thousands of unauthorized NSA database queries. Do you remember that story? Very, very big deal. This judge obviously passing these things out like candy and the FBI misusing its power and authority. Again, what could possibly go wrong?
By the way, President Obama apparently has been telling us that we should use the no fly list to keep people from owning guns.
There's already a database maintained by the FBI. This whole thing is, as I said, a red herring things are going to get really bad if law enforcement does this. Frankly, they're going to do it. There's no two ways about it.
We have to be more careful about keeping our information, our data private. That's what this whole course that started last week was all about. Improving your Windows privacy and security. Locking it down because the way Microsoft ships windows and the way it installs and configures itself by default does not keep your data private. That's a problem. So that's what we're going through. Hopefully, you were able to get into that before we closed it Friday night.
Remind yourself of this and just keep chanting nothing bad could happen here, right? Ah, the joys of all of these computers and databases and the way the work in nowadays.
By the way, if your information is out there at all, even if you use fake names and numbers and addresses and things like I do when it's not required. Right.
I don't lie to the bank. I don't lie to the IRS. Nobody else needs to know the truth. Even if you have been, keep it private, good chance that they know who you are and where you are. Crazy. Crazy.
Hey, visit me online. Craig peterson.com.
Make sure you subscribe to my weekly newsletter.
Hi everybody. Of course, Craig Peterson here. We're going to talk today about these drone swarms, your personal privacy risk tolerance breach highlights here over orgs individuals. What's going on? Ransomwares way up.
As usual, a lot to talk about. Hey, if you miss part of my show, you can always go online to Craig peterson.com. You'll find it there. If you're a YouTube fan CraigPeterson.com/youtube.
This is really an interesting time to be alive. Is that a good way to put it right? There used to be a curse "May you live in interesting times" Least that was the rumor.
One of the listeners pointed this out, there was a TV show that was on about five years ago, apparently, and it used this as a premise. I also saw a great movie that used this as a premise and it was where the President was under attack. He was under attack by drones.
The Biden administration has a policy now where they're calling for research into artificial intelligence, think the Terminator, where you can have these fighting machines.
These things should be outlawed, but I also understand the otherside where if we don't have that tech and our enemies end up having that tech, we are left at a major disadvantage.
Don't get me wrong here. I just don't like the idea of anybody doing Terminators, Skynet type of technology. They have called for it to be investigated.
What we're talking about right now is the drone swarms. Have you seen some of these really cool drones that these people called influencers? Man, the term always bothers me. So many people don't know what they're doing. They just make these silly videos that people watch and then they make millions, tens of millions, I guess it's not silly after all.
These influencers make these videos. There are drones that they can use if they're out hiking, you might've noticed or mountain biking or climbing. They have drones now that will follow them around, automatically. They are on camera. It's following them. It focuses in on their face. They can make the drone get a little closer or further away. As long as the sky is clear there's no tree branches or anything in the way that drone is going to be able to follow them, see what they're doing and just really do some amazing shots. I've been just stunned by how good they are.
Those drones are using a form of artificial intelligence and I'm not going to really get into it right now, but there are differences between machine learning and artificial intelligence, but at the very least here, it's able to track their faces.
Now this is where I start getting really concerned. That's one thing. But they are apparently right now training. When I say they, the Chinese and probably us, too, are designing drones that not only have cameras on them, but are military drones. They have without them having to have a central computer system controlling them or figuring out targets, they're able to figure out where there's a human and take them out.
These small drones, they're not going to take them out by firing, a 50 caliber round at them. These drones can't carry that kind of firepower. It's just too heavy, the barrels and everything else -- it's a part of that type of a firearm. We're talking about small drones again. So obviously they're not going to have a missile on them either.
What they do is they put a small amount, just a fraction of an ounce, of high explosives on the drone. The idea is if that drone crashes into you and sets off its explosives, you're dead, particularly if it crashes into and sets off explosives right there by your head. Now that's pretty bad when you get down to it.
I don't like the whole Skynet Terminator part of this, which is that the drones are able to find that human and then kill them.
Think of a simple scenario where there is, let's say there's a war going on. Let's use the worst case scenario and, enemy troops are located approximately here. You send the drones out and the drone has of course, GPS built into it, or some other inertial guidance system or something in case GPS gets jammed.
That drone then goes to that area.
It can recognize humans and it says, Oh, there's a human and it goes and kills the human. Now that human might be an innocent person. Look at all of the problems we've had with our aerial drones, the manually controlled ones, just the ones that we've been using in the last 10 years where we say, okay, there's a terrorist here. Now they fly it in from, they've got somebody controlling it in Nevada or wherever it might be, and they get their strike orders and their kill orders. They go in and they'd take it out. There are collateral damages. Now that's always been true.
Every war.
Look at Jimmy Stewart. For example, a younger kids probably don't know who it is. Mr. Smith goes to Washington was one of his movies. He had some great Christmas movies and stuff too. Anyhow, Jimmy Stewart was a bomber. I think he was a pilot actually in World War II. He flew combat missions over Germany. Think of what we did in Germany, in Japan, where we killed thousands, tens of thousands, hundreds, probably of thousands of civilians.
We now think, Oh we're much better than that. We don't do that anymore. We're careful about civilian casualties. Sometimes to the point where some of our people end up getting in harm's way and killed. For the most part, we try and keep it down.
A drone like this that goes into an area, even if it's a confined area, and we say, kill any humans in this area, there are going to be innocent casualties. It might even be friendly fire. You might even be taking out some of your own people.
They've said, okay we've got a way around this. What we're going to do is we're going to use artificial intelligence. The drone doesn't just pick out, Oh, this is a human. I'm going to attack that person. It looks at the uniform, it looks at the helmet. It determines which side they're on. If they're wearing an American or Chinese uniform, whatever, it might be programmed for it again, it goes into the area, it finds a human and identifies them as the enemy. Then it goes in and hits them and blows up killing that person. That's one way that they are looking to use drones.
The other way is pretty, scary. It's, you can defend yourself against a drone like that. You've got a drone coming. You're probably going to be able to hear it. Obviously it depends. That drone gets close. I don't know if you've ever had the kids playing with drones, flying them around you, or you've done the same thing. You can always hit it out of the air, can't you?
If you're military and you have a rifle in your arm, you can just use the rifle and play a little baseball with that drone. There's some interesting stories of people who've been doing that already.
What happens if we're not talking about a drone, we're talking about a drone swarm. I don't know that you could defend against something like that. There have been studies that have been done. So think, you think there nobody's really working this suit? No, they sure are.
What's going to happen? Well, the Indian army is one that has admitted to doing tests and they had a swarm of 75 drones. If you have 75 drones coming after you, let's say you're a high value target. There is no way you're going to be able to defend yourself against them, unless you can duck and cover and they can't get anywhere near you with their high explosives. The Indian army had these Kamikaze-attack drones. They don't necessarily have to even have high explosives on them.
This is a new interpretation under Joseph Biden. Mr. President of the Pentagon's rules of use of autonomous weapons. We've always had to have "meaningful human control." That's the wording that they Pentagon uses meaningful human control over any lethal system. Now that could be in a supervisory role rather than direct control. So they call it "human on the loop" rather than "human in the loop." But this is a very difficult to fight against.
The US army is spending now billions of dollars on new air defense vehicles. These air defense vehicles have cannons two types of missiles, jammers. They're also looking at lasers and interceptor drones, so they can use the right weapon against the right target at the right time.
That's going to be absolutely vital here because it's so cheap to use a drone. Look what happened. What was a year plus ago now? I'm trying to remember, Central America, Venezuela, somewhere in there where El Presidente for life was up giving a speech. I'm sorry. I didn't mean that to be insulting, but that often is what ends up happening. A drone comes up and everybody's thinking: Oh, it's a camera drone, wave to the camera thing. It got very close to the President and then blew up. On purpose, right? They were trying to murder the president. That's a bad thing. He was okay. I guess some of the people got minor injuries, relatively speaking.
When we're looking at having large numbers of incoming threats, not just one drone, but many drones, many of those drones may be decoys.
How cheap is it to buy one of these drones? Just like the ones that were used in China over the Olympic stadium, where they were all controlled by a computer. You just have these things, decoys, all you need is a few of them that can blow up and kill the people you want to kill very concerning if you ask me.
We're paying attention to this as are other countries as they're going forward.
We're going to talk about building your privacy risk tolerance profile, because if you're going to defend yourself, you have to know what you're going to defend against and how much defense do you need?
Hey, we take risks every day. We take risks when we're going online. But we're still getting out of bed. We're still going into the bathroom. We're still driving cars. How about your online privacy risk tolerance? What is it?
Hi everybody. Thanks for joining me.
We all take risks, and it's just part of life. You breathe in air, which you need. You're taking the risk of catching a cold or the flu, or maybe of having some toxic material inhaled. We just don't know do we?
Well on any given day, when we go online, we're also facing risks. And the biggest question I have with clients when I'm bringing businesses on or high value individuals who need to protect themselves and their information is: okay... what information do you have that you want to try and protect? And what is your personal privacy risk tolerance? So we build a bit of her profile from that and you guys are going to get the advantage of doing that right now without having to pay me my team. How's that for simple?
First of all, we got to understand that nothing is ever completely safe. When you're going online, you are facing real risks and no matter what people tell you, there is no way to be a hundred percent sure that your data is going to be safe online or that your individual personal, private information is going to be safe while you're online. And there's a few reasons for this.
The most obvious one, and the one we think about, I think the most has to do with advertising. There are a lot of marketers out there that want to send a message to us at exactly the right time. The right message too obviously? So how can they do that? They do that by tracking you via Google. So Google that's their whole business model is to know everything they can about you and then sell that information.
Facebook, same thing. Both of those companies are trying to gather your information. They're doing it when you are not just on their sites, but when you are on other people's sites. Third party sites are tracking you. In fact, if you go to my website @ craigpeterson.com, you'll see that I do set a Facebook cookie. So I know that you're on Facebook and you visited my site and you might be interested in this or that.
Now I'm not a good marketer. Because I'm not using that information for anything, at least not right now, hopefully in the future, we'll start to do some stuff. But that's what they're doing. And the reason why I don't think it's a terrible thing don't know about you.
I don't think it's bad that they know that I'm trying to go ahead and buy a car right now. Because if I'm trying to buy a car, I want advertisements about cars and I don't want to advertisements about the latest Bugatti or Ferrari, whatever it might be. I want a Ford truck, right? Just simple something I can haul stuff around. You already know I have a small farm, and I need a truck because you need one. I'd love to have a front loader and everything too, those costs money and I ain't got it. So that makes sense to me.
And now there's the other side, which is the criminal side. And then there's really a third side, which is the government side.
So let's go with the government side here. In the United States our government is not supposed to track us. Now I say "supposed to," because we have found out through Edward Snowden and many other means that they have been tracking us against the law. And then they put in some laws to let them do some of it, but our government has been tracking us.
And one of the ways it tracks us is through the "five eyes" program and now that's been expanded and then expanded again. But the five eyes program is where the United States asks the United Kingdom. Hey, listen. Hey bro. Hey, we can't and we're not allowed to track our citizens, but your not us. How about we have you track, Trump and his team? Yeah, that's what we'll do.
So there's an example of what evidence is showing has happened. So they go to a third party country that's part of this agreement,d where all of these countries have gotten together, how signed papers and said, yeah, we'll track each other citizens for each other.
And that way the United States could say, Hey, we're not tracking you. And yet they're tracking because they're going to a third party country. And the United States, if you are going out of the country, then again, they can track you. Any communications are going out of the country. So that's the government side.
And then of course, there's governments that track everything. You look at China and how they control all of the media. They control all of the social networking sites. They basically control everything out there.
We have to be careful with all of that stuff because it can and will be used. And we've seen it has been used to really not just harass people, but do things like throw them in prison disappear them. Look at what just happened in China, with the head of China's biggest company, basically the Amazon competitor over there. And he disappeared for months and then came back, just praising the Chinese Communist government and how great it is to have all of these people over there. Just telling them what to do and how to do it.
We obviously don't live in China. We obviously, I think have oligarchs nowadays. We have people who are rich, who are running the country. They're giving money to campaigns, they get the ear. You seen all of the bribery allegations against the Biden crime family, or his brother, his son, other members, himself as well, based on a hundred Biden's laptop.
So I don't trust government for those very reasons.
The hackers let's get into the hackers here. When it comes to hackers, there are, again, a few different types. You've got hackers that are working for governments. And what they're doing is in the case of a small government, like North Korea, they're trying to get their hands on foreign currencies so that they can use those currencies to buy grain, to buy oil, coal, whatever it is they might need to buy.
You have governments like China and Russia that are trying to basically run World War three. And they're out there with their hacking teams and groups and trying to figure out how do we get into the critical infrastructure in the United States? Okay. So this is how we get in. Okay. We're in over there. So if we ever want to shut down all of the power to New York City, this is what we do.
Now remember, that's what happened back in, in when was that 2004, I guess that was, yeah. I remember I was down in, I was heading actually to New York city and then all of a sudden, all of the power went out.
That apparently was an accident, but it didn't need to be an accident. There are all kinds of, allegations about what actually happened there. But that's why China and Russia are trying to get into our systems. And then they obviously want to play havoc. Look at the havoc that was caused in the U S economy by this China virus that came obviously from China for Huan. if they wanted to shut down our economy, they now have proof that's all it takes. And they are working on the genetics of some of these viruses over there in China. And they're trying to modify the genes and they are the running experiments on their troops to enhance them, to make these super soldiers that maybe, need less sleep or less food are stronger or et cetera, et cetera, they are doing that.
So China is a real threat from just a number of different ways. What would it be like if they could shut down our banking system or make it so we don't trust it anymore?
Okay. That's part one of your Personal Privacy Risk Tolerance Profile. Stick around because we're going to talk more about this and what you can do to help you have privacy.
What is your online, personal privacy risk tolerance? It's going to vary, I help high value individuals. I help businesses with this, and now I'm helping you as well. So let's get into part two.
Craig Peterson here.
When people ask me, what should I do? That is a very nuanced question. At least it's a very nuanced to answer because you could say something like: if you want to be private, use Signal for messaging and useTorr for web browsing, that's fine. And it works in some ways and not in others. For instance, Tor is a web browser that is like a super VPN. It is set up so that you're not just coming from one exit point, you're coming from a whole bunch of different points on the internet. So it's hard to track you down. The problem, however, with Tor is the same problem that you have with VPN services. And I talk about this all the time.
VPN services do not make your data secure. It does not keep it private. And in the case of VPN services that you might get for free or even buy, and also the case with Tor. Using those VPN services that can make you less secure again. Why did Sutton rob banks? He robbed banks because that's where the money was, where he is a bad guy going to go. If they want easy and quick access to lots of peoples. Private information?
They're going to hack a VPN server aren't they? Yeah. And if they can't hack the VPN server, why not just have server space in the same data center that VPN provider is renting their space from and then hack it from there, try and get in from there. Or maybe get into the service; the data centers will logs or the VPN servers logs, because even when they say they don't log, they all log, they have to log, they have to have your information otherwise, how can they bill you? And the ones that say we don't log, which are those people are "lieing" by the way. But those guys that have these VPN servers and they're trying not to log, they're trying not to log where you're going. They get fooled all of the time as well. Because their servers have logs, even if they're deleted and disappear.
So I just wanted to make it clear that you, I, if you have a low risk tolerance, when it comes to your privacy, Tor is not going to do it for you. VPN services are not going to do it for you. You have to look at all of the individual things you're doing online and then decide based on those. What is it that is the most. Beneficial for you in that particular case. Okay.
So Signal, I brought it up. So let's talk about it for a minute. Signal is the messaging app to use bar none. Signal is encrypted and do, and it is known to be highly secure, which again, Doesn't mean it's a hundred percent, but with Signal, you can talk to people on other platforms. You can have a Mac and talk to somebody on a, on an Android or a windows device.
But another consideration is who are you talking to? If you're talking to other people that have Macs and you don't want your information to get out, but you're not horrifically worried about it, right? You want it to be private. You want end to end encryption. You're better off using iMessage on your Mac.
If you're on Windows or Android, there are not any great built-in messaging apps. WhatsApp. If you listened last week and I've got it up on my website, WhatsApp is not great. They claim it's not horrible, but why would you use it if there's a question use Signal instead.
All right. So there's just a lot to consider when we're talking about it, but here is your big bang for the buck thing. That you can do. And that is use password manager. Now we talked about how Google Chromium Google's Chrome and of course now Microsoft edge. Actually it was the other way around Microsoft edge came up with it first and now Google's adding it.
But Edge has this password manager built-in. That's all well and good, but I don't know, trust those. I use a third party password manager that is designed for password management and that's all the company does. They're focused on the security behind it, which is why I recommend 1Password and lLastPass. 1Password being my absolute favorite. Use those password managers. That's the biggest bang for your buck if you have a low tolerance for your information, getting out. All right?
Now that will help to enforce good password habits. It will generate passwords for you, both of those, and it'll generate good passwords and it'll keep them for you, which is really great.
If you don't want to be tracked while you're browsing online, you can use an ad blocker. I have a couple of webinars I've done on that. If you want a video of one of those webinars to go through that talks about these different blockers ad blockers and others. I'd be glad to send you a link to one of them, but you're going to have to email [email protected].
And I will send you a link to one of those webinars I did on that stuff. No problem. But some websites are going to break when you use an ad blocker. So sometimes you have to turn it off and you have to turn it back on. The ones I tell you how to use and how to configure, I actually show you a step-by-step we walked through it. Those allow you to turn off that particular ad blocker on an individual site that was broken because of the ad blocker. So pretty straightforward. You don't have to remember to turn it all on and all off. All right.
Now studies are showing that people are concerned about their privacy. In fact, I believe last I saw said that I think it was about 70% of Americans believe that their smart phones are being tracked by advertisers, and the tech companies provide them with the information. May, 2020 Pew research report talked about this, but 85% of consumers worry, they can trust corporations with their data. So what do you do? Because. Most people don't have the support or the tools. They don't have. I have the money, they didn't get a big inheritance. They're not a high value individual that needs my help and can afford it -- where we go through everything that they do and make sure they have the best solution for each thing, including banking, including going online and trading stocks, all of that stuff.
You gotta be very careful with all of that stuff. I'm really sad that I have to say this here, but there are no online privacy solutions that will work for everybody. And there are no solutions that work in every situation either.
So what you need to do is understand what you care the most about. And I think for all of us, what we should care the most about is our financial situation and anything associated with that: our intellectual property, if we're businesses, our bank accounts, all of that sort of stuff is stuff we really should be concerned about. And that means you need to watch it. Make sure you're not sharing stuff that you really don't want to share.
Okay?
So even privacy experts like myself, don't lock everything down. We locked most of it down. Particularly since we have department of defense clients, we have to maintain a very high standard.
All right. Stick around and visit me online. CraigPeterson.com. Make sure you sign up for my newsletter.
You'll get all of the latest news and the tips I send out every week.
I don't want to leave you hanging. We're going to get into a few more things to consider here, because obviously we are going to share some of our personal information. So I'm going to tell you how I share my personal information and it might be a bit of a surprise.
Hello everybody. Thanks for listening.
We all enjoy products and services, and that's what I'm saying. When when I talk about security experts, we don't lock everything down. I've used 23 in me. I did that thing, of course, I'm sending in my DNA. That's been an issue in some cases, but that's what I did.
I use these online map programs. I use Google maps. I use weighs more than Google maps. I use Apple maps cause I'm trying to figure out how do I get to where I want to go in a reasonable amount of time. But what I do is I lie about the answer to the security questions. Okay. I don't want them to know my dad's name.
My mother's maiden name, the street. I was, I grew up on my first school, my first car, none of their business. Because it's a lot of that information is actually publicly available. How many of us on LinkedIn have right there in our profile? Yeah I went to McGill university or I w I grew up here's pictures of my childhood home, and that picture has GPS coordinates in it.
So if we use the real information. We are giving away way too much. I use a little phrase I coined here, which is lie to your bank. And you might remember. I did a show on that sometime ago. And the idea here is in your line to the bank about your financial situation, it's nothing like that. You're lying to your bank about this personal information.
They don't need to know these personal questions. They give you for their security questions. It's really important to understand all of this stuff. Okay. For instance, this is Jennifer Granick, she's at the ACL, you and she said her dad died recently. And the accountant said it's really important to report the death to credit companies because the answers to many of the security questions are on the public death certificate.
So answers to security questions really can be a nightmare, but that doesn't mean you have to give them the right answers. So for instance, I found a site online. I should try and dig that up again, but it generated fake identities. And I had a generate like 5,000 of them for me thinking, okay, they might go at some point and it even generated fake social security numbers, fake phone numbers, names, addresses, everything, everything you'd need for a fake identity. And the idea here isn't to cheat anybody out of anything. The idea is, Hey, Mr. Website, you don't know, you don't need to know who I really am. So on some websites, I'm female some websites I've, I'm only 30 years old on other websites. I'm 80 years old. It doesn't matter.
You can call it a lie if you want. But in reality, you're just trying to keep your information straight not and another advantage. Of these password managers. Cause you're trying to keep your information straight, right? It's hard to remember a lie and you have to tell a lie to enforce a lie. You're not, all that stuff your mother told you.
And she's right about that too, by the way. But if you're using a password manager, what I do is I create a unique email address. In fact, my email addresses are extremely unique, so I'll use a plus sign as part of my email address and my mail server knows. Oh, okay. That's just Craig trying to track who is using.
That email address. So I'll have Craig plus YouTube for instance, [email protected]. I actually have a whole bunch of domains that I use as well. And if you want a secure email service have look at proton mail. They're actually very good from a security standpoint. So there's nothing illegal about giving them this information.
Yeah. You're lying to them, but you gotta keep your lies straight. Another reason to use a password manager because I have the password manager generate my. My password I put in the email, which is unique for every website I go to, I never use that same email address twice if I can avoid it. And then I, and I use aliases too in my email server.
And then I go and in my notes section for that website in my password manager, I put in the answers to the security questions and I just make stuff up nonsensical stuff. So it's asking what my first car, it might be a transformational snooze. There you go. I just made something up. So I'll put those notes into my notes in my password manager and save them.
So if I ever have to do some sort of a recovery with those guys, it's going to be simple. Because I just look in my password manager, I got to go in there anyways to get my password right. And my email address or username to login. And there it is, there's my security questions. And then the password manager, cause I'm using one password.
It has a little database, it keeps and everything in there is encrypted. And the only way to decrypted is with my password, my one password, that's it. You only have to remember one password and that's the password to one password so that you can decrypt that little vault of a database of all of your information.
So I have, I bought a, I think it's a 30 plus character password I use for one password because yeah, I'm a little bit paranoid about all that sort of stuff. So that's a really good way to be able to keep your information safe. I talked last week about a friend of mine. Whose wife went on Facebook to get some help, some tips on selling her investments investment anyways, and the disaster.
That was okay. So a lot of people have regrets about what they've posted on Facebook, and there's a really cool thing out of CMU. Carnegie Mellon university, where these, how many, it's six guys and gals. They put together this special report. I regretted the minute I pressed share a qualitative study of regrets on Facebook.
Very interesting. So they looked at all of this stuff as best they possibly could. And what did they find? Some examples, just think for yourself what regrets you might have. I know friends of mine in the grads that they have had. But there are a lot, so they go through privacy risk. I can send you a copy of this article if you're interested.
It talks about their methodology. They analyze comments on the New York times website and others Craig's list to regroup people. They, so they've got all of the stuff. Here you go sensitive content. Number one. So alcohol and illegal drug use. Think about that. Think about your employer, your next employer or the police.
They got a report on you. Oh my, this is a bad person. So they go onto your Facebook page and they find. Oh, photos posted from a party with some very non unflattering photos in it. And even maybe mentioning a illegal drug use, what it thinks is going to happen. How about if you get stopped at the border coming back from Canada, Mexico, Europe.
And they decide to do a little deeper look into you and they find this stuff online. The next one sexual content, you can imagine what that is. Think of a Congressman from New York, in fact, religion and politics apparently is one of the things people have regretted posting online, profanity and obscenities, personal and family issues.
Working company here, negative or offensive comments it's arguments, lies and secrets, venting frustration, good intentions intended purposes. I didn't think about it. Hot. State. Yeah. Oh, my this thing just goes on and on, but keep all of this in mind, when you are trying to keep your information private, whether you are a business or an individual, you have to have eternal vigilant watch when your emotions are high, right.
It's like drunk dialing. Don't do it. Or your emotions are high. Something's been going on. Don't put it online. So that's I think a real good bottom line about your. Personal privacy, risk tolerance profile. Okay. Be very careful. , don't put stuff that you don't want other people to see. It's not true that once it's out on the internet, it's there forever.
It's not true that once you've posted it, it's there for anyone to discover. None of that's true. Not at all. Okay. But be very careful cover up your laptop cameras. In fact, in the improving windows security course, I go into this in quite a bit of detail, what you can do, what kind of cameras you can and should use, what sort of microphones you can or should use.
Many people just cover up the laptop cameras with the sticky note. When they're not using it disable automatic image loading in your mail program. That's important. I do that as well, because that image that's in the email is usually being used to track you. It's really that simple. You've got new privacy laws in many States and in Europe, they are really not going to work or help you with your privacy, except with the really big companies out there.
So keep all of that in mind. All right, everybody. I want to encourage you go to Craig peterson.com. You'll see all kinds of great information there. You're going to be able to also listen to my whole show, pick up all the little training tips and even find out about the courses that I'm offering. Craig peterson.com
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
I was on WGAN this morning with Matt Gagnon. He jumped right in with a question about the problems with the internet and why are there so many outages. Will they continue? What can be done? Then we talked about the Facebook hack and release of the personal information of 533 Million users and we wrapped up with a discussion about how long it will be until we have fully autonomous vehicles. Here we go with Matt.
And more tech tips, news, and updates visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Craig Peterson: Good morning, everybody. I was on with Mr. Matt Gagnon this morning and he is in Maine, as you probably know. I'm carried there through there are stations in Maine and parts of eastern New Hampshire and Southern Maine. Because of an outage, they had on the internet that hit parts of New Hampshire, as well as Maine he asked me about the internet backbone and much of it was kind of surprising to him. Frankly, I don't think it's really good news.
[00:00:31]We also talked a bit about what's happening with autonomous vehicles. Why aren't they just everywhere already? When are we going to consider them safe? So here we go with Mr. Matt.
[00:00:44] Matt Gagnon: So Craig, let's get to your topics and what we need to talk about with you here this morning, sir. Okay. So we had a huge power outage recently. We had a huge internet outage recently. Are we worried about this? Like in the future is this a sign of things to come? What caused it? I mean, what's going on here?
[00:01:00] Craig Peterson: Yeah. There's well, there's a couple of different reports. One talks about breaks in two different fibers. There's a power problem. Here's, what's really going on behind the scenes. The major internet providers have multiple connections to the internet. Let's explain what the internet is to help really understand it.
[00:01:19] The internet is an interconnected network of networks. There is no internet. It doesn't exist as you don't pay your bill to the internet.
[00:01:32] Matt Gagnon: A United States Senator once called it a series of tubes as you recall. Right.
[00:01:40]Craig Peterson: What happens is all of these different providers that we get it from, like spectrum, for instance, that had the outage. They all get internet connections to other providers. The idea is that the internet can have thousands of networks that are almost, you might call them backbones, but none of them really are right now.
[00:02:02] Most of the data on the internet is actually being routed through Amazon who is running these big data centers. Spectrum will have a connection to a network provider over here and another provider over there. There are some major central hubs, if you will, of this internet connectivity. If you lose one piece of fiber and you are connected to the internet at different points using the other pieces of fiber, you're still okay.
[00:02:33]If you only have two fiber connections to the internet itself, then you lose both of them. You are off the air. Whether it's because of a break or because of a power failure, it doesn't really matter. If you're going to be really reliable as an internet provider, you have to remember that upstream from you they could go down.
[00:02:54] To now the big problem we're seeing now, nowadays. The internet was designed to withstand a nuclear explosion anywhere in the United States. We could lose the entire city of New York and the internet would still run. That's because again, all of these small networks together.
[00:03:13] However, as time has gone on, we've seen happen to the internet that's happened in many other industries, there's been consolidation.
[00:03:20] I mentioned Amazon handles much of the traffic for the internet, and frankly, Netflix is about half of the internet traffic on any given day. We now have, instead of thousands of these networks connected together, in reality, just a handful.
[00:03:37] There's only really about a dozen that you might call backbones that almost everybody connects to. If you lose one of those, we're in big trouble. So, to answer your question, yes, this is something we can continue to expect more and more of.
[00:03:53]One of the more troubling things is just within the last year a minor player in the internet backbone business. A small business bought one of the biggest companies out there and they just haven't been taking care of the internet. They were trying to keep the price low. They have people working for them. Some of them are brilliant. We've got a lot of them. This is brand new to them. They have brought the internet down a number of times over the last even six months. This is growing pains. I think it's going to get a little bit worse and I'm not sure it's going to get that much better.
[00:04:31] Matt Gagnon: Well, that's a happy thought. Thanks a lot, Craig. Appreciate it.
[00:04:33] Craig Peterson, our tech guru. You hear him not only here at this time, every Wednesday, but also on the same radio station you're listening to right now on Saturdays at one o'clock WGAN of course. Check out that for some more in-depth analysis and talk over many of these same topics.
[00:04:47] Craig also, the Facebook hack. I have to ask you about here a little bit as well. Apparently, everybody now knows Mark Zuckerberg's phone number because of this. So tell me what happened and what's the fallout from it?
[00:04:58] Craig Peterson: Yeah, it's about 533 million Facebook users. Their data was stolen and it has been sold and reused.
[00:05:08] Now this type of data is data that is used for phishing, which is trying to fool us. They got all kinds of information about all these half a billion Facebook users. They had Zuck's name, his location, his marriage information, date of birth, Facebook user ID, his phone number.
[00:05:28] But they had it on half, a billion, other people as well.
[00:05:32] Absolutely crazy, what happened?
[00:05:35]The hackers have been selling this information to other bad guys if you will for about two years. They no longer have any, any buyers for this data, you know, half a billion people's personal information. So they posted it openly on the internet for anyone to download, not just their network of friends that have been paying them.
[00:06:00]You've just got to love the response that came from our friends over at Facebook when they were asked about it. This was the Daily Mail that asked by the way. The Facebook spokesman said, this is old data that was previously reported on in 2019. Okay, but don't you care that you've got half a billion people's personal information.
[00:06:23] It's been resold, sold for quite a while, and just on Saturday, it was posted for free for anyone on the internet.
[00:06:33] So, it's okay. Obviously, the same old stuff, right? Make sure you change your password. Use two-factor authentication, get one password as a password manager, but what's really upsetting to me is the nonchalant attitude.
[00:06:49] All of these things, businesses have, including the Equifax's of the world. Remember they didn't just steal your basic in personal information, Equifax, they stole everything. They show your income, your job history, they stole your social security number. According to reports out there, it was all of this information and more. No one is going to prison over this. There have been no charges, one or two people lost their jobs. That's the extent of it.
[00:07:19] We have to get these large companies to really honor our data, keep it private and respond in a reasonable way. Not, Oh, it's yesterday's news.
[00:07:35] Craig Peterson joins us at this time every Wednesday to go over what's happening in the world of technology really quickly.
[00:07:40] Matt Gagnon: Craig, we only have a couple of minutes left maybe, but I wanted to ask you about self-driving cars. Does the question continue to remain about these things if they're ever going to be safe? I continue to believe that someday none of us are driving anything any more. Am I right?
[00:07:52] Craig Peterson: Yeah, you are absolutely correct. The Jetson's world might come our way.
[00:07:56] There are now autonomous cabs, basically, uber's in some cases that will fly. So yeah, it'll eventually be there. The problem we're seeing is how do we evaluate them as you mentioned, are they safe? Well, how do you define safe? One of these autonomous cars is going to react differently in a situation, than a human driver.
[00:08:19]That's the problem we've had. Most of the accidents that have happened with the autonomous vehicles that are already on the road have been rear renders. Not them rear-ending somebody, but somebody rear-ending them. We have as drivers, certain expectations as to how another driver's going to behave on the road and these cars do not behave the same way.
[00:08:42] So its going to be a little while. If they were all autonomous now, that probably would go away. This is going, this problem, for a good 20 plus years, I think.
[00:08:51] Matt Gagnon: All right. Well, Craig Peterson, our tech guru. You can hear him here, not only every Wednesday but on Saturdays at one o'clock.
[00:08:56] Thanks a lot, Craig. Appreciate it as always. . We'll talk to you again next week.
[00:08:59] Take care, Matt. Bye-bye.
[00:09:00] Hey, one last reminder. I have discount coupons for people who are signing up for my Improving Windows Privacy and Security course.
[00:09:10]If you haven't signed up yet, you don't have much time because this is closing on Friday night at midnight.
[00:09:17] It is a phenomenal course. It is designed for basic users all the way through intermediate. Of course, as usual, I've got the whole guarantee thing going on. I think you're really going to like it.
[00:09:29]We're probably gonna do a couple of phone calls as well. Maybe a little webinar you can call in if you'd rather, but all of that is on my email. You know, if you don't sign up right now, you're not going to find out about it.
[00:09:41]When it goes onto my site, it is going to be full price. It's only now that you can get the coupon. So you might want to email me M [email protected]. If you haven't signed up already, or if you want more details.
[00:09:54] I am more than glad to send them to just open your email and send it to me. M [email protected]. I'd be glad to send you all the details you'd like.
[00:10:04]Of course this weekend I will be back as well.
[00:10:07] Take care everybody.
[00:10:10] Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed