
Sign up to save your podcasts
Or


Good morning, everybody.
I was on this morning on WTAG with Jim Polito. We discussed not only that Elon Musk's Tesla Organization is now accepting Bitcoin for payment but an additional interesting twist to that. Then we talked about the Suez Canal and the problems with the Ever Given. Here we go with Jim.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Mining equipment. It's like those guys that you watch on the discovery channel, where they're mining for gold up in Alaska. The guys that make the money, they've got these massive machines moving all of this stuff and they're making lots of money. Well, there's specialized equipment as well for mining for Bitcoin.
Good morning, Craig Peterson here. Of course, I was on with Mr. Jim Polito this morning. I had to talk about the Suez canal, this blockage. So we did, we got into that. Then also a little bit about Tesla and Bitcoin. What is Elon Musk doing? What what's he thinking? I had a couple of ideas and we talked about them with Jim.
Here we go.
Jim Polito: [00:00:44] You can buy now a Tesla with Bitcoin. There are organizations that will accept Bitcoin. Here's what's different here. Most of those organizations take the Bitcoin converted to regular currency and then that's it.
Well, Elon Musk must be betting on Bitcoin. I don't know. I need a guy much smarter than me here, which doesn't take a lot of work. That is in no way to take anything away from our next guest, who is our good friend and tech talk guru. Craig Peterson. Good morning, Craig.
Craig Peterson: [00:01:20] Hey, good morning, Mr. Jim. Yeah. What a different world.
Jim Polito: [00:01:24] Yeah. You can buy a Tesla with Bitcoins, which is that crazy currency that we talk about frequently here. When he takes the Bitcoin in, unlike other businesses, he's not then converting it. Like when you go to Europe and you're converting your money into euros. He's not converting it. He's keeping the Bitcoin.
Does that mean he thinks Bitcoin is viable?
Craig Peterson: [00:01:50] Yeah, boy does he ever. He's been talking about it and promoting it for a while. He bought one and a half billion dollars, of course, that sends the price up. It isn't just ransomware now being used for Bitcoin. Everything's going crazy.
Look at this musician Grimes. I don't know if you heard about this, but he sold the collection of digital work for 6.3 million.
Jim Polito: [00:02:19] The digital artwork just makes me laugh. Somebody makes a piece of digital artwork, which, unlike the Mona Lisa, you can't go there and just pick it up and say, I'm going to bring it home, or I'm going to take a copy of it. You can't do that digital artwork as far as I'm concerned is worthless.
Craig Peterson: [00:02:37] It's a perfect copy, right? It's not like the Mona Lisa a forgery.
Jim Polito: [00:02:42] It's actually right. You're right. If you copy a piece of digital artwork, it's exactly the same.
Craig Peterson: [00:02:49] It absolutely is.
They filed at Tesla here. This is a regulatory filing with the securities and exchange commission about a month ago now saying that they would begin accepting Bitcoin as payment for Tesla cars.
Now, I'm not sure who they're going after or what they are gonna use bitcoin for, maybe he sees a Bitcoin going up even further. We've certainly seen some major runs in it. You referred to it as a currency. I think that's an interesting word because of what is. What is the currency?
We have dollars that we have right now that has the full faith and credit of the government just laughable in and of itself. But anyway, everybody takes it right from the pizza shop, that first took 10,000 Bitcoin for two pizzas. They're the first Bitcoin transaction ever. So figure out how much they were worth then far less than a penny. Now, Tesla saying, yeah, you can bring in one Bitcoin and I'll give you a full car.
Jim Polito: [00:03:57] I don't know. I'm just not getting it, you know what, as they say, that I think the chance to get in on the ground floor was a long time ago. I'm just not getting in on the ground floor. I'll stick with all that stuff.
Craig Peterson: [00:04:09] My son and I started doing mining, years ago, Bitcoin mining. It was just so expensive to do because we didn't have specialized mining equipment.
It's like those guys that you watch on a discovery channel where they're mining for gold up in Alaska, the guys that make the money. They've got these massive machines moving all of this stuff and they're making lots of money. Well, if there's specialized equipment as well for mining for Bitcoin, and with the cost of electricity here in the Northeast, it's just not worth doing.
If you go to eBay right now, You could do a search for Bitcoin mining equipment and you would find all kinds of used stuff for sale because the next generations out. And the only way they can stay effective is to get the next generation. So right now it is cheaper to mine a Bitcoin than to pay for the electricity. It's about 25 to $30,000 for one Bitcoin.
If you're trying to mine it, it's going to vary. It's a little bit of a luck of the draw too, by the way, the Bitcoins they're in the $50,000 range. Okay, that makes some sense to do some mining. But again, you've still got to have this specialized equipment.
That's going to cost you a lot of money and get busy. He's obviously betting on it going up. Yeah, he may be just saying, I'll convert it to a hard currency, when I hit the hundred thousand dollars a Bitcoin, he really hasn't said.
Jim Polito: [00:05:37] There really are people who believe that it will too.
Craig Peterson: [00:05:41] Oh yeah.
Jim Polito: [00:05:42] Eric Bolling who used to be on Fox. He's a former investment person who then worked at the business channels. Then it gets a Fox. Then he had a sexual harassment allegation against him he's out. He does work for Newsmax now a few others. I listened to a podcast with him talking about it and he's betting on it.
He's not a stupid guy, he's betting on it.
Craig Peterson: [00:06:06] I wish I had money to bet on it. I just don't right. I'm trying to build a business and raise a family, support a wife, kids, chickens, by the way, the Fox got four or two foxes came by this morning I got four my chickens, but, we get it.
Jim Polito: [00:06:22] We gotta talk about that after, but keep that thought in mind. Cause I gotta tell you a good story. Go ahead.
Craig Peterson: [00:06:28] It's that time of year. We'll see what happens, Bitcoin. I just don't know. I've never had the trust in it. It takes trust to buy Bitcoin.
The major drive driving force behind Bitcoin has been corporations buying Bitcoin so they can pay for a ransom when they get ransomware. They're buying Bitcoin in advance. That's part of their plan for disaster if they get hit with ransomware.
Then the other thing that's really driven up Bitcoin over the years is people buying it to pay ransoms themselves.
And that's a real big deal. That's something we're covering on the improving windows security course this week too. You got to keep yourself safe. How do you mitigate it?
There just aren't that many places that accept it. Maybe Elon saying while we've got all of these total geeks that mine Bitcoin, now they'll trade it over.
The fact that he bought a billion and a half drove the value of Bitcoin up. Is he playing the market? Is he gaming it by buying it? Driving it up, testing it, which will drive it up, right? The value just keeps going up. Who knows maybe that's even illegal.
Jim Polito: [00:07:41] Well, he's been in trouble before with the SEC. Remember some of the statements he made. He should stop smoking pot, live on a podcast. He should maybe start with that. You have to give him some credit though for what he's done was SpaceX and other things. The very fact that he bought $1.5 billion worth of Bitcoin, right after that purchase is closed. The price goes up because people seem to just see that Elon Musk bought Bitcoin maybe he's part of the whole thing and like old man, Joe Kennedy used to do. He knew when to get in the market and when to get out. Maybe Elon Musk got a little bit of that. I just think it's fascinating.
Craig Peterson: [00:08:21] Hey, I gotta bring up those Suez canal thing here too, Jim.
Oh no, go
Jim Polito: [00:08:25] Go ahead. Go ahead.
Craig Peterson: [00:08:26] I've got two kids in the maritime industry and you know that. It was three actually that have been. One of whom is a Master Mariner. She has unlimited oceans, unlimited tonnage command vessels for the US Navy and merchant vessels. And she's been through that very Suez canal before.
She's told me some stories about it. I'm not sure that the pilots, now remember pilots when it comes to ships, are the specialized people, that know the harbors.
Jim Polito: [00:08:59] Usually, they come out to the ship. Bring them out, they climb up the side, get in. They know the local waterways they take over for the Captain.
Craig Peterson: [00:09:09] Those are the guys. You know what nepotism is, right?
Jim Polito: [00:09:12] Oh yes, I do. We have quite a bit of that in Rhode Island and Massachusetts. We have a little bit of that going on.
Craig Peterson: [00:09:19] I'm not sure these ships pilots over there by the descriptions I have heard. From the family members and others, I'm not sure those ship pilots are actually even qualified to get a Massachusetts voters license.
Jim Polito: [00:09:35] No.
Craig Peterson: [00:09:36] They are the least competent people I have ever heard of, nepotism runs rampant. If you actually want to get through the canal, you have to make sure when you go over there that your ship, you might be hauling oil, you might be hauling it doesn't matter what, but you better be hauling Marlboro Reds and M&M's because that's what powers the Suez Canal..
Jim Polito: [00:10:01] You know what, that's great. One of the busiest waterways in the world, what is it? How much of the trade of the world? 11% of the world's trade goes through and you're telling me that if you don't have the Marlboro Reds, forget about the Marlboro lights but if you don't have the Marlboro Reds and some M&M's, it's all over.
Craig Peterson: [00:10:20] Forget about it. You're going to end up blocking that Canal.
Jim Polito: [00:10:25] That's very, very interesting. There's a cool little app out there right now that allows you to put the ship anywhere that you want. Like, you can drop it on a map anywhere. You can drop it on your street on the map.
Craig Peterson: [00:10:42] Boston public library curator. It's called when the Suez.
Jim Polito: [00:10:48] I'm seeing quite a few online of people taking it and putting it in interesting places. Hey, you mentioned it and then maybe we should just now close with is that program that you're putting on. We always ask you at the end, how can folks get more information from Craig Peterson?
Craig Peterson: [00:11:06] Absolutely. Now's the time to do this. This is an Improving Windows Security course. You probably also got an email if you're active on the email list. I don't want to bother people who aren't that interested.
First of all, Big big problem right now with iOS Apple's operating system for its mobile devices, you should have already received and installed a patch from Apple, even an old Apple phone. Okay, good.
Jim Polito: [00:11:38] Yeah, I saw
Craig Peterson: [00:11:42] Android. That's why I don't like Android. Apple gets it out even for old, old phones,
Number two, this Improving Windows Security course is starting this week. I hope to get the email out this afternoon with all of the details. It is going to help you tighten up your windows computer. If you're not on that email list, get on it now. Credit Peterson.com/subscribe, because I send out tips and tricks and training.
We do free webinars, just all kinds of stuff. You'll only know if you go to Craig peterson.com/subscribe
Jim Polito: [00:12:17] Craig that is great. Good. Good to hear from you. Thank you as usual for making the very complex simple, and we'll catch up with you next week.
Craig Peterson: [00:12:28] Bye-bye
Jim Polito: [00:12:28] Bye-Bye. Craig Peterson.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Craig Peterson here. This morning I was on with Chris Ryan on NH Today. I jumped right into a conversation with regards to vaccines. I might disagree a bit with Chris on this subject a little. Anyway, then we got into the Conviction of the teen Twitter hacker who hacked accounts of celebrities, Elon Musk, Joe Biden, Barack Obama, and Kanye West for Bitcoin. He will be doing 3 years in Prison for this escapade. Here we go with Chris.
These and more tech tips, news, and updates visit.
- CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here on New Hampshire Today with Mr. Chris Ryan. We talked about a friend of mine who passed some years ago, in fact, quite a few years ago now, and a little bit about vaccines, cause he's talking a whole lot about it. I certainly disagree with him on some of the things he was saying this morning, but there are some interesting effects of that really have happened here over the last one.
When did Jonas Salk come up with that first one? A hundred or so years ago? We chat a little bit about that, as well as that kid that hacked all of these blue check accounts on Twitter, including President Obama's, Kanye West, Joe Biden, and Elon Musk's accounts. Do you remember that? Then he was giving away free Bitcoin? Well, he just got sentenced. We'd talked a little bit about that as well. So here we go.
Chris Ryan: [00:00:56] Craig Peterson, right now, host of tech talk on news radio 610 and 96.7 Saturdays at 11:30 AM.
Craig Peterson: [00:01:04] Hey, I'm doing well. This brings back a memory of a friend of mine. His name was Gordon MacDonald and he died from complications of polio. I remember it ever so well, right around 1970.
This whole thing now with the vaccinations. We have pretty much eliminated a lot of these diseases that were terminal back in the day.
Chris Ryan: [00:01:24] Right. I think that whenever, even before COVID, I would hear anti-vaxxers talking about why people should not get vaccinations and the potential side effects and a wide range of conspiracy theories about why certain things are happening and trying to assign them to vaccines.
You think about Franklin Delano Roosevelt who we talked about earlier in the show. You think about smallpox and other things that were eradicated were such a predominant part of American culture. Where that you did not think that your life was going to go on for a long period of time, based upon smallpox outbreaks, based upon polio and its prevalence.
So. Vaccines have had such an incredibly positive effect on our culture as is the case with everything there are trade-offs. There is no perfect thing. I hate to break it to people, there are trade-offs. At times it's not exactly the way you want it to be, but where would we be as a country? Where would we be as a civilized society?
You think about the AIDS vaccine and how it was distributed in Africa in the early two-thousands and what that has done there. There has been such incredible work that has been done by medicine, and we give so much credence to crackpots who want to come out and talk about various conspiracy theories on vaccines. There are negatives, there are side effects, there's no question about that. There is no perfect thing, but vaccines have had such an important part
Craig Peterson: [00:02:54] Just because you're paranoid, Chris, doesn't mean that they're not coming after you.
Chris Ryan: [00:02:58] True.
Craig Peterson: [00:03:01] Oh my.
Chris Ryan: [00:03:01] So let's talk a little bit about things in your realm here over the last few days.
I want to start with this, We have seen various hackers have success as of late. One individual that hacks the Twitter accounts of Elon Musk, Barack Obama, for Bitcoin. That person has been given three years in prison for hacking into the accounts of Obama, Musk, Kanye West, as well as Joe Biden.
What are your thoughts on that?
Craig Peterson: [00:03:32] Yeah, you might remember this. What he did was, he was able to hack these accounts. He was at 17 years old at the time, so he was a minor and he entered a plea deal. He hacked these accounts, the so-called blue check brigade, right? He was able to post on those accounts and say, Hey, listen because I'm giving away lots of money here. If you send me a thousand dollars worth of Bitcoin, I'll send you back $3,000 worth of Bitcoin and people fell for it and he got more than a hundred thousand dollars worth of Bitcoin for this whole scam. But because he was a minor at the time, and he's entered into a plea deal, he is going to be getting three years in prison for this. It brings up a couple of really good points.
One is we have to be careful if something's too good to be true it probably isn't, even if it might be a Nigerian Prince, right, which is how this whole mess started. So be careful of that.
We're seeing it all of the time. We're seeing it with business email compromises, which is our cost and our businesses billions of dollars. We're seeing that now with ransomware and extortion. Where you have tripled in the last 12 months the number of ransoms we're paying out here in the United States. It's crazy. Stop. Read what it says right now and ask yourself. Does this seem legitimate?
Chris Ryan: [00:05:02] Right. I think that in those circumstances, it's very different than when you get an email that says your cousin is being held in the UK, and we need money.
Obviously, those have gone down a little bit with the lack of travel, but there's various scams that are out there. But when you see Kanye West or a celebrity, Elon Musk saying to do this, that's something that really is it would seem to make sense to somebody, right? That's something that they would definitely fall for. I think In these times, you always need to be cognizant.
Going back to the vaccines again, do your due diligence. I'm not telling people to get the vaccine or not get the vaccine. I think it's a good idea and I'm going to do it, but you need to do your due diligence and to go through and become educated and to listen to people about the vaccine. Listen to people about what's taking place in this environment, regards to hacking, and make your own best decisions.
Craig Peterson: [00:05:54] Yeah, absolutely. In this case, he was facing a 10-year sentence. A lot of people fell for this. He entered into that plea deal. Unfortunately, Chris, we're not seeing enough prosecutions of this because so much of, it's hard to prove. Hard to track down. When it comes to hacking these accounts that are very prominent, they showed up the next day at this kid's house and arrested him. He wasn't being very careful about it.
We do have to be ultra-careful. Particularly, now we have hospitals that fell for these scams for personal protective equipment. Where it was being sold supposedly. They paid the bills, it never showed up. We're getting anxious about things. We're even seeing it now with vaccines. Just like this morning, Justin, how much did you pay to get that vaccine registration?
Chris Ryan: [00:06:44] At least a hundred dollars
Justin McIssac: [00:06:47] Yeah. $0.
Craig Peterson: [00:06:50] That's a scam it's happening right now, too. So be careful everybody.
Chris Ryan: [00:06:54] Craig, as always. Thank you so much.
Craig Peterson: [00:06:57] Take care.
Chris Ryan: [00:06:58] Craig Peterson, joining us here on Hampshire day. He hosts Tech Talk at 11:30 AM on Saturday.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
I know that I have been telling you about this course that I have been making for you -- Guess what it is done and this week, I will be making it available. It has taken a lot of work for both my wife, Karen and me but it is well worth it to get you this information on how you can Improve your Windows security. I walk you through all the basics of tightening up your security on Windows 10 and not only that but why you have to. his week was quite busy for me with meetings and presentations for my business. If you have not yet signed up for my email list do so today and you will be getting a large discount coupon for the course. This will be the only time that we offer this type of discount so be sure you are on my list before we release the course.
Craig
Welcome!
Today we will talk about Intel and its war with Apple and what they did that they believe will give them an advantage but might just backfire big time. Then we will talk about DDoS attacks, BEC attacks, and Ransomware. Then we will discuss how hackers are trying to get into Apple by trying to attack their developer's computers. If you have been breached -- what did you learn you might be surprised. Then what can you do if the Feds buy all your location data from one of their security consultants? How much do you trust your security vendors? All that and even more, so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
Intel hires Justin Long to mock Macs in throwback to 2000s "I'm a Mac" ads
~4,300 publicly reachable servers are posing a new DDoS hazard to the Internet
Ransom Payments Have Nearly Tripled
Attackers are trying awfully hard to backdoor iOS developers' Macs
What CISOs Can Learn From Big Breaches: Focus on the Root Causes
FBI: Business Email Compromise Cost $1.8B in 2020
One company wants to sell the feds location data from every car on Earth
Tech Vendors' Lack of Security Transparency Worries Firms
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hey, I did a webinar this week for the Massachusetts society for healthcare risk management. I thought there were some things that everybody needs to know, not just healthcare providers.
Hi everybody. Craig Peterson here. Thanks for joining me today. There is so much to talk about. I have such fun doing it too, which is great. We will be discussing this in some more detail and the ransomware numbers are just scary.
I was approached to give this webinar. You probably know if you've listened for the long time that I have done hundreds. If not thousands of webinars over the years. I have been doing them for our friends at the FBI InfraGard program.
I did them many times, two, three, four a month for years with them all on cybersecurity. Plus, I do the free webinars for. People who are on my email list. I send out little audio grams every week as well, where I do a deeper dive, three minutes or so into a specific topic. It's really fun. I enjoy doing it. So I get approached all of the time, as I'm sure you can imagine doing these webinars for different organizations.
I am always glad to do them. It might take me a little bit of time to schedule it into the schedule. You know how that goes, but I always end up doing them. This particular one was about risk mitigation because that's what these guys do, right? There's this society for healthcare risk management. How do identify the cyber threats? What are they preventing unauthorized access to PHI, which is your patient health information?
Now, we all have personally identifiable information that's supposed to be protected and so is our healthcare information. So that's what we talked about, it was really fun to get into some detail, but there are a few things I wanted to bring up here with you guys. We're going to be including them this week.
By the way, if you haven't noticed in my emails, I've been mentioning this Improving Windows Security course that is starting this next week.
If you responded to one of my emails over the last few months where I said, Hey I'm going to be doing this course on Improving Windows Security. I would have probably responded to you saying, okay great. I'm working on it. We have been for months and because of has been months, what we're going to do for people who have asked for this already in responding to the newsletter that what I am going to do is give you guys coupons for this.
So keep an eye on your email box. Everybody else. Okay. You're not going to get quite the deal. Actually, if you sign up today or tomorrow and get that newsletter should be going out a Sunday morning. Just respond and say Improving Windows Security so that you can get the full course, not just the free stuff that we're going to be giving.
Man, you're going to love this anyway. It's just Craig peterson.com. If you want to sign up for that. I do these all of the time.
One of the things that really stood out to me and I thought I would talk about actually, there's a few things is the security breaches in healthcare, because we all have some form of health care.
If it's Obamacare, and guess what? Obama isn't your doctor. He's not seeing you, right? You've got a local doc. Sure. You go in, you talk to your doctor or they examine you. Maybe you have to go to the hospital, outpatient, whatever it might be. There are records of yours that are private, and there are people who want to get their hands on those records.
Why is that? First of all this statistic just absolutely blew me away. A research company called black book market research, and surveyed about 3000 security professionals from healthcare provider organizations. 96% of those people who were surveyed believed that the bad guys are outpacing healthcare security, 96% of them. Isn't that just amazing?
56% are relying on medical devices using Microsoft windows seven. Seven hasn't been supported in quite some time. Eight isn't supported 8.1 has some support for it, but nowadays you pretty much have to be on Windows 10. If you want any support that is astounding. When you get right down to it.
We also have the problem of medical internet of things, devices, M I O T think about, again, all of the devices a doctor uses. Now they might have an iPad that's relatively safe, but have you noticed there are Bluetooth thermometers now that they might use to check your temperature? Did you notice that even people who are in intensive care might be hooked up to an IV those things are connected via wifi and Bluetooth? The x-ray machines, the cat scans, everything now in the doctor's offices. Practically everything is electronic is hooked up to computers.
We're helping a medical office right now doing a bit of a transition on their phone system so that they have integrated with their phone system. Now, automatic text reminders. If someone calls in or the office calls out, all of that is logged in the patient records, screen pops that come up and tell them, Hey okay is calling in and it shows all of the records before they even answer the phone.
56% of healthcare providers are using unsupported operating systems. That's just on their computers. Most organizations don't even know what is inside their machines. Cause you remember almost every machine nowadays has a computer on it. Then on top of it, they're using this 20-year-old antivirus software and insecure systems. They're really not vetting things, failure to access. It's just absolutely crazy.
Now the bad guys are able to get in about 86% of the time. That's according to Verizon's 2020 data breach investigations report. That's just crazy. 86% of them are about money. The attackers usually take the easiest route to obtain all this information that they need.
43% of the breaches are due to the cloud. How many of our businesses are saying Oh, I'm going to use the cloud. I'm going to use salesforce.com. This is an example. I'm not trying to pick on salesforce.com. They've had their problems, but so has pretty much everybody else it's. We're gonna use salesforce.com for all of our client records and emails going out to et cetera, et cetera.
That's just a word for someone else's computer, the cloud. It is a computer. It is still existing out there. You cannot, whether you're in healthcare or you're a regular business, you cannot just push off the responsibility for your data to a third-party cloud provider.
Now in the medical business, they have these business process agreements, BPA partner agreements that say, okay, you Google, I'm going to be paying you extra for this special healthcare version.
So they pay extra and they get that special healthcare version. And Google says we will keep your data safe. Oh, okay. That's well and good, but you have to pay for that version.
43% almost half of the breaches were due to people trying to use. What's called the cloud.
27% were attributed to ransomware. It is running rampant and we'll get into some of those stats here in a minute.
This is the part that I would think everybody needs to hear and that is your patient health information worth 20 times more than credit cards are worth. Did you hear that? 20 times more, 2000% more than credit cards.
So you might ask yourself why does that matter? What's the big deal with my patient information? If they have your credit card, they can use it a few times, hopefully, you'll notice it pretty quickly. You're using something like a credit monitoring service to notice, Hey, wait a minute. What's going on here.
If they've got your social security number, they could potentially buy a house or a car in your name. You don't know that they bought a car in your name until the tow truck shows up asking for the car back. Because it's now being foreclosed on, but guess what? You don't have it. It's not yours.
You have to spend 300 hours trying and straighten it all out and clear up your name? But when it comes to PHI this patient's health information, probably has your social security number. Remember when you fill out those forms when you go to the doctor's office, criminals can pull off stealing your identity that can go undetected for months, but it's even worse than that, frankly, because if they have a child's information, Oh, so again, we're talking about a birthday to name and address a social security number because you remember the government's forcing us to get social security numbers for all of our babies as they're born.
Yeah. So they've got that social security number, which will never be used to track us. Will only ever be used for social security and can not be asked by anyone outside of the federal government and the social security administration.
Another promise from the federal government was completely ignored.
That child's personal information can now be used for at least 10 years, probably closer to 15 years by a bad guy. It can be sold to illegal aliens who now have a name social security number and maybe a fake birth date because they're really a little bit older than they appear to be on that birth certificate. That's why it's worth 20 times more.
It's really something's going on.
All right. You are listening to Craig Peterson. We're talking about our health care information. We're going to talk a little bit more about that.
We all have healthcare records and they have some of our most personal information. That's what we're talking about today in follow-up to a webinar that I did last week for the healthcare industry. We're going to talk right now a little bit more about your privacy.
Hey everybody. Thanks for tuning in, Craig Peterson here.
Getting right down to the real hard stats here on our healthcare records, a lot of them have been stolen. We covered that, of course, in the last segment. If you miss that, you can catch that online on your favorite podcasting app. I'm pretty much everywhere, nowadays.
It's just crazy to think about because, in reality, we have had millions of records stolen, 300 million healthcare records stolen to be exact since 2015, which is pretty bad.
I'm looking at a chart right now that I showed to this healthcare industry group that showing that the hacking event has almost doubled over the last three years, year to year, every year. So in 2018, 164 major hacks, 2019, 312. That's a good double. 2020, 430, which isn't quite a double. So we are seeing a lot of data being stolen. Of course, stolen data means misused data, which is a very big problem.
Now, in the healthcare industry, they've got a separate problem. That is these HIPAA rules. Now HIPAA has been in place for quite a while. It's supposed to have been provided portability of our records. Does anybody have any real luck with that? I know there are some I haven't.
Portability, I don't even know where my health records have ended up. Frankly, cause my doctor ended up closing up shop and I just have no idea. But it's supposed to be portability and privacy. Well, the most common violations of these HIPAA regulations revolve around professional hackers.
Then you've got business associate disclosure. Remember I mentioned that. The cloud is not an excuse for not protecting your data. You cannot hand that off to a third party. There's many more that I go into in the presentation.
Of course, I talk about some of the ransomware that's been going around the fines they can get from some of these.
Then here's the next thing I wanted to talk with you guys about. And that is the amount of ransomware out there. I'm going to have a little bit of a ransomware offering. Take a look in some training and stuff here. Take a look at your emails. If you get my newsletter, it'll probably, I'm going to try and get this in for tomorrow's newsletter.
The one that comes out on Sunday, if you're not a subscriber right now, go to craig peterson.com/subscribe. You'll actually see it on the site @craigpeterson.com. If you scroll around, do a few things on the site, it should pop up automatically for you.
I'm going to make a note to myself here about the ransomware stuff. So you guys can hop on and get more information about how to protect yourselves too.
Now we're just talking about healthcare and of course, this is every business and every person out there.
I talked about this Conti gang. I don't know if you've heard of them. C O N T I.
Now, remember what I've said before about ransomware. It used to be that you'd get ransomware. Your computer would now have it's data encrypted, and then it would pop up this big red screen up that said you've got ransomware in order to get to all of your data back because what the ransomware did was encrypt it. You need to go to this website. You need to pay this amount of Bitcoin to this Bitcoin wallet and off it goes, right? That's the idea.
According to the FBI, about half of the time, you'll get all your data back half the time. That's even if you pay the ransom. And now, too, that the. The State departments might come after you, and the FBI, if you pay a ransom because now you are supporting terrorist organizations, not just criminal enterprises very big deal.
Now the other side of ransomware, and this is what just hit with a few different medical providers here. What I talked about was the Rehobeth McKinney Christian health center services, New Mexico, because now it's much more advanced instead of just getting on your computer, encrypting your files, demanding a ransom to get the decryption key. They even pre-install the decryptor for you. Isn't that handy? Yeah.
What they are doing is they get onto a computer and then they start East-West spreading. Now we've seen that for years. I remember one of our clients, a car dealer, and this was five-seven years ago. They got some ransomware. Somebody clicked on something that they shouldn't have, and all of a sudden their machine gets ransomware. The machine, of course, is hooked up to the network and. It is also not just hooked up to the network, it is in fact, mounting drives from their file server. So his machine has access to all of these files. This guy was a manager over there at this car dealership. So he had access to all of the files.
Think about that for a minute. What his machine did back then is it said, Oh great. Here's some network drives. It started encrypting the S drive and the H drive and the K drive. All of these different letters for these SMB mounted drives from the file server.
We were in there beforehand and we installed our security stuff. When his machine got this brand new strain of ransomware, and of course he didn't want us looking at what was on his machine. So we couldn't install all of the antivirus software because then we would have access to it. We've got another client that's like that too, where the owner of the business doesn't want us installing software to really keep his machine clean.
I don't know why people do that. It just, are they just trying to play their cards close to the chest? Is that what they're trying to do? Are they looking at something they shouldn't be looking at work or ever? Why do people do that?
If you got hints, let me know. Cause I would love to know [email protected]. Why do people do that?
Anyhow, his machine got the ransomware. It tried to start spreading to the file server. Now, we had special hardware and software installed. So we saw that spread start. We immediately shut down. It was all automatic. It was just shut down. I shut down his network port, in fact, so his computer can go anywhere.
His computer had the ransomware. We were able to just go ahead and restore from backup. The bad guys know that if all they're doing is encrypting your data, then who cares? You restore from backup.
Now, hopefully, you're following a three-two-one backup scheme. Most places don't. Hopefully, you're testing it as well. We test every backup that we make for our customers every day. We usually about once a week, will, if it's a server or even a workstation, we will spin up the servers in a virtual environment and make sure that it can boot so that we know we have a good backup. I got to tell you guys, most of the time the backups are not working and it gets to be a real problem.
What these guys have figured, including this Conti gang is we're not going to be able to get as much money out of them by just encrypting their discs. We need to do something else. So while they're trying to spread East-West inside, what they're doing is okay, so they got a hold of this manager's computer. They start scanning for other computers and scanning for vulnerabilities scanning for ways it can gain access.
Unfortunately, the statistics show us that most of us have file share turned on our windows machines. That's one of the things I talk about in my Improving Windows Security course, what to do, how to do, how to turn that off because that is the second target of ransomware. Once it gets onto your machine.
You've got to turn off those file-sharing services. So we'll tell you what Conti and these other guys do once they're there in, and they have found another machine. Maybe it has filesharing services. Maybe it's good old-fashioned vulnerability because nobody patched.
Man, I can't believe how fast this computer is. We just did an upgrade on my iMac here in the studio. It is blindingly fast now.
But we're talking about. Ransomware and what's the Conti gang and others doing, nowadays.
Hello everybody. Craig Peterson here.
Thanks for joining us today. Appreciate you spend a little bit of time and I enjoy helping to bring you guys up to speed on what is happening. There's just so much of it. You wouldn't believe what I have to filter out.
The Conti gang have been very successful, but their money started to dry up fairly recently when people figured out if they had a decent backup, they could just go ahead and ignore the ransom demand. Instead of paying that ransom, just go ahead and restore from backup. So they had to do something different.
What the Conti gang did, as well as pretty much everybody else in the ransomware business, is okay, what we're going to do now is we're going to find all of the other machines we can find on the network. Then we're even going to have real people get onto these computers remotely that they've compromised and have a poke about. See is there patient healthcare information? Are the bank account numbers on this machine? Are there plans on what to do? Where to go? What's the business going to do next week?
But particularly stuff they can sell right away. If you take credit cards, you know that the payment card industry is all over you if credit card numbers are stolen. Those are nowhere near as valuable as patient health record information. As I mentioned a little bit earlier, we're talking about 2000% more than 20 times more value to your healthcare records.
Now what happens is the Conti gang says Oh looky. We've got patient information here. It has names, addresses, social security numbers. It has birth dates. It has diagnostic information, and then they upload it.
We had something like this happened with one of our clients. It wasn't a ransomware attack, ultimately may have been. They came in through an unsecured VPN and that they would not let us shutdown. We told them to shut it down and they didn't.
In come the bad guys, they actually were coming up via Mexico in this case. Although I doubt they were located in Mexico. They took that VPN connection, they used it now to get on to the computer and found something interesting. So they started to exfiltrate the data.
In other words, Take that data and send it out. That's exactly what the Conti gang and others are doing now.
We noticed, wait a minute, this is all automatic. Why is data going out from this host at that speed to this address at this time of day? It wasn't a normal pattern. So our hardware-software that's sitting there in their network automatically shut it down hard.
They were able to exfiltrate just a tad bit of data and then it was stopped instantly.
That's what they're doing nowadays. So the Conti gang gets your data and then they try and say pay up from an extortion standpoint. Instead of just holding your data ransom, they're extorting you. Saying, if you do not pay us we will release this data. The Conti ransomware gang has its own website out there. It's called a leak site. There are many of them out there.
If you go to that site, I'm not going to give you the URL. It's right there. There's their logo. Conti gang has a logo and it says Conti news. It's talking about how you can make your payments to them and what data was released and that this person paid up, but it was too late. We don't have the data anymore, which means it was released and too bad. So sad. I wouldn't want to be you.
Here's another ransomware gang. I've talked about with the Massachusetts society for healthcare risk management in this webinar, and that's the Avedon ransomware gang. So again, they had stolen personal information. They had health information and they had not just the ransom side, but the extortion side built into it. This was in relation to an attack on the Capitol medical center in Olympia, Washington.
They have leaked some of it they're threatening to leak even more. If Washington Olympia capital medical center doesn't pay up.
Now, I went through here with Karen, helped me out with Karen and we got some other stats.
First of all, 70% of the time now, ransomware results in data exfiltration. In other words, 70% of the time, your data is stolen prior to the file encryption. Pretty bad. Pretty bad. Things can get particularly harmful because these ransomware attacks are a growing concern. They're disrupting patient care and healthcare, right?
Disabling critical systems because they have been even holding ransom some of the diagnostic equipment, MRI machines that were connected to the network. There were running Windows. Who would use Windows in the machine that's healthcare critical?
Obviously interrupt revenue flow and they had to now go get involved with real expensive remedies. It really puts him in a very bad spot, very bad.
We've had almost double the number of healthcare institutions attacked this year versus last year.
I'm not going to go through all of these things here. I explained to them the difference between some of these real sites and fake sites and how you can get access to it.
By the way, if you're interested in this, I did record this, I'd be glad to send it out to just let me know, just email [email protected] and I can send you some of this healthcare stuff, the slide deck, or whatever you might like.
Phishing campaigns, way up. You probably heard about that. I gave some examples of that emailing patient information without encrypting it. Wireless infusion pumps are, of course, compromised because they're running an operating system that hasn't been patched. Usually Windows. Think of that there's Windows in that infusion pump, but it could be a version of Linux. It's not patched. It's crazy. Vital sign equipment. Oh my gosh.
We're also seeing that this patient's health information being stolen now is being used to create fake insurance claims.
You might've been wondering in a previous segment here, I was talking about how. Much this is worth and it's worth a lot while this is one of the reasons it's worth a lot, your personal, private patient health information.
If you have a diagnostic info and that diagnosis has been stolen, and then they can file a health insurance claim. Yeah. You see where I'm going with your information as though you received some treatment or some care for the diagnosis that was in your healthcare records. It's just that simple.
The average cost of a data breach right now, by the way, if you are a regular business, it's $158 per record for non-healthcare and it's $408 per record. If you are in healthcare at all.
That's a doctor's office. That's not just hospitals, it's anybody. And by the way, mobile breaches are really big 43% of healthcare organizations who reported a mobile breach, said the mobile breach caused long-lasting repercussions.
Now, think about this. If you're a patient. How well are your records protected? I can tell you based on what I've seen and talked with healthcare, people have seen statistics they're not protected very well at all.
People will start going to jail over this. People in the healthcare industry that is.
So just in case, you were thinking that couldn't happen to you.
I'm gonna spend a couple of minutes now talking about what happened a long time ago, in February. 2021 with healthcare records. This is amazing.
Hi everybody. This is not the healthcare network. No, it is not.
I'm looking at these slides that I had put together, of course, based on research that I did, for the Massachusetts society for healthcare risk management.
It was an online webinar. I do webinars all the time. I do them for listeners where we talk about something that's hot in the news. You might see me doing various lives. I haven't done one in a little while.
Do you think I should be doing Facebook lives or YouTube lives? I know a lot of people have a real problem with Facebook. That's certainly understandable from my standpoint, but do you think it's worth it?
Get on and I can answer questions and things. Let me know [email protected]. I've done them before. I usually get a handful of people on. I'm not sure how much it's worth or not.
They are coming for you when we're talking about the health organization. So as healthcare organizations. So we're focusing on the bigger ones because that's who I was presenting to. I always make these slide decks. This one took me a week to put together right. Karen and I because there's so much research and I know I shouldn't spend that much time on these things, particularly if I don't charge for them, but I've got to do it.
I was talking to a friend of mine who's an attorney. He said, do you know what? You would be one of the richest men in America if you did not have morals. Oh my.
February 2021, we had Gore medical management out of Griffin, California, with 80,000 people affected. Nevada Orthopedic and spine center. Las Vegas, 50,000 people. UPMC life-changing medicine out of Pittsburgh and only 40,000 people there. Remember, this is February. 2021. Oh, wait. There's more Grand River Medical group out of Dubuque, Iowa, Harvard eye associates out in Laguna Hills, California, Texas spine consultant out of Addison, Texas.
UPMC Health plans out of Pittsburgh, PA. Granite wellness centers, Grass Valley California. Granite is Northeast, people. Aetna Hartford, Connecticut. Isn't this something, February 2021. 12 Oaks recovery center, NAVAIR Florida. Pennsylvania Dalton teen challenge in Pennsylvania. Data Logic software, Harlington, Texas.
Yeah, it goes on here. The house next door, Deland, Florida. Project Vita health center, el Paso, Texas.
Just in February.
Lake Charles Memorial health system, Lake Charles Louisiana. UT Southwestern medical center, Dallas, Texas. Hackley community care center out of Michigan. Rainbow Rehab center, Lavonia, Michigan. Jacobson medical hospital care center Elgin, North Dakota. Pitkin County, Colorado. Piedmont health services, North Carolina. Hope healthcare service, Fort Myers. I like Fort Myers. Jacobson Memorial hospital and healthcare in Elgin. You getting you guys getting the gist here and you pick it up what I'm putting down.
Jacobson Memorial hospital. This was a data accident involving an employee email account potentially exposing current and former patient data to authorized individuals.
You know what, the number one question I had. I got to put that together. Let me just jot this down so I don't forget. Gmail. Doctors.
The Number one question I had was how do we stop doctors from using their Gmail accounts? That's the same type of thing that happened on February 23rd, 2021, right here, where they were forwarding email and this happens.
We see this all the time. Somehow doctors think, I dunno, they're immune to these things, or it's not going to happen to them. I don't know. An email comes in and it comes into a secure email system. Then the doctor configures it to forward his email that comes into the secure clinic, his doctor's office, whatever it is, forwards it to Gmail.
What happens at that point? It's now in Gmail, it may or may not be secure. If you're not paying Gmail for your account, you can be pretty sure it's not terribly secure.
There is an encryption standard, an email called TLS and Gmail does not provide TLS services, guaranteed, for free accounts.
In fact, I don't think they provide them at all for Gmail accounts other than the paid accounts. This is an absolutely huge problem. The FBI and the Department of Homeland security CISA came out with another warning here about healthcare. This is affecting all of us because this is our personal information.
Why are healthcare records so much more valuable? I mentioned earlier a couple of things. One is they usually have a social security number, name, and address, so it can be used now to steal someone's identity. They often have diagnostic information. So that means it can be used to file fraudulent insurance claims.
What else can you do with some of this medical data that is stolen? If they have your medical data, it's so much different than your credit card, because credit card you can cancel.
In fact, even if you don't cancel, if you notice you get a new credit card, every what is it - three to five years, new credit card here it is. There's a new number, at least a new code on the back, right? CVC code. You look at that and say new card okay, whatever.
It's such a pain because you have to go and change it on any website or with anyone that's doing an automatic ordering.
But when you get right down to it, What can happen if your credit card numbers are stolen? They can run up your credit card. You can, before you pay it, file a claim and say, Hey, someone stole my credit card number. That is bad. I did not authorize these charges and they will back out the charges for you, right? You haven't put a dime of your own money out there.
Now, a debit card. Yeah. They've taken your money and now you got to fight a bit to get it back, but you can get it back from all the major credit card issuers, but you get a new credit card number.
What happens if your social security numbers are stolen? Did you know that the social security administration will not issue you a new social security number? Is your number stolen? Did you know that?
How about the rest of your information? Most people live in a home for at least 10 years, not longer. That's a lot longer than your credit card number's going to be around so they can now again, continue to file for loans under your name, your address, your birthdate, maybe for the rest of your life. This is our personal information.
And as you probably noticed early on, I was talking about how upsetting it is to me that we have a national ID stamped on our forehead effectively.
We have a social security number that we now have to use for everything it's called a social security number because it was put in place for this Fake insurance program that the federal government put together because it's not an insurance program. It is not run like an insurance program. They put it together and they called it social security. They gave you a number because they had to keep track of your account. And really it was your account number. Now it's used everywhere. There's proposals out there. Hey, let's come up with a digital ID, a digital identifier. A digital passport, if you will, as though that's going to solve the problem. The problem is we now have our data stolen. It's already out there. It's everywhere. Can you imagine what China might be thinking about doing with it? China has been, it's been verified now. China has stolen the records of pretty much every federal employee, every background check record of every background check that was done for clearance via the FBI. What's going to happen if they decide they really don't like us anymore and they just let loose?
What a great way to shut down our economy. Like overnight, by all of a sudden creating millions of fake accounts. Using real identities, our identities. This is just nuts, it is absolutely nuts.
We've seen these hacks and we just ran through some of the healthcare hacks that happened in February of 2021 one month. These are the ones we know about. Most of them are in fact, probably not reported at all. Add on top of that, now we have doctors that are working from home that are using what we're calling loosely, telemedicine. They're getting onto platforms that were never designed to keep our data safe is not HIPAA compliant. They are exposing our data even more than ever before.
I don't have the answer for this, because they are not, I can guarantee you, they are not pounding down my door to have me come and help them. I could. That's what I do. They're not. In fact, when I reach out to most of them they hardly care at all. Not a big deal, right? Not going to happen to me, can't afford it. Yet they're pushing all of this burden onto us. It is extremely upsetting. Something has to be done. Something has to be done about healthcare. We need to enforce these HIPAA rules and regulations, and people need to go to jail for blatantly ignoring what they've been saying, by signing these forms, blatantly ignoring what they've been saying. They've been doing now for what 20 years?
Visit me online. Craig peterson.com. Make sure you get on that newsletter so that you don't miss a thing.
I think we beat healthcare to death in the last hour.
We're going to be getting into a bunch of new topics here. This whole thing about Intel hiring Justin Long has stuck in my craw too. So we'll start with that.
Hi everybody, Craig Peterson here. Of course, it sounds like its a stuck in my craw week, but we got to keep you guys informed and it just really irks me, that so many businesses are trying to do the right thing. They are spending money. They're getting training for their people. They're getting the right kinds of equipment. They might be buying stuff from me or whomever. It really doesn't matter. They're trying to do it right. That costs them. There's no question about it.
They are competing against people who don't care. That's what really bothers me. They're competing against people that are barely spent a dime. Maybe they bought a SonicWall firewall 10 years ago, but that's the last time they did anything for security.
To me, that is a sin and should be a crime. If you've got a company, like maybe you've got a DOD contractor, and they've spent 200,000, maybe as much as a million dollars if their really quite a bit bigger on just trying to secure their networks and okay they sell to the DOD, but they sell to a lot of other companies as well.
How do they compete? How do they compete against somebody that just hung up a shingle and is out there selling a competing product?
Nowadays, you can't tell. This is an old one, right? Do you remember the Lycos commercials on the internet? No one can tell you're a dog. That's exactly what this is about. No one can tell going to the website. How good are you? How long have you been around? How much have you spent on cybersecurity? Is it any good? It's just nasty. It is really bad, bad stuff.
We are getting attacked so much. Ransomware attacks have tripled in 2020 and remember ransomware isn't just ransomware anymore. Most of the time it's also got extortion built-in. It's just crazy.
Make sure you are on my email list. If you're a home user, that's great. There's lots for you to learn. If you're a business that's great, there's lots for you to learn as well, and I'll let you sort it out. But even when I have stuff specifically for business or targeted to business concerns, there's stuff you can learn from it as an individual.
I want you to pay attention to it, but you can only do that if you have my newsletter coming to you every week. Of course, the best way to do that is this go to my website, Craig peterson.com. You'll find it all there.
I appreciate you guys. I, again, I just can't say it enough. You have been great. I appreciate all of the feedback I get and I answer all of the emails. Again. It might take me a little while it usually takes a few days. But I do answer them and I answer them personally. Most people are really shocked when they get a newsletter, they hit reply. I replied to them. Thinking that I must be some big internet marketer, which I'm not, I'm here for you.
I appreciate everybody that signs up for the list. You guys referring to people. It's interesting. Every time I send out my weekly newsletter, I get even more people signing up for the newsletter. So you guys must be forwarding it to your friends. Who is then signing up? I really appreciate that too. Cause I want to get the word out. 99% of what I do, what I say, is absolutely free to anybody who will care to listen. It's there for you. I really do want to help.
You might remember these commercials from way back in the two thousand in the double ots, triple ots. Hello, I'm a Mac and I'm a PC.
Hey Mac. Did you hear the good news PC choice chat? Sorry, I didn't hear you there. What'd you say, allow me to introduce the top-of-the-line PC? Okay. What are you doing in a pizza box? Go on, rip it in half. And since it's beautiful that he needs an upgrade and I'm having a very difficult time finding pictures of my friend. I couldn't hear you through my virus-proof mask. Bongiorno. Hello. Let's go to the commercial. We are a commercial. Let's go to another commercial, your first class, all the way PC and Danesh. You are banished.
I have to chuckle when I hear those. Isn't that great? Those are just excerpts from some of those commercials from years ago. Of course, get a Mac.
What Apple was doing at the time performed by John Hodgman. He was the guy that did the PC side and Justin Long, who was the guy that did the Mac side saying I'm a Mac. It's fascinating to me now that Intel has decided to go ahead and hire Justin.
Now what's most fascinating about it is that Intel hires Justin. Wait, what are we comparing here? A PC is when you think of it, it's Windows, right? You're not thinking about Intel inside. You're buying a Windows machine. You're not buying a computer because of the chip it has in it, most of the time, right? You might buy this is when I said faster chip or that one has a slower chip. That makes a lot of sense.
You're buying a computer so you can run an application. I remember very well back when the Apple two came out, the two-plus and people bought them in droves because of an application. You could get VisiCalc on there, a spreadsheet program. It was the first, it was the best. It was the most popular at the time. Then others came out that were arguably a lot better. But it still sold. VisiCalc still sold and went over to the Windows platform.
So Justin is now doing commercials talking about Intel. So he's saying on the Mac, you can't touch the screen, which by the way, you can if you get a touch screen for the Mac, No two ways about it.
I have one sitting right in front of me. I use this on my Mac it's a touch screen. I use it for doing presentations. I can highlight things, move things around, touch things, open them up, click on them with my finger right there on this screen.
None of those have anything to do with the fact that inside that might be an Intel processor.
We've got Intel now out there with I think misleading, but potentially you could argue, that they're misrepresenting Intel. All Intel is doing is providing the main processor maybe some other support chips on there. Maybe it's using Intel memory. I don't know, but in reality, what we should be comparing is our Mac, our Intel-based Mac versus our Intel-based Windows computer. Remember Macs will still run Intel.
I just gave it away. Did you catch that?
What's really going on here. What's really going on is, Apple is upset with Intel for some very good reasons. Intel has been massively overcharging for its processors for a very long time. Intel processors have never been that great, frankly, but because of what was called the WinTel monopoly.
Intel really went along for the ride. They went along with the ride with Microsoft because people bought Windows so they could run Excel or whatever the other applications were, that they wanted to run.
So what has Apple done? When Apple came out with the iPhone, it never had an Intel processor in it.
The same thing's true now, with all of the new Apple equipment that's coming out. So your I-phones don't use Intel processors, your iPads, don't use Intel processors. I have sitting right in front of me, a Mac mini that has an M1 processor from Apple. And in fact, Apple right now is trying to get rid of Qualcomm as well. It can help increase their profit margins, but these things are not easy to design and implement.
It took Apple years to get to the point where they had one that was really quite a good processor. I can buy a Mac mini with an Apple processor in it that is better than a hundred percent faster than a Mac mini with an Intel processor, for less money.
The Apple chip costs me less money than the Intel-based processor and it's twice as fast according to Adobe, who just released their performance metrics on illustrator and Photoshop.
Intel is getting very nervous because they're seeing their business go down the tubes. Intel has not been able to deliver on lower power processors. It has not been able to deliver on faster processors other than going to multiple cores. It's also having problems with manufacturing, the smaller, thinner, and thinner processors, which help with of course, using less power that makes them faster and they have less heat.
Intel is saying, Oh my gosh, we're in trouble here because even Windows runs without Intel processors now. You can get a surface tablet that doesn't have any Intel in it and run windows on it. So they're in trouble there.
They're seeing to the market share that's being taken from Microsoft by these Google Chrome tablets. Chromebooks, which are laptops, which are very inexpensive, very fast, very user-friendly, and very secure.
Although, Google does spy on you a bit and they don't use Intel.
What does Intel do? We're going to hire Justin and make people very confused about what's really going on.
Don't worry about those ads, stick with anything you need to use. If you can get out of the space of windows. Get out of this space of Apple. Go with something as simple as you can. Maybe Linux, maybe ChromeOS.
Hey, it's 2021, and ransom payments have nearly tripled then targeting many factoring healthcare, construction and the average ransom is now $312,000.
Hi everybody Craig Peterson here. We were talking a little bit earlier about ransom and ransomware gangs. We've talked about how it can just totally destroy somebody.
If you're a home user and let's say that they get onto your computer and they encrypt all of your photos your grandpa, grandma, your parents. You've got pictures of the kids and grandkids, great-grandkids, whatever it might be on your computer. Now, they're demanding $10,000. If you ever want to see your pictures again.
That is a very good reason to have your photos and other documents you care about somewhere else, not on your local computer.
I know far too many people who hook up a local hard disc to their computer and then back up to it.
They're backing up to a USB drive that just isn't going to cut it. That USB drive is attached to your computer. If your computer gets ransomware on it, it's going to encrypt your USB drive.
That's why I advise people if you are going to have to use a USB drive, let's say you've got a database that you have to open, but you don't have to have it open all day long. Put it in an encrypted volume and only mount it up and decrypt it when you're using it. Then go ahead and re-encrypt it when you're done.
That's called data at rest. The idea is when you're not using it, nobody has access to it. That's what you should be doing. Remember too that if you still have that disc plugged in, and if that disc is encrypted, they can still encrypt it and hold you ransom. But they're not going to be able to do the extortion because the data they have is encrypted. They have no idea what they have. They may not even grab it because some of this ransomware software is just that smart.
Ransomware gangs now that are aiming at businesses are grabbing even more money than they've ever been able to get before. The average amount that's paid, jumped 171% in 2020.
There's a new report out from Palo Alto Networks. They provide all kinds of networking equipment. You probably know, I already use Cisco primarily we've used some Palo Alto. We've stuck with Cisco. I like that integrated environment, but Palo Alto is good. Just not great.
Palo Alto uses data from ransomware investigations, these data leak sites, as I mentioned earlier, where some of these ransomware gangs post to the data that they have stolen from people. Those are called data leak sites. They looked at some of those things to try and figure out what's going on out there in the industry.
They found that these main industries, which are manufacturing and healthcare, construction companies had almost 40% of all ransomware attacks in 2020.
It's just amazing because again, the ransomware attacks are being fine-tuned to go after organizations that have data that is very valuable. The highest ransom paid that we know of was $10 million. Isn't that amazing. The highest ransom demand was $30 million.
Almost a third of the average demand paid more than $312,000. So it's just crazy. When you start looking into this and these ransomware groups are really getting ahead of the defenders.
They are using all kinds of different types of innovation, which is again, why antivirus software does not work. I put that into my presentation. In fact, I had in the presentation here, some slides with John McAfee, I had him for one of them, and then I had a quote from now trying to remember what he was. He was a high-end guy in Symantec which makes Norton, and both of them said this, "their software is just useless" bottom line. It's useless because these ransomware gangs are using different techniques, different styles, they're improving things, pretty dramatically, frankly, and getting these ransoms up higher and higher. By the way, they are still being paid using cryptocurrency and that surged 311% last year.
By the end of 2020, ransomware payments began to decline. A lot of that seems to be because the victims don't believe they're going to be able to get their data back, which is correct as I've mentioned before.
Be very careful out there. If you are a victim of ransomware, realize guys, you're probably not going to get your data back even if you pay. Also, realize that there is another extortion coming your way in most of these cases. That extortion is to pay up or I'm going to release your data to everybody. Then you're going to have to decide what to do. Cleaning up after ransomware isn't cheap. The average cost of forensic engagement is over $73,000 for enterprises and 40 grand for small and medium businesses.
It's pretty bad what they're doing right now. All right next up here. We've got attackers who are going after specific targets. Now I mentioned that just now, but in this case, what they're doing is they're trying to get back doors into iOS developers' Macs. Here's how it works.
If you have an iPhone or an iPad that is running an operating system. That's based on a Unix kernel called iOS that's Apple's operating system for those mobile devices. It behaves differently than the desktop operating system. That makes sense, right?
Windows trying to shoehorn in the touch screens without really considering all of the implications of that, I think was a huge mistake. If you want to go back many years in Windows eight when they introduced tiles. On my archive, you will find me saying that very thing. However, If you are a developer for iOS, you're not going to be using Windows. You are going to be using a Mac.
What the Mac developers use is something called X code. This is a developer tool that Apple makes available to developers who are writing apps for iOS or Mac OS, as well. The bad guys are doing a supply chain attack and they are putting fake libraries that are being used by the developers, into the developer pool. The idea behind that is if they can get this fake little library in there, they can then take control of any machine that's running that library.
I don't want to get into this too techie here and have people zone out, but it tells you something here that the bad guys, rather than attacking iOS head-on like they do with Windows. They are trying to get into the developer libraries and get in that way.
Now they are, don't get me wrong, they are trying to do this with Windows. It's just usually so easy to use a new zero-day on Windows, as opposed to going into all the trouble to try to get into developers' machines in order to install these back doors. It's also known as a home watering hole attack, and they send this to targeted developers.
There's a visual studio project that's available right now with a proof of concept exploit for some of this stuff, but we're aware of it. We're trying to deal with it. Apple is trying to deal with it. Windows eight is happening in that area as well.
GitHub has seen a whole lot of problems with this type of injection and the whole industry is working hard to stop it. I think that makes a whole lot of sense. All right.
Let's talk about selling the feds, location data from every car on earth. Does that make sense? I don't know.
Apple made a change in its podcasts. We'll talk about that as well.
Hey, are you somebody who listens to podcasts as well as the radio Apple figured something out to the most other podcasters really figured out some years ago? So we're going to talk about the one-word change. Apple just made it.
You're listening to Craig Peterson here on news radio, WGAN AM 560 and FM 98.5. Thanks for joining me today.
As we've been talking about some of the great articles out this week that I was going to say the great questions that have plagued humanity, but. I don't think that's quite true. There certainly are questions we all need to have answered and I answer your questions as well.
Make sure you go to Craig peterson.com. You can right there. Sign up for my newsletter. You can send me a question if you'd like to right there, or you can just email me M [email protected]. I'd be more than glad to answer them. It is a wonderful thing to be able to help you guys out. I appreciate you so much for spending these two hours here with me on your Saturday.
Podcasts are something that Apple really kicked into gear. I've been for more than 20 years doing what today we would call podcasts, and that is making available audio from our radio show. Audio from interviews. All kinds of audio for people to listen to. Many other people do. It has become a huge thing. Now there are millions of podcasts out there covering every topic you can think of talking about long tail, just microscopic and lead nailed down different topics.
Apple had the iPod. You might even remember that. And I still use an iPod to this very day. I still have my iPod classic and I that's the one I use. So it is how old now? 12, 13, 14 years old. I don't know, pretty old. And I've had to replace pieces in it. But I really liked that user interface. It's pretty easy to use.
I have over the years, I've put a lot of different music on there and I've also put podcast. It is an iPod with video, which means that it can play certain videos. It has been a wonderful little device. Because of the iPod and the popularity of people listening to the audio, like my show, Apple was able to really dominate that market. They became known as podcasts because of the Apple iPod. People could carry them around with them.
Nowadays we stream, for instance, you can listen to WGAN on tune-in, which is available as an app. It's a website. You can listen any time anywhere. It just couldn't get much easier for any of us. It's fantastic. You can certainly download them into the app. You can download them into the Apple podcast app that's there on your iPhone. On Android with Google play. In fact, you'll find my podcast on all of those platforms, but what is really different about all of this is that now Apple is no longer the leader.
It looks like Spotify is about to take over the leadership position in the podcast if they haven't already. I've made sure my podcast was on Spotify. I hadn't had it on there. They had changed the rules. I don't know some time ago might've been last week. I really don't know. But they changed the rule since the last time I looked. It was easy enough to get mine on there. I think they wanted me to pay before.
Now I have a podcast that's in the top 10% of all podcasts worldwide, which I think is pretty darn cool, frankly. We're having thousands of people listen every week and that just does my heart good. I stopped doing the podcast for a while and it really hurt me, while it was like a year and a half- two years and I wasn't releasing content.
I really lost traction because I had 20 million-plus downloads of the podcast, which I can still say, because that's true, but I've only had about a quarter-million downloads in the last little while still top 10% of all podcasts worldwide.
What Apple is trying to do now, is try and help people understand a little better and get rid of fear by changing one word in podcast land. If you go to Apple for instance, if you go to Craigpeterson.com/apple. That's what it is you'll see. It'll take you automatically to the Apple podcast page.
Once you're on the Apple podcast page, you'll see that you can listen right there on the page. It might open your podcast app or on your Mac. It might automatically open your music player, they keep changing the names of some of these things and let you subscribe.
If you do, I would really appreciate it.
The word is "subscribe." That word has been a problem apparently for Apple because most people when they think of subscribing they're thinking they have to pay for something. You see where they're coming from. So a lot of people didn't want to subscribe because they didn't want to pay.
Podcasts are free. No one charges you for them. Now, there are some subscription models. Don't get me wrong, but in general, podcasts are free. What Apple has done now is they changed the word, subscribe to follow. Which they think most people will understand. Following someone doesn't cost you anything. That comes from all of the social media platforms that have really changed things up for them. This change to the Apple podcasts app is going to come with the release of iOS 14.5 and. We'll see if it actually makes it in there.
It was noticed by PodNews, which is a website that reports on the podcasting industry. They were showing, Hey, look at this beta version of iOS where they're changing it. So that's how we know it's coming. I think it makes sense.
Edison research I've quoted them before they're a market analysis company. They found that 47% of people who don't listen to podcasts thought it cost money to subscribe to podcasts.
That's true with most of these apps nowadays, you can get it for free, but they also have paid versions. In Tune-In the paid version, lets you pause, live radio, and go back and listen to it later. I used to use that a lot back in the day. You also have different features on these different podcast listening apps.
Most people are confused about it. 47% think it costs money to listen. So Edison research vice president or senior VP Tom Webster said the reason for this is because of the one word subscribe. That's a huge problem with nearly half the people surveyed. Won't listen to a podcast because they think they have to pay for it.
Now, Spotify, which is edging up, if not surpassing Apple with the number of people who listen to podcasts has already switched. They're using the word follow to describe the feature that adds your favorite podcasts to your playlist. Spotify has also played around with this idea of paid podcast subscriptions, which could be separate from the idea of a paid podcast offering. It's a premium paid music and everything else. So it's I think it's going to be interesting. We'll see.
Apple has switched pretty clear to help get rid of some of the confusion on its platform.
Have a look for me, Craig Peterson in your favorite podcast app. Sometimes the easiest way to find me is just to go to Craig peterson.com/the name of your favorite podcast app.
All right we've got one more segment here before we leave for the day.
So don't go anywhere.
We've got one company that wants to sell the U.S. Federal government location data from every car on earth. Did you even know that was possible? We're going to talk about what's going on.
Hey everybody. Thanks for listening. This is, of course, Craig Peterson.
Man, we have a problem coming our way and then get another one. This has to do with our cars. You might have heard, I heard that Massachusetts decided that they would start charging attacks based on how many miles you drove in the Commonwealth, and the reason behind all of this, supposedly, and it probably is, was that we have cars that don't burn any gas, electric cars, and they are using the same roads. They need the same law enforcement people. They need the same bridge repairs as everybody else, but they're not paying any gas tax. So how do we make them pay as they should? Mass it hasn't gotten very far with that yet.
There's this port in your car called an ODB port or ODB2. This is a port that was mandated by the Federal Government I think in the late seventies when they started this whole mess up.
That port gives them access to the onboard computer. That's there in your car? Hint. ODB, onboard computer. Important there in your car. There's so many three-letter abbreviations that sometimes I kind of mess them up.
So Mass was saying, we can just hook up your car now we're hooking it up anyways when we're checking the emissions cause your car squeals on you. It's not like the days back in the eighties where they would stick a sensor up the tailpipe. To see what your emissions were like. They just ask the computer. What are the emissions like? What's the NOx? The CO2 emissions? How fast is he accelerating?
That same port has been used to give trap traffic tickets but in different areas. Yeah. OBD port, I just looked it up just to make sure I had the right name for it. And it's been used to give tickets up in Canada and Montreal. There's a report that came in of somebody that was racing up and down one of the main streets in Montreal and the police got there and nobody was racing up and down. But a car by the description was there. So they pulled the car over, they hooked up the OBD reader to the port in the car. The car said, yeah, I have been going at this speed recently. The cops gave the guy ticket just based on that.
Our cars had been squealing on us for a long time. Mass wants to use it to say, how many miles has the car driven? Then there's questions about can you charge people mileage, not in your state? Obviously, they are already. If you live in New Hampshire and you happen to drive into Mass one time and you buy gas there, you are paying mass gas tax, which by the way, Charlie Baker apparently wants to double. There are some limits, but I don't know how far they go.
There's a lawsuit right now in the Supreme court between New Hampshire and Mass, over Massachusetts charging income tax to New Hampshire residents that never even stepped set foot in the state of Mass. So it's really convoluted.
We have over 9,000 different tax jurisdictions here in the United States, and that makes things really crazy. When you think about all these different government agencies that want to put their hands in the Till and want to do stuff.
How does that tie into the cars? Our cars are getting smarter and smarter. This port that was put in decades ago was the first step. The car's squeal on ya and the tell information that should be private. Some of the cars now, these better, faster, smarter cars, like the Teslas keep track of everywhere you've gone. Where you're driving? How fast you're driving? The cameras are actually recording all of the activity, everything that they see. There's seven cameras on these cars and all of that stuff is stored and could be pulled out, certainly in a court of law. We're seeing in some jurisdictions that their police want to get their hands on it. There is something going on right now.
There's a company out there called Ulysses. They are a surveillance contractor, and they're claiming that they can remotely geo-locate vehicles in nearly every country, except for North Korea and Cuba on a near real-time basis. That's from Vice motherboard.
So Ulysses is obtaining vehicle telematics from data that's coming out of these embedded sensors and communication centers that are in our cars and in the roadways. Some of these cars are now sharing data. This is a technology that was pioneered by NASCAR and formula one so that the cars could avoid accidents with each other. So the cars could be much safer for the drivers. That makes sense. The cars all talk to each other on this mesh network.
Now we have these companies that have these autonomous features self-driving cars if you will, that are doing much the same thing. They are looking to use mesh communications and some of them already are. By grabbing things from these connected cars, like the engine temperature, your acceleration, where you started your journey, where you're ending the journey, it is a real problem.
There are more new cars now being added to cellular networks. The new cell phones. Here's an article from ARS Technica from a couple of years back, it says in particular, this Shanta Sharman Consulting noted that AT&T has been adding a million or more new cars to its network each quarter for the last 11 quarters. While they didn't break out the numbers for other service providers. It also revealed that Verizon is set to make at least $1 billion from the internet of things and telematics and previous research from Gartner suggested that in this year, a few years back, 98% of new cars will be equipped with embedded modems. It's probably close to a hundred percent by now, by the way.
Our Teslas and pretty much any other self-driving car is guaranteed to be called home because they use that call home function in order to upload new software for the car in case there's some sort of a problem to upload driving data so that they can figure out why did the driver have to hit the brakes or grab the steering wheel to make it smarter?
So our cars are recording all of that data is coming together. Ulysses claims it can currently access more than 15 billion vehicle locations around the world each month and estimate that by 2025, 100% of new cars will be connected and transmitting gigabytes of collectible data. Definitely a concern here. Definitely concern.
Keep an eye out for that. Maybe, I'm gonna keep my 1980 Mercedes diesel. I chuckle because it's rusting out, rusting up pretty badly, but I don't know that I want one of these cars getting tracked everywhere. Bad enough having an easy pass on the cars.
Let's talk about tech vendors and their lack of security. I really picked on healthcare for the first hour of today's show, but a majority of companies are saying they're more likely to buy from suppliers that are open about security issues.
The federal government is now enforcing this SPRS, which is a score that is from zero to 110, that it has to be self-generated at this point by DOD contractors to indicate how secure they are. Then the Department of Defense can look at that and say, okay it's a nut or a bolt and we only buy this once a year. I really don't care if they score highly or not. All the way on the other side.
We don't see this for regular businesses. An increasing number of companies have identified security as a major consideration in their decisions to purchase hardware, software, and services. We just had this conversation with a manufacturer. We had this conversation within the last week with, again, some of these medical providers, the Ponemon Institute says that nearly two-thirds of the people, that were polled in the survey, consider it very important for their technology providers to be transparent about vulnerabilities, security, updates, and ways to patch security issues. But most vendors failed to offer that transparency. According to 47% of the people who say they're not satisfied with the security information provided by vendors.
I was really harping on this near the beginning of the show today that it is bothersome to me that so many businesses are trying to do the right thing. They're pouring a lot of money into cybersecurity, and yet they have to compete with businesses that don't care. That don't know how to do it. They don't care to learn how to do it. That's what I mean by don't care.
I think everybody cares to some degree about cybersecurity, but in reality, if you're not doing enough about it and you just don't care enough.
So I really want to extol to everybody. Take some time, make sure you are on my email list. Cause I have a lot of stuff I send out over all kinds of free tools, third-party tools, right?
Not everything I send out is from me, about me, buying me. I send links to other websites and things, and I do that every week to help keep you informed.
I also have some special programs that I do and this next week I am starting a course for Improving your Windows Security.
If you let me know by sending me an email Craig at me, [email protected], and tell me that you're interested in Improving your Windows Security. I'm going to be giving you a special coupon that nobody else can get for this core course that you need for cybersecurity.
So check it out online, make sure you are on my email list. So you get all of this great free stuff you find out about paid stuff.
If you can do it. If you can't, don't worry about it. I want to help. Craig peterson.com.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig Peterson: [00:00:00] Ooh, what a week final preparations are in place for the improving windows security course, which is starting next week. My wife has put her foot down. We're going to make it happen. Today I was on with Mr. Matt gag now, and we spent a little bit of time talking about business, email, compromise, how that is.
[00:00:20] Talked about also ransomware, and it's near tripling and just in long, Hey, I'm Mac and how Intel's newest ads are absolutely ridiculous. It's obviously Apple and Intel going at it. Intel is just mad. That's the only explanation I can come up with. So here we go with
[00:00:47] Matt Gagnon: [00:00:47] Mr. Matt. It is 7:36 on the WGAN morning news. Craig Peterson, our tech guru, joins us now every week.
[00:00:54] And guess what? He's here again, Craig. How are you this morning?
[00:00:57] Craig Peterson: [00:00:57] Hey, good
[00:00:58] Matt Gagnon: [00:00:58] morning. Pleasure having you as always, of course, you hear Craig also on the weekends at one o'clock. If you want to hear about all these topics and more in more depth and detail, listen up Saturday at one o'clock, and you'll hear Craig Peterson's voice right here once again.
[00:01:10] So Craig, lots of stuff to get to here. Maybe a fun one to begin with. Apparently, Intel has hired Justin Long. And if you don't know who Justin Long is if you think back way back to the early two-thousands, he was doing these ads, the I'm a Mac actor. Remember that guy?
[00:01:26]Now he's in an ad to mock Macs. Yeah. And I, I've seen this in a, I think it didn't. Was it Verizon that hired the sprint guy or sprint hire the Verizon guy? I don't remember. Many of these actors were in these iconic roles, for some of these tech companies are getting snapped up to either make fun of or argue against their old essentially.
[00:01:46] It's funny to see this kind of thing
[00:01:47] Craig Peterson: [00:01:47] happen. Yeah, it is that I think you're thinking of the can you hear me now? Exactly. Yeah, this is interesting. And it's showing, I think, frankly, of some concern, maybe even fright on the part of Intel, you see what's been happening over the years, not just with Apple, but with other manufacturers is Intel processors are getting dropped.
[00:02:12] Out of our devices. We started seeing that with smartphones. If you have a smartphone today, it doesn't matter if it's Android or based on Apple's iOS. It does not have an Intel processor score. And we've seen more of that surface tablets without Intel. Some of them have them, some of them don't.
[00:02:32] And of course, all of these Google Chromebooks at all. So don't have it. So Intel has always been struggling to be recognized, and that's why they came up with a whole Intel inside campaign. However, they have also been one of the most expensive little CPUs little processor. If you want a professional Intel processor, it can cost you as much as $8,000.
[00:02:59] Just for the CPU. So Apple has decided we're getting rid of Intel entirely after Intel missed certain benchmarks for performance and battery usage and heat and everything else. And Apple started developing its own chipset here a few years ago, or the CPU is now completely moving away from Intel over the next two years.
[00:03:23] And in fact, if you buy a Mac mini, I have one in front of me right now. That doesn't have an Intel CPU in there. It has the new Apple, one chip Apple is just abandoning them. So they hired Justin Long. The I'm a Mac guy to show you, Oh, this is a, an Intel. Computer. And of course, it really has nothing to do with Intel, and he touches the screen and moves this finger around, and it isn't that neat.
[00:03:52] It pops up and, oh, look at this. We've got two screens on this computer, and I can touch them both. But this Mac book, I can't touch the screen and have it do anything. No, that has anything to do with him, Joe, Matt. It's crazy.
[00:04:07] Matt Gagnon: [00:04:07] Indeed, while we were talking to Craig Peterson, our tech guru, who joins us on Wednesdays at this time to go over what's happening in the world of technology in a more serious perhaps story here.
[00:04:16] the knowledge here that ransom payments have more than tripled is a pretty big deal. Ransomware gangs are apparently out there roaming around the internet and successfully milking. Many people out of cash, basically taking them hostage or taking their machines hostage, if you will. And then promising to give it back.
[00:04:34] If only you give them cash. Talk to me a little bit about the story.
[00:04:37] Craig Peterson: [00:04:37] Yeah. That's really driven up the price of Bitcoin because the ransomware gangs are demanding Bitcoin and payment. It's a little bit harder to trace, but it is still traceable depending on what it is and the FBI just yesterday. Yeah.
[00:04:53] Released another warning about ransomware attacking businesses, government entities, just on and on, but it has a huge impact on anybody that gets ransomware, and a man, the tripling of rent more attacks go hand in hand with people working from home. And that's why I've got this improving windows, securities core starting next week for everybody where we're.
[00:05:19] Helping you to clean it up because we're working at home. We're not as careful as we were at the office. Because of that, it now makes it even easier for them to get valuable information. So the best thing you can do is make sure your computer's patched up. Unfortunately, Windows does not. Ship a hasted care re-secured version of windows out of the box.
[00:05:44] You've got to go in; you have to do a bunch of things. That's part of what we cover in our newsletters every week. And then some of these courses, but these attackers are improving their techniques. 2020 was a great year for them. They've got this whole double extortion thing now where they will get on your computer.
[00:06:03] Particularly if it's a business-related computer, if you're on a VPN connection to the office, they will. Spread is not only inside your home to other computers but across the VPN to the office. And they'll start stealing your data before you even know it's happening, and they might be doing that for a week or more.
[00:06:23] And then once they've got your data, They'll go ahead and encrypt your machines so you can gain access to it. And then they'll say, okay, pay up sucker. And if you don't pay up, you don't get your data. If you do pay up, there's only a 50%. Yeah. Only half the time will you get your data back, even if you pay them.
[00:06:42] And by the way, their justice department says, if you pay them, you're supporting terrorism, and you might get criminal charges against you and to make matters even worse. They'll then say, Oh, okay. By the way, where we are another organization, we have your data. If you don't pay out, we will post your data online, and then you'll be in real trouble.
[00:07:06] Matt Gagnon: [00:07:06] And Craig, the other thing that's worth mentioning here in terms of. Businesses and people that are experiencing some financial extortion, if you will. A business email compromise is also a huge deal. And frankly, I've gotten the emails here about that in this Berry station; make sure that your email is being protected and that you're not falling for phishing scams and all this other stuff. And a lot of email compromised does happen and apparently accounts for a lot of money.
[00:07:30] Craig Peterson: [00:07:30] Yeah, it does. We're talking billions of dollars worldwide. Right now, the FBI estimates that this has cost over 16 billion.
[00:07:39] We're seeing here last year in the us almost $2 billion, and there are some easy ways to deal with this. And I'd put it in my newsletter here a couple of weeks ago when you can always email. [email protected]. I'll send you a link to it, but Google has a free website that you can use, and it has some examples of fishing it's designed for training.
[00:08:04] You can use it for yourself at home. It's wonderful. It gives you a real interactive. Pieces of email that you can see on your screen. It is not going to compromise you at all. This is all online because, with these latest business email compromise attacks, people are getting extortion. It might be tech support romance scams, which have been very big here during this lockdown because people are frankly lonely.
[00:08:35] And they'll do things like being friends. People will be friends, you may be, and we'll say, Hey, listen, my aunt really needs surgery. Eventually, get around to asking you four or five grams to help with this whatever family problem is. And you're romantically involved online, maybe even had a video chat with them.
[00:08:57] So you don't realize that some kid in a basement somewhere over in Eastern Europe, but man, it has gotten awful. So be careful with this BC-type attack and take a minute. You can even Google's phishing scam website, and it'll really help you out a lot. All
[00:09:19]Matt Gagnon: [00:09:19] That's been Craig Peterson, our tech guru who joins us on Wednesdays at this time.
[00:09:22] Thanks a lot, Craig, as always, appreciate it. And we will talk to you again, sir, next week.
[00:09:27] Craig Peterson: [00:09:27] Take care. Bye-bye. You bet. No, my dad used to say you bet all the time. I haven't heard that expression in a very long time. Hey, if you are a windows user, you've got to make sure you spend a few minutes and sign up on my newsletter list, and you can get that to go into Craig peterson.com.
[00:09:49] I will be doing. Windows training here. I've got a course coming up. This is a phenomenal course. I think I explained the why behind what you're doing. So you understand it, you understand the reasons. And then I get into the details of the how, so this is a course. I think everybody needs to get it. So I've got some special deals for you guys.
[00:10:18] If you. Request information on the course, if you've already requested it by responding to one of my emails, my newsletters, and saying, yeah. Tell me more about improving my windows security. I'm going to be giving you guys a coupon that is going to give you two-thirds off. And those coupons are going to be good for you to share with your friends as well for two months.
[00:10:47] Okay. So this is going to be a real quick launch next week. It's only going to be open. You can only buy this course. I think Monday is when we're planning on opening, and it will. And Thursday night. So you guys that asked about it beforehand, you signed up before you will get this coupon to help out your friends.
[00:11:09] So when they're saying, Hey, how do I improve this window security thing? You can give them that code. And as I said, it was good for 60 days. Nobody else is going to get that code. So if you're on my regular email list, you are not going to get that code. The only people who will get it are the people who have already expressed interest by responding to one of my newsletters in advance of me starting this course on Monday or opening the cart on Monday.
[00:11:41] So it's going to be a huge win for you. It's going to be $200. Off. Okay. I'm trying to make this affordable for everybody. And on top of it all, I have promised this for four months. Again, talking about Karen, putting her foot down, she said, I got to do something for all of these people have been asking for it.
[00:12:02] And I haven't got it out yet. So this is going to be great. It is months in the making, and I really think you're going to enjoy it. I'm finishing, loading it all up. Bye, I'm actually reactivating all of the videos because I wouldn't say I liked the way the captioning was working. I have all of these videos captioned.
[00:12:24] So if you can't, I can't hear it. Or if you want to have it running without the sound on at work or wherever it's burned right into the video. Okay. But the captioning, which is a transcription of me speaking. Okay. That captioning was getting cut off at the top. So I thought that might be distracting.
[00:12:45] So I'm, re-editing all of the videos to put the captioning a little bit lower down on the screen. And the way I did it is the desktop slides. All of the examples are below the camera optioning. So the captioning is not going to blockโany part of the video. So you'll be able to see the screenshots and see the slides and everything else with the full caption because I know a lot of you guys like to sit there in front of the computer and do this, and of course, you're able to do it on as many computers as you want, because you're going to have access to this program for six months.
[00:13:28] And I think that's going to be an excellent thing. And it's about five-week. Program is how it's designed. And anyway, so w so if you sign up in advance, there's a little bit of a trick. You can get the coupon; you can share it with anybody good for it. Two months. Nobody else gets that. All right.
[00:13:50] Everybody take care, and I'll be back on Saturday. And then Monday, expect the opening email to let you know that I'm opening the cart to improve Windows security. Of course. All right. Take care, guys.
Craig Peterson: [00:00:00] Hello everybody. Craig Peterson here. I was on with of course, Mr. Jim Polito, and with him on parts of Vermont central and Eastern Mass, Rhode Island, Connecticut. He has a big show that covers all kinds of territory. And so we're covering new England. What can I say with all of these different stations, I'm on in Vermont directly and all throughout New Hampshire and Maine and stuff. So it's just really cool. And without you guys, it just wouldn't be happening. So thank you. Thank you to you. And also I got to mention playing my podcast. Listens are way. Oh, and again, thanks.
[00:00:42] Thank you to all of you guys. I so appreciate it. And to that end I am going to, as of next week on Monday going to be opening up a course that I've put together. Yes. That core is the one that promising now for how many months. And so this is as a thanks to you guys. I am going to be giving. A, I hope you're sitting down basically two third, all in fact, exactly.
[00:01:14] Two thirds off on this, you're gonna be saving 200 bucks. I'm making it cheap under a hundred dollars. It's going to be 99 and it is going into the Y. And the how of doing your windows security, the basic security windows, that configuration settings you need to be doing. So keep an eye out for that on Monday.
[00:01:38] And by the way, here's the, a little secret and it's going to be a surprise to a lot of people, but if you respond beyond to my email newsletter, if you responded to my email newsletter and you told. Me that you were interested in, improving who wouldn't know security. If that happens before Monday, I'm also going to be giving you a special coupon that only you guys will get.
[00:02:04] And that coupon, it will be good for two months. And you can share that with your friends, so that your friends can get. A two-thirds discount on the improving windows security course. So it's really important that all you guys get this course, it is so important. And it's going to help, prove to my wife that it's worth me spending all of these hours every week.
[00:02:32] And in fact, a at least a day, a week dedicated to. And putting together all this stuff, the newsletter and the radio show and all these other appearances. So to convince her that it's worth it to do all of this, did you guys appreciate it? And it's a great way to show it. So if you go to one of my newsletters, even an older one, and you say, yes just hit reply and put IWS in the subject line.
[00:02:56] I'll tag you. And you'll get one of these coupons you can share with your friends. So when you're talking about what you've done to improve windows security, you'll be able to say, and by the way, you can do it too with this coupon. Good for two months for them. Anyhow, take care guys. Here we go with Mr.
[00:03:17] Jim Polito.
[00:03:18]Jim Polito: [00:03:18] It appears that there's a company who can they can track where your car is. And they want to sell this data to the government. What. This, by the way this news comes as we hear that the Chinese don't want Tesla in China anymore, because they think that Tesla is basically a CIA backed company.
[00:03:46] That's spying on the Chinese. All right. Let's sort all this out. And just bring in the voice of reason and the voice of real intellect. I'm talking about our tech talker ruin good friend, Craig Peter song. Good morning, sir.
[00:04:01] Craig Peterson: [00:04:01] Hey, good morning. How you doing
[00:04:03] Jim Polito: [00:04:03] Mr. Jim? I'm very good Craig. We can get into the Tesla thing and the Chinese saying you're spying on us and kicking them out.
[00:04:10] And meanwhile, they're trying to they're building components for R F 16 fighter jet, but that's all right. Let's get to this company. You sent me this as a company. Who collects this data tracking cars. First of all, I didn't know my car could be tracked, but, anyway and then they want to sell it.
[00:04:27] They're trying to sell it, bundle it and sell it to the United States government. Yeah,
[00:04:32] Craig Peterson: [00:04:32] they are. Wow. This is pretty concerning here. This is a contractor that has been doing surveillance for a long time for the government. It's told you lyses, which is an interesting main site, but yeah. Wherever we're going to this gym is a whole new direction.
[00:04:50] Pardon the pun with our cars. We now have cars that are moderately smart to mention Tesla, but there are more and more coming online. And the idea is to have a web of. Cars, sensors and cars talking to each other. We already have that basic technology existing in NASCAR and in formula racing where the cars actually talk to each other, they know how far apart they are is, and that's something that's really.
[00:05:26] That's what we're going to need for the cars on the road today. So I was watching this British show where they're racing around the world. It's like the amazing race, but they mispronounce words.
[00:05:43] They were in China and and they were just as shocking to me to see some of these things. I don't know if you've seen the pictures, but there's this one road it's 20 lanes in each direction, coming up to a toll booth. Backed up for miles. The traffic there is crazy. And I lived in Los Angeles for about eight years.
[00:06:03] I had a client that I used to go to the largest savings and loan company in the country and their headquarters were, Oh, not even 40 miles from where I lived. Public goes to the 30 miles from where I lived out there in LA. I was actually just over the line in Ventura County for those that know that area out there.
[00:06:24] But the problem that I faced was to go that 30 to 40 miles, Jim would take me more than three hours. So I was on the road. For six hours a day. And most of the congestion that we see on the road is caused by people, the sole person in the fast lane and people weaving in and out of traffic. All of the things you've heard over the years.
[00:06:52] So what we've been doing is putting sensors in the roadways. You see them a lot. West and they have, if you go on and on ramp, there is a stop light, right before you merge. Have you seen those before? Yes. Yes. So you have to come to a full, to come to a full stop. Yeah, it's crazy. What they're trying to do is when the light goes green, only one car can go through.
[00:07:15] These sensors are detecting where the cars are, how fast they're going. So where we're going to is embedded sensors, everywhere communication, sensors on all of our cars, just like they are at the races so that we can now have two to three times more vehicles on the road safely. And at the same time in decrease the amount of time it takes.
[00:07:40]
[00:07:40]Jim Polito: [00:07:40] No, go ahead, Craig, finish your thought.
[00:07:43] Craig Peterson: [00:07:43] I'm looking forward to that sort of a thing, because it's going to be huge, but it brings up the point that you just brought up. Yeah.
[00:07:51] Jim Polito: [00:07:51] You weren't talking with Craig Peterson, our tech talk guru. And so Craig. Yeah. I go for all of that. Anything that can make a safer Noah, hold on a second.
[00:08:00] I don't want to give up privacy for these things, moving cars along on the highway. Better Mo you know, making traffic flow better. We learn every year, these things, but you're right. It reminds me of the movie demolition man, which is, supposed to be in the future. And they say, okay Where is he?
[00:08:19]No, we'll just go two, two, two, two, two. And everybody's chipped, but also every vehicle is chipped and everything else you can find and cameras are all over the city. So you can find anybody just by the press of a button and yeah. I that part, I don't like I don't want I fat because I just think that it's inappropriate for the government to be able to do that.
[00:08:42]I don't trust it being in the hands of people, especially after what happened with the old P dossier, the thing that they, the Russian collusion thing, they brought up against Trump, which turned out to be. Absolutely false. You're going to hate anything you want about Trump, but that thing was false.
[00:09:00] And yet the FBI ran with it. And when the, when I find out that the FBI, the leadership of the FBI will run with something like that, I don't trust them with the other stuff.
[00:09:12] Craig Peterson: [00:09:12] Yeah let's have that issue. So here's what we're looking at right now. You've got this OBD port in your car, every car mandated by Congress.
[00:09:22] It's in there now. It's been in there for decades now. And when you go to the car repairs shop, they plug it in and the car said, tells them the technician. Why that check engine light came on. And they are now taking that to the next step, which is they are transmitting it, transmitted that information, that OBD port, that onboard computer knows everything about your car.
[00:09:49] It knows if your seatbelts are fashion, but are fastened. It knows. You're the engine. What's the temperature? What are your emissions? How hard are you accelerating? And so let's put all of this in a pot and stirred up a little bit. They are obtaining already this company called Ulysses what's called telematics data.
[00:10:10] It's all of this data about the cars already from embedded sensors, from communication sensors that are embedded in the roads. That are reading our license plates as we drive under bridges or pass these little cameras and pull yeah. Pulling it all together. So these cars, a hundred million new cars manufactured worldwide every year are increasingly conscious to the manufacturer and match part of the problem China has with Tesla.
[00:10:41] Jim Polito: [00:10:41] Wow. Craig. Here's the thing. There's not going to be any way for you to block this. If you worry about on your. Desktop computer or your laptop computer. If you worry about the camera being on like the cameras they sell now, even have that little thing, you slide over covers up the lens.
[00:10:59]You can unplug the microphone. You got, you knew all those things so that you can't be monitored. But you can't do anything with this stuff. If they put it out.
[00:11:08]Craig Peterson: [00:11:08] Your Tesla and part of what China is complaining about is you hear you're driving a car around with what is it? Seven cameras on it, including a camera aimed at the driver, and then Tesla calls home every night on why fi.
[00:11:22] What state is it transmitting? What does it know? What pictures has it taken, talking about a hat target don't China's concerned. Hey the CIA NSA, FBI, who knows what TLA three letter agency might be tracking this stuff and you know what. They're not
[00:11:40] Jim Polito: [00:11:40] wrong. Yeah. I hate I hate to agree with the but the Chinese communists on something like this, but they they are, right there.
[00:11:49] They don't want it. They don't want anyone. Taking pictures of things that went well, that basically that's what you have in a totalitarian state.
[00:11:58] Craig Peterson: [00:11:58] And I want to twist this to okay. And that is Jim. Okay. Have you noticed that I noticed this when I was young, my parents blamed me in doing things I never did.
[00:12:11] What did they did? And the Democrat blame Republicans for things Republicans never did, but they did hence the Russian hoax against president Trump, where they were saying president Trump, collusion, Russians collusion, Russians. What we're looking at now is the Chinese saying we don't want your technology because it's spying on us because that's how you something.
[00:12:34] Jim Polito: [00:12:34] Yeah. It really does. I do know that they don't want people freely taking video of anything in their country because they want to control any information about their country. That leaves, God forbid somebody in a Tesla drive by one of the Weger concentration camps where they're committing genocide against that.
[00:12:55] Muslim minority. Somebody might pick it up on a Tesla camera and it might end up in the hands of the the public. But you're right. Craig, this was a fascinating segment is usual how to folks get more information from Craig Peterson.
[00:13:12]Craig Peterson: [00:13:12] I got to let everybody know next week. I am starting that improving windows security course.
[00:13:18] I've been promising for three, four months. It starts on Monday. You'll find out more, but you only find out if you are on my newsletter list. You can get all of the details, but you've got to go to Brent peterson.com. Make sure you sign up to the newsletter letter. You'll get the show notes, including stuff that I send to Jim.
[00:13:38] You'll get that every week. You'll find out about the free trainings, about the courses, about everything that I'm doing to try and help people understand where we're at and where we're going.
[00:13:52] Jim Polito: [00:13:52] Craig, thank you so much. Always a pleasure. And we'll catch up with you next week or. There's a big tech story maybe before.
[00:14:01] Craig Peterson: [00:14:01] Indeed. Thank you, Craig.
Craig Peterson: [00:00:00] Good morning, everybody Craig Peterson here. And I was just talking with Mr. Chris, Ryan about some of the impact that we are beginning to feel with the remote hackers, right? Was this China was this Russia. And I thought it was interesting because Chris was obviously going online and. Doc going some of these different topics that we were talking about and 19 administration officials that were saying things that I don't think were true, frankly.
[00:00:36] So here we go with Mr. Chris Ryan.
[00:00:39]Chris Ryan: [00:00:39] The program right now, Craig Peterson, host of tech talk here on news radio 610 and 96.7, which airs on Saturdays at 11:00 AM, actually 1130, Craig, how are you?
[00:00:52] Craig Peterson: [00:00:52] I am doing fine. And yeah, there's only one right lane.
[00:00:55] Chris Ryan: [00:00:55] Thank you. Thank you at score another one for Chris.
[00:00:59] He's not just sucking up to me because I'm the host. He is legit in this circumstance. Craig, I got a lot of important things to talk about with you and I want to start with what the United States is doing in regards to cyber attacks reportedly against Russia and retaliation for what Vladimir Putin has done in regards to election interference.
[00:01:17] And also. Some of the cyber attacks that they've perpetrated against this country. What's the latest on this. And what do you see as being the state of play?
[00:01:25]Craig Peterson: [00:01:25] There have been outages of course, here in the us and a lot of them attributed to just us making mistakes. So a lot of people businesses that are running parts of the internet that.
[00:01:37] Did the wrong thing. So remember, again, the internet is not run by one organization. It isn't run by the federal government. It is a whole bunch of networks that are connected together. Now that said, we have seen some major strikes against outs here in the U S from both. Russia. And from China, frankly, China has been much, much worse at this, but the Biden administration has decided to really try and single out Russia.
[00:02:07] In fact, president Biden came out and criticize them and said, we are going to retaliate. We had a problem in Russia where the Russian main Russian government websites were shut down and they went off the air is that as he sent them down on purpose and we've seen similar things before. So Chris, I suspect we have been involved.
[00:02:30] Chris Ryan: [00:02:30] Yeah, the Biden administration, according to Yahoo news is preparing a series of aggressive cyber attacks on Russia. I'm in a major shift in tactics designed as a warning shot to rival powers. They are saying that they're not going to target civilian structures or networks, but the hack will instead serve as a direct challenge to Vladimir Putin and his cyber army, according to the telegraph.
[00:02:56] Craig Peterson: [00:02:56] Yeah, but the one to really worry about is China. I, there's this whole Russia thing has really gone overboard here. All of the. Real cyber experts are saying that China's the big one. We just had two major attacks that attacked and compromised tens of thousands of businesses here in the United States, as well as government agencies, as well as our schools, stealing our information, grabbing bank account information, personal information, personal health information.
[00:03:26] And none of that is attributed to Russia. It is entirely including the federal government Homeland security and the FBI it's entirely attributed to China. But yeah, it looks like we've done a little saber rattling, according
[00:03:41] to what the American government has said, the agencies believe that the attack was the solar winds attack was actually perpetrated and they have traced.
[00:03:50] Back to the Kremlin and this is going to be retaliation for that. So you do not believe that's the case. You believe it is China.
[00:04:00] Yeah. Most of what we're seeing with solar winds is actually originated with Microsoft and Microsoft office three 65 system, and more particularly with Microsoft exchange servers and apparently. Both countries, there's all, some others have been involved in this. No, I don't say that it was not Russia at all, because there is some evidence that they were involved in it, but the most dramatic stuff has been caused by China has been coming from China.
[00:04:29] Now I've got to explain one other thing here. Sure. The reason there are questions about this isn't because people are trying to hide things or cover up or blame a country that had no involvement. The reason it's so hard to figure this out entirely is we don't know where it really originates. No, we can track down a little bit.
[00:04:50] We know, okay. There's an IP address that came from, but that IP address was someone's home computer that had been compromised and as part of a bot net, and then that home computer, if we get our hands on it, we can see, Oh, that was compromised from this machine in India. Oh. And that compromise came from here or there, the way we tell.
[00:05:10] Whether or not a machine has been compromised from a certain place is by looking at how it was done. And I've worked with the FBI on these cases before. And so I can tell you what we're looking at is a fingerprint. What tools did they use? How did they use them once they got into the network?
[00:05:29] How did they spread? And it is easy enough. For the Russians or the Chinese or the North Vietnamese now to come in and do something just as though they are someone else. And it's much like these people that commit crimes and they, the police look at it and say, okay, this has the same ammo.
[00:05:52] Motorcyle Rhonda, is this other crime? Therefore they're probably related. That's what we're doing here, Chris. So there's no hard and fast rules that this was, or was not Russia on. And you're talking about one specific part of one specific tack. We do know most. Countries were involved. And we do know that China has been doing most of this over the last really 15 years,
[00:06:20] Chris Ryan: [00:06:20] U S national security advisor, Jake Solvan who's from New Hampshire was a part of the delegation that met with the Chinese in Alaska.
[00:06:27] And that wrapped up over the weekend. It began with a very tense. Standoff between the two nations, which was supposed to be a photo op and instead they engaged in, as you referenced before, or some saber rattling between the two sides. And I'm interested in what your takeaways were from that. As Mr.
[00:06:46] Sullivan has continually. Said that traditional sanctions are not going to be what the Biden ministration uses in these circumstances. And there's going to be different elements as the United States. Again, looking at the cyber side of things in regards to attacks and and following up from previous attacks, perhaps perpetrating new ones in a new type of response.
[00:07:11] Craig Peterson: [00:07:11] Yeah, there are many options available. We do in every branch of the armed services, have people who are not just there to defend, but to attack. And we are continually looking into that. Of course, the NSA we've seen before for tools that were offensive. Cyber warfare tools we've seen them used. And we just saw China here last week, how Tesla, but it cannot be selling cars in China because it has seven cameras and it has all of this other computer equipment.
[00:07:44] And they think that we might be using it to steal information. Of course, Elon Musk came out and said, no, that's not the case. But that's the sort of thing we really could be doing. If we wanted to do it, you can be sure we're probing their networks. You can be sure we're into them as much as we can be. So how we resigned, it's hard to say, but there are a lot of options available and we have been shooting around the corners in shutting down power plants in Russia, in shutting down some of the infrastructure in China an hour.
[00:08:20] Fingerprints are all over those things, just like it was in Iran with those centrifuges that were being used reportedly to make nuclear fuel for bombs. We have a record of doing this sort of thing. Preston. So in saber rattling might well be backed up by something. That's a very, obviously from the UK.
[00:08:41] Chris Ryan: [00:08:41] And I think it has to be, I think that talk particularly in the current world, climate only goes. So far and it has to be followed by reciprocal action where we'll be seen as just being talk. Craig, thank you so much. And I look forward to chatting again next week. Take care, Chris. That is Greg Peterson.
[00:09:01] He hosts tech talk on news radio six, 10 and 96, seven Saturdays at 11:30 AM.
Sorry guys, this week was quite busy for me with meetings and presentations for my business. We will be back next week with a new so but for today this is a re-air of the February 20th Podcast. Check out the website for the latest articles I found for you to read.
Craig
Welcome!
We lost a Radio Icon this week and he had a big impact on me, I have a short tribute to him but it was also another busy week on the technology front. We are going to get into the differences between Backups, Disaster Recovery and Business Continuity, often these get tossed around in discussions as one in the same - they are not. Then we will discuss Bitcoin and it metoric rise and why that happened. Next we'll discuss Apple and Google and why Google is trying to play hardball but may end up getting burned. Then we are headed to Space and NASA space travel and a discussion on Rocket Fuel for future missions to Mars and there is even more, so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
Breached water plant employees used the same TeamViewer password and no firewall
As Prices Surge, Bitcoin Now Reportedly Consumes More Electricity Than Argentina, Netherlands, And UAE
Google flags its iOS apps as "out of date" after two months of neglect
White House hastens to address global chip shortage
Report: NASA's only realistic path for humans on Mars is nuclear propulsion
A Windows Defender vulnerability lurked undetected for 12 years
Hackers try to contaminate Florida town's water supply through a computer breach
Barcode Scanner app on Google Play infects 10 million users with one update
SolarWinds Attack Reinforces Importance of Principle of Least Privilege
U.S. Unprepared for AI Competition with China, Commission Finds
Brave Launching Privacy-Focused Brave Search
Hackers are finding ways to hide inside Apple's walled garden
Apple changes 'subscribe' to 'follow' on Podcasts because people think subscribing means paying
Russian government websites go dark after the U.S. vowed retaliation for SolarWinds hack
Exchange servers first compromised by Chinese hackers hit with ransomware
Google must face $5B lawsuit over tracking private internet use, judge rules
Want to borrow that e-book from the library? Sorry, Amazon won't let you.
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] I've got to say the big story of the week is this breached water plant and how it really affects all of us. Not just because our water could be poisoned by a hacker, but it gives us a bit of a lesson on what we should be doing and what we did.
Hi everybody. Craig Peterson here.
There are many things that we did over this lockdown. Things we did. In fact, the lockdown itself to try and help stop not just the spread of the virus, but remember it was a two-week lockdown just so that we did not overwhelm our hospitals. Who could disagree with that, right?
We all stayed home for two weeks that make sure that we're flattening the curve, that we're not going to have a lot of. People in hospitals. Unfortunately, other people who couldn't make it into the hospitals needed it. That two-week locked down to flatten the curve has turned into what? Now, almost a year later we are still seeing these lockdowns. These lockdowns have caused havoc.
We've talked about many of them. Of course, you hear them all the time on the radio. Everything from suicides of our children. Through our parents dying in these homes and without the comfort of their family and without human touch for almost a year. It's just so, so, so sad to see.
Now I'm not going to get into the political sides of this and what should we have done? What shouldn't have we'd had done? I've got my opinions on some of this. What I want to talk about is what we did with our jobs? What did we do with our businesses? I think we did some terrible things there, too.
What I'm talking about is we need to stay home, but we have certain businesses that need to stay open. Now, frankly, every business needs to stay open. It's a business because it's fulfilling a need, right? It is so basic. It's hard to think that people don't understand this, but obviously, they don't.
We shut down businesses. Businesses that will never, ever come back. People's lives destroyed. People whose entire savings, their entire retirement plan, everything was based on the business. That's where their money was. The people working there were counting on having that money to pay the rent, to pay the electric bills and other utilities. To pay for all of the things in life that we need to pay.
It's one thing to have credit card bills that you can't pay because they're not a whole lot they can do about unsecured debt. They can certainly harass you. When it comes to things like your home or whatever it is, you're renting, whether you own it or not, how can you make those payments if you don't have money coming in. The money that the government is issued has just been a mere pittance. I get it.
In some cases, people had just incredible amounts of money compared to what they were normally making with unemployment, with the federal subsidies, et cetera. That didn't last. PPP money, this payroll protection money, lasted for about six weeks for those businesses that could get it. Those that qualified.
My business didn't qualify for PPP money. Not because it's too big, but because it's too small. Most of what happens in my business are done by my family members. I've got myself, I've got my wife, of course, you've probably seen Karen mentioned in some of my emails that go out.
I've got my eldest son involved. He loves security. He's great at it. He's been working with me now for more than 10- 15 years on this. I've got one of my daughters working with this on me. So it's primarily a family business. We've got contractors who will do different things for us. We have a lot of suppliers and we have to pay those bills, but no payroll per se. You know what? That's a lot of businesses. The number of businesses that were in the same boat as I is huge. That's how things get started in this country.
All of these companies could have started. The companies that had started had entered into lease agreements. That had started to provide services for their customers. Whether it be B2B like mine, business to business, or business to consumer they were all stifled.
What have we done to ourselves? Really? What have we done? The virus itself is obviously pretty nasty and can be lethal in a lot of cases. It has been. Now we found out that people like governor Cuomo apparently just cooked the books. Cooked the books, something awful.
We went home, we started working from home. Our businesses said, what can we do? We had people getting very, very busy trying to figure it out. There are a lot of little remote programs that you can use in one of those is Team Viewer.
Now there's nothing particularly wrong with Team Viewer. I'm not fond of the idea of things like Team Viewer, remote desktop, and others, but sometimes it is the best solution for a particular problem. Team viewer in this case was used by a small government agency. Think about what would have happened. You had to shut down, you still had to do work. What did you do as a business?
You probably got something like Team Viewer, one of these logins, remote login programs. Maybe you set up a remote desktop so people could get in remotely. Maybe you set up a VPN because that's going to solve all of your problems. Which of course it causes almost as many as it solves, but most people don't realize this.
That's the case here. We're talking about a small town, 15,000 people, called Oldsmar. I don't think it's because they're a small town. I think this problem happened because they did what most of us did. We were not ready for a shutdown.
As businesses, we weren't ready for a shutdown. In fact, the year before they did the shutdown, they had this massive pandemic planning session about eight months before. They all agreed that a shutdown was the wrong thing to do in the case of a worldwide pandemic. They also redefined pandemic. I think maybe getting the angle I'm coming from here. Right.
They decided no, we're not going to do that. They did not plan for pandemics. In fact, they didn't plan for a lockdown.
Obviously, you don't. Well, I don't know, maybe you do plan for a pandemic. If you're coming up with a virus you're going to release it, but they were not planning for a pandemic. They were not planning for the lockdown and neither were businesses. Most businesses, government agencies, and NGOs had no plans in place, even for disaster recovery or business continuity. You may or may not be aware of this, but there are different levels.
You've got basic backups and you should be doing backups because hard disks fail. One of my customers' CEO thought that hard desks never fail. She was really upset when a disc crashed that we'd been warning her about because we keep an eye on things called smart stats on the disks. We said you've got this disc it's going to fail. You probably need to fix things because you're not in a raid array. You've fallen out of that already. Things didn't just get worse.
You have a backup. You hope that Mac going to work. If you get ransomware and I got to tell you, nowadays, the answer's no. There's two sides to ransomware, but we've talked about that before. I'm not going to get into it right now.
You've got the backup mainly in case the disk fails, or you accidentally delete a whole bunch of files and you want to get them back.
The next step that you have is disaster recovery. You have a disaster like there's a massive snowstorm that caused a water main to break in the roof. All of your computer equipment is covered with water and none of it will work anymore. In a disaster recovery situation, you now take your backups and you get new machines and you load it all on, and hopefully, your backups are remote. They weren't damaged by the water. Unfortunately, most businesses, again, not thinking this through just hoping, crossing their fingers, that they're not going to be one of that 50% of businesses that is out of business because of a disaster. Actually is closer to 75%.
It depends on whose numbers you're looking at. So they're hoping. No, no, I'm going to be part of your disaster. Disaster recovery. Is just think of that, of a snowstorm and the roof collapses of a fire and the computers have burned. Can you get your business back in business?
Then there is business continuity. That's a whole other level of planning and business continuity is where you say, Hey, I need to make sure my business continues to conduct business. If you have a hundred, 200, 300 employees, You're much better off being able to let's say the computer room burns down as an example that or that roof caves in because of the snow and you've lost those computers. You're much better to be back in business in four hours or less. We've had business continuity solutions where we had equipment on site in a different part of the building. If there was a problem in one part of the building, we could failover to the other part. Now this is an awfully big building and we had fiber links between them, but they could be back in business in less than 10 minutes. It's just that quick. That is business continuity, right?
If you are a public company or you are a division of a public company by law, you cannot be out of business for more than four hours. Now, that's just public companies. By the way, those same rules are in place for doctor's offices, for hospitals, any medical personnel you have to be able to get at the patient's records within four hours.
How many of us are ready for that? Then along comes a shutdown, remote workers. We're going to get into this a little more detail. We're going to talk about these SCADA systems, supervisory control, and data acquisition. What does that mean? And why is this a problem for all of our infrastructure? How did this guy poison or at least try to a town of 15,000?
You're listening to Craig Peterson.
What happened to that town, a Florida city of about 15,000, Northwest of Tampa when hackers got into their water supply and hacked up the amount of lye by a factor of 100.
Hello everybody. Craig Peterson here.
This whole concept of having a backup versus some sort of disaster recovery plan versus business continuity is something most businesses really don't pay enough attention to. Now, we've got another problem which is really a business continuity problem. What do you do when your employees can't get into the business?
When we've set up business continuity for businesses, in the past, what we've done is I mentioned earlier this data center where we duplicated part of it in another part of this massive building. If there was a problem with something, could just be some of the core switches go down or something, we could automatically failover and continue running within 10 minutes. That's one way to do it.
But how about if the rest of the building went away? How about if your main servers okay, but the roof collapses or there's some sort of a fire? What happens if your employees can't come to work because there's a lockdown? There are so many reasons you need to have business continuity in place.
We didn't have it right. Not we, as in me, but so many people, so many companies didn't have that. That's what happened in Oldsmar, Florida. They have a water plant. Of course, they have all of the normal things any city of 15,000 people would have. They had in their water treatment plant these devices that are called SCADA devices that are used to control valves. These valves are exactly what you think of a water plant. They're used to control the mixture of various chemicals to divert water around the plant. The source of the water, the type of filter switched over to a new filter so that the older filter can be replaced. In many cases, the main filtration is just done through sand and it has to backwash every once in a while. This is all controlled by computer, nowadays.
They were running a Windows seven machine. No, I know you're saying, well, I've got Windows seven I'm okay. The problem is Windows seven is no longer supported by Microsoft unless you're paying them ungodly amounts of money. I'm talking about $50,000 a year per machine sort of money. It's just crazy amounts of money. Most companies don't have that, right? I don't know anybody outside the federal government that actually has that. There's probably some, but they will not release it to the general public.
Sometimes they'll release a few little security patches because something was just so apparent that they had overlooked. But most of the time, no. Most of the time these security patches just aren't available for older versions of Windows. So they had a Windows machine that was controlling this network with all of these valves on it.
They had that machine hooked up to something called Team Viewer. The idea behind Team Viewer is, Oh, this is really handy. I can put Team Viewer on our control machine. Then I can have my employees be at home and then use that control machine remotely over Team Viewer.
That's what Team Viewer is designed for, isn't it? Well, as it turns out, they were using Team Viewer throughout the water district. That became a bit of a problem because they did not have proper firewalls to protect it. And they were all sharing the same password.
The interesting advisory that came out about this particular problem from the Commonwealth of Massachusetts, if you can believe it. This cybersecurity advisory for public water suppliers is talking about how water suppliers can guard against cyberattacks on water supplies. It goes through a lot of these basic things that I've talked about. They should listen to my show every once in a while, right? Or attended the briefings that I had put on for the FBI's InfraGard program. It would be pretty simple for them. The state of Florida came out with some guidelines, et cetera, after the fact. As did Massachusetts.
They were running Windows seven. They were remotely accessing plant controls. The computer had no firewall installed. Well, that's what they're saying. In reality, Windows ships with a firewall installed, but that doesn't mean it's going to do any good. I talk a lot about that in some of my courses, but the computer was visible to the internet apparently. Okay.
They all shared the same password. What do you want to bet it was a bad password and employees could remotely log into city systems using this Team Viewer application. It was really that simple.
Now this actor's here apparently is more than one and they are unidentified. So we don't have a whole lot of information on it, but I did get a notice. It's called a pin, which is a notice from the FBI it's labeled green, which means I can share it with everybody. It's saying that they obtained unauthorized access to it.
Now, here's the most important part. These cyber actors likely access the system by exploiting cybersecurity weaknesses, including poor password security and outdated Windows seven operating system to compromise the software used to remotely manage water treatment.
The actor also likely uses the desktop sharing software Team Viewer to gain authorized access to the system. We've seen this, not only with Team Viewer, we have seen this with remote desktop and many other systems that people have been using to allow their workers to get in remotely. All of this because of the lockdown, people working at home. All of this should have been handled properly by having a business continuity plan in place. It's really that simple.
Now the putting the plan together, isn't that simple, frankly, but we've got to think about what happens here.
No. I also think about this particular hack and who did it. Well, it could have been the Russians, right? It could have been the Chinese or the North Koreans. We know Vietnam has gotten into the game lately. It could have been any of those guys.
But do you know who the most likely people are to do this sort of thing? It's somebody who works for the company or in this case, very likely that it's a disgruntled employee. They all shared the same password. They use Team Viewer. I said, I'm not blaming Team Viewer here, but this is not good. This is really bad. This is not just something that could happen at a water plant where they're moving the amount of lye from a hundred parts per million to 11,000 parts per million. They're using it in drinking water to change the Alkalinity, the acidity of the water.
I don't know, I don't know. We've got to do something about this. I'm going to have some training on this, what you should be doing for remote workers.
If you're interested, let me know I'm going to plan some, but I'm not going to do it until I hear from you to know it's worth my time to put it all together. Email me M E at Craig Peterson. Let me know that you'd like to know about remote workers or maybe this whole business continuity idea. Again, email me [email protected]. Let me know.
Hey, you'll find a whole lot of stuff. If you go to Craig peterson.com and it's all good information that you need. Make sure you sign up for my newsletter right there. Craig peterson.com
Hey, we can't go without talking about Bitcoin. It has surged surged surged. It may go up, it may go down. I'm not somebody who advises on investments, but we're going to talk about what it is and why people are mining it.
Hello everybody. Craig Peterson here.
Well, we have a really big thing to talk about when it comes to Bitcoin, but first I have to take a minute and honor a man who has inspired me in broadcasting for decades. A man who has changed the whole face of radio. AM radio was pretty much dead. Then he started his national show. Of course, I'm talking about Rush Limbaugh.
Whether you agree with him politically, and I think most of you guys probably do. We all have our differences, or not, he is a man that deserves great respect. He changed the face of American politics. He literally single-handedly saved AM radio. He created this whole concept of a nationally syndicated talk radio show, and it has helped to educate millions of people.
I started listening to him back in the late eighties, quite a while ago. I was just amazed with him and the way he did it. One of the things that inspired me about it is he took callers, but they weren't the guest, he was the guest. They were asking him questions. That is so topsy turvy from how, even today, most radio shows are.
People would call him up and they would ask him questions and he'd be able to answer them. He also asked them some questions, obviously, in order to figure things out, he also was not afraid to take opposing calls. He would look for those and he would put those at the top of the queue. He would take those callers that disagreed with him before he took callers that agreed with him, his ditto heads, as they like to call themselves.
When I heard this week that he had passed, I knew it was coming, but it hit me hard. It hit me really hard. He's not that much older than me. Although I remain in really good health, knock on wood here I am just flabbergasted. I don't have words for his passing. So it would not be right for me not to have mentioned a man who inspired me, who educated me, and played a role in my life, such that when he passed, I was just gobsmacked.
It's absolutely a sad, sad time. I really wish my best, obviously to his wife. I guess Catherine is his fourth wife, so I'm guessing he didn't have the best home life out there. Things obviously didn't do well on that front. I think he's a little bold and brash and maybe that's part of it.
But my memories of him being down in Cambridge, Mass. I was working as a contractor for about a year and a half at the Open Software Foundation. I was working on the operating system and that was rewriting the TCPIP stack. If you know what that is, it's the basis of the internet today and the Open Software Foundation provided its code to pretty much everybody out there. That's how I can say with a high degree of confidence, the code I wrote is still in use today to help run the internet. I was working down there as a contractor for about 18 months. I also put in the i18n, the internationalization code into many of the Unix libraries and at lunchtime. I had a small radio with me and I would go out and walk around for lunchtime and listen to Rush Limbaugh while I was out walking around. He had been quite the companion for me, gave me a lot of things to think about, disagree with him on, and agree with him on. Conversations were spurred with other people. I've come to realize, I mentioned this to my wife, as well, this week after he passed that as someone who's on radio, call us personalities or whatever you might want to call us. But as someone on the radio, this is a very personal medium. I've come to realize that Rush taught me something. I realized it when he passed, I've never met the man. I have a photograph of him signed by him around here, somewhere. He taught me something else and that is, I never met the guy, yet I felt an attachment to him that I had never felt really to anybody else.
Certainly, I've never felt that way about a movie actor that died. I've never felt that way about an author whose books I loved. I've missed some of them, some of these books where there a series of books and the author died. You could tell mid-book that the voice changed and it was being written at that point by someone else. I was just disappointed by that. I didn't feel that sense of loss that I felt this week. It helps me to realize. How important it is for me with you guys. Without you guys listening, we wouldn't have a radio station. Without you guys buying from the advertisers it couldn't afford to, pay for the electricity and all of the people that are involved. It's the listeners. Right.
I have an obligation to you to present the information that you need in a way that you can understand and hopefully in a way that you can use it, right?
What good is a show like this? If I'm giving you stuff that there's nothing you can do about it? You notice, I always try and do that, but that's the way Rush was too. Rush wouldn't just sit there and complain. Rush would talk about the facts, what's happening, where he thinks it should go, and what we should be doing. What we should be doing as a nation and what we should be doing as individuals. To me, that was very inspirational. Frankly, that's how I've patterned this show. I've had this radio show for over 20 years and I've patterned it that way, where I try and help. If you've ever sent me an email you get a personal reply from me because I am here to help. And I felt that way about Rush.
I've sent him emails. I'd never gotten responses, right? But you, I feel this attachment to these people. That's part of the beauty of these smaller radio stations, where there are people, we are local, we do care about you. These advertisers tend to be local as well. Certainly, local businesses advertise locally, and we really have an obligation to you, to every one of you. So I appreciate you. I really do. I really do want to help. I am beginning to understand some of the responsibilities that I have it isn't just to help you understand technology a little better to keep your machines clean, to stop your businesses from being stolen from, by hackers, or by Snowfall that might bring your building down.
It is to help you as best I can, as often as I can. So that's why I do it. That's why I do these courses, the newsletters, everything else. Rest in peace, Rush. We're going to miss you.
Visit online as well, Craig peterson.com, and sign up for my newsletter so I can help you a little more.
Well, we really, are going to talk about Bitcoin in this segment. So stick around. I had to talk about Rush this last time around. Bitcoin, the prices are surging. People are mining. What does that mean? And why are they using more electricity than the country of Argentina?
Craig Peterson here.
Bitcoin has been around for a while. I don't think anybody out there has not heard about Bitcoin. It is a power in and of itself. We don't know who actually came up with this whole concept. There's a concept behind Bitcoin called blockchain technology. Blockchain technology is based on the concept of ledgers. Where you have ledgers, just like a bank ledger that keeps track of every transaction. There are hundreds of thousands. Just so many ledgers in the world. In order to verify transactions, half of those ledger entries have to agree. So it's pretty basic on that level.
What is Bitcoin itself, which sits on top of this blockchain technology? Well, if you want to look at it, simply take a look at prime numbers.
Hopefully, you can name the first five prime numbers, right? What do we get? One, three, five, seven, 11. There you go those are the first five prime numbers and a prime number a number that is only divisible by itself and one, which is why one is a prime number.
We use prime numbers a lot nowadays. Most of the encryption that you're using is based on prime numbers. If you go to a secure website, you're using something called SSL, which is the secure socket layer and that's what shows up in your browser, in that URL line as a little lock, if you see that lock that you have effectively a VPN, a virtual private network between your browser and that remote site.
Guess what? You already have a VPN, right? Why use one of these VPNs that spies on you?
That is encrypted data and it's very difficult to encrypt in between. How does it do that? It's using something known as public-key technology, the RSA algorithm. We're not going to go any further down that, but basically, it allows someone to have a public key and use that public key to encrypt a message. then you, the person who's receiving the message whose private key was used to do the encryption can decrypt it using their private key. So the public key side, and the private keys side, it allows the encryption from end to end. That's what the SSL is all about.
Well, when we're talking about Bitcoin, we are talking about something that goes and uses some of the similar technology. What it's doing is using these prime numbers. That's what the RSA algorithm is using this encryption algorithm, using these very large, very complicated prime numbers because you get past 11 and let us see 12. That's not a prime, right? Uh, because it's divisible by. Two and six and three and four, and then let's see 13. Okay. That's a prime 14, no 15, no 16. No. It gets more difficult.
I remember way back when, writing a little program that just found prime numbers and it looked for prime numbers and the easiest way to do it was I would start, first of all, you take a number, divide it into. There's no reason to go any higher than that when you're trying to figure out if it's prime or not. Then I would start looking at some of the base numbers to try and figure it out. Of course, real mathematicians were able to figure out better ways to find primes.
Well, when we're talking about Bitcoin and some of these other cryptocurrencies, they are also using these very large prime numbers, just like you're being used for this public key encryption. They also have some other parameters around some of these prime numbers.
To have a Bitcoin is to have this digital number that represents a unique prime number. If you want to mine, what you're doing is you are trying to find a prime number that no one has ever found before, just to oversimplify things a little bit. You find that prime number and Tada now you have a Bitcoin. Sounds easy enough, sounds quick enough. It is not easy and it is not quick.
It's not just based on the prime number algorithm, but we're keeping this simple here. We have found millions now of these Bitcoins. I should look that up and find out exactly how many, but there are many Bitcoins. The whole algorithm, the whole system is set up to do some restrictions here, there's only a certain number of these Bitcoins that will ever be mined.
It's estimated that something like 20% of the Bitcoins that were found has been lost because the encryption was used to keep the keys. People forgot it.
You probably heard about this guy that has a quarter of a billion dollars in Bitcoin in this wallet. He only gets eight tries before it auto destructs. He hasn't found them yet. There's a quarter of a billion dollars that's unreachable, but that's what we're talking about here.
Bitcoin mining. In this day and age, Bitcoin mining is so hard and it takes so much computing power that it is using a couple of things. First of all, the thing that bothers me the most is it's using up these GPU's these graphical processing units, because GPU, which we typically use for graphics processing is set up so that we have are hundreds, thousands of processes that can be happening on that card simultaneously, various small little tiny processes that can be set up to somewhat be optimized for Bitcoin mining or mining, any of these other cryptocurrencies.
Then the people who really want to make money on mining these cryptocurrencies have machines that are special machines. They are designed specifically to mine, one type of coin, one of these crypto coins. We're talking about Bitcoin. There are machines that are designed to mine bitcoins, go to E-bay and look for Bitcoin miners. They used to have them on Amazon. I haven't checked in a while, but you'll find them in both places. At least you used to be able to, you can certainly still find the money bank. You'll find some that are old, that are used and some brand new ones.
Well, it is expensive to mine them. One of my sons and I, decided years ago to try and do a little mining. We probably should have tried harder but we gave up. It was a, who knows what's going to happen with Bitcoin.
There are so many cryptocurrencies and today there are people introducing new cryptocurrencies all of the time. I avoid those like the plague because you never know what's going to happen.
Bitcoin is definitely the 800-pound gorilla out there. We were able to mine I guess my son said he mind a couple of other little currencies they're worth a penny or two, not a very big deal.
We have now so many people in China that were doing Bitcoin mining China could not produce enough electricity to mine Bitcoins. China went around and shut down anybody that was mining Bitcoin. We have something called the Cambridge Bitcoin electricity consumption index. This is an index designed to figure out how much electricity is being used in order to mine Bitcoin.
This is, of course, over in England, the University of Cambridge the judge business school. I'm looking at a graphic right now that they have, and this is showing the electricity and Bitcoin mining. They actually have all of the data for downloading, if you ever wanted to do some serious analysis. It's showing there was hardly anything, if anything, back in 2016. Summer 2017, when it started to jump up and that's, of course, when the price of Bitcoin started to go up.
Why? Well, mainly because of ransomware. People having to pay ransomware and buy Bitcoin in order to pay that ransom.
In terawatts. Now we are showing at about, okay, this is Wednesday, February 10, 2021, 288 terawatts of electricity on that one day. Isn't that something? The amount of electricity that's being used has been surging because, of course, the price of Bitcoin has been going up. Just been going up in crazy, crazy rates. The amount of mining going on has doubled, almost doubled since October last year. We're talking about using more electricity than the entire country of Argentina, the Netherlands, and the United Arab Emirates. It is absolutely amazing, amazing how much we're using. People are alarmed by this. Countries are having major problems in trying to figure this out.
What else is funny about it? They talk about Bitcoin being one of these so-called green technologies. Well, it turns out that Bitcoin because of the electricity that it's using for people to mine now has a carbon footprint comparable to the entire country of New Zealand. It's producing about 37 megatons of carbon dioxide per year. I think that's funny, frankly, because they call it green. Right?
It's like green cars that are electric. Well, guess what? They aren't green in so many ways. They're cool as heck don't get me wrong, but don't think they're green because they're not. A lot of reasons for that. I've talked about it many times in the past, on my radio show.
If you go to my website, you can just look that up and you can find out why, and I've got hard numbers there, anything else?
All right, everybody, make sure you visit me online. We have started some new stuff. If you are a frequent reader of my, now Sunday newsletter, which has my show notes. You are getting also one or two other newsletters during the week just short pieces of training.
I'm trying to help you out, but if you're not opening that newsletter if you don't download the images. That's how I tell that you opened it, then you're not going to get all of the supplemental material, including some audio programming that you can't get anywhere else. So make sure you go to Craig peterson.com and sign up for the newsletter. Open the silly thing.
So you get all of this free training and more. Craig peterson.com.
Apple has been really busy trying to make sure we know who's using our data and what they're using it for turns out Google's not too happy about that. You'll be surprised what they did this week.
Hi everybody. Thanks for joining me.
I've talked here about how Apple is really taking some major steps up in trying to defend our privacy. Apple does not make money off of our data. They don't sell it. They don't compile it and then sell it, Google, however, is trying to be the repository of all of our information. So much for the don't be evil thing. Right?
Well, Apple's got these almost like nutritional labels. You remember when the CDC or it wasn't the CDC, it was some federal agency, I can't even remember forced food companies to put labels on the packaging, telling us about calories, fat, various other types of things. You could make a bit of an informed decision by looking at that.
Obviously, there's other stuff that I don't know what this word means. I don't know what that is. What's red dye number two, all of those types of things, but at least it brings it to your mind. You can also see how many servings there are. It'll say this muffin is 500 servings and only a calorie a piece, right.
The reality is that box is really meant to be two or three or four servings, including that Coke that you might be drinking. I am more of a Pepsi man, but I haven't drunk either in years now, frankly.
Well, Apple is trying to do kind of the same thing. They've got millions of apps up at their app store. In the app store, of course, you can not only find the apps, but you can download them. You can buy them depending on what the app is. Most of these apps that are free, are really not free right? We've talked about that before. I don't know that we need to get into a lot of detail, but it goes back to that saying of if it's free, then your, probably the product.
That's been very true. Apple and Google both have caught a lot of companies. Who's been trying to steal our information successfully in some cases. Obviously, that's a bad thing particularly when you don't know about it.
So these labels that Apple is having app developers put on their apps have got a whole bunch of people upset, Google ran full-page ads in newspapers, complaining about it and how it's going to hurt small business.
The reality is, it is going to hurt some small businesses that do advertising. That's very, very narrow. It's going to hurt me if I'm doing that type of advertising no question about it. I don't do that. But one of these days, I hope to be able to do it.
What it is doing now, is stopping companies like Facebook. Facebook has always been doing tracking, not just when you're running their app. Facebook has been getting information from other websites from web pages like mine, for instance, I've got a Facebook pixel on my website so I know if you came from Facebook, what you're interested in and in what you're doing so that I can present information to you based on your interest.
I'm doing now for the very first time, this week, a similar thing. With my newsletter. If you have, for instance, said that you're interested in my improving windows security course, the newsletter isn't going to bother you about that anymore because I have this little signature at the bottom, here are a few things that I could do for you. If you want a little extra help. Some of it's paid, some of it's free, obviously, but. I think it's annoying personally to keep getting the same message every week. I've put into my email program, some conditional stuff so that if you've asked for the improving windows security course, I'm not going to bother you about that anymore. By the way, no, the course hasn't started yet. It's a labor of love. What can I say?
There are a lot of different types of tracking that are done and not all of them are bad. For instance, I just gave you an example of something that I've started doing, and I am doing some tracking in order to do that because I don't want to annoy you. I want to give you the information you need when you need it, right? Bottom line. It's like, I've always said, if I'm interested in buying a Ford F150, then I don't mind seeing ads for it, but if I'm not interested in buying a pickup truck or a Silverado, why would I want to see a GM ad when I'm going to get a Ford, right? It's really that simple.
Google, as I mentioned, has been complaining. They've done the full-page ads. They've complained to congress critters they've spent so much money. Lobbying, it's a real problem and a difficult solution to it. If you want to get rid of lobbyists, obviously the bottom line is you have to get rid of the money going to, and coming from Washington DC. If they don't have control over our money. If they don't have control over our lives. Then the lobbyists aren't going to be going there.
I don't care which side of the aisle you are on, or if you're right in that middle of the aisle. Lobbyists do not represent our interests as a nation. That's the bottom line.
Google's down there spending money saying, Oh, you're going to hurt the small businesses. When in reality, the biggest target that's going to be hurt by Apple cracking down on people taking our information without letting us know is Google.
It's going to be a problem for Google, so how to get around it. One of the things that Apple has for its apps that are on your iPhone and on also your tablets is a tracker. When was the last time that app was updated? Of course, when the app gets updated, Apple has a look at it and tries to see if there's anything malicious going on.
Now it's impossible to catch everything. Some of the stuff is very well, obfuscated. I can't blame Apple or Google for letting some of this malware through. But the bottom line is they want to know. When did you update it? What's going on?
Google apparently flagged its own Apple apps. The apps designed for iOS.
Think about the Google apps, obviously. There's the Google app itself. There are Google maps. Apps can be very useful, including Waze. I was so upset when they bought Waze, but that goes into the anti-trust stuff that is going on right now in Congress.
But I was looking at the phone and looking at the app and they were flagged as out of date. It had been two months since Google updated iOS apps. It has been updating its apps in the Android space, but not the iOS apps. The theory is that Google has not been doing updates on its Apple apps because of this new privacy labeling that Apple's come up with.
You see back in early January, Google could have said, we haven't been updating our apps because of the lockdown. The engineers are busy trying to handle this and that. We just had the holidays and I would have accepted that you would have accepted that. Well, that was what now six weeks ago. Google has, every year around the holidays a code freeze, which means no one can make any changes, that is done with right now. The company Google should have released two new versions, particularly since they come out with the new versions for the Android operating system, Gmail, Google Maps, Google search, Chrome, drive, photos, keep and Duo have all been frozen since Apple launched these privacy requirements.
What do we think is going on? Well, it looks like frankly, Google just doesn't want us to know what data they're trying to get at. What they're doing? What they're selling? What they're tracking, the inter-app tracking.
Google's been doing as well as Facebook and many of these others. What's the easiest way to not have to worry about that don't have a new release so that you don't have to abide by the new terms from Apple, which include, Hey, what information are you gathering? How are you gathering? What are you doing with my personal information?
It looks like Google took the easy way out again. It's phenomenal. I'm looking right now at, Gmail and it has not been updated on iOS since December 1st. The Android version of Gmail has had four updates since then. That's a pretty big deal, frankly.
Apple's definitely got people's attention. The app developers' attention. I am glad they're doing it as a user. I'm not so sure. I'm glad if I decide to try and do targeted marketing through some of this online pay-per-click and some of these other ways of reaching people. But you guys, already how I feel about you and I'm going to be giving you lots of good information.
Some of you guys become my clients because your businesses and you need that little extra help for your poor overworked IT people internally.
Lots of what's going on with Google. We'll see when they do come up with the next update, but it's a real problem.
Hey, if you want to get my weekly email where I have my show notes.
Now, these show notes are what I use here on the show. That's what all of these stations pick from, my show notes. The only way you can get them and get information about what's going on in the world and things you have to do right now is by signing up for my email.
Craig peterson.com.
Boy, I love space stuff. I have for years. I was so excited to play an extremely minor role, but to get involved with the NASA space shuttle program. Let's talk a little bit about what's next up for it.
I remember that day. I can't remember what day of the week it was, but that day when we landed on the moon watching it live. It was just mind-blowing. Of course the newspaper, the first time I had ever seen a color cover on a newspaper and it was a picture of our astronauts there on the moon. It was just so incredible.
Of course, you're listening to Craig Peterson.
NASA has been trying to get back to the moon for a long time. We haven't been funding them. Priorities have changed. A lot of people say why don't we spend the money domestically rather than on the space program?
The space program has provided us all kinds of benefits over the years. It's benefited mankind, not just by giving us things like Tang, for instance. It's given us all kinds of technology and science that we would never have had any other way. I'm looking right now at a report that was put together by AIESEC, which is the international space exploration, coordination group. It just a top-level executive summary. Numerous cases of societal benefits, new knowledge and technology from space exploration, things like solar panels came from the space program, implantable heart monitors. Cancer therapy, lightweight materials, water purification systems, improved computing systems, global search and rescue systems, course rockets as well. There's so much more, things we just weren't expecting. Thin materials, power generation, energy storage, recycling, and waste management, advanced robotics, health and medicine, transportation, engineering, computing, and software. Not just the $800 hammers. Okay.
Culture and inspiration. As you can tell I find this very, very inspiring. We've got all kinds of things that we are using just day-to-day that we don't even think about it. As space scientists, engineers overcome obstacles, in some cases, we never even realized were there and I think that's another phenomenal thing.
Well, right now, what we're doing is having private organizations competing to send our missions up. For many years now, since the space shuttle program was ended and it lasted far longer than they expected it to. But now that the space shuttle program has been over.
We've mostly been using Russian rockets to get our astronauts into space and also to get things to things like the international space station. What are we going to end up doing in the future?
We already know who was it, Bob and somebody, right? A couple of astronauts. They went up on the Elon Musk rocket and docked with the space station.
It was again, one of the most amazing things ever. I sat there glued watching it on the computer. It was just, wow. To see that.
We're looking at going to Mars. Now, we're looking at exploring some of Mars's moons more than we have in the past, doing all kinds of things that are just going to make a huge, huge difference to humanity.
It's been quite a while since that Apollo program of 50 years ago took humans to the moon and they were using chemical propulsion. What that means that you had rocket engines burn liquid oxygen and hydrogen in a combustion chamber. Nowadays we're playing around with hydrogen peroxide in order to get that oxygen.
They use to have their advantages and that gives NASA the ability to start and stop an engine really quickly. Back in the sixties, this was the most mature technology for space travel. We'd been using rockets. They were really piloted in world war two. It made a lot of sense back then.
However, now we've got some other problems we've gone to prepare for. We're going to be sending four or more astronauts to Mars. We want to colonize Mars, but relying on chemical propulsion to get beyond the moon, bottom line, it just won't cut it. The main reason is the amount of rocket fuel. Most of that rocket fuel is going to be consumed getting out of the atmosphere.
It's crazy how much we're talking about $2 billion for a flight of one of these huge rockets. These block one B configurations, NASA's SLS or space launch system rocket, is going to be able to carry 105 tons to lower earth orbit. That's a lot of money. They're not going to be able to get that many of them up there. That only takes it to lower earth orbit.
Now, of course, the idea is to do what in fact, the Apollo mission had looked at, which is get the fuel up to orbit and then have a rocket up there that maybe is assembled an orbit and is refueled in orbit. Then it goes to the moon. That was actually the plan NASA was originally going to pursue.
We're looking at that now when we're talking about going to Mars while we're talking about going even further out there. What can we do? Just for the fuel, by the way, $20 billion just to get the fuel up. That's just absolutely crazy.
There were some tests that were done, some studies that were done on behalf of NASA for a mission to Mars in 2039. So this one's quite a ways out. Of course, Elon Musk wants to do it even sooner. He is relying on these chemical rockets. By the way, to get back home from Mars, he's relying on being able to make rocket fuel right there on the surface of Mars and then charge up the rocket engines in the launch vehicle and then launch back up to get back to earth.
It's going to be really, really interesting to see what we end up doing. They are looking at a nuclear propulsion system. It's going to be interesting. NASA has had a budget for this. They got $110 million for nuclear, thermal propulsion development. We know a lot about nuclear fuel nuclear propulsion. We'll see what happens.
This starship concept that space X is building to send humans to Mars using chemical propellant. They're countering the costs involved with the chemical propellant by having this low-cost reusable launch system. We just saw one blow up here a few weeks ago, but that's okay there was no intention of having astronauts sitting on that candle. That was just a test system. We've seen him repeatedly now land successfully.
All of those boosters and it's amazing what's been happening now. They're not the only ones. We've got a number of other companies that are working on these types of systems. Space X, ultimately we're talking about pushing the boundaries of reuse and heavy-lift rockets to extreme limits which is exactly what space X is trying to do. They're looking for some other answers.
Hey, make sure you sign up Craig peterson.com. I want you to make sure you have all of the latest materials.
Craig peterson.com.
We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up killing people. Yeah. Yeah. Death by a police officer. Here we go.
If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information that I have available my podcasts, and a few articles that we've written, and you'll also have the opportunity to subscribe to my newsletter.
I just want to get the message out is my bottom line.
We have these home cameras that we have welcomed into our homes. And one of the ones that have been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.
And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.
There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them live Real-time access to all of the ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.
And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring doorbell cameras
Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because why does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate, the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.
And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened on a number of occasions and far more than we like to talk about is that there are.
The bad guys or people who don't like their neighbors and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting a prank led police to shoot dead, a 28-year-old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.
After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth. You can have.
Teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. And apparently, they believe the report was an act of swatting where.
Somebody makes a false report to a police department that causes the police to respond with a SWAT team. Now the audio of these emergency calls been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.
The color also said he had a handgun that had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.
When Mr. Finch came to the door, they said one round was released by the officers after the 28-year-old failed to comply with verbal orders to keep his hands up. Why would he, what did he do wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.
And they said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them dead or Injured nor taken hostage. His family told local media, he was not involved in online gaming.
Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that those hackers are out there who do this swatting maneuver on somebody. And then they have the hacked ring camera at that house and they watch the SWAT team respond. Can you believe that?
And the FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices. How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that his.
His revenue, his pay from the work he was doing, delivering food to people's homes were stolen by a hacker because he was using the same email address. Yes. To log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells that have allowed hackers to steal pet network passwords, et cetera.
In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, causes death, many examples of that, and we're still reusing passwords. Give me a break.
We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.
But anyway our businesses and government got broken that's what we're going to talk about right now.
Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly, since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.
Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.
And in fact, That's a big problem still, but we'll talk about this right now. SolarWinds is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWinds. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.
We dropped SolarWinds as a vendor, and the reason we dropped them and we made it very clear to them as we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWinds a couple of years ago, and they wouldn't do anything about it.
So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWinds. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.
Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presumed now to being the hand of a Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.
He said SolarWinds, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it easy target interviews with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWinds websites stopped offering the client the compromised programs.
Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached too, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.
This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because, I didn't tell you guys this, but I do love the fact that I was right again.
How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce Schneider.
You've probably seen him before. He is also, I think he writes for the Washington Post. But remember when this came out the word about the SolarWinds hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.
Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.
In other words, going out after other countries in the cybersecurity realm. And we benefit from the lack of norms that are in cybersecurity. But here's what I really liked that Bruce said and I agree with it entirely. I'm glad, he must listen to the show. The fundamental problem is one of economic incentives.
The market rewards, quick development of products. It rewards new features. It rewards spying on customers, end-users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram, or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.
It doesn't reward reliability past a bare minimum, and it does not reward resilience at all. And this is what happened with SolarWinds. SolarWinds ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.
It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure it. It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.
I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely inexcusable, right? Inexcusable. So this is happening with SolarWinds right now, but it's going to be happening with other places out there.
We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWinds is a Puerto Rican-born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.
The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from the tech beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the US treasury department was hacked the US Department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cybersecurity, and infrastructure agency CISA, the department of Homeland security, the US department of state, the department of justice, the national nuclear security administration, the US department of energy, three US state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others.
I use two of those.We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem.
How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody to use a password manager and I will have a course on that this year.
Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.
The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an IT security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.
Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have email coming in and going out SMTP Imap.
They should be controlled and controlled pretty tightly. According to the department of justice, apparently, their email accounts were compromised about 4,000-ish people's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.
It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.
Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email [email protected] and let me know, be glad to send you stuff.
ME@Craig peterson.com.
Take care guys.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Good morning, everybody.
I was on this morning on WTAG with Jim Polito. We discussed the new Amazon, ebooks, libraries, digital rights management and what some States are demanding from Amazon. Here we go with Jim.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] In Rhode Island have bills as well as New York that would require Amazon, as well as everybody else, to sell eBooks to libraries with quote reasonable terms endquote.
Jim Polito: [00:00:13] Okay.
Craig Peterson: [00:00:14] Hey everybody, Craig Peterson here. Just got off the phone with Mr. Jim Polito and we had some fun talking about libraries, Jeff Bezos and even George Orwell, got into the act here. Anyhow, here we go with Mr. Jim Polito.
Jim Polito: [00:00:34] Hey, Amazon started off as a place to sell books. You know, online books and they basically destroyed the bookstore. I mean, we contributed to it. But now it seems that they're out to destroy libraries. Taking over the world, isn't enough for these folks.
I don't know, that's the accusation. Well, let's see if we can confirm it. Let's bring in our good friend and tech talk guru of Craig peterson.com. The man that website is named after, Craig Peterson.
Good morning, Craig.
Craig Peterson: [00:01:13] Good morning, Jim.
Jim Polito: [00:01:14] Oh, so here's the deal? We were just talking a little while ago about Jeff Bezos, started with his garage selling books out of there. Then mail order, then all of a sudden they sold everything.
They basically changed retail. They made what we told online shopping would be like 25 years ago. People said, Oh no, you're going to be buying everything online. We said, sure we will. But we are, COVID helped that.
Now there's talk that he's gonna close libraries and I went wait a minute. Is this a wild accusation?
Craig Peterson: [00:01:48] Well, it is kind of wild, and certainly an accusation. Unfortunately it's also true. If you look at the libraries work over the years, Jim, you go in and you borrow a book. Well, where did that book come from, right? The library bought it. Libraries for a long time, have been paying more for a book than you would. You might go into the bookstore and you pay 20 bucks for the book, but the library is going to pay a lot more for that same book. 50, even a hundred dollars sometimes.
So Jeff Bezos is doing right now. Is okay great. You've been paying for these books over price sometimes as much as a hundred dollars for one ebook and it can only be lent so many times, that ebook can. If you want to have five copies of that book out for people to read, you have to buy five licenses, that's what it's been.
Jim Polito: [00:02:44] All right. So wait a minute. Let me just make sure, because make sure I understand this. So in the old days before we had, you know, you bought a book online and you read it on your nook or whatever.
Hold on a second. So if I was buying a book for a library. I paid a higher rate because the library knew you were going to be loaning that book out, yada, yada, yada. Almost like the publisher said, Hey, we want a little bit more than the average person for this book. Is that true?
Craig Peterson: [00:03:14] Absolutely.
Jim Polito: [00:03:15] Okay. All right. So now I get this, you have intellectual property. You have a book that is virtual. I mean it's online. If you are a library and you want to let people be able to read that, download it and read it. You're going to have to pay a pretty penny to Jeff Bezos?
Craig Peterson: [00:03:38] Yeah. If he will sell it to you. See that's the change that's happened more recently? Jeff Bezos has decided, well, Amazon, right? I'm not sure it was him personally, but they decided that it will not sell, at any price, downloadable versions of it's more than 10,000 eBooks it publishes.
Think about an acquisition that Amazon made a few years ago, I have been an Audible subscriber for many, many years. Of course, Audible is the company that sells audio versions of books. Amazon bought Audible. Amazon has said, okay, you used to be able to go and borrow tapes at the library, and you'd listen as you're driving or whatever. You kept up on the latest business book or history or whatever he wanted.
So Bezos also owns Audible , which is number one for audio books. They say, Hey, listen, not only, are, we not going to sell any of our eBooks to libraries, but we're not going to let them get any audio books either.
Jim Polito: [00:04:43] Wow. Now that is pretty bad. Look from a business perspective, I understand. You're selling a product that now, why would someone buy it, if they could just join the library and download the book.
There's gotta be somewhere in between. So libraries will be destroyed. I mean, libraries are great places for research and other things and talented librarians can help you out quite a bit. A talented librarian sometimes is a lot better than what Google will tell you. When you go into a search about a certain topic. Librarians are much better, and don't, usually have an agenda, like Google. You should buy this while you're researching that, you know what I mean?
This could completely destroy libraries.
Craig Peterson: [00:05:35] Of course, we're on in Rhode Island and right now. Lawmakers in Rhode Island have bills, as well as New York, that would require Amazon as well as everybody else to sell eBooks to libraries with reasonable terms and quotes.
So we'll see, we'll see what happens, Maryland's already passed a law like that, but this is a real problem as you go forward.
Now, remember, Amazon is the one you mentioned, the Kindle, or actually you mentioned the Nook
Jim Polito: [00:06:06] That'sBarnes and noble, isn't it? Yeah.
Craig Peterson: [00:06:08] Yeah, it is whoever they are. Yeah.
Jim Polito: [00:06:12] Wait a minute. Hold on. Barnes and Nobles is on the phone.
Danny DME. Don't take that call. Yeah.
Craig Peterson: [00:06:21] Yeah. So whoever they are. Amazon has the number one ebook reader. Now, for those that have never done this, and ebook reader allows you to keep hundreds of books right there in this little almost like a display. They're fantastic. That's how I read 99% of my books.
So they've got the number one ebook reader out there. And because of that, they kind of control the whole thing.
But if you bought George Orwell's 1984, you might remember this was a few years back, Amazon decided you couldn't have that book anymore and removed it from everybody's ebook reader. All of the Kindles, they remove copies of 1984.
Jim Polito: [00:07:05] What is the reasoning behind this, because I thought that 1984 was no longer under copyright, but I could be wrong.
Craig Peterson: [00:07:10] Yeah, it is. The copyright holders told Amazon. That they didn't like the terms Amazon was putting the books under. So Amazon pulled them all back.
That's another problem with eBooks, especially with digital rights management, they can take them away, that copy that you have in those Dr. Seuss books could disappear from your Kindle, because you don't own it.
You see, if you buy a book and you read the book and you want to have a yard sale and sell the book for a buck or whatever it is, you can, because you own that book.
If you get a book from Amazon on your Kindle, or any of these other places, you don't own that, in almost every case. You're just getting a right to read it and. They can pull it back.
Jim Polito: [00:08:02] You know, it's interesting. My, my neighbor across the street, when he retired Dominic, Dominic, and his wife, Lucy, she's a school teacher. She's still working. He built one of those beautiful boxes that looks like a really big bird house with a glass door and it's for the neighborhood, put a book in, take a book, whatever. He can do that because people own the books. You own it.
Craig Peterson: [00:08:25] Right.
Jim Polito: [00:08:26] Good. Hey, whatever happened while we're on this topic with Apple and Apple music, when I downloaded a song for 99 cents and I thought I owned that song, I technically, did they change this? I technically didn't own it.
Craig Peterson: [00:08:45] Yeah, you never have actually. That's the way they're doing it, nowadays. Apple said, Hey, listen, we're going to do this. And Amazon did too. It's going to be much cheaper for them to distribute it. But again, think back, you and I both remember albums, records, the black vinyl, you know, or that, of course the acetate and other things and we switched over to CDs. The compact disk. People don't know, those are thesedays either. Right? It was much, much cheaper for the record industry to produce a CD than it was to produce a record. Their costs went from a couple of bucks down to just a dime, but they charged more for the CD.
What Amazon did. Yeah. More margin. Is, they said, Hey, listen guys, your distribution costs are going to be nil because all you're doing is copying digital books around. You're not going to have to have a warehouse. You're not going to have to ship these. You're not going to have trucks or anything else. We expect you to sell them for less. And the Amazon using its market power strong armed these publishing houses to lower their prices.
Now the publishing houses are really pushing back and saying, no, you can'ttell me I can only sell it for $10 and make $9.99 cents. Whereas before I was only making $2, now I want more money and it's a shame, but that's, what always happens.
Jim Polito: [00:10:11] And then your Don Quixote and you're going after windmills. Because you're going up against Amazon.
This is one of the dangers of a big success, like Amazon. You know, what's sad is in the whole thing. 1984, isn't it ironic that George Orwell's book about big brother and this and that you can't get it on Amazon.
When in fact the people who are using Amazon should know a little something about big brother, and it would be a good book for people to read right now.
Craig Peterson: [00:10:46] You can get it.
Yeah, it was just temporary. You can get it. You can get it.
All right. Good. I'm glad his descendants have, and they've worked at it. Craig fascinating is usual with you.
Folks. We always podcast segments. Which you can get on the station website, go to the Jim Polito show. On that page, you'll see Jim's podcasts on the right hand side. Just click there and this will be podcasted.
Craig, if folks want to get more information from you, how do they do it?
Well, just go online to Craig peterson.com and I also have my iHeart podcasts and tolisten to those things, just go to Craig peterson.com/iheart. That'll take you to the right spot.
I was listening, in France, iHeart, so I can pick up my safe space.
Jim Polito: [00:11:37] Nice. Craig as usual. Thank you. You always bring great stuff to the table. We'll talk with you next week.
Craig Peterson: [00:11:43] Take care, Jim. Bye-bye.
If you're in the healthcare industry, I am speaking for the big Massachusetts association this Friday. I am conducting a webinar for them on, of course, cybersecurity, particularly in the healthcare industry. If you are a member of an organization of some sort, and you'd like to have me on and do a webinar for you guys to let me know, I do make some time available for that and I may be able to help you out.
Just email me M [email protected]. I know of few of you guys are going to be there on Friday at 10:00 AM. I think it is as we go over healthcare industry stuff. Then I'm also going to be doing a few more webinars afterwards, delving into some of these topics a little bit deeper.
All right, everybody take care.
We'll be back tomorrow.
Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Craig Peterson here. This morning I was on with Chris Ryan on NH Today. I jumped right into a conversation in regards to the irresponsible way that the States and Federal Government have been going about creating websites to schedule and distribute the Covid-19 vaccines. Here we go with Chris.
These and more tech tips, news, and updates visit.
- CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Instead of going out to the private sector and say, you know what, booking an appointment for a vaccine. That's a lot like booking an appointment or a ticket to go see a concert. Why don't we just use something that already exists. There's dozens of them, like Cvent and just modify that slightly. Have that company modify it.
Well, you're familiar with the debacle that was and is. It's still there. It's just crazy. The problems with healthcare.gov. We got the Feds now rolling out their own websites. We've got States rolling out their own websites.. What can we expect from that? That's exactly what we talked about this morning, Chris Ryan and I on NH Today.
Chris Ryan: [00:00:45] Craig Peterson joins us on the show, now from tech talk that you hear on news radio 610 and 96.7 Saturdays at 11:30 AM. Craig, how are you?
Craig Peterson: [00:00:54] Hey, good morning, doing pretty well. You mentioned power, we lost it a couple of times over the last two days. Its no fun with all this wind.
Chris Ryan: [00:01:03] Indeed.
I could go into my pitch for the automatic standby generator from Generac, which you should get one of those. I'll refrain from going all in on it.
Justin McIssac: [00:01:11] Nicely done.
Chris Ryan: [00:01:12] But we do, we do recommend that, particularly in this given environment.
I want to ask you about the prevalence of scams and the prevalence of identity thefts and things of that nature. How much of that has to do with our usage of phones and hackings and things of that nature? We heard last week, from the States aspect of securities, regulation and protection. We've talked a lot about this outside of just your appearances. Has there been a sizeable uptick as in regards to that area?
Craig Peterson: [00:01:48] Yeah, there has been. What's interesting too, is it's been both directions. We've seen a huge uptick in finding some of these problems. Some of them have existed now for many months, maybe as much as a year or more. We only recently found out about, and this includes hacks from the Chinese and from the Russians, and of course that's nothing new, but the depth of these attacks has been brand new.
It's just astounding how they have really come after every last one of us, particularly businesses. They've been very, very targeted. Government agencies have been hit hard. DOD, Department Of Defense contractors have been hit hard.
You mentioned things like our smartphones that we're using all of the time now. Those are also starting to get hit. We've seen some responses. Samsung has said, Hey, we are going to support our phones now with security updates for three years or more.
It looked like maybe we did something in return because these Russian government websites all went offline after we vowed, President Biden said, we're going to retaliate for some of these attacks.
Chris Ryan: [00:03:08] That's really interesting. Whenever these things take place, whether there's an outage of a particular server or a website goes down, one of the first things that comes into my mind. Is this a glitch? Is this a problem? Is this an upgrade? Or they hit their their capacity. Or is this something a little more nefarious? Generally, is it just when a website goes down or a server is having some problems. Is it generally not nefarious or a lot of times is it well
Craig Peterson: [00:03:36] It's a little bit of both.
A lot of times it is. I've got to say that more recently, over the last year or so, we've been seeing something that we'd never seen in the Internet. That is that the internet was designed to be able to withstand atomic blast. It was very, very decentralized. The decentralized internet tended to be a very stable internet.
What's been happening more recently is that there have been acquisitions going on. We've got more and more the internet concentrated in individual hands. Look at how Amazon is running about 60% of the internet traffic, nowadays. Some of it, it's generating, et cetera.
We have seen, frankly, companies and Amazon is not one of them, but companies who are less and less able to understand what the consequences of their actions are. They're making changes to the internet and the networks.
These big outages we've seen over the last year, almost all of them were due to, let's just call it incompetence on the part of small companies that have been buying large parts of control of the internet. That's going to be continuing for quite a while.
So, it's not necessarily nefarious when something goes down. In fact recently, it's been a lot less nefarious than it used to be. It's just the normal course of things. More and more power concentrated in fewer and fewer companies that have less and less ability to do what they shouldn't be doing.
Chris Ryan: [00:05:13] The Washington Post had a really good article this weekend about the rollout of the new vaccine website and the federal website. Intalking with Kathleen Sebelius, who was the Health and Human Services secretary during the Obamacare and healthcare.gov roll-out, which of course was a disaster.
This website rollout is obviously significant. Every aspect of this is significant because Biden has called his shot. He has said, this is when things are going to take place. He has set a date. He has given that date. And, some may view it as being ambitious. Some may say we're already on that glide path, anyway.
The aspect of pushing forward, a website of this nature, how do things go wrong? How could they go wrong? Particularly in light of what happened with healthcare.gov, which was delayed for weeks, as a result of various glitches, despite spending millions and millions and millions of dollars on it.
Craig Peterson: [00:06:11] Yeah, my, I predicted that correctly, by the way. I had said it will take the about three years to get healthcare.gov to be working properly and that's exactly what it took.
We had massive outages. The problem I see here with this Federal Government roll out, this new website that was announced. Americans, all being eligible for the vaccine by May first. It's all part of a strategy that has been around a while.
The problem is that somehow businesses think that we're different. My business is entirely different from your business. Yet all businesses are 96-98% exactly the same. We have the same problems. The same concerns. Governments doing the same thing instead of going out to the private sector and saying, you know what? Booking an appointment for a vaccine that's a lot like booking an appointment for a ticket to go see a concert. Why don't we just use something that already exists. There's dozens of them, like Cvent. Just modify that slightly, have that company modify it. No, instead of that, we've got all of these people working for these government agencies, spending tens of millions of dollars of taxpayers' money to roll out something that is going to have major problems. We've seen that again and again, it's to me, Chris, just ridiculous what we're doing.
We could have this thing rolled out in a week from start to finish and have it cost of maybe a couple of hundred grand total with all the modifications and have it working day one.
Chris Ryan: [00:07:51] Yep. I mean this is the same thing that happened with healthcare.gov. If you had gone to, and that was in my view, a simpler website than this one is, you got to connect people with the location, the availability and all that the healthcare.gov in my view was a little bit easier. There was, not as much of a time constraint and there were best practices about those types of websites that already existed and could have been done at a fraction of the cost.
It'll be fascinating to see how much this vaccine website plus, I mean the state of New Hampshire just rolled out their own website on this. Now you have duplicity as well, where you can go to your state website, you go to the federal website. Could you go to both and shop for a better date? Are they both drawing from the same, you would assume from the same locations, right?
You go to the federal website, you go to the state website, you're going to get your vaccine still at the same spot, I assume. We've spent money, federal money on a state website, and now we're going to spend federal money on a federal website where they're both going to be doing the same thing.
Craig Peterson: [00:08:53] Yeah. Yeah, this is a problem and frankly, the biggest problem they've got is the back end integration. I inferred from what you were saying, which is how do we tie it in with the local Rite Aid store? All of these different tie-ins that have to occur. It gets very, very, very complicated.
Frankly, this is simpler than what they did with healthcare.gov, which had a lot more tie-ins to insurance companies in the backend. Leave it to the feds if you want something to get really messed up
Chris Ryan: [00:09:23] As always, I appreciate you joining us here on New Hampshire today.
Craig Peterson: [00:09:27] Take care.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
It is now up to 100s of thousands of organizations that have been affected by this Microsoft Exchange Server Vulnerability and it was so large that you could drive a freight train through it. Oh yes -- Microsoft did issue a patch but that did not fix the problem which was the backdoor that the bad guys installed. Nation-states, especially China and Russia have been spying on us an it will take a lot of research to determine what information they were able to get their hands on and what damage they can do with that information. We have deep fakes in the news again and there is more so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
Tens of thousands of US organizations hit in ongoing Microsoft Exchange hack
Samsung just out-Googled the Pixel at guaranteeing Android updates
Google's Getting Rid of Third-Party Cookies, But Their Replacement Is a Terrible Idea
Google claims it will stop tracking individual users for ads
Tesla asks fans to lobby the government on its behalf
Make Deepfake Videos of Your Ancestors, But Consider Your Data Privacy When Making MyHeritage 'Deepfakes'
China's and Russia's spying sprees will take years to Unpack
A new type of supply-chain attack with serious consequences is flourishing
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] If you've been listening to me for a while, you may not believe this, but I've got a recommendation here on Android phones. Coming up we're going to talk about Google's new replacement for cookies, and a little bit about what Teslas' been up to. I don't like this.
I have never been a fan of Android phones, and you know why I haven't been a fan? The biggest problem with Android phones is the lack of security updates. That really does concern me a lot. Google also has not been the best when it comes to the Playstore and making sure that everything on the store is actually safe.
Here is some very promising news for people who like the Android platform or maybe dislike the Apple platform for one reason or another. Frankly, there's a lot of reasons there too.
Samsung has always been the leader when it comes to keeping their number one phones updated in the past. I've always said, make sure you can get updates. Samsung with its Galaxy phones has been good for about two years. They provide you with the security updates you need with some patches.
Even if Google comes out with a patch, most of the phones out there that are running Android, do not get the updates. Ever.
Some of these phones are older, they don't bother supporting them. Some manufacturers drop support within months after you buy the phone.
Samsung has been good for about two years. So my rule of thumb has always been, if you're going to buy Android, if you gotta do it. Stick with Samsung and stick with their number one model.
It is now promising four years of security updates for more than 130 Galaxy phones. That's pretty big when you consider that frankly, Android phones have been the butt of many a joke over the years.
Samsung is working pretty hard to make sure that they are really able to deliver for the Galaxy owners. Now, this is cool because Samsung just early, I think, this year it was that the Samsung promise that most new Galaxy phones would be getting about three generations of Android version updates. Now, that amounts to a few years, as a rule, the generations in the Android world are pretty much about a year.
Google has been providing updates for its own phone that it has. They provided to these other companies, like Samsung, to then take it and modify it to fit what they want and then they provide it to you. So, three generations are good. Now, they have said four years of security updates. Now, that's a pretty impressive promise. What they're trying to do is compete with Apple that has historically provided about five years of support. There's a big difference, obviously between two years and five years, but there isn't as much of a difference between four years' worth of security updates, and the five, six, seven years that Apple has been doing depending on what kind of security updates. That's very impressive.
Of course, Samsung just a year ago wasn't guaranteeing anything in terms of updates. Most new phone purchases were good for a year or two of updates, but only the Pixel, which is made by Google and Android. One base phones were on the record about how long you could be getting updates from the manufacturer.
Now Samsung is doing one better than Google. Remember, Google is the guy that actually provides the Android operating system. Google's only guaranteed three years of version and security updates for Pixel phones and that's not very many phones.
Frankly, Google Pixel is not been selling well. It's the standard that all of the Android manufacturers use in order to have a kind of proof of concept. So this is what it should look like. This just should be how it acts.
I'm looking at this list here. This thing is huge of all of these phones from Samsung that is going to be supported, here.
You've got the Galaxy foldable devices. The whole family of folds. The Galaxy S series and starts at the S 10 plus moving on to the S 20, S 25 G, S 20 plus blah, blah, blah. A bunch of different S 20 models and the S 21. That's pretty darn good. That's a lot of phones. Also, the Galaxy Note series, starting at the Note 10, all the way up to the current Note, 20 ultra-five GS the Galaxy AA series. Again, certainly, the 10 going up to eight 45, the Galaxy AMS, the up through the Galaxy X covers series and again tab series, which has been pretty popular for a lot of people.
If you're thinking about picking up one of your Android phones here soon, maybe you should give a second thought to the Galaxy. Now, they're guaranteeing that they're going to provide these security updates for you for four years. Yeah. Yeah. Okay, a guarantee we'll see how long that lasts. The other problem is how quickly are they going to get it out?
You'll see Apple devices, who just this week they had a security patch, they pushed it out and they expect to see 70, 80% of all of the phones with that security patch installed within a week. That's your Apple iPhones.
Google comes out with a security patch. They push it out. It has to go to the vendors like Samsung and then the vendor like Samsung has to take that add the device drivers that need for all of these models. Think about that for a minute. That's a lot of device drivers. That's a lot of different models. I think it's going to take them a while to do that and then they'll get it to you.
That security update that comes from Google, we've seen takes six months in the past before it gets on to your phone. If you're looking at. Security, if that's a real concern of yours and sure should be particularly after this disaster of a company called Microsoft and their windows products. Particularly now this Microsoft exchange server bug.
I'm so upset with Microsoft, but you know what? We'll get into that a little bit later.
The Samsung, the galaxies, the Google Androids are not designed for all of the safety and security that you really do need, frankly. When you think about the models were talking about 130 models that Samsung is going to be providing new updates for. Okay.
When we look at Apple and the iPhone models let me see how many iPhone models are there out there. I'm going to Google that right now, even as we're talking. So 2007, that is when they first came up with them. Okay. So since the very first iPhone, according to the pho iPhone Wiki, there have been 29 models of the iPhone. 29. Two nine. How many did I say Samsung is going to be updating? 130. So who has an easier time of providing updates, security, updates, testing the updates, pushing the updates, having people install the updates, the company that in the last, how many years has been making iPhones yet since 2007? Okay. So all the way up to 2021, that's a lot of years. Versus the Android who has been making these Galaxy's for many years, but is only going to be providing updates back to the Galaxy S 10 from 2019. That covers the 130 models. Are you getting what I'm selling here? Are you buying it? Yeah, it's impossible. Really? For Samsung, even with all that, they're trying to do here. They're trying to help out. It's impossible for them to keep up with security-based unless they have this massive team. I don't expect that they do have a massive team that's going to be working in parallel. 130 teams, one for each phone. That just isn't happening.
So again, if security is a concern, Android is not the way to go.
If, for some reason you morally, ethically, religiously cannot use an iPhone and then have a solid look at Samsung because of this promise they came up with, here in the last two weeks, of four years of security updates for more than 130 phones.
Finally, there is an Android phone that will have security updates at some point in time, versus what we've had over the years of really, you can only count on it for one or two years. It's just not worth it. Not a good thing.
Hey, I am sending out on my newsletter, not just my show Notes, but I have also been sending out one or two other emails a week that have some very narrow training. What I've been doing is making audiograms for you guys. This is a video that is of me speaking, explaining something. On that video, you can see all of the words you can read along, which is great for people who are hearing impaired, or maybe you want to have that computer muted for whatever reason. It makes it easy.
You can find me on YouTube, just go to Craig peterson.com/youtube, and you can catch those audiograms.
You can also get them. If you are an active subscriber to my newsletter, active means you open it. You read it. I know you do. If I don't consider you active you just don't get this extra information. So, make sure you open those emails.
A lot of us have been complaining about cookies and tracking for a long time. Google has finally heard us? I'm not sure about this. We're going to talk about third-party cookies, right now.
Hi, everybody. Thanks for joining me, Craig Peterson here.
Well, third-party cookies are where you go to a website, and that web browser kind of squeals on you, shall we say.
What happens is Google, for instance, is trying to track you as you go online. As you go between websites. They're calling this kind of an advertising surveillance industry on the web.
Frankly, this third-party cookie has really been an important part of this whole surveillance industry. What it does now is it allows a website to have a look at where you have been online. When I say it allows a website, it's really Google, that's doing the tracking. Obviously, you're going to a website, Google doesn't own every website out there. In fact, it barely owns any, when you look at the number of websites that are out on the internet.
So Google has this whole concept of if you're visiting this site and you have visited this site and this other site, I know something about you. So it sells that information because it's seeing the pattern, right? That's the whole idea behind the advertising.
Phasing out these tracking cookies and these other persistent third-party identifiers have been something people have been trying to get rid of for a very long time. The Electronic Frontier Foundation you'll find them [email protected] has been jumping up and down trying to get everybody to pull up their socks if you will.
One of the first players to really jump into this was Apple. Apple has pretty much told the whole industry, you got to stop doing some of this tracking. Some of the tracking is okay.
Again, how many times have I said, if I'm looking for a Ford F-150 then I don't mind seeing ads for the Ford F-150. Why would I want to see ads for a motor scooter when I'm looking for a pickup truck. Frankly, if I'm looking for an F-150, I expect to see ads maybe for a Chevy Silverado or a Dodge truck, does that make sense to you? I'm looking for something and that's when I'm interested in seeing it.
Google is now jumping on this bandwagon because Apple has said we are going to be doing a couple of things. We are going to be forcing you, app developers, to tell everybody exactly what you are doing with their information, what you're tracking, who you're selling it to, what it's being used for. That's a very big deal.
It's got the whole advertising industry very worried. Google is coming along saying, okay, Apple will do you a little bit of one better. Of course, the biggest complaint from Facebook who ironically has been buying newspaper ads, if you can believe that. Google has been destroying the newspaper industry and now it's going to newspapers to try and get people to stop Apple from destroying Facebook's industry by blocking some of the advertising tracking that Facebook has been doing.
Now, what Google is doing is looking to replace these third-party cookies. How were they going to do that?
They are already doing a few rather sneaky things. For instance, they fingerprint your browser. Your browser has a fingerprint because you have certain extensions on your browser that you've added. You have your computer, which has an operating system that has a certain version. It has a certain amount of memory. It has a certain amount of disc storage. A lot of the private information, personal information about your computer can be gleaned by a website.
One of the things they've been doing this, you're blocking cookies. No problem. I can still figure out who you are and they don't necessarily know exactly who you are, but they have a very good idea.
One of the proposals Google has come out with is called the federated learning of cohorts, which is very ambitious and could be the replacement, if you will, for these third-party cookies that could be the most harmful. What it is is a way to make your browser do the profiling. Itself.
Historically they've been able to track your browser as you go around and then they have to pull all of that information together. They pull it together and they come up with a picture of you and who you are. Yeah. You're interested in buying a pickup truck, particularly an F150. This is an example.
That picture gets detailed about you, but it's something that the advertisers have to put together. What this flock or federated learning of cohorts is doing is it's boiling down your recent browsing activity into a category. They're calling this a behavioral label, and then they're sharing it with websites and advertisers.
The idea is basically your web browser itself is going to put you in one or more buckets and the websites that you're visiting and the advertisers that are advertising on those websites will be able to get that label that your browser has put on you. Yeah, you like that?
So what EFF is saying is that this could exacerbate many of the worst non-privacy problems with behavioral ads, including discrimination and predatory targeting. You can guess what those things mean, right? They're calling this a privacy sandbox, right? It's always the opposite.
If Congress is passing a bill, that is a COVID relief bill, you can bet that there's very little to do with COVID relief in the bill. Wait a minute, actually, that's true. There's only 9% of the money in this almost $2 trillion spending plan. 9%, that actually goes to COVID relief. Instant COVID relief bill.
Same thing here with Google, right? This is the privacy sandbox and it's going to be better, Google says.
In the world, we have today where data brokers and ad tech giants, track and profile everybody with complete impunity. Just like Equifax has. Just like Equifax lost our personal identifiable information, our social security numbers, or addresses or names or date of birth, et cetera, et cetera. Yeah. Yeah. Okay. We pay a small fine. Yet. We go on.
Are they out of business? Have they lost business? In fact, they gained business because people have been paying Equifax to monitor their credit. Oh my gosh.
That framing that Google is talking about is based on a false premise that you have to choose between tracking and new tracking. Does that sound familiar? Yeah. It's not an either-or. We really should be rejecting this whole new federated learning of cohorts proposal Google has come out with.
You can bet that Apple is going to reject this outright because it's really rather terrible.
If you care about your privacy on the other hand again, I look at it and say I want an F-150. I don't mind ads for pickup trucks, so what's wrong with that? Okay. There's two sides to this.
I just don't like them calling me by name when I walked past a billboard.
Stick around, we'll be right back.
I'm a fan of much of what Elon Musk has done, what he's trying to do when it comes to technology, and being a proponent of technology.
I'm not fond of Elon Musk taking over $3 billion from the taxpayers though.
Hi, everybody. I appreciate you spending a couple of hours with me here on the weekend. There's so much to cover.
Elon Musk it was $3 billion that he had received in government subsidies. Now we're looking at this, according to good jobs, first.org. We're looking at $4.9 billion dollars that Elon Musk has received basically from the taxpayer.
It's really sad when you get right down to it. Now, Tesla got money from taxpayers he's paid some of it back. It's really the government trying to name a winner.
There's a lot of competing technologies. There's even non-electric cars out there. How many of you even aware of this? That use, for instance, hydrogen instead of electricity. Now there's, of course, with any technology there's complications here and there. Hydrogen is absolutely amazing. It's an electric car. You fill it up with hydrogen and the only byproduct of the burning, if you will, the hydrogen, is water. In fact, it doesn't burn the hydrogen. It combines it with oxygen to make the water and produce electricity all at the same time. Very cool.
There are some prototypes out already on the roads out in California and some other places around the world.
When the government's giving out billions of dollars to electric cars, they're effectively naming a winner. Aren't they? Does that make sense? I don't think so. We've got to have a free market and this is not a way to have a free market.
It's just like with solar, wind, some of these other technologies where the government is taking our tax dollars and is saying this particular technology, and even worse, look at Solyndra, look at some of these others just absolute debacles.
Now, even worse they give money to a specific company within a certain industry. That is not a good thing. Government has a terrible record at picking winners. Even investors, you look at people who are angel investors and who are venture capitalists. They are lucky. If they make money in one of 10 of their investments. It is not a great way for them to make money.
A professional investor does terribly. Imagine how poorly a politician does. The politician is going to be listening to the people knocking on their door, saying here's some money for next time you run for the house or Senate. Or locally, in local elections, it even happens. That is a very bad thing.
It's been proven again, and again over particularly in the last about 140 years. Governments' terrible about picking winners. Yet they do it every day of the week. Tesla has gotten money, right? Some, of its tax benefits, some of it is actual cash. The bottom line, they've some great technology.
Now what's happening is Tesla is asking Tesla fans to lobby the government on its behalf. Great article by Rachel Kraus over on Mashable about this week. I love it.
She says a Tesla fan. Your mission. Should you choose to accept it is to go to bat politically for the company. Check this out online. You might want to too because Tesla has launched a new online portal called the Tesla engagement platform. CNBC spotted this about a week ago, and this is a hub where Tesla posts actions its users can take like contacting government officials when there is a potential law that would affect the company.
In fact, it says in a blog post on this hub Tesla built. Engage Tesla is a new platform for both Tesla's public policy team and Tesla owners clubs. Its goal is to create a digital Homebase for all of our work and to make it easier for Tesla community members to learn what's top of mind for us. Take meaningful action and stay in the loop. We hope you'll enjoy our, excuse me, will we hope you'll join us in getting involved? Oh my gosh.
So, I'm on Engage Tesla, it is at engage.tesla.com. Very pretty pictures. By the way, of some of these new Tesla cars, very cool cars. I would absolutely drive one of these things.
One exception, I don't like the handles. I talked about that a couple of years back. About door handles on the outside. Having been in emergency medicine for a while. EMS, I can tell you, in accidents, you want something you can grab onto and have serious leverage. The doors get bent, things happen. There's at least one case I'm aware of where someone got trapped inside the car that was involved in an accident and then burned to death because the people who were trying to rescue him could not get him out of the car because there are no door handles to pull on.
Yes. I know the handles come out automatically when everything's working right. I'm talking about the most extreme of problems here. Anyhow, I'm digressing again.
Uber is doing much the same thing, by the way. It isn't just Tesla. Uber is, in fact, they had their drivers this was October last year, sue Uber over what these drivers called pressure to vote and advocate for the proposition in California. Not a good thing when you get right down to it.
It is it's a real problem when you look at this in detail now. I'm not sure it's a terrible problem, but I do have a serious problem with companies soliciting the government in order to get things like tax subsidies in order to get special favors.
A lot of people do too. Look at all of the people who were upset with Tesla for trying to get a tax holiday for its battery plant and for some of its other facilities and things that they're doing.
By the way, there is currently a post on this Tesla engagement platform asking Nebraska residents to contact lawmakers about a law coming up for a vote that would enable Tesla to open showrooms and service stations in the state where it's currently prohibited.
Now I brought that one up, particularly because I think again, free market. There's no reason in today's world. No legitimate, let me put it that way, reason to have dealerships. I think we should be able to buy a vehicle directly from a manufacturer. If they want to have certified repair shops, knock yourselves out, but we don't need somebody sitting there anymore in a dealership. Same thing with most of these distributorships. I think we have been shown that a car can be ordered online, configured, online shipping to us. We can be pretty darn happy with it. By the way, that they are shipping it to us in our state gives them what's called a legal nexus. So, they do have a presence in the state. They can be sued in the state if there is a problem. This whole thing in Nebraska, I don't think there should be dealerships that are exclusively provided the right to sell vehicles within the state.
My opinion. All right. Hey, stick around. Cause we will be back.
We're going to talk a little bit about deep fakes. This is cool because MyHeritage is doing something that's scaring a few people.
You're listening to Craig Peterson.
Make sure you check out my website, Craig peterson.com and sign up.
You might've seen some of these deep fakes out there. Videos where it's putting Elon Musk's face on people or others in videos. Did you know that there's audio as well? They're using it to bring back our ancestors.
Hi guys. I really appreciate you listening to me.
There is a website out there called MyHeritage and it's very popular. It's a site that allows you to do a genealogical examination of yourself, a little look at DNA, they'll look at your family tree. They've got some research stuff up there. They have something new called Deep Nostalgia and I think this is very cool.
It really introduces some interesting problems, frankly. This allows you to animate a face in a photo. It's unnerving. When you have a look at this thing. You can check it out, again. MyHeritage.com/deep-nostalgia N O S T A L G I A. In case you're wondering how to spell it. They require you to create an account on their site and then you upload the photograph.
It takes that photograph and it has them pose it's really uncanny. I'm looking at a picture black and white that was taken it's right there on their site of a couple. I would guess this is a 1960-ish-era photograph based on the hairstyles and the glasses. It's just so weird because they have this photo. It's a head-on face-on photo and they've animated it so that the woman in this photo she's moving her head around. She's smiling. This is a really great smile. She blinked. She moves her head up and down and looks over to her and looks back again. Wowsers. It is absolutely amazing. You might want to check it out. It's a form of artificial intelligence that's doing this.
Of course, it has to make a bunch of assumptions. So if you look, you don't even have to look that closely, but if you look fairly closely at the picture, you'll see some detailed problems with her hair, the ends of her hair. At the top of her head, because you can't see the whole top of her head in the original picture. You can obviously not see both sides of her face or her head because that particular picture just a straight-on shot. It's making it up as it goes.
We're seeing deep fakes more and more. We're going to see a real problem, coming up in another couple of years, certainly by the time 2024 arrives with deep fakes.
We've already got Russians influencing our elections. Of course, not as much as the oligarchs out in Silicon Valley have been influencing our elections, but they are already influencing us in a very big way.
China, as well, imagine what'll happen when they start producing deep fakes of our presidential candidates saying things or doing things that they have never said nor done.
What I did is. I figured I want to give you guys an example. Audio seems to be a little bit harder for the deep fakers than some of the videos. At least the technology and audio hasn't quite come as far. I'm going to play for you right now. A deep fake of my voice.
This is not my voice, you're about to hear. Then I'm going to play a completely computer-generated deep, fake. So let's go here. I'm going to play my voice right now. This is an example of a deep fake using my voice. Did you catch that? That wasn't me. That was a computer again. I'm going to play it for you one more time.
This is an example of a deep fake using my voice. Now you can hear some of the problems with it. If you listen really closely that it's not really me, but it's close enough that if you weren't paying a whole lot of attention, you would not notice that it really wasn't me saying something.
Expect within the next year, that type of technology to get to the point where you won't be able to tell.
So think about it. What would happen? If a tape was released, talking about, Mitt Romney for instance, saying half of the voters that are never going to vote for me anyway, and that was recorded. I guess, by one of the waiters, it was at an event.
If you took this voice of mine and you created a deep fake, cause all you need is about five seconds worth of someone's voice to make a deep fake. You had politician X, let's say that Hillary is running again for precedent, okay in 24. You could have her say almost anything. The audio quality might not be up to it, but with most of these recordings that are made on people's cell phones either, is it.
I want to play another deep fake. This is a completely fabricated female voice. This is an example of a deep fake using a completely generated voice. Yes, indeed. I created that. I can make her say anything I want to.
Help me. Craig is holding me hostage inside his computer. Yeah. This is going to be a huge problem in the future.
There are concerns about what they are doing over at MyHeritage. Look at some of these pictures. Here's one it's cool. It's unnerving. Here's again, a guy with a family, this one's in color, he's got a right ear, the really pops out there, but he's looking around.
Have you used an iPhone and taken a picture and they call them live pictures. You can see the person right before the shutter is closed. You can see the person moving around. It's really a little video right in front of the picture. That's what these things look like.
Ah, here's this little kid he's looking around. Here's one, a very old one. Oh my goodness, it is creepy. You got to check this out online. MyHeritage is.com/deep nostalgia.
Now here's where the concern comes in. In an article on Life Hacker. By David Murphy, he is talking about taking these old pictures could be very old pictures of somebody sitting around somewhere, uploading it to the site. Then you get a little bit of nostalgia. I get creepy nostalgia that only comes from this static image now moving around on your screen.
I don't get it, really, I don't myself. I think that it's just plain creepy, but if you decide to do it, cause it is cool. Okay.
You probably should use a temporary account to make it to make your account over on MyHeritage and maybe also delete the photos that you upload and turn into these deep fakes. So many other websites out there, if you do go ahead and upload it, they go and claim the rights to it because it's a derivative piece. They made this little video from your photos. So, that's not your photo anymore. It's now theirs. It gives them a royalty-free worldwide perpetual and non-exclusive license to host copy, post, and distribute the content. It could be a problem, but I can tell you one thing that definitely would be a problem, that is if you use a username and the password you've used elsewhere.
Now, I have to bring this up because most of us are using the same password on every website or maybe, yeah we're really smart. We got three passwords and we vary them. I did that for years, but that was many decades ago. We just can't do that anymore.
If you are going to make an account on MyHeritage or anywhere else, make sure you don't use a password that you've used anywhere else because it is a problem.
Ultimately, it's a real problem for you and you can't believe your eyes or your ears anymore.
You share these pictures. I don't know that they allow you to download them because I did not put my own pictures up there. If these pictures are watermarked. Delete your account. Click that blue link under the big grid text to get started. That's supposed to delete anything anyways. You can figure it out but have a look anyway, it's in my newsletter that comes out on Sunday morning. There'll be a link in there that you can click on and see what they've been able to do.
Remember. When it comes to particularly things coming up in this next election where it really matters who we vote for, it really matters. Other countries have a very big opinion about who we should be electing to office.
Look at what happened with Rep Swalwell out in California. Here's a guy who was running for mayor the Chinese socialist government decided they would put a honeypot into his campaign. So they got this woman who was trained in seducing people. They seduced Swalwell and she raised money for him, for his campaign as mayor and stuck with him over the years, all the way until he was in Congress.
Then in Congress, she helped him get onto the very influential committee in Congress, where he had full access to our government secrets. Certain secrets that are. She apparently was feeding all the information right back to China. That is not a good thing, not a good thing at all. It goes to how much. China is willing to do to directly influence and infiltrate our government and our businesses.
If they will assign one of their spies to seduce a mayor of a small city in California, and then help elevate him to Congress and to the chairmanship in Congress. By the way, The speaker of the house, Nancy Pelosi has not removed him from that seat. She's got a Chinese spy problem herself. That's another story.
They're willing to do anything.
It's going to be a rough little time here going forward. Let me tell you these deep fakes are getting more and more real.
I'll be right back with a whole lot more.
You're listening to Craig Peterson.
I've been talking about this on the radio all week, at least since midweek. I want to talk about it now, and why I am so upset with Microsoft. I can hardly contain myself. This is crazy.
This is Craig Peterson here. You heard it right. The guy that's very upset with Microsoft. What shall I say? We're going to be getting into that in just a couple of minutes.
This is a real problem. What are we supposed to do? We have bad guys now doing what is called supply chain attacks.
The simple way to explain this is you have someone who is supplying software for you. It could be Microsoft. We heard about something, that happened very recently with SolarWinds and how they had software that they were providing their customers, which included government agencies. All kinds of them. It included many businesses. A lot of managed services providers were hacked by this.
A very, very big problem, because they were trusting the software that came from SolarWinds, and that software had been digitally signed, so they knew it was legitimate. Everything's good. Nothing to worry about here, let's go on with our lives.
However, the reality was that the SolarWinds software had been hacked many months prior to anybody really noticing. It was hacked in such a way that when SolarWinds provided their software to their customers were now infected.
Now, you might look at it and say SolarWinds, they should be signing their software. They should be watching the chain of custody for their software. They did, in both cases, they were signing it digitally so that their customers knew, okay, this is legit. This is really from us. You can install it. It's good.
But you're checking the signature didn't do any good. You were still going to be hacked because it was in SolarWinds software.
Microsoft has been providing us with software for many years. I helped develop some of the Windows NT code ways back when. Their new technology, that's what the current versions of Windows are based on. I can remember way back then, just what a mess it was I couldn't believe the way they did so many things. It was just absolutely crazy.
Of course, David Cutler, VMS guy, for those of you who remember all of that, really spearheaded that NT project. There were a lot of VMS systems in it, but then Microsoft ripped them out. They ripped them out because they didn't want to have to support an operating system that enforced security. VMS has been a very secure operating system is written by true programming professionals, not interns, as it was exposed with Microsoft, having interns develop one of their versions of their operating system, like 80% of it. It was crazy. That was only found out because of discovery.
Yet Microsoft is sitting on cash. A whole lot of cash. It's billions of dollars. Let me see. I'm looking up right now. Microsoft is sitting on $136 billion in cash, right now, according to MacroTrends. Now, were they using that cash, that $136 billion in cash, to make their products more secure? Doesn't look like it does it.
They had such a huge hole. You could drive a freight train through. The Chinese were able to infiltrate, in fact, many of our machines. This isn't tens of thousands of our machines, this isn't just something like ransomware, where you know about it because Hey, they're asking a ransom, right? They're threatening they're going to release our secrets, our software, our personal information. If we don't pay up it wasn't one of those things.
What they did is they got onto these machines in education. In other words, school districts. Hospitals, doctor's offices, government agencies, including defense department guys, Homeland security guys. Okay.
Our businesses all the way across the world. They put back doors on. What a backdoor is. it is something that allows them to go to your machine anytime they want? In this case do pretty much anything they want it to.
Microsoft comes out with fixes this last week. This is specifically for the Microsoft exchange server. By the way, if you're running Microsoft Exchange server, either locally in your business or in the cloud, you have this bug. They released a patch that supposedly closes the hole. It was used by the Chinese to install permanent back doors and what did they not do? They didn't remove the back doors that the Chinese had put in.
What's Microsoft saying to us then, are they saying, Hey, listen, you're fools for buying our software. I don't think they're saying that.
I am at the point now where I'm saying that we are fools for trusting Microsoft. We're fools for trusting these companies that have a product to sell. All they're trying to do is sell the product.
Look at what's been happening with some of these antivirus products. Look at what's happening with these VPN products. They have the software to sell and they're going to sell it.
They're not going to tell you the whole truth, nothing but the truth. Forget about it. They're going to do anything they can to sell you the product. So are Microsoft people.
Are people getting fired for buying Microsoft? It's like IBM in the seventies and the eighties, you never got fired for buying IBM.
People should be fired for buying Microsoft.
If you have a Microsoft Exchange server, not only do you need to make sure you install all of the patches. There were four critical Microsoft exchange servers, zero-day vulnerabilities patch.
In other words, things that they hadn't been able to patch it and know about yet. Supposedly, right? There are articles I've read that say they've known about at least one of these vulnerabilities for a year plus. There are other vulnerabilities Microsoft knows about that they haven't bothered closing the door on.
They are in our supply chain. They are getting us the software that we need and they're signing it and it's installed in it.
We're upgrading our machines. Sometimes the upgrades that they provide, the security patches actually work, in this case. It may close the door. What it's not doing is providing us with a way out of this huge mess.
Velma agrees with me here. Okay. No, she absolutely does.
They released fixes on March 2nd. Microsoft has been saying they've been used in limited and targeted attacks against law firms, infectious disease researchers, defense contractors, policy think tanks among other victims. Yeah. Yeah.
How is it a problem? I don't see it.
Oh, my goodness. Companies are seeing abuses of these Microsoft exchange server problems starting in January. There are reports that I found out there online. There are three clusters of vulnerabilities. Tens of thousands of US-based organizations are running Microsoft exchange servers that have been backdoored by these threat actors, who we are thinking are Chinese. They are stealing administrative passwords. They're exploiting these critical vulnerabilities in the email systems and calendaring application.
They've done nothing, Microsoft to disinfect the system's already been compromised. Can you believe this?
I got this from Krebs on security. They were the first ones to report this mass hack and Krebs has got some great stuff they have had for many years now, frankly.
Brian Krebs put the number of compromised US organizations, at least at 30,000 worldwide. Krebs said that there were at least a hundred thousand hacked organizations. Now, an organization is a government agency. It could be a hospital, could be a doctor's office, could be a business, right? Anything is an organization, tens of thousands in the U. S. This is the real deal. This is a very big deal.
You have to assume if you are running a Microsoft Exchange server, this is the server that is used for email. This is how small businesses often run. Their email is an exchange server. This is how hospitals and government agencies, et cetera, run their exchange server, which is ridiculous.
I have never purposely used an exchange server, right? If there's any way around it I've always has gone to something better, a Unix-based system.
Postfix, almost anything rather than the incredibly buggy software from Microsoft. It is just horrible.
Anyway, you have to assume that you were compromised between near the end last week of February and the first week of March.
Absolutely incredible limited targeted attacks. This isn't something that was just absolutely widespread. They went after companies because they knew they could get something out of the companies, a very skilled hacking group from China.
They're focused primarily on stealing data from US-based infectious disease researchers. As I said, law firms, right? Higher education institutions, defense contractors, policy, think tanks and NGOs. It's absolutely incredible what they've been doing and we cannot put up with it anymore.
I want to put a little word here. If you are a business and you have been using Microsoft exchange server restore from a backup. I would say in the January timeframe, you'd probably be safe. Probably, didn't have any back doors in January. Hopefully, you've got a backup that goes back that far. Okay.
Then find something else. Don't use this. Microsoft does not care. You cannot have $136 billion cash on hand, and not spending serious amounts on security. You can't tell me they care. Because frankly, I don't think they do.
Hey, go online. Craig peterson.com get some of the free training, other things, and I'm offering right there. Craig peterson.com.
Hey, welcome back everybody we're talking right now about InfoSec, information security. Have you thought about maybe taking up a bit of a new career? Well, there are some estimated 2 million open jobs in this one?
This is Craig Peterson. Thanks for joining me today.
This article appeared in dark reading. Now, dark reading is an online magazine, right? It's a website. And they had this article that I absolutely had to read because it reminded me of someone I know. One of our listeners, who decided he needed a new career. He'd lost his job. He'd been out of work for over a year and he had been managing a retail camera shop and they shut it down. He was stuck. What do I do? He'd been listening to the show for a long time. He decided he wanted to go into information security. He took some courses on it and he got himself a job. A full-time job being the chief IT security guy for this company after just a few months.
So that tells you how desperate these companies are. Kind of jerking his chain a little bit, but not right, because he just barely had any background. If you want me to connect you with him, if you are serious about thinking about one of these careers, I'll be glad to forward your request to him, just to see if he's willing to talk to you. Just email me M [email protected] and make sure you mentioned what this is all about. So I know what's going on.
Ran Harel, who is security principal and product manager over at Semperis said, when I was growing up, I was quite an introvert, by the way, that sounds like a lot of us in it. I didn't realize until much later on in my career, just how great the security and tech community is looking back. I realize how quickly I could have solved so many issues, by just asking on an IRC channel or forum.
IRC is an internet relay chat, a bit of a technical thing, but it's an online chat.
I would tell my former self, the problem you are facing now is probably been dealt with multiple times in the past year alone. Don't be afraid to ask the InfoSec community and then learn from them.
That's absolutely true. I found an online IRC channel basically, and they were set up just to talk about CMMC is this new standard that department of defense contractors are having to use.
As you probably know, we have clients that are manufacturers and make things for the Department of Defense and they have to maintain security. It's been interesting going in there answering questions for people and even asking a couple of questions. It is a great resource. This particular kind of IRC is over on discussion.
You can find them all over the place. Reddit has a bunch of sub- Reddits. It's dealing with these things, including, by the way, getting into an InfoSec career. So keep that in mind.
There's lots of people like myself that are more than willing to help because some of the stuff can get pretty confusing.
All right. The next one. Is from Cody Cornell, chief security officer, and co-founder over at swimlane. He said, apply for jobs. You are not qualified for everyone else is.
Man. I have seen that so many times everybody from PhDs all the way on, down throughout a high school and who have sent me applications that they were not even close to qualified for.
Now, you can probably guess with me, I don't care if you have a degree. All I care about is can you do the work. Can you get along with the team are you really going to pull your weight and contribute? I have seen many times that the answer to that is no, but I've seen other times where, wow, this person's really impressive.
So again, apply for jobs you're not qualified for because everybody is. Security changes every day. New skills techniques and the needs of organizations are always shifting. And to be able to check every box from an experience and skills perspective is generally impossible. Looking back at 20 years of jobs in the security space, I don't believe that I was ever a hundred percent qualified for any of them, but felt confident that I could successfully do them.
So keep that in mind. Okay.
Again, imposter syndrome, we're all worried about it. This applies to more than just InfoSec. This applies to every job, every part of life, we all feel as though were impostors and that we're not really qualified, but the question is, can you figure it out? Can you really do it?
Next up here is Chris Robert, a hacker in residence, he calls himself over at Semperis and he says, overall, the most important lessons that I'd tell my younger self are not tech-based. Rather they focus on the human aspect of working in the cybersecurity industry. I think cybersecurity professionals in general, tend to focus on technology and ignore the human element, which is a mistake and something we need to collectively learn from and improve.
I agree with him on that as well. However, we know humans are going to make mistakes, so make sure you got the technology in place that will help to mitigate those types of problems.
Next up, who's got, Marlys Rogers. She's CISO over at the CSAA insurance group that's a lot of four-letter acronyms. You are nothing without data. Data is queen. Coming from an insurance person, right? Without hard data, you can only speak to security in more imagined ways or ways. The board and C-suite are aware of in the media cost-benefit is only achievable with related data points. Demonstrating how much we are fighting off and how the tools, processes, and people make that happen.
Next up we have Edward Frye, he's CSO over at our Aryaka. When I first started out, I was fairly impatient and wanted to get things done right away. While there are some things that need to be done right now, not everything needs to be done. Now have the ability to prioritize and focus on the items that will have the biggest impact.
I think one of the biggest lessons I've learned along the way is while we may need to move quickly, this race is a marathon, not a sprint.
Patience is essential for security pros. I can certainly see that one.
Chris Morgan, senior cyber threat intelligence analyst over at Digital Shadows, despite the way that many in media liked to portray cyber threats, not everything will bring about the end of the world.
For those getting into incident response and threats, try to have a sense of perspective and establish the facts before allowing your colleagues to push too quickly towards remediation mitigation, et cetera.
Expectation management amongst senior colleagues is also something you'll frequently have to do to avoid them breaking down over a mere phishing site. The quote, one of my former colleagues try to avoid chicken, little central.
I've seen that before as well.
The next one is things are changing daily and the last one is a perception of security is still a challenge.
So great little article by Joan Goodchild. You'll see it in my newsletter, which we're trying to get out now Sunday mornings.
You can click through the link if you'd like to read more.
As you can see. 2 million open jobs while between one and 3 million, depending on whose numbers you're going at in cybersecurity.
You don't have to be an expert. As I said, one of our listeners went from not knowing much about it at all. He can install windows. That's it. To having a job in cybersecurity in less than six months, stick around. We'll be right back.
I'm doing a special presentation coming up next month for the New England Society of Physicians and Psychiatrists. We're going to be talking a little bit about what we will talk about right now. What can you do to keep your patient information safe? What can we do as patients to help make sure our data's safe.
Hi, everybody. You'll also find me on pretty much every podcast platform out there. Just search for my name, Craig Peterson. I have a podcast and it makes it pretty easy. I've found some of them don't understand if you try and search for Craig Peterson, tech talk, some of them do.
I've been a little inconsistent with my naming over the years, but what the heck you can find me. It's easy enough to do.
I've got this new kind of purple-ish logo that you can look for to make sure it's the right one. And then you can listen to subscribe, please subscribe. It helps all of our numbers.
You can also, of course, by listening online with one of these devices, help our numbers too. Cause it's you guys that are important. The more subscribers we have, the way these algorithms work, the more promotion we'll get. I think that's frankly, a very good thing as well.
What do you do if you need to see a doctor, that question has a different answer today than it did a year ago. I won't be able to say that in about another month, right? Because mid March is when everything changed last year, 2020, man, what a year?
To see a doctor nowadays, we are typically going online aren't we. You're going to talk to them. So many doctors have been using some of these platforms that are just not secure things like zoom, for instance, which we know isn't secure.
Now, the fed kind of loosens things up a little bit under the Trump administration saying, Hey. People need to see doctors. The HIPAA PCI rules were loosened up a little bit in order to make things a little bit better. Then there's the whole DSS thing with HIPAA. All of these rules are just across the board are loosened up.
That has caused us to have more of our information stolen. I'm going to be talking a little bit about this FBI, actually multi-agency warning that came out about the whole medical biz and what we need to be doing. Bottom line, Zoom is not something we should be using when we're talking to our doctors.
Now, this really bothers me too. Zoom is bad. We know that it's not secure and it should not be used for medical discussions, but Zoom has been private labeling its services so that you can go out and say, Hey, zoom, I want to use you and I'm going to call it my XYZ medical platform.
People have done that. Businesses have done that. Not really realizing how insecure Zoom is. I'm going to give them the benefit of the doubt here. You go and you use the XYZ medical platform and you have no clue of Zoom. Other than man, this looks a lot like Zoom, that's the dead giveaway.
Keep an eye out for that because a lot of these platforms just aren't secure. I do use Zoom for basic webinars because everybody has it. Everybody knows how to use it. I have WebEx and the WebEx version of it is secure. In fact, all the basic versions, even of WebEx are secure and I can have a thousand people on a webinar or which is a great way to go. It's all secure end to end.
Unlike again, what Zoom had been doing, which is it might be secure from your desktop, but it gets to a server where it's no longer secure. That kind of problem that telegram has, frankly.
If you are talking to your doctor, try and use an approved platform. That's how you can keep it safer.
If you're a doctor and you have medical records be really careful. Zoom has done some just terrible things from a security standpoint. For instance, installing a complete web server on a Mac and allowing access to the Mac now via the webserver. Are you nuts? What the heck are you doing? That's just crazy. Just so insecure.
This is all part of a bigger discussion and the discussion has to do with Zero trust architectures. We're seeing this more and more. A couple of you, Danny. I know you reached out to me asking specifically about zero trust architectures. Now Danny owns a chain of. Coffee shops and his family does as well.
He says, Hey, listen, what should I do to become secure? So I helped them out. I got him a little Cisco platform, and second Cisco go that he can use as much more secure than the stuff you buy the big box retailers or your buying at Amazon, et cetera, and got it all configured for him and running.
Then he heard me talk about zero-trust and said, Hey, can I do zero-trust with this Cisco go, this Muraki go, is actually what it is and the answer is, well so here's the concept that businesses should be using, not just medical businesses, but businesses in general and zero trust means that you do not trust the devices, even the ones that you own that are on your network. You don't trust them to be secure. You don't trust them to talk to other devices without explicit permission.
Instead of having a switch that allows everything to talk to everything or a wifi network where everything can talk to everything, you have very narrow, very explicit ways that devices can talk to each other. That's what zero-trust is all about. That's where the businesses are moving.
There's zero trust architecture, and it doesn't refer to just a specific piece of technology. Obviously, we're talking about the idea that devices, and even on top of that, the users who are using the devices only have the bare minimum access they need in order to perform their job.
Some businesses look at this and say that's a problem. I'm going to get complaints that someone needs access to this and such. You need that because here's what can happen. You've got this data that's sitting out there might be your intellectual property. You might be a doctor in a doctor's office and you've got patient records. You might have the records from your PCI your credit card records that you have. I put on. Those are sitting there on your network that is in fact a little dangerous because now you've got something the bad guys want. It's dangerous if the bad guys find it and they take it, you could lose your business. It's that simple.
They are not allowing you to use the excuse anymore because of COVID. That excuse doesn't work anymore. The same thing's true with the credit card numbers that you have the excuse of I'm just a small business. It's not a big deal. Doesn't work anymore. They are taking away your credit card privileges.
We had an outreach from a client that became a client, that had their ability to take credit cards taken away from them because again, there was a leak.
So we have to be careful when you're talking and you have private information, or if you don't want your machine to be hacked, do not use things like Zoom. I covered this extensively in my Improving Windows Security course. So keep an eye out for that as well. If you're not on my email list, you won't find out about this stuff.
Go right now to Craig peterson.com. If you scroll down to the bottom of that homepage and sign up for that newsletter so you can get all of what I talk about here and more.
Hey, thanks to some hackers out there. Your application for unemployment benefits might've been approved and you didn't apply for it in the first place. Turns out somebody stealing our information again.
Hi everybody. Craig Peterson here. This is a big concern of mine and I've often wondered because I have not been receiving these stimulus checks. I did not get the first round. I did not get the second round and I contacted the IRS and the IRS says depends on when you filed for 2019.
Oh my gosh. Of course, I was a little late filing that year. They still haven't caught up. I guess that's good news, right? That the IRS data processing centers are terrible.
It goes back to aren't you glad we don't get the government we pay for is the bottom line here, but I've been concerned. Did somebody steal my refund?
Did somebody steal my unemployment benefits, did somebody steal my stimulus checks? It is happening more and more. There is a great little article talking about this, where someone had stolen the author's John personal information again. Now we probably all have had our personal information stolen, whether you're aware of it or not.
As usual, I recommend that you go to have I been poned.com and pwnd is spelled, pwn, D have I been poned.com and find out whether or not your data has been stolen and is out there on the dark web.
They have a really good database of a lot of these major hacks. Many of us have been hacked via these credit bureaus and one in particular Equifax who have all kinds of personal information about us, had it all stolen.
It's easy enough for people to steal our identities file fake tax returns. That's why the IRS is telling you, Hey, file your return as soon as possible. That way when the bad guys file, we'll know it's the bad guys' cause you already filed it. As opposed to you file your tax return and the IRS comes back and says, Oh, you already filed. We already sent you a refund or whatever. You already filed it.
That is a terrible thing to have to happen because now you have to fight and you have to prove it wasn't you. How do you prove a negative? It's almost impossible. At least in this case, hopefully, the check was sent to some state 50 States away, another side of the world. So you can say, Hey, listen, I never been there, then they can hopefully track where it was deposited.
Although now the bad guys are using these websites that have banks behind them, or maybe it's a bank with a website that is designed for people to get a debit card and an account just like that. That, in fact, is what was used to hack my buddy. My 75-year-old buddy has been out delivering meals and had his paychecks stolen through one of those.
These fraudulent job claims are happening more and more. It's really a rampant scam. We've had warnings coming out from the FBI and they have really accelerated during the lockdown because now we've had these jobless benefits increased, people, making more money staying in their home than they made on the job. Disincentives for working, frankly.
He's saying here the author again, John Wasik, that a third of a million people in his state alone were victims of the scam. This is an Illinois. This is where he lives. A third of the people in the state of Illinois, including several people that he knew.
We've got some national tallies underway. I don't know if you've seen these. I've seen them on TV and read about them, California. It is crazy. People were applying for California unemployment that didn't live in the state at all, would come into the state and once you're there in the state pick up the check, right? Cause that's all they were doing. Some people have been caught with more than a million dollars worth of California unemployment money.
Of course, it wasn't a check, it was actually a debit card. The same basic deal and California is estimating that more than $11 billion was stolen. Can you imagine that tens of millions of people could have been scammed because of this?
This is the third time the author had been a victim of identity theft and fraud. He wanted to know how could they get his information.
Well, I've told you, check it out on, have I been pwned. It'll tell you which breaches your information was in. It does it based on your email address. It'll also tell what type of data was stolen in those breaches. So it's important stuff. I think you should definitely have a look at it.
He is very upset and I can understand it. Data breaches last year, more than 737 million data files are ripped off according to act.com. Frankly, that was a digital pandemic, with more and more of us working at home.
I just talked about the last segment. Your doctor's office and you are talking to your doctor. How now? Cause you don't go into the office. There are so many ways they can steal it.
The FBI's recording now a 400% increase in cybercrime reports that we had this mega hack of corporate and government systems.
This whole thing we've talked about before called the SolarWinds hack, although it was really more of a Microsoft hack, and it went out via SolarWinds as well as other things. Be careful everybody out there. If you find yourself in these breach reports, have I been pwned make sure you go to the website. Set yourself up with a new password. At the very least use a password manager.
I just responded to an email before, when it went on the air today, from a listener who was talking about two-factor authentication. He's worried about what you're to use. I sent him my special report on two-factor authentication, but it is the bottom line, quite a problem.
Again, Use one password, use two-factor authentication with one password. Don't use SMS as that and you'll be relatively safe.
I don't know I can't say do this and you'll be safe. I don't think there's any way to be sure your safe.
Having these organizations, businesses, government agencies hacked all the time that don't seem to care about losing our data, right? Oh, it's a cost of doing business, some of these businesses, and I've talked to them, they'll look at it and say, how much will it cost us in fines if our data is stolen? Versus, how much will it cost us to keep our data relatively safe? For even a larger small company, a hundred employee company, you're talking about something that is going to be costing you about 25 grand a month. That's if it's outsourced.
If you're trying to do it yourself and a hundred-person company, you can easily be spending a hundred grand a month. It's expensive to do. They'll look at it and say, okay, this is going to cost us a million dollars a year, odds are, it'll be two years, maybe three before we're hacked. That's this statistic, although you're rolling the dice, it might be tomorrow that you get hacked. $3 million versus our fines are going to be about a million dollars. We'll just take the fine.
That to me is just disgusting. How can these people live with themselves? I don't know. Maybe it's just me. I'm going crazy.
That leads us to this New York Times article I was talking about on the radio this week. The New York Times article talking about how the United States, really, we are losing control of information warfare. Our warriors have been working at the national security agency and the FBI. They leave those agencies and go to work for private contractors. The tools that we've been using to hack other people have been stolen. The tools that we're paying to be developed, we meaning the US taxpayer, the tools that we have paid to develop aren't even being used, and that mega attack I was just talking about. That's an example of one of these attacks that would have been stopped had we been using the tools that the federal government paid for. It's just crazy. What's going on?
So here's the bottom line, everybody you can't trust most of these vendors that are out there. They have a product to sell. They don't have the best solution for you, right? They really don't. If they cared about you they would not be selling you antivirus software because it does not work.
If Microsoft cared about you, they would have come out with their anti-malware stuff. Windows defender, years and years ago. They would have redesigned Microsoft Office and Microsoft Windows, as well, because those were huge security holes.
Look at Adobe. They've been the source of the most security problems of anything out on the market, bar none. Flash was terrible. Java, another example of something that's been a terrible security hole for years. These businesses are trying to get a product to market as quickly and as inexpensively as possible. Quick is usually the number one goal. It has to be inexpensive for them to develop it. That means now they go out and they sell it because they got it. They're going to sell it. It doesn't matter if it's good. It doesn't matter if it even works overall for you.
That's why I'm doing these courses, these classes, these emails, I'm recording special stuff for you each week. I've got special emails that are going out for you each week.
We've got these radio show podcasts. This stuff is all free. All of it.
Now I charge for some courses, but everything else is absolutely free. Now I hope I have some clients that come from some of this stuff and I do get them, but most of the clients I get are by referrals.
I really believe in this. I'm putting my time, my money, my energy where my mouth is. But you have to take a step. You have to go to Craig peterson.com and you have to sign up right there. Craig peterson.com. Scroll down to the bottom of this screen. You'll see a little signup thing and I will start sending you my weekly newsletter.
Some of these little micro pieces of training that only take you a few minutes and information on courses and more. Craig peterson.com.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed