Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Tech Talk with Craig Peterson Podcast: Backups versus Disaster Recovery versus Business Continuity, Apple wants Privacy - Google wants Your Info and more

    Sorry guys, this week was quite busy for me with meetings and presentations for my business. We will be back next week with a new so but for today this is a re-air of the February 20th Podcast. Check out the website for the latest articles I found for you to read.

    Craig

    Welcome!

    We lost a Radio Icon this week and he had a big impact on me, I have a short tribute to him but it was also another busy week on the technology front. We are going to get into the differences between Backups, Disaster Recovery and Business Continuity, often these get tossed around in discussions as one in the same - they are not. Then we will discuss Bitcoin and it metoric rise and why that happened. Next we'll discuss Apple and Google and why Google is trying to play hardball but may end up getting burned. Then we are headed to Space and NASA space travel and a discussion on Rocket Fuel for future missions to Mars and there is even more, so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Breached water plant employees used the same TeamViewer password and no firewall

    As Prices Surge, Bitcoin Now Reportedly Consumes More Electricity Than Argentina, Netherlands, And UAE

    Google flags its iOS apps as "out of date" after two months of neglect

    White House hastens to address global chip shortage

    Report: NASA's only realistic path for humans on Mars is nuclear propulsion

    A Windows Defender vulnerability lurked undetected for 12 years

    Hackers try to contaminate Florida town's water supply through a computer breach

    Barcode Scanner app on Google Play infects 10 million users with one update

    SolarWinds Attack Reinforces Importance of Principle of Least Privilege

    U.S. Unprepared for AI Competition with China, Commission Finds

    Brave Launching Privacy-Focused Brave Search

    Hackers are finding ways to hide inside Apple's walled garden

    Apple changes 'subscribe' to 'follow' on Podcasts because people think subscribing means paying

    Russian government websites go dark after the U.S. vowed retaliation for SolarWinds hack

    Exchange servers first compromised by Chinese hackers hit with ransomware

    Google must face $5B lawsuit over tracking private internet use, judge rules

    Want to borrow that e-book from the library? Sorry, Amazon won't let you.

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] I've got to say the big story of the week is this breached water plant and how it really affects all of us. Not just because our water could be poisoned by a hacker, but it gives us a bit of a lesson on what we should be doing and what we did.

    Hi everybody. Craig Peterson here.

    There are many things that we did over this lockdown. Things we did. In fact, the lockdown itself to try and help stop not just the spread of the virus, but remember it was a two-week lockdown just so that we did not overwhelm our hospitals. Who could disagree with that, right?

    We all stayed home for two weeks that make sure that we're flattening the curve, that we're not going to have a lot of. People in hospitals. Unfortunately, other people who couldn't make it into the hospitals needed it. That two-week locked down to flatten the curve has turned into what? Now, almost a year later we are still seeing these lockdowns. These lockdowns have caused havoc.

    We've talked about many of them. Of course, you hear them all the time on the radio. Everything from suicides of our children. Through our parents dying in these homes and without the comfort of their family and without human touch for almost a year. It's just so, so, so sad to see.

    Now I'm not going to get into the political sides of this and what should we have done? What shouldn't have we'd had done? I've got my opinions on some of this. What I want to talk about is what we did with our jobs? What did we do with our businesses? I think we did some terrible things there, too.

    What I'm talking about is we need to stay home, but we have certain businesses that need to stay open. Now, frankly, every business needs to stay open. It's a business because it's fulfilling a need, right? It is so basic. It's hard to think that people don't understand this, but obviously, they don't.

    We shut down businesses. Businesses that will never, ever come back. People's lives destroyed. People whose entire savings, their entire retirement plan, everything was based on the business. That's where their money was. The people working there were counting on having that money to pay the rent, to pay the electric bills and other utilities. To pay for all of the things in life that we need to pay.

    It's one thing to have credit card bills that you can't pay because they're not a whole lot they can do about unsecured debt. They can certainly harass you. When it comes to things like your home or whatever it is, you're renting, whether you own it or not, how can you make those payments if you don't have money coming in. The money that the government is issued has just been a mere pittance. I get it.

    In some cases, people had just incredible amounts of money compared to what they were normally making with unemployment, with the federal subsidies, et cetera. That didn't last. PPP money, this payroll protection money, lasted for about six weeks for those businesses that could get it. Those that qualified.

    My business didn't qualify for PPP money. Not because it's too big, but because it's too small. Most of what happens in my business are done by my family members. I've got myself, I've got my wife, of course, you've probably seen Karen mentioned in some of my emails that go out.

    I've got my eldest son involved. He loves security. He's great at it. He's been working with me now for more than 10- 15 years on this. I've got one of my daughters working with this on me. So it's primarily a family business. We've got contractors who will do different things for us. We have a lot of suppliers and we have to pay those bills, but no payroll per se. You know what? That's a lot of businesses. The number of businesses that were in the same boat as I is huge. That's how things get started in this country.

    All of these companies could have started. The companies that had started had entered into lease agreements. That had started to provide services for their customers. Whether it be B2B like mine, business to business, or business to consumer they were all stifled.

    What have we done to ourselves? Really? What have we done? The virus itself is obviously pretty nasty and can be lethal in a lot of cases. It has been. Now we found out that people like governor Cuomo apparently just cooked the books. Cooked the books, something awful.

    We went home, we started working from home. Our businesses said, what can we do? We had people getting very, very busy trying to figure it out. There are a lot of little remote programs that you can use in one of those is Team Viewer.

    Now there's nothing particularly wrong with Team Viewer. I'm not fond of the idea of things like Team Viewer, remote desktop, and others, but sometimes it is the best solution for a particular problem. Team viewer in this case was used by a small government agency. Think about what would have happened. You had to shut down, you still had to do work. What did you do as a business?

    You probably got something like Team Viewer, one of these logins, remote login programs. Maybe you set up a remote desktop so people could get in remotely. Maybe you set up a VPN because that's going to solve all of your problems. Which of course it causes almost as many as it solves, but most people don't realize this.

    That's the case here. We're talking about a small town, 15,000 people, called Oldsmar. I don't think it's because they're a small town. I think this problem happened because they did what most of us did. We were not ready for a shutdown.

    As businesses, we weren't ready for a shutdown. In fact, the year before they did the shutdown, they had this massive pandemic planning session about eight months before. They all agreed that a shutdown was the wrong thing to do in the case of a worldwide pandemic. They also redefined pandemic. I think maybe getting the angle I'm coming from here. Right.

    They decided no, we're not going to do that. They did not plan for pandemics. In fact, they didn't plan for a lockdown.

    Obviously, you don't. Well, I don't know, maybe you do plan for a pandemic. If you're coming up with a virus you're going to release it, but they were not planning for a pandemic. They were not planning for the lockdown and neither were businesses. Most businesses, government agencies, and NGOs had no plans in place, even for disaster recovery or business continuity. You may or may not be aware of this, but there are different levels.

    You've got basic backups and you should be doing backups because hard disks fail. One of my customers' CEO thought that hard desks never fail. She was really upset when a disc crashed that we'd been warning her about because we keep an eye on things called smart stats on the disks. We said you've got this disc it's going to fail. You probably need to fix things because you're not in a raid array. You've fallen out of that already. Things didn't just get worse.

    You have a backup. You hope that Mac going to work. If you get ransomware and I got to tell you, nowadays, the answer's no. There's two sides to ransomware, but we've talked about that before. I'm not going to get into it right now.

    You've got the backup mainly in case the disk fails, or you accidentally delete a whole bunch of files and you want to get them back.

    The next step that you have is disaster recovery. You have a disaster like there's a massive snowstorm that caused a water main to break in the roof. All of your computer equipment is covered with water and none of it will work anymore. In a disaster recovery situation, you now take your backups and you get new machines and you load it all on, and hopefully, your backups are remote. They weren't damaged by the water. Unfortunately, most businesses, again, not thinking this through just hoping, crossing their fingers, that they're not going to be one of that 50% of businesses that is out of business because of a disaster. Actually is closer to 75%.

    It depends on whose numbers you're looking at. So they're hoping. No, no, I'm going to be part of your disaster. Disaster recovery. Is just think of that, of a snowstorm and the roof collapses of a fire and the computers have burned. Can you get your business back in business?

    Then there is business continuity. That's a whole other level of planning and business continuity is where you say, Hey, I need to make sure my business continues to conduct business. If you have a hundred, 200, 300 employees, You're much better off being able to let's say the computer room burns down as an example that or that roof caves in because of the snow and you've lost those computers. You're much better to be back in business in four hours or less. We've had business continuity solutions where we had equipment on site in a different part of the building. If there was a problem in one part of the building, we could failover to the other part. Now this is an awfully big building and we had fiber links between them, but they could be back in business in less than 10 minutes. It's just that quick. That is business continuity, right?

    If you are a public company or you are a division of a public company by law, you cannot be out of business for more than four hours. Now, that's just public companies. By the way, those same rules are in place for doctor's offices, for hospitals, any medical personnel you have to be able to get at the patient's records within four hours.

    How many of us are ready for that? Then along comes a shutdown, remote workers. We're going to get into this a little more detail. We're going to talk about these SCADA systems, supervisory control, and data acquisition. What does that mean? And why is this a problem for all of our infrastructure? How did this guy poison or at least try to a town of 15,000?

    You're listening to Craig Peterson.

    What happened to that town, a Florida city of about 15,000, Northwest of Tampa when hackers got into their water supply and hacked up the amount of lye by a factor of 100.

    Hello everybody. Craig Peterson here.

    This whole concept of having a backup versus some sort of disaster recovery plan versus business continuity is something most businesses really don't pay enough attention to. Now, we've got another problem which is really a business continuity problem. What do you do when your employees can't get into the business?

    When we've set up business continuity for businesses, in the past, what we've done is I mentioned earlier this data center where we duplicated part of it in another part of this massive building. If there was a problem with something, could just be some of the core switches go down or something, we could automatically failover and continue running within 10 minutes. That's one way to do it.

    But how about if the rest of the building went away? How about if your main servers okay, but the roof collapses or there's some sort of a fire? What happens if your employees can't come to work because there's a lockdown? There are so many reasons you need to have business continuity in place.

    We didn't have it right. Not we, as in me, but so many people, so many companies didn't have that. That's what happened in Oldsmar, Florida. They have a water plant. Of course, they have all of the normal things any city of 15,000 people would have. They had in their water treatment plant these devices that are called SCADA devices that are used to control valves. These valves are exactly what you think of a water plant. They're used to control the mixture of various chemicals to divert water around the plant. The source of the water, the type of filter switched over to a new filter so that the older filter can be replaced. In many cases, the main filtration is just done through sand and it has to backwash every once in a while. This is all controlled by computer, nowadays.

    They were running a Windows seven machine. No, I know you're saying, well, I've got Windows seven I'm okay. The problem is Windows seven is no longer supported by Microsoft unless you're paying them ungodly amounts of money. I'm talking about $50,000 a year per machine sort of money. It's just crazy amounts of money. Most companies don't have that, right? I don't know anybody outside the federal government that actually has that. There's probably some, but they will not release it to the general public.

    Sometimes they'll release a few little security patches because something was just so apparent that they had overlooked. But most of the time, no. Most of the time these security patches just aren't available for older versions of Windows. So they had a Windows machine that was controlling this network with all of these valves on it.

    They had that machine hooked up to something called Team Viewer. The idea behind Team Viewer is, Oh, this is really handy. I can put Team Viewer on our control machine. Then I can have my employees be at home and then use that control machine remotely over Team Viewer.

    That's what Team Viewer is designed for, isn't it? Well, as it turns out, they were using Team Viewer throughout the water district. That became a bit of a problem because they did not have proper firewalls to protect it. And they were all sharing the same password.

    The interesting advisory that came out about this particular problem from the Commonwealth of Massachusetts, if you can believe it. This cybersecurity advisory for public water suppliers is talking about how water suppliers can guard against cyberattacks on water supplies. It goes through a lot of these basic things that I've talked about. They should listen to my show every once in a while, right? Or attended the briefings that I had put on for the FBI's InfraGard program. It would be pretty simple for them. The state of Florida came out with some guidelines, et cetera, after the fact. As did Massachusetts.

    They were running Windows seven. They were remotely accessing plant controls. The computer had no firewall installed. Well, that's what they're saying. In reality, Windows ships with a firewall installed, but that doesn't mean it's going to do any good. I talk a lot about that in some of my courses, but the computer was visible to the internet apparently. Okay.

    They all shared the same password. What do you want to bet it was a bad password and employees could remotely log into city systems using this Team Viewer application. It was really that simple.

    Now this actor's here apparently is more than one and they are unidentified. So we don't have a whole lot of information on it, but I did get a notice. It's called a pin, which is a notice from the FBI it's labeled green, which means I can share it with everybody. It's saying that they obtained unauthorized access to it.

    Now, here's the most important part. These cyber actors likely access the system by exploiting cybersecurity weaknesses, including poor password security and outdated Windows seven operating system to compromise the software used to remotely manage water treatment.

    The actor also likely uses the desktop sharing software Team Viewer to gain authorized access to the system. We've seen this, not only with Team Viewer, we have seen this with remote desktop and many other systems that people have been using to allow their workers to get in remotely. All of this because of the lockdown, people working at home. All of this should have been handled properly by having a business continuity plan in place. It's really that simple.

    Now the putting the plan together, isn't that simple, frankly, but we've got to think about what happens here.

    No. I also think about this particular hack and who did it. Well, it could have been the Russians, right? It could have been the Chinese or the North Koreans. We know Vietnam has gotten into the game lately. It could have been any of those guys.

    But do you know who the most likely people are to do this sort of thing? It's somebody who works for the company or in this case, very likely that it's a disgruntled employee. They all shared the same password. They use Team Viewer. I said, I'm not blaming Team Viewer here, but this is not good. This is really bad. This is not just something that could happen at a water plant where they're moving the amount of lye from a hundred parts per million to 11,000 parts per million. They're using it in drinking water to change the Alkalinity, the acidity of the water.

    I don't know, I don't know. We've got to do something about this. I'm going to have some training on this, what you should be doing for remote workers.

    If you're interested, let me know I'm going to plan some, but I'm not going to do it until I hear from you to know it's worth my time to put it all together. Email me M E at Craig Peterson. Let me know that you'd like to know about remote workers or maybe this whole business continuity idea. Again, email me [email protected]. Let me know.

    Hey, you'll find a whole lot of stuff. If you go to Craig peterson.com and it's all good information that you need. Make sure you sign up for my newsletter right there. Craig peterson.com

    Hey, we can't go without talking about Bitcoin. It has surged surged surged. It may go up, it may go down. I'm not somebody who advises on investments, but we're going to talk about what it is and why people are mining it.

    Hello everybody. Craig Peterson here.

    Well, we have a really big thing to talk about when it comes to Bitcoin, but first I have to take a minute and honor a man who has inspired me in broadcasting for decades. A man who has changed the whole face of radio. AM radio was pretty much dead. Then he started his national show. Of course, I'm talking about Rush Limbaugh.

    Whether you agree with him politically, and I think most of you guys probably do. We all have our differences, or not, he is a man that deserves great respect. He changed the face of American politics. He literally single-handedly saved AM radio. He created this whole concept of a nationally syndicated talk radio show, and it has helped to educate millions of people.

    I started listening to him back in the late eighties, quite a while ago. I was just amazed with him and the way he did it. One of the things that inspired me about it is he took callers, but they weren't the guest, he was the guest. They were asking him questions. That is so topsy turvy from how, even today, most radio shows are.

    People would call him up and they would ask him questions and he'd be able to answer them. He also asked them some questions, obviously, in order to figure things out, he also was not afraid to take opposing calls. He would look for those and he would put those at the top of the queue. He would take those callers that disagreed with him before he took callers that agreed with him, his ditto heads, as they like to call themselves.

    When I heard this week that he had passed, I knew it was coming, but it hit me hard. It hit me really hard. He's not that much older than me. Although I remain in really good health, knock on wood here I am just flabbergasted. I don't have words for his passing. So it would not be right for me not to have mentioned a man who inspired me, who educated me, and played a role in my life, such that when he passed, I was just gobsmacked.

    It's absolutely a sad, sad time. I really wish my best, obviously to his wife. I guess Catherine is his fourth wife, so I'm guessing he didn't have the best home life out there. Things obviously didn't do well on that front. I think he's a little bold and brash and maybe that's part of it.

    But my memories of him being down in Cambridge, Mass. I was working as a contractor for about a year and a half at the Open Software Foundation. I was working on the operating system and that was rewriting the TCPIP stack. If you know what that is, it's the basis of the internet today and the Open Software Foundation provided its code to pretty much everybody out there. That's how I can say with a high degree of confidence, the code I wrote is still in use today to help run the internet. I was working down there as a contractor for about 18 months. I also put in the i18n, the internationalization code into many of the Unix libraries and at lunchtime. I had a small radio with me and I would go out and walk around for lunchtime and listen to Rush Limbaugh while I was out walking around. He had been quite the companion for me, gave me a lot of things to think about, disagree with him on, and agree with him on. Conversations were spurred with other people. I've come to realize, I mentioned this to my wife, as well, this week after he passed that as someone who's on radio, call us personalities or whatever you might want to call us. But as someone on the radio, this is a very personal medium. I've come to realize that Rush taught me something. I realized it when he passed, I've never met the man. I have a photograph of him signed by him around here, somewhere. He taught me something else and that is, I never met the guy, yet I felt an attachment to him that I had never felt really to anybody else.

    Certainly, I've never felt that way about a movie actor that died. I've never felt that way about an author whose books I loved. I've missed some of them, some of these books where there a series of books and the author died. You could tell mid-book that the voice changed and it was being written at that point by someone else. I was just disappointed by that. I didn't feel that sense of loss that I felt this week. It helps me to realize. How important it is for me with you guys. Without you guys listening, we wouldn't have a radio station. Without you guys buying from the advertisers it couldn't afford to, pay for the electricity and all of the people that are involved. It's the listeners. Right.

    I have an obligation to you to present the information that you need in a way that you can understand and hopefully in a way that you can use it, right?

    What good is a show like this? If I'm giving you stuff that there's nothing you can do about it? You notice, I always try and do that, but that's the way Rush was too. Rush wouldn't just sit there and complain. Rush would talk about the facts, what's happening, where he thinks it should go, and what we should be doing. What we should be doing as a nation and what we should be doing as individuals. To me, that was very inspirational. Frankly, that's how I've patterned this show. I've had this radio show for over 20 years and I've patterned it that way, where I try and help. If you've ever sent me an email you get a personal reply from me because I am here to help. And I felt that way about Rush.

    I've sent him emails. I'd never gotten responses, right? But you, I feel this attachment to these people. That's part of the beauty of these smaller radio stations, where there are people, we are local, we do care about you. These advertisers tend to be local as well. Certainly, local businesses advertise locally, and we really have an obligation to you, to every one of you. So I appreciate you. I really do. I really do want to help. I am beginning to understand some of the responsibilities that I have it isn't just to help you understand technology a little better to keep your machines clean, to stop your businesses from being stolen from, by hackers, or by Snowfall that might bring your building down.

    It is to help you as best I can, as often as I can. So that's why I do it. That's why I do these courses, the newsletters, everything else. Rest in peace, Rush. We're going to miss you.

    Visit online as well, Craig peterson.com, and sign up for my newsletter so I can help you a little more.

    Well, we really, are going to talk about Bitcoin in this segment. So stick around. I had to talk about Rush this last time around. Bitcoin, the prices are surging. People are mining. What does that mean? And why are they using more electricity than the country of Argentina?

    Craig Peterson here.

    Bitcoin has been around for a while. I don't think anybody out there has not heard about Bitcoin. It is a power in and of itself. We don't know who actually came up with this whole concept. There's a concept behind Bitcoin called blockchain technology. Blockchain technology is based on the concept of ledgers. Where you have ledgers, just like a bank ledger that keeps track of every transaction. There are hundreds of thousands. Just so many ledgers in the world. In order to verify transactions, half of those ledger entries have to agree. So it's pretty basic on that level.

    What is Bitcoin itself, which sits on top of this blockchain technology? Well, if you want to look at it, simply take a look at prime numbers.

    Hopefully, you can name the first five prime numbers, right? What do we get? One, three, five, seven, 11. There you go those are the first five prime numbers and a prime number a number that is only divisible by itself and one, which is why one is a prime number.

    We use prime numbers a lot nowadays. Most of the encryption that you're using is based on prime numbers. If you go to a secure website, you're using something called SSL, which is the secure socket layer and that's what shows up in your browser, in that URL line as a little lock, if you see that lock that you have effectively a VPN, a virtual private network between your browser and that remote site.

    Guess what? You already have a VPN, right? Why use one of these VPNs that spies on you?

    That is encrypted data and it's very difficult to encrypt in between. How does it do that? It's using something known as public-key technology, the RSA algorithm. We're not going to go any further down that, but basically, it allows someone to have a public key and use that public key to encrypt a message. then you, the person who's receiving the message whose private key was used to do the encryption can decrypt it using their private key. So the public key side, and the private keys side, it allows the encryption from end to end. That's what the SSL is all about.

    Well, when we're talking about Bitcoin, we are talking about something that goes and uses some of the similar technology. What it's doing is using these prime numbers. That's what the RSA algorithm is using this encryption algorithm, using these very large, very complicated prime numbers because you get past 11 and let us see 12. That's not a prime, right? Uh, because it's divisible by. Two and six and three and four, and then let's see 13. Okay. That's a prime 14, no 15, no 16. No. It gets more difficult.

    I remember way back when, writing a little program that just found prime numbers and it looked for prime numbers and the easiest way to do it was I would start, first of all, you take a number, divide it into. There's no reason to go any higher than that when you're trying to figure out if it's prime or not. Then I would start looking at some of the base numbers to try and figure it out. Of course, real mathematicians were able to figure out better ways to find primes.

    Well, when we're talking about Bitcoin and some of these other cryptocurrencies, they are also using these very large prime numbers, just like you're being used for this public key encryption. They also have some other parameters around some of these prime numbers.

    To have a Bitcoin is to have this digital number that represents a unique prime number. If you want to mine, what you're doing is you are trying to find a prime number that no one has ever found before, just to oversimplify things a little bit. You find that prime number and Tada now you have a Bitcoin. Sounds easy enough, sounds quick enough. It is not easy and it is not quick.

    It's not just based on the prime number algorithm, but we're keeping this simple here. We have found millions now of these Bitcoins. I should look that up and find out exactly how many, but there are many Bitcoins. The whole algorithm, the whole system is set up to do some restrictions here, there's only a certain number of these Bitcoins that will ever be mined.

    It's estimated that something like 20% of the Bitcoins that were found has been lost because the encryption was used to keep the keys. People forgot it.

    You probably heard about this guy that has a quarter of a billion dollars in Bitcoin in this wallet. He only gets eight tries before it auto destructs. He hasn't found them yet. There's a quarter of a billion dollars that's unreachable, but that's what we're talking about here.

    Bitcoin mining. In this day and age, Bitcoin mining is so hard and it takes so much computing power that it is using a couple of things. First of all, the thing that bothers me the most is it's using up these GPU's these graphical processing units, because GPU, which we typically use for graphics processing is set up so that we have are hundreds, thousands of processes that can be happening on that card simultaneously, various small little tiny processes that can be set up to somewhat be optimized for Bitcoin mining or mining, any of these other cryptocurrencies.

    Then the people who really want to make money on mining these cryptocurrencies have machines that are special machines. They are designed specifically to mine, one type of coin, one of these crypto coins. We're talking about Bitcoin. There are machines that are designed to mine bitcoins, go to E-bay and look for Bitcoin miners. They used to have them on Amazon. I haven't checked in a while, but you'll find them in both places. At least you used to be able to, you can certainly still find the money bank. You'll find some that are old, that are used and some brand new ones.

    Well, it is expensive to mine them. One of my sons and I, decided years ago to try and do a little mining. We probably should have tried harder but we gave up. It was a, who knows what's going to happen with Bitcoin.

    There are so many cryptocurrencies and today there are people introducing new cryptocurrencies all of the time. I avoid those like the plague because you never know what's going to happen.

    Bitcoin is definitely the 800-pound gorilla out there. We were able to mine I guess my son said he mind a couple of other little currencies they're worth a penny or two, not a very big deal.

    We have now so many people in China that were doing Bitcoin mining China could not produce enough electricity to mine Bitcoins. China went around and shut down anybody that was mining Bitcoin. We have something called the Cambridge Bitcoin electricity consumption index. This is an index designed to figure out how much electricity is being used in order to mine Bitcoin.

    This is, of course, over in England, the University of Cambridge the judge business school. I'm looking at a graphic right now that they have, and this is showing the electricity and Bitcoin mining. They actually have all of the data for downloading, if you ever wanted to do some serious analysis. It's showing there was hardly anything, if anything, back in 2016. Summer 2017, when it started to jump up and that's, of course, when the price of Bitcoin started to go up.

    Why? Well, mainly because of ransomware. People having to pay ransomware and buy Bitcoin in order to pay that ransom.

    In terawatts. Now we are showing at about, okay, this is Wednesday, February 10, 2021, 288 terawatts of electricity on that one day. Isn't that something? The amount of electricity that's being used has been surging because, of course, the price of Bitcoin has been going up. Just been going up in crazy, crazy rates. The amount of mining going on has doubled, almost doubled since October last year. We're talking about using more electricity than the entire country of Argentina, the Netherlands, and the United Arab Emirates. It is absolutely amazing, amazing how much we're using. People are alarmed by this. Countries are having major problems in trying to figure this out.

    What else is funny about it? They talk about Bitcoin being one of these so-called green technologies. Well, it turns out that Bitcoin because of the electricity that it's using for people to mine now has a carbon footprint comparable to the entire country of New Zealand. It's producing about 37 megatons of carbon dioxide per year. I think that's funny, frankly, because they call it green. Right?

    It's like green cars that are electric. Well, guess what? They aren't green in so many ways. They're cool as heck don't get me wrong, but don't think they're green because they're not. A lot of reasons for that. I've talked about it many times in the past, on my radio show.

    If you go to my website, you can just look that up and you can find out why, and I've got hard numbers there, anything else?

    All right, everybody, make sure you visit me online. We have started some new stuff. If you are a frequent reader of my, now Sunday newsletter, which has my show notes. You are getting also one or two other newsletters during the week just short pieces of training.

    I'm trying to help you out, but if you're not opening that newsletter if you don't download the images. That's how I tell that you opened it, then you're not going to get all of the supplemental material, including some audio programming that you can't get anywhere else. So make sure you go to Craig peterson.com and sign up for the newsletter. Open the silly thing.

    So you get all of this free training and more. Craig peterson.com.

    Apple has been really busy trying to make sure we know who's using our data and what they're using it for turns out Google's not too happy about that. You'll be surprised what they did this week.

    Hi everybody. Thanks for joining me.

    I've talked here about how Apple is really taking some major steps up in trying to defend our privacy. Apple does not make money off of our data. They don't sell it. They don't compile it and then sell it, Google, however, is trying to be the repository of all of our information. So much for the don't be evil thing. Right?

    Well, Apple's got these almost like nutritional labels. You remember when the CDC or it wasn't the CDC, it was some federal agency, I can't even remember forced food companies to put labels on the packaging, telling us about calories, fat, various other types of things. You could make a bit of an informed decision by looking at that.

    Obviously, there's other stuff that I don't know what this word means. I don't know what that is. What's red dye number two, all of those types of things, but at least it brings it to your mind. You can also see how many servings there are. It'll say this muffin is 500 servings and only a calorie a piece, right.

    The reality is that box is really meant to be two or three or four servings, including that Coke that you might be drinking. I am more of a Pepsi man, but I haven't drunk either in years now, frankly.

    Well, Apple is trying to do kind of the same thing. They've got millions of apps up at their app store. In the app store, of course, you can not only find the apps, but you can download them. You can buy them depending on what the app is. Most of these apps that are free, are really not free right? We've talked about that before. I don't know that we need to get into a lot of detail, but it goes back to that saying of if it's free, then your, probably the product.

    That's been very true. Apple and Google both have caught a lot of companies. Who's been trying to steal our information successfully in some cases. Obviously, that's a bad thing particularly when you don't know about it.

    So these labels that Apple is having app developers put on their apps have got a whole bunch of people upset, Google ran full-page ads in newspapers, complaining about it and how it's going to hurt small business.

    The reality is, it is going to hurt some small businesses that do advertising. That's very, very narrow. It's going to hurt me if I'm doing that type of advertising no question about it. I don't do that. But one of these days, I hope to be able to do it.

    What it is doing now, is stopping companies like Facebook. Facebook has always been doing tracking, not just when you're running their app. Facebook has been getting information from other websites from web pages like mine, for instance, I've got a Facebook pixel on my website so I know if you came from Facebook, what you're interested in and in what you're doing so that I can present information to you based on your interest.

    I'm doing now for the very first time, this week, a similar thing. With my newsletter. If you have, for instance, said that you're interested in my improving windows security course, the newsletter isn't going to bother you about that anymore because I have this little signature at the bottom, here are a few things that I could do for you. If you want a little extra help. Some of it's paid, some of it's free, obviously, but. I think it's annoying personally to keep getting the same message every week. I've put into my email program, some conditional stuff so that if you've asked for the improving windows security course, I'm not going to bother you about that anymore. By the way, no, the course hasn't started yet. It's a labor of love. What can I say?

    There are a lot of different types of tracking that are done and not all of them are bad. For instance, I just gave you an example of something that I've started doing, and I am doing some tracking in order to do that because I don't want to annoy you. I want to give you the information you need when you need it, right? Bottom line. It's like, I've always said, if I'm interested in buying a Ford F150, then I don't mind seeing ads for it, but if I'm not interested in buying a pickup truck or a Silverado, why would I want to see a GM ad when I'm going to get a Ford, right? It's really that simple.

    Google, as I mentioned, has been complaining. They've done the full-page ads. They've complained to congress critters they've spent so much money. Lobbying, it's a real problem and a difficult solution to it. If you want to get rid of lobbyists, obviously the bottom line is you have to get rid of the money going to, and coming from Washington DC. If they don't have control over our money. If they don't have control over our lives. Then the lobbyists aren't going to be going there.

    I don't care which side of the aisle you are on, or if you're right in that middle of the aisle. Lobbyists do not represent our interests as a nation. That's the bottom line.

    Google's down there spending money saying, Oh, you're going to hurt the small businesses. When in reality, the biggest target that's going to be hurt by Apple cracking down on people taking our information without letting us know is Google.

    It's going to be a problem for Google, so how to get around it. One of the things that Apple has for its apps that are on your iPhone and on also your tablets is a tracker. When was the last time that app was updated? Of course, when the app gets updated, Apple has a look at it and tries to see if there's anything malicious going on.

    Now it's impossible to catch everything. Some of the stuff is very well, obfuscated. I can't blame Apple or Google for letting some of this malware through. But the bottom line is they want to know. When did you update it? What's going on?

    Google apparently flagged its own Apple apps. The apps designed for iOS.

    Think about the Google apps, obviously. There's the Google app itself. There are Google maps. Apps can be very useful, including Waze. I was so upset when they bought Waze, but that goes into the anti-trust stuff that is going on right now in Congress.

    But I was looking at the phone and looking at the app and they were flagged as out of date. It had been two months since Google updated iOS apps. It has been updating its apps in the Android space, but not the iOS apps. The theory is that Google has not been doing updates on its Apple apps because of this new privacy labeling that Apple's come up with.

    You see back in early January, Google could have said, we haven't been updating our apps because of the lockdown. The engineers are busy trying to handle this and that. We just had the holidays and I would have accepted that you would have accepted that. Well, that was what now six weeks ago. Google has, every year around the holidays a code freeze, which means no one can make any changes, that is done with right now. The company Google should have released two new versions, particularly since they come out with the new versions for the Android operating system, Gmail, Google Maps, Google search, Chrome, drive, photos, keep and Duo have all been frozen since Apple launched these privacy requirements.

    What do we think is going on? Well, it looks like frankly, Google just doesn't want us to know what data they're trying to get at. What they're doing? What they're selling? What they're tracking, the inter-app tracking.

    Google's been doing as well as Facebook and many of these others. What's the easiest way to not have to worry about that don't have a new release so that you don't have to abide by the new terms from Apple, which include, Hey, what information are you gathering? How are you gathering? What are you doing with my personal information?

    It looks like Google took the easy way out again. It's phenomenal. I'm looking right now at, Gmail and it has not been updated on iOS since December 1st. The Android version of Gmail has had four updates since then. That's a pretty big deal, frankly.

    Apple's definitely got people's attention. The app developers' attention. I am glad they're doing it as a user. I'm not so sure. I'm glad if I decide to try and do targeted marketing through some of this online pay-per-click and some of these other ways of reaching people. But you guys, already how I feel about you and I'm going to be giving you lots of good information.

    Some of you guys become my clients because your businesses and you need that little extra help for your poor overworked IT people internally.

    Lots of what's going on with Google. We'll see when they do come up with the next update, but it's a real problem.

    Hey, if you want to get my weekly email where I have my show notes.

    Now, these show notes are what I use here on the show. That's what all of these stations pick from, my show notes. The only way you can get them and get information about what's going on in the world and things you have to do right now is by signing up for my email.

    Craig peterson.com.

    Boy, I love space stuff. I have for years. I was so excited to play an extremely minor role, but to get involved with the NASA space shuttle program. Let's talk a little bit about what's next up for it.

    I remember that day. I can't remember what day of the week it was, but that day when we landed on the moon watching it live. It was just mind-blowing. Of course the newspaper, the first time I had ever seen a color cover on a newspaper and it was a picture of our astronauts there on the moon. It was just so incredible.

    Of course, you're listening to Craig Peterson.

    NASA has been trying to get back to the moon for a long time. We haven't been funding them. Priorities have changed. A lot of people say why don't we spend the money domestically rather than on the space program?

    The space program has provided us all kinds of benefits over the years. It's benefited mankind, not just by giving us things like Tang, for instance. It's given us all kinds of technology and science that we would never have had any other way. I'm looking right now at a report that was put together by AIESEC, which is the international space exploration, coordination group. It just a top-level executive summary. Numerous cases of societal benefits, new knowledge and technology from space exploration, things like solar panels came from the space program, implantable heart monitors. Cancer therapy, lightweight materials, water purification systems, improved computing systems, global search and rescue systems, course rockets as well. There's so much more, things we just weren't expecting. Thin materials, power generation, energy storage, recycling, and waste management, advanced robotics, health and medicine, transportation, engineering, computing, and software. Not just the $800 hammers. Okay.

    Culture and inspiration. As you can tell I find this very, very inspiring. We've got all kinds of things that we are using just day-to-day that we don't even think about it. As space scientists, engineers overcome obstacles, in some cases, we never even realized were there and I think that's another phenomenal thing.

    Well, right now, what we're doing is having private organizations competing to send our missions up. For many years now, since the space shuttle program was ended and it lasted far longer than they expected it to. But now that the space shuttle program has been over.

    We've mostly been using Russian rockets to get our astronauts into space and also to get things to things like the international space station. What are we going to end up doing in the future?

    We already know who was it, Bob and somebody, right? A couple of astronauts. They went up on the Elon Musk rocket and docked with the space station.

    It was again, one of the most amazing things ever. I sat there glued watching it on the computer. It was just, wow. To see that.

    We're looking at going to Mars. Now, we're looking at exploring some of Mars's moons more than we have in the past, doing all kinds of things that are just going to make a huge, huge difference to humanity.

    It's been quite a while since that Apollo program of 50 years ago took humans to the moon and they were using chemical propulsion. What that means that you had rocket engines burn liquid oxygen and hydrogen in a combustion chamber. Nowadays we're playing around with hydrogen peroxide in order to get that oxygen.

    They use to have their advantages and that gives NASA the ability to start and stop an engine really quickly. Back in the sixties, this was the most mature technology for space travel. We'd been using rockets. They were really piloted in world war two. It made a lot of sense back then.

    However, now we've got some other problems we've gone to prepare for. We're going to be sending four or more astronauts to Mars. We want to colonize Mars, but relying on chemical propulsion to get beyond the moon, bottom line, it just won't cut it. The main reason is the amount of rocket fuel. Most of that rocket fuel is going to be consumed getting out of the atmosphere.

    It's crazy how much we're talking about $2 billion for a flight of one of these huge rockets. These block one B configurations, NASA's SLS or space launch system rocket, is going to be able to carry 105 tons to lower earth orbit. That's a lot of money. They're not going to be able to get that many of them up there. That only takes it to lower earth orbit.

    Now, of course, the idea is to do what in fact, the Apollo mission had looked at, which is get the fuel up to orbit and then have a rocket up there that maybe is assembled an orbit and is refueled in orbit. Then it goes to the moon. That was actually the plan NASA was originally going to pursue.

    We're looking at that now when we're talking about going to Mars while we're talking about going even further out there. What can we do? Just for the fuel, by the way, $20 billion just to get the fuel up. That's just absolutely crazy.

    There were some tests that were done, some studies that were done on behalf of NASA for a mission to Mars in 2039. So this one's quite a ways out. Of course, Elon Musk wants to do it even sooner. He is relying on these chemical rockets. By the way, to get back home from Mars, he's relying on being able to make rocket fuel right there on the surface of Mars and then charge up the rocket engines in the launch vehicle and then launch back up to get back to earth.

    It's going to be really, really interesting to see what we end up doing. They are looking at a nuclear propulsion system. It's going to be interesting. NASA has had a budget for this. They got $110 million for nuclear, thermal propulsion development. We know a lot about nuclear fuel nuclear propulsion. We'll see what happens.

    This starship concept that space X is building to send humans to Mars using chemical propellant. They're countering the costs involved with the chemical propellant by having this low-cost reusable launch system. We just saw one blow up here a few weeks ago, but that's okay there was no intention of having astronauts sitting on that candle. That was just a test system. We've seen him repeatedly now land successfully.

    All of those boosters and it's amazing what's been happening now. They're not the only ones. We've got a number of other companies that are working on these types of systems. Space X, ultimately we're talking about pushing the boundaries of reuse and heavy-lift rockets to extreme limits which is exactly what space X is trying to do. They're looking for some other answers.

    Hey, make sure you sign up Craig peterson.com. I want you to make sure you have all of the latest materials.

    Craig peterson.com.

    We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up killing people. Yeah. Yeah. Death by a police officer. Here we go.

    If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information that I have available my podcasts, and a few articles that we've written, and you'll also have the opportunity to subscribe to my newsletter.

    I just want to get the message out is my bottom line.

    We have these home cameras that we have welcomed into our homes. And one of the ones that have been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

    And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

    There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them live Real-time access to all of the ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

    And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring doorbell cameras

    Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because why does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate, the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

    And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened on a number of occasions and far more than we like to talk about is that there are.

    The bad guys or people who don't like their neighbors and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting a prank led police to shoot dead, a 28-year-old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

    After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth. You can have.

    Teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. And apparently, they believe the report was an act of swatting where.

    Somebody makes a false report to a police department that causes the police to respond with a SWAT team. Now the audio of these emergency calls been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

    The color also said he had a handgun that had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

    When Mr. Finch came to the door, they said one round was released by the officers after the 28-year-old failed to comply with verbal orders to keep his hands up. Why would he, what did he do wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

    And they said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them dead or Injured nor taken hostage. His family told local media, he was not involved in online gaming.

    Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that those hackers are out there who do this swatting maneuver on somebody. And then they have the hacked ring camera at that house and they watch the SWAT team respond. Can you believe that?

    And the FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices. How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that his.

    His revenue, his pay from the work he was doing, delivering food to people's homes were stolen by a hacker because he was using the same email address. Yes. To log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells that have allowed hackers to steal pet network passwords, et cetera.

    In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, causes death, many examples of that, and we're still reusing passwords. Give me a break.

    We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

    But anyway our businesses and government got broken that's what we're going to talk about right now.

    Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly, since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

    Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

    And in fact, That's a big problem still, but we'll talk about this right now. SolarWinds is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWinds. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

    We dropped SolarWinds as a vendor, and the reason we dropped them and we made it very clear to them as we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWinds a couple of years ago, and they wouldn't do anything about it.

    So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWinds. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

    Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presumed now to being the hand of a Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

    He said SolarWinds, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it easy target interviews with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWinds websites stopped offering the client the compromised programs.

    Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached too, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

    This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because, I didn't tell you guys this, but I do love the fact that I was right again.

    How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce Schneider.

    You've probably seen him before. He is also, I think he writes for the Washington Post. But remember when this came out the word about the SolarWinds hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

    Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

    In other words, going out after other countries in the cybersecurity realm. And we benefit from the lack of norms that are in cybersecurity. But here's what I really liked that Bruce said and I agree with it entirely. I'm glad, he must listen to the show. The fundamental problem is one of economic incentives.

    The market rewards, quick development of products. It rewards new features. It rewards spying on customers, end-users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram, or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

    It doesn't reward reliability past a bare minimum, and it does not reward resilience at all. And this is what happened with SolarWinds. SolarWinds ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

    It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure it. It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

    I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely inexcusable, right? Inexcusable. So this is happening with SolarWinds right now, but it's going to be happening with other places out there.

    We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWinds is a Puerto Rican-born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

    The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from the tech beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the US treasury department was hacked the US Department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cybersecurity, and infrastructure agency CISA, the department of Homeland security, the US department of state, the department of justice, the national nuclear security administration, the US department of energy, three US state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others.

    I use two of those.We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem.

    How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody to use a password manager and I will have a course on that this year.

    Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

    The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an IT security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

    Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have email coming in and going out SMTP Imap.

    They should be controlled and controlled pretty tightly. According to the department of justice, apparently, their email accounts were compromised about 4,000-ish people's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

    It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

    Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email [email protected] and let me know, be glad to send you stuff.

    ME@Craig peterson.com.

    Take care guys.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 21 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Amazon, Digital Rights, Libraries, and Apple Music

    Good morning, everybody.

    I was on this morning on WTAG with Jim Polito. We discussed the new Amazon, ebooks, libraries, digital rights management and what some States are demanding from Amazon. Here we go with Jim.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] In Rhode Island have bills as well as New York that would require Amazon, as well as everybody else, to sell eBooks to libraries with quote reasonable terms endquote.

    Jim Polito: [00:00:13] Okay.

    Craig Peterson: [00:00:14] Hey everybody, Craig Peterson here. Just got off the phone with Mr. Jim Polito and we had some fun talking about libraries, Jeff Bezos and even George Orwell, got into the act here. Anyhow, here we go with Mr. Jim Polito.

    Jim Polito: [00:00:34] Hey, Amazon started off as a place to sell books. You know, online books and they basically destroyed the bookstore. I mean, we contributed to it. But now it seems that they're out to destroy libraries. Taking over the world, isn't enough for these folks.

    I don't know, that's the accusation. Well, let's see if we can confirm it. Let's bring in our good friend and tech talk guru of Craig peterson.com. The man that website is named after, Craig Peterson.

    Good morning, Craig.

    Craig Peterson: [00:01:13] Good morning, Jim.

    Jim Polito: [00:01:14] Oh, so here's the deal? We were just talking a little while ago about Jeff Bezos, started with his garage selling books out of there. Then mail order, then all of a sudden they sold everything.

    They basically changed retail. They made what we told online shopping would be like 25 years ago. People said, Oh no, you're going to be buying everything online. We said, sure we will. But we are, COVID helped that.

    Now there's talk that he's gonna close libraries and I went wait a minute. Is this a wild accusation?

    Craig Peterson: [00:01:48] Well, it is kind of wild, and certainly an accusation. Unfortunately it's also true. If you look at the libraries work over the years, Jim, you go in and you borrow a book. Well, where did that book come from, right? The library bought it. Libraries for a long time, have been paying more for a book than you would. You might go into the bookstore and you pay 20 bucks for the book, but the library is going to pay a lot more for that same book. 50, even a hundred dollars sometimes.

    So Jeff Bezos is doing right now. Is okay great. You've been paying for these books over price sometimes as much as a hundred dollars for one ebook and it can only be lent so many times, that ebook can. If you want to have five copies of that book out for people to read, you have to buy five licenses, that's what it's been.

    Jim Polito: [00:02:44] All right. So wait a minute. Let me just make sure, because make sure I understand this. So in the old days before we had, you know, you bought a book online and you read it on your nook or whatever.

    Hold on a second. So if I was buying a book for a library. I paid a higher rate because the library knew you were going to be loaning that book out, yada, yada, yada. Almost like the publisher said, Hey, we want a little bit more than the average person for this book. Is that true?

    Craig Peterson: [00:03:14] Absolutely.

    Jim Polito: [00:03:15] Okay. All right. So now I get this, you have intellectual property. You have a book that is virtual. I mean it's online. If you are a library and you want to let people be able to read that, download it and read it. You're going to have to pay a pretty penny to Jeff Bezos?

    Craig Peterson: [00:03:38] Yeah. If he will sell it to you. See that's the change that's happened more recently? Jeff Bezos has decided, well, Amazon, right? I'm not sure it was him personally, but they decided that it will not sell, at any price, downloadable versions of it's more than 10,000 eBooks it publishes.

    Think about an acquisition that Amazon made a few years ago, I have been an Audible subscriber for many, many years. Of course, Audible is the company that sells audio versions of books. Amazon bought Audible. Amazon has said, okay, you used to be able to go and borrow tapes at the library, and you'd listen as you're driving or whatever. You kept up on the latest business book or history or whatever he wanted.

    So Bezos also owns Audible , which is number one for audio books. They say, Hey, listen, not only, are, we not going to sell any of our eBooks to libraries, but we're not going to let them get any audio books either.

    Jim Polito: [00:04:43] Wow. Now that is pretty bad. Look from a business perspective, I understand. You're selling a product that now, why would someone buy it, if they could just join the library and download the book.

    There's gotta be somewhere in between. So libraries will be destroyed. I mean, libraries are great places for research and other things and talented librarians can help you out quite a bit. A talented librarian sometimes is a lot better than what Google will tell you. When you go into a search about a certain topic. Librarians are much better, and don't, usually have an agenda, like Google. You should buy this while you're researching that, you know what I mean?

    This could completely destroy libraries.

    Craig Peterson: [00:05:35] Of course, we're on in Rhode Island and right now. Lawmakers in Rhode Island have bills, as well as New York, that would require Amazon as well as everybody else to sell eBooks to libraries with reasonable terms and quotes.

    So we'll see, we'll see what happens, Maryland's already passed a law like that, but this is a real problem as you go forward.

    Now, remember, Amazon is the one you mentioned, the Kindle, or actually you mentioned the Nook

    Jim Polito: [00:06:06] That'sBarnes and noble, isn't it? Yeah.

    Craig Peterson: [00:06:08] Yeah, it is whoever they are. Yeah.

    Jim Polito: [00:06:12] Wait a minute. Hold on. Barnes and Nobles is on the phone.

    Danny DME. Don't take that call. Yeah.

    Craig Peterson: [00:06:21] Yeah. So whoever they are. Amazon has the number one ebook reader. Now, for those that have never done this, and ebook reader allows you to keep hundreds of books right there in this little almost like a display. They're fantastic. That's how I read 99% of my books.

    So they've got the number one ebook reader out there. And because of that, they kind of control the whole thing.

    But if you bought George Orwell's 1984, you might remember this was a few years back, Amazon decided you couldn't have that book anymore and removed it from everybody's ebook reader. All of the Kindles, they remove copies of 1984.

    Jim Polito: [00:07:05] What is the reasoning behind this, because I thought that 1984 was no longer under copyright, but I could be wrong.

    Craig Peterson: [00:07:10] Yeah, it is. The copyright holders told Amazon. That they didn't like the terms Amazon was putting the books under. So Amazon pulled them all back.

    That's another problem with eBooks, especially with digital rights management, they can take them away, that copy that you have in those Dr. Seuss books could disappear from your Kindle, because you don't own it.

    You see, if you buy a book and you read the book and you want to have a yard sale and sell the book for a buck or whatever it is, you can, because you own that book.

    If you get a book from Amazon on your Kindle, or any of these other places, you don't own that, in almost every case. You're just getting a right to read it and. They can pull it back.

    Jim Polito: [00:08:02] You know, it's interesting. My, my neighbor across the street, when he retired Dominic, Dominic, and his wife, Lucy, she's a school teacher. She's still working. He built one of those beautiful boxes that looks like a really big bird house with a glass door and it's for the neighborhood, put a book in, take a book, whatever. He can do that because people own the books. You own it.

    Craig Peterson: [00:08:25] Right.

    Jim Polito: [00:08:26] Good. Hey, whatever happened while we're on this topic with Apple and Apple music, when I downloaded a song for 99 cents and I thought I owned that song, I technically, did they change this? I technically didn't own it.

    Craig Peterson: [00:08:45] Yeah, you never have actually. That's the way they're doing it, nowadays. Apple said, Hey, listen, we're going to do this. And Amazon did too. It's going to be much cheaper for them to distribute it. But again, think back, you and I both remember albums, records, the black vinyl, you know, or that, of course the acetate and other things and we switched over to CDs. The compact disk. People don't know, those are thesedays either. Right? It was much, much cheaper for the record industry to produce a CD than it was to produce a record. Their costs went from a couple of bucks down to just a dime, but they charged more for the CD.

    What Amazon did. Yeah. More margin. Is, they said, Hey, listen guys, your distribution costs are going to be nil because all you're doing is copying digital books around. You're not going to have to have a warehouse. You're not going to have to ship these. You're not going to have trucks or anything else. We expect you to sell them for less. And the Amazon using its market power strong armed these publishing houses to lower their prices.

    Now the publishing houses are really pushing back and saying, no, you can'ttell me I can only sell it for $10 and make $9.99 cents. Whereas before I was only making $2, now I want more money and it's a shame, but that's, what always happens.

    Jim Polito: [00:10:11] And then your Don Quixote and you're going after windmills. Because you're going up against Amazon.

    This is one of the dangers of a big success, like Amazon. You know, what's sad is in the whole thing. 1984, isn't it ironic that George Orwell's book about big brother and this and that you can't get it on Amazon.

    When in fact the people who are using Amazon should know a little something about big brother, and it would be a good book for people to read right now.

    Craig Peterson: [00:10:46] You can get it.

    Yeah, it was just temporary. You can get it. You can get it.

    All right. Good. I'm glad his descendants have, and they've worked at it. Craig fascinating is usual with you.

    Folks. We always podcast segments. Which you can get on the station website, go to the Jim Polito show. On that page, you'll see Jim's podcasts on the right hand side. Just click there and this will be podcasted.

    Craig, if folks want to get more information from you, how do they do it?

    Well, just go online to Craig peterson.com and I also have my iHeart podcasts and tolisten to those things, just go to Craig peterson.com/iheart. That'll take you to the right spot.

    I was listening, in France, iHeart, so I can pick up my safe space.

    Jim Polito: [00:11:37] Nice. Craig as usual. Thank you. You always bring great stuff to the table. We'll talk with you next week.

    Craig Peterson: [00:11:43] Take care, Jim. Bye-bye.

    If you're in the healthcare industry, I am speaking for the big Massachusetts association this Friday. I am conducting a webinar for them on, of course, cybersecurity, particularly in the healthcare industry. If you are a member of an organization of some sort, and you'd like to have me on and do a webinar for you guys to let me know, I do make some time available for that and I may be able to help you out.

    Just email me M [email protected]. I know of few of you guys are going to be there on Friday at 10:00 AM. I think it is as we go over healthcare industry stuff. Then I'm also going to be doing a few more webinars afterwards, delving into some of these topics a little bit deeper.

    All right, everybody take care.

    We'll be back tomorrow.

    Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • AS HEARD ON NH Today WGIR-AM 610: Irresponsible Behavior of States with Regard to Websites

    Welcome,

    Craig Peterson here. This morning I was on with Chris Ryan on NH Today. I jumped right into a conversation in regards to the irresponsible way that the States and Federal Government have been going about creating websites to schedule and distribute the Covid-19 vaccines. Here we go with Chris.

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Instead of going out to the private sector and say, you know what, booking an appointment for a vaccine. That's a lot like booking an appointment or a ticket to go see a concert. Why don't we just use something that already exists. There's dozens of them, like Cvent and just modify that slightly. Have that company modify it.

    Well, you're familiar with the debacle that was and is. It's still there. It's just crazy. The problems with healthcare.gov. We got the Feds now rolling out their own websites. We've got States rolling out their own websites.. What can we expect from that? That's exactly what we talked about this morning, Chris Ryan and I on NH Today.

    Chris Ryan: [00:00:45] Craig Peterson joins us on the show, now from tech talk that you hear on news radio 610 and 96.7 Saturdays at 11:30 AM. Craig, how are you?

    Craig Peterson: [00:00:54] Hey, good morning, doing pretty well. You mentioned power, we lost it a couple of times over the last two days. Its no fun with all this wind.

    Chris Ryan: [00:01:03] Indeed.

    I could go into my pitch for the automatic standby generator from Generac, which you should get one of those. I'll refrain from going all in on it.

    Justin McIssac: [00:01:11] Nicely done.

    Chris Ryan: [00:01:12] But we do, we do recommend that, particularly in this given environment.

    I want to ask you about the prevalence of scams and the prevalence of identity thefts and things of that nature. How much of that has to do with our usage of phones and hackings and things of that nature? We heard last week, from the States aspect of securities, regulation and protection. We've talked a lot about this outside of just your appearances. Has there been a sizeable uptick as in regards to that area?

    Craig Peterson: [00:01:48] Yeah, there has been. What's interesting too, is it's been both directions. We've seen a huge uptick in finding some of these problems. Some of them have existed now for many months, maybe as much as a year or more. We only recently found out about, and this includes hacks from the Chinese and from the Russians, and of course that's nothing new, but the depth of these attacks has been brand new.

    It's just astounding how they have really come after every last one of us, particularly businesses. They've been very, very targeted. Government agencies have been hit hard. DOD, Department Of Defense contractors have been hit hard.

    You mentioned things like our smartphones that we're using all of the time now. Those are also starting to get hit. We've seen some responses. Samsung has said, Hey, we are going to support our phones now with security updates for three years or more.

    It looked like maybe we did something in return because these Russian government websites all went offline after we vowed, President Biden said, we're going to retaliate for some of these attacks.

    Chris Ryan: [00:03:08] That's really interesting. Whenever these things take place, whether there's an outage of a particular server or a website goes down, one of the first things that comes into my mind. Is this a glitch? Is this a problem? Is this an upgrade? Or they hit their their capacity. Or is this something a little more nefarious? Generally, is it just when a website goes down or a server is having some problems. Is it generally not nefarious or a lot of times is it well

    Craig Peterson: [00:03:36] It's a little bit of both.

    A lot of times it is. I've got to say that more recently, over the last year or so, we've been seeing something that we'd never seen in the Internet. That is that the internet was designed to be able to withstand atomic blast. It was very, very decentralized. The decentralized internet tended to be a very stable internet.

    What's been happening more recently is that there have been acquisitions going on. We've got more and more the internet concentrated in individual hands. Look at how Amazon is running about 60% of the internet traffic, nowadays. Some of it, it's generating, et cetera.

    We have seen, frankly, companies and Amazon is not one of them, but companies who are less and less able to understand what the consequences of their actions are. They're making changes to the internet and the networks.

    These big outages we've seen over the last year, almost all of them were due to, let's just call it incompetence on the part of small companies that have been buying large parts of control of the internet. That's going to be continuing for quite a while.

    So, it's not necessarily nefarious when something goes down. In fact recently, it's been a lot less nefarious than it used to be. It's just the normal course of things. More and more power concentrated in fewer and fewer companies that have less and less ability to do what they shouldn't be doing.

    Chris Ryan: [00:05:13] The Washington Post had a really good article this weekend about the rollout of the new vaccine website and the federal website. Intalking with Kathleen Sebelius, who was the Health and Human Services secretary during the Obamacare and healthcare.gov roll-out, which of course was a disaster.

    This website rollout is obviously significant. Every aspect of this is significant because Biden has called his shot. He has said, this is when things are going to take place. He has set a date. He has given that date. And, some may view it as being ambitious. Some may say we're already on that glide path, anyway.

    The aspect of pushing forward, a website of this nature, how do things go wrong? How could they go wrong? Particularly in light of what happened with healthcare.gov, which was delayed for weeks, as a result of various glitches, despite spending millions and millions and millions of dollars on it.

    Craig Peterson: [00:06:11] Yeah, my, I predicted that correctly, by the way. I had said it will take the about three years to get healthcare.gov to be working properly and that's exactly what it took.

    We had massive outages. The problem I see here with this Federal Government roll out, this new website that was announced. Americans, all being eligible for the vaccine by May first. It's all part of a strategy that has been around a while.

    The problem is that somehow businesses think that we're different. My business is entirely different from your business. Yet all businesses are 96-98% exactly the same. We have the same problems. The same concerns. Governments doing the same thing instead of going out to the private sector and saying, you know what? Booking an appointment for a vaccine that's a lot like booking an appointment for a ticket to go see a concert. Why don't we just use something that already exists. There's dozens of them, like Cvent. Just modify that slightly, have that company modify it. No, instead of that, we've got all of these people working for these government agencies, spending tens of millions of dollars of taxpayers' money to roll out something that is going to have major problems. We've seen that again and again, it's to me, Chris, just ridiculous what we're doing.

    We could have this thing rolled out in a week from start to finish and have it cost of maybe a couple of hundred grand total with all the modifications and have it working day one.

    Chris Ryan: [00:07:51] Yep. I mean this is the same thing that happened with healthcare.gov. If you had gone to, and that was in my view, a simpler website than this one is, you got to connect people with the location, the availability and all that the healthcare.gov in my view was a little bit easier. There was, not as much of a time constraint and there were best practices about those types of websites that already existed and could have been done at a fraction of the cost.

    It'll be fascinating to see how much this vaccine website plus, I mean the state of New Hampshire just rolled out their own website on this. Now you have duplicity as well, where you can go to your state website, you go to the federal website. Could you go to both and shop for a better date? Are they both drawing from the same, you would assume from the same locations, right?

    You go to the federal website, you go to the state website, you're going to get your vaccine still at the same spot, I assume. We've spent money, federal money on a state website, and now we're going to spend federal money on a federal website where they're both going to be doing the same thing.

    Craig Peterson: [00:08:53] Yeah. Yeah, this is a problem and frankly, the biggest problem they've got is the back end integration. I inferred from what you were saying, which is how do we tie it in with the local Rite Aid store? All of these different tie-ins that have to occur. It gets very, very, very complicated.

    Frankly, this is simpler than what they did with healthcare.gov, which had a lot more tie-ins to insurance companies in the backend. Leave it to the feds if you want something to get really messed up

    Chris Ryan: [00:09:23] As always, I appreciate you joining us here on New Hampshire today.

    Craig Peterson: [00:09:27] Take care.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Tech Talk with Craig Peterson Podcast: Supply chain hacks, Nation-state spying, Tesla, Microsoft Exchange Server Hack and More

    Welcome!

    It is now up to 100s of thousands of organizations that have been affected by this Microsoft Exchange Server Vulnerability and it was so large that you could drive a freight train through it. Oh yes -- Microsoft did issue a patch but that did not fix the problem which was the backdoor that the bad guys installed. Nation-states, especially China and Russia have been spying on us an it will take a lot of research to determine what information they were able to get their hands on and what damage they can do with that information. We have deep fakes in the news again and there is more so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Tens of thousands of US organizations hit in ongoing Microsoft Exchange hack

    Samsung just out-Googled the Pixel at guaranteeing Android updates

    Google's Getting Rid of Third-Party Cookies, But Their Replacement Is a Terrible Idea

    Google claims it will stop tracking individual users for ads

    Tesla asks fans to lobby the government on its behalf

    Make Deepfake Videos of Your Ancestors, But Consider Your Data Privacy When Making MyHeritage 'Deepfakes'

    China's and Russia's spying sprees will take years to Unpack

    A new type of supply-chain attack with serious consequences is flourishing

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] If you've been listening to me for a while, you may not believe this, but I've got a recommendation here on Android phones. Coming up we're going to talk about Google's new replacement for cookies, and a little bit about what Teslas' been up to. I don't like this.

    I have never been a fan of Android phones, and you know why I haven't been a fan? The biggest problem with Android phones is the lack of security updates. That really does concern me a lot. Google also has not been the best when it comes to the Playstore and making sure that everything on the store is actually safe.

    Here is some very promising news for people who like the Android platform or maybe dislike the Apple platform for one reason or another. Frankly, there's a lot of reasons there too.

    Samsung has always been the leader when it comes to keeping their number one phones updated in the past. I've always said, make sure you can get updates. Samsung with its Galaxy phones has been good for about two years. They provide you with the security updates you need with some patches.

    Even if Google comes out with a patch, most of the phones out there that are running Android, do not get the updates. Ever.

    Some of these phones are older, they don't bother supporting them. Some manufacturers drop support within months after you buy the phone.

    Samsung has been good for about two years. So my rule of thumb has always been, if you're going to buy Android, if you gotta do it. Stick with Samsung and stick with their number one model.

    It is now promising four years of security updates for more than 130 Galaxy phones. That's pretty big when you consider that frankly, Android phones have been the butt of many a joke over the years.

    Samsung is working pretty hard to make sure that they are really able to deliver for the Galaxy owners. Now, this is cool because Samsung just early, I think, this year it was that the Samsung promise that most new Galaxy phones would be getting about three generations of Android version updates. Now, that amounts to a few years, as a rule, the generations in the Android world are pretty much about a year.

    Google has been providing updates for its own phone that it has. They provided to these other companies, like Samsung, to then take it and modify it to fit what they want and then they provide it to you. So, three generations are good. Now, they have said four years of security updates. Now, that's a pretty impressive promise. What they're trying to do is compete with Apple that has historically provided about five years of support. There's a big difference, obviously between two years and five years, but there isn't as much of a difference between four years' worth of security updates, and the five, six, seven years that Apple has been doing depending on what kind of security updates. That's very impressive.

    Of course, Samsung just a year ago wasn't guaranteeing anything in terms of updates. Most new phone purchases were good for a year or two of updates, but only the Pixel, which is made by Google and Android. One base phones were on the record about how long you could be getting updates from the manufacturer.

    Now Samsung is doing one better than Google. Remember, Google is the guy that actually provides the Android operating system. Google's only guaranteed three years of version and security updates for Pixel phones and that's not very many phones.

    Frankly, Google Pixel is not been selling well. It's the standard that all of the Android manufacturers use in order to have a kind of proof of concept. So this is what it should look like. This just should be how it acts.

    I'm looking at this list here. This thing is huge of all of these phones from Samsung that is going to be supported, here.

    You've got the Galaxy foldable devices. The whole family of folds. The Galaxy S series and starts at the S 10 plus moving on to the S 20, S 25 G, S 20 plus blah, blah, blah. A bunch of different S 20 models and the S 21. That's pretty darn good. That's a lot of phones. Also, the Galaxy Note series, starting at the Note 10, all the way up to the current Note, 20 ultra-five GS the Galaxy AA series. Again, certainly, the 10 going up to eight 45, the Galaxy AMS, the up through the Galaxy X covers series and again tab series, which has been pretty popular for a lot of people.

    If you're thinking about picking up one of your Android phones here soon, maybe you should give a second thought to the Galaxy. Now, they're guaranteeing that they're going to provide these security updates for you for four years. Yeah. Yeah. Okay, a guarantee we'll see how long that lasts. The other problem is how quickly are they going to get it out?

    You'll see Apple devices, who just this week they had a security patch, they pushed it out and they expect to see 70, 80% of all of the phones with that security patch installed within a week. That's your Apple iPhones.

    Google comes out with a security patch. They push it out. It has to go to the vendors like Samsung and then the vendor like Samsung has to take that add the device drivers that need for all of these models. Think about that for a minute. That's a lot of device drivers. That's a lot of different models. I think it's going to take them a while to do that and then they'll get it to you.

    That security update that comes from Google, we've seen takes six months in the past before it gets on to your phone. If you're looking at. Security, if that's a real concern of yours and sure should be particularly after this disaster of a company called Microsoft and their windows products. Particularly now this Microsoft exchange server bug.

    I'm so upset with Microsoft, but you know what? We'll get into that a little bit later.

    The Samsung, the galaxies, the Google Androids are not designed for all of the safety and security that you really do need, frankly. When you think about the models were talking about 130 models that Samsung is going to be providing new updates for. Okay.

    When we look at Apple and the iPhone models let me see how many iPhone models are there out there. I'm going to Google that right now, even as we're talking. So 2007, that is when they first came up with them. Okay. So since the very first iPhone, according to the pho iPhone Wiki, there have been 29 models of the iPhone. 29. Two nine. How many did I say Samsung is going to be updating? 130. So who has an easier time of providing updates, security, updates, testing the updates, pushing the updates, having people install the updates, the company that in the last, how many years has been making iPhones yet since 2007? Okay. So all the way up to 2021, that's a lot of years. Versus the Android who has been making these Galaxy's for many years, but is only going to be providing updates back to the Galaxy S 10 from 2019. That covers the 130 models. Are you getting what I'm selling here? Are you buying it? Yeah, it's impossible. Really? For Samsung, even with all that, they're trying to do here. They're trying to help out. It's impossible for them to keep up with security-based unless they have this massive team. I don't expect that they do have a massive team that's going to be working in parallel. 130 teams, one for each phone. That just isn't happening.

    So again, if security is a concern, Android is not the way to go.

    If, for some reason you morally, ethically, religiously cannot use an iPhone and then have a solid look at Samsung because of this promise they came up with, here in the last two weeks, of four years of security updates for more than 130 phones.

    Finally, there is an Android phone that will have security updates at some point in time, versus what we've had over the years of really, you can only count on it for one or two years. It's just not worth it. Not a good thing.

    Hey, I am sending out on my newsletter, not just my show Notes, but I have also been sending out one or two other emails a week that have some very narrow training. What I've been doing is making audiograms for you guys. This is a video that is of me speaking, explaining something. On that video, you can see all of the words you can read along, which is great for people who are hearing impaired, or maybe you want to have that computer muted for whatever reason. It makes it easy.

    You can find me on YouTube, just go to Craig peterson.com/youtube, and you can catch those audiograms.

    You can also get them. If you are an active subscriber to my newsletter, active means you open it. You read it. I know you do. If I don't consider you active you just don't get this extra information. So, make sure you open those emails.

    A lot of us have been complaining about cookies and tracking for a long time. Google has finally heard us? I'm not sure about this. We're going to talk about third-party cookies, right now.

    Hi, everybody. Thanks for joining me, Craig Peterson here.

    Well, third-party cookies are where you go to a website, and that web browser kind of squeals on you, shall we say.

    What happens is Google, for instance, is trying to track you as you go online. As you go between websites. They're calling this kind of an advertising surveillance industry on the web.

    Frankly, this third-party cookie has really been an important part of this whole surveillance industry. What it does now is it allows a website to have a look at where you have been online. When I say it allows a website, it's really Google, that's doing the tracking. Obviously, you're going to a website, Google doesn't own every website out there. In fact, it barely owns any, when you look at the number of websites that are out on the internet.

    So Google has this whole concept of if you're visiting this site and you have visited this site and this other site, I know something about you. So it sells that information because it's seeing the pattern, right? That's the whole idea behind the advertising.

    Phasing out these tracking cookies and these other persistent third-party identifiers have been something people have been trying to get rid of for a very long time. The Electronic Frontier Foundation you'll find them [email protected] has been jumping up and down trying to get everybody to pull up their socks if you will.

    One of the first players to really jump into this was Apple. Apple has pretty much told the whole industry, you got to stop doing some of this tracking. Some of the tracking is okay.

    Again, how many times have I said, if I'm looking for a Ford F-150 then I don't mind seeing ads for the Ford F-150. Why would I want to see ads for a motor scooter when I'm looking for a pickup truck. Frankly, if I'm looking for an F-150, I expect to see ads maybe for a Chevy Silverado or a Dodge truck, does that make sense to you? I'm looking for something and that's when I'm interested in seeing it.

    Google is now jumping on this bandwagon because Apple has said we are going to be doing a couple of things. We are going to be forcing you, app developers, to tell everybody exactly what you are doing with their information, what you're tracking, who you're selling it to, what it's being used for. That's a very big deal.

    It's got the whole advertising industry very worried. Google is coming along saying, okay, Apple will do you a little bit of one better. Of course, the biggest complaint from Facebook who ironically has been buying newspaper ads, if you can believe that. Google has been destroying the newspaper industry and now it's going to newspapers to try and get people to stop Apple from destroying Facebook's industry by blocking some of the advertising tracking that Facebook has been doing.

    Now, what Google is doing is looking to replace these third-party cookies. How were they going to do that?

    They are already doing a few rather sneaky things. For instance, they fingerprint your browser. Your browser has a fingerprint because you have certain extensions on your browser that you've added. You have your computer, which has an operating system that has a certain version. It has a certain amount of memory. It has a certain amount of disc storage. A lot of the private information, personal information about your computer can be gleaned by a website.

    One of the things they've been doing this, you're blocking cookies. No problem. I can still figure out who you are and they don't necessarily know exactly who you are, but they have a very good idea.

    One of the proposals Google has come out with is called the federated learning of cohorts, which is very ambitious and could be the replacement, if you will, for these third-party cookies that could be the most harmful. What it is is a way to make your browser do the profiling. Itself.

    Historically they've been able to track your browser as you go around and then they have to pull all of that information together. They pull it together and they come up with a picture of you and who you are. Yeah. You're interested in buying a pickup truck, particularly an F150. This is an example.

    That picture gets detailed about you, but it's something that the advertisers have to put together. What this flock or federated learning of cohorts is doing is it's boiling down your recent browsing activity into a category. They're calling this a behavioral label, and then they're sharing it with websites and advertisers.

    The idea is basically your web browser itself is going to put you in one or more buckets and the websites that you're visiting and the advertisers that are advertising on those websites will be able to get that label that your browser has put on you. Yeah, you like that?

    So what EFF is saying is that this could exacerbate many of the worst non-privacy problems with behavioral ads, including discrimination and predatory targeting. You can guess what those things mean, right? They're calling this a privacy sandbox, right? It's always the opposite.

    If Congress is passing a bill, that is a COVID relief bill, you can bet that there's very little to do with COVID relief in the bill. Wait a minute, actually, that's true. There's only 9% of the money in this almost $2 trillion spending plan. 9%, that actually goes to COVID relief. Instant COVID relief bill.

    Same thing here with Google, right? This is the privacy sandbox and it's going to be better, Google says.

    In the world, we have today where data brokers and ad tech giants, track and profile everybody with complete impunity. Just like Equifax has. Just like Equifax lost our personal identifiable information, our social security numbers, or addresses or names or date of birth, et cetera, et cetera. Yeah. Yeah. Okay. We pay a small fine. Yet. We go on.

    Are they out of business? Have they lost business? In fact, they gained business because people have been paying Equifax to monitor their credit. Oh my gosh.

    That framing that Google is talking about is based on a false premise that you have to choose between tracking and new tracking. Does that sound familiar? Yeah. It's not an either-or. We really should be rejecting this whole new federated learning of cohorts proposal Google has come out with.

    You can bet that Apple is going to reject this outright because it's really rather terrible.

    If you care about your privacy on the other hand again, I look at it and say I want an F-150. I don't mind ads for pickup trucks, so what's wrong with that? Okay. There's two sides to this.

    I just don't like them calling me by name when I walked past a billboard.

    Stick around, we'll be right back.

    I'm a fan of much of what Elon Musk has done, what he's trying to do when it comes to technology, and being a proponent of technology.

    I'm not fond of Elon Musk taking over $3 billion from the taxpayers though.

    Hi, everybody. I appreciate you spending a couple of hours with me here on the weekend. There's so much to cover.

    Elon Musk it was $3 billion that he had received in government subsidies. Now we're looking at this, according to good jobs, first.org. We're looking at $4.9 billion dollars that Elon Musk has received basically from the taxpayer.

    It's really sad when you get right down to it. Now, Tesla got money from taxpayers he's paid some of it back. It's really the government trying to name a winner.

    There's a lot of competing technologies. There's even non-electric cars out there. How many of you even aware of this? That use, for instance, hydrogen instead of electricity. Now there's, of course, with any technology there's complications here and there. Hydrogen is absolutely amazing. It's an electric car. You fill it up with hydrogen and the only byproduct of the burning, if you will, the hydrogen, is water. In fact, it doesn't burn the hydrogen. It combines it with oxygen to make the water and produce electricity all at the same time. Very cool.

    There are some prototypes out already on the roads out in California and some other places around the world.

    When the government's giving out billions of dollars to electric cars, they're effectively naming a winner. Aren't they? Does that make sense? I don't think so. We've got to have a free market and this is not a way to have a free market.

    It's just like with solar, wind, some of these other technologies where the government is taking our tax dollars and is saying this particular technology, and even worse, look at Solyndra, look at some of these others just absolute debacles.

    Now, even worse they give money to a specific company within a certain industry. That is not a good thing. Government has a terrible record at picking winners. Even investors, you look at people who are angel investors and who are venture capitalists. They are lucky. If they make money in one of 10 of their investments. It is not a great way for them to make money.

    A professional investor does terribly. Imagine how poorly a politician does. The politician is going to be listening to the people knocking on their door, saying here's some money for next time you run for the house or Senate. Or locally, in local elections, it even happens. That is a very bad thing.

    It's been proven again, and again over particularly in the last about 140 years. Governments' terrible about picking winners. Yet they do it every day of the week. Tesla has gotten money, right? Some, of its tax benefits, some of it is actual cash. The bottom line, they've some great technology.

    Now what's happening is Tesla is asking Tesla fans to lobby the government on its behalf. Great article by Rachel Kraus over on Mashable about this week. I love it.

    She says a Tesla fan. Your mission. Should you choose to accept it is to go to bat politically for the company. Check this out online. You might want to too because Tesla has launched a new online portal called the Tesla engagement platform. CNBC spotted this about a week ago, and this is a hub where Tesla posts actions its users can take like contacting government officials when there is a potential law that would affect the company.

    In fact, it says in a blog post on this hub Tesla built. Engage Tesla is a new platform for both Tesla's public policy team and Tesla owners clubs. Its goal is to create a digital Homebase for all of our work and to make it easier for Tesla community members to learn what's top of mind for us. Take meaningful action and stay in the loop. We hope you'll enjoy our, excuse me, will we hope you'll join us in getting involved? Oh my gosh.

    So, I'm on Engage Tesla, it is at engage.tesla.com. Very pretty pictures. By the way, of some of these new Tesla cars, very cool cars. I would absolutely drive one of these things.

    One exception, I don't like the handles. I talked about that a couple of years back. About door handles on the outside. Having been in emergency medicine for a while. EMS, I can tell you, in accidents, you want something you can grab onto and have serious leverage. The doors get bent, things happen. There's at least one case I'm aware of where someone got trapped inside the car that was involved in an accident and then burned to death because the people who were trying to rescue him could not get him out of the car because there are no door handles to pull on.

    Yes. I know the handles come out automatically when everything's working right. I'm talking about the most extreme of problems here. Anyhow, I'm digressing again.

    Uber is doing much the same thing, by the way. It isn't just Tesla. Uber is, in fact, they had their drivers this was October last year, sue Uber over what these drivers called pressure to vote and advocate for the proposition in California. Not a good thing when you get right down to it.

    It is it's a real problem when you look at this in detail now. I'm not sure it's a terrible problem, but I do have a serious problem with companies soliciting the government in order to get things like tax subsidies in order to get special favors.

    A lot of people do too. Look at all of the people who were upset with Tesla for trying to get a tax holiday for its battery plant and for some of its other facilities and things that they're doing.

    By the way, there is currently a post on this Tesla engagement platform asking Nebraska residents to contact lawmakers about a law coming up for a vote that would enable Tesla to open showrooms and service stations in the state where it's currently prohibited.

    Now I brought that one up, particularly because I think again, free market. There's no reason in today's world. No legitimate, let me put it that way, reason to have dealerships. I think we should be able to buy a vehicle directly from a manufacturer. If they want to have certified repair shops, knock yourselves out, but we don't need somebody sitting there anymore in a dealership. Same thing with most of these distributorships. I think we have been shown that a car can be ordered online, configured, online shipping to us. We can be pretty darn happy with it. By the way, that they are shipping it to us in our state gives them what's called a legal nexus. So, they do have a presence in the state. They can be sued in the state if there is a problem. This whole thing in Nebraska, I don't think there should be dealerships that are exclusively provided the right to sell vehicles within the state.

    My opinion. All right. Hey, stick around. Cause we will be back.

    We're going to talk a little bit about deep fakes. This is cool because MyHeritage is doing something that's scaring a few people.

    You're listening to Craig Peterson.

    Make sure you check out my website, Craig peterson.com and sign up.

    You might've seen some of these deep fakes out there. Videos where it's putting Elon Musk's face on people or others in videos. Did you know that there's audio as well? They're using it to bring back our ancestors.

    Hi guys. I really appreciate you listening to me.

    There is a website out there called MyHeritage and it's very popular. It's a site that allows you to do a genealogical examination of yourself, a little look at DNA, they'll look at your family tree. They've got some research stuff up there. They have something new called Deep Nostalgia and I think this is very cool.

    It really introduces some interesting problems, frankly. This allows you to animate a face in a photo. It's unnerving. When you have a look at this thing. You can check it out, again. MyHeritage.com/deep-nostalgia N O S T A L G I A. In case you're wondering how to spell it. They require you to create an account on their site and then you upload the photograph.

    It takes that photograph and it has them pose it's really uncanny. I'm looking at a picture black and white that was taken it's right there on their site of a couple. I would guess this is a 1960-ish-era photograph based on the hairstyles and the glasses. It's just so weird because they have this photo. It's a head-on face-on photo and they've animated it so that the woman in this photo she's moving her head around. She's smiling. This is a really great smile. She blinked. She moves her head up and down and looks over to her and looks back again. Wowsers. It is absolutely amazing. You might want to check it out. It's a form of artificial intelligence that's doing this.

    Of course, it has to make a bunch of assumptions. So if you look, you don't even have to look that closely, but if you look fairly closely at the picture, you'll see some detailed problems with her hair, the ends of her hair. At the top of her head, because you can't see the whole top of her head in the original picture. You can obviously not see both sides of her face or her head because that particular picture just a straight-on shot. It's making it up as it goes.

    We're seeing deep fakes more and more. We're going to see a real problem, coming up in another couple of years, certainly by the time 2024 arrives with deep fakes.

    We've already got Russians influencing our elections. Of course, not as much as the oligarchs out in Silicon Valley have been influencing our elections, but they are already influencing us in a very big way.

    China, as well, imagine what'll happen when they start producing deep fakes of our presidential candidates saying things or doing things that they have never said nor done.

    What I did is. I figured I want to give you guys an example. Audio seems to be a little bit harder for the deep fakers than some of the videos. At least the technology and audio hasn't quite come as far. I'm going to play for you right now. A deep fake of my voice.

    This is not my voice, you're about to hear. Then I'm going to play a completely computer-generated deep, fake. So let's go here. I'm going to play my voice right now. This is an example of a deep fake using my voice. Did you catch that? That wasn't me. That was a computer again. I'm going to play it for you one more time.

    This is an example of a deep fake using my voice. Now you can hear some of the problems with it. If you listen really closely that it's not really me, but it's close enough that if you weren't paying a whole lot of attention, you would not notice that it really wasn't me saying something.

    Expect within the next year, that type of technology to get to the point where you won't be able to tell.

    So think about it. What would happen? If a tape was released, talking about, Mitt Romney for instance, saying half of the voters that are never going to vote for me anyway, and that was recorded. I guess, by one of the waiters, it was at an event.

    If you took this voice of mine and you created a deep fake, cause all you need is about five seconds worth of someone's voice to make a deep fake. You had politician X, let's say that Hillary is running again for precedent, okay in 24. You could have her say almost anything. The audio quality might not be up to it, but with most of these recordings that are made on people's cell phones either, is it.

    I want to play another deep fake. This is a completely fabricated female voice. This is an example of a deep fake using a completely generated voice. Yes, indeed. I created that. I can make her say anything I want to.

    Help me. Craig is holding me hostage inside his computer. Yeah. This is going to be a huge problem in the future.

    There are concerns about what they are doing over at MyHeritage. Look at some of these pictures. Here's one it's cool. It's unnerving. Here's again, a guy with a family, this one's in color, he's got a right ear, the really pops out there, but he's looking around.

    Have you used an iPhone and taken a picture and they call them live pictures. You can see the person right before the shutter is closed. You can see the person moving around. It's really a little video right in front of the picture. That's what these things look like.

    Ah, here's this little kid he's looking around. Here's one, a very old one. Oh my goodness, it is creepy. You got to check this out online. MyHeritage is.com/deep nostalgia.

    Now here's where the concern comes in. In an article on Life Hacker. By David Murphy, he is talking about taking these old pictures could be very old pictures of somebody sitting around somewhere, uploading it to the site. Then you get a little bit of nostalgia. I get creepy nostalgia that only comes from this static image now moving around on your screen.

    I don't get it, really, I don't myself. I think that it's just plain creepy, but if you decide to do it, cause it is cool. Okay.

    You probably should use a temporary account to make it to make your account over on MyHeritage and maybe also delete the photos that you upload and turn into these deep fakes. So many other websites out there, if you do go ahead and upload it, they go and claim the rights to it because it's a derivative piece. They made this little video from your photos. So, that's not your photo anymore. It's now theirs. It gives them a royalty-free worldwide perpetual and non-exclusive license to host copy, post, and distribute the content. It could be a problem, but I can tell you one thing that definitely would be a problem, that is if you use a username and the password you've used elsewhere.

    Now, I have to bring this up because most of us are using the same password on every website or maybe, yeah we're really smart. We got three passwords and we vary them. I did that for years, but that was many decades ago. We just can't do that anymore.

    If you are going to make an account on MyHeritage or anywhere else, make sure you don't use a password that you've used anywhere else because it is a problem.

    Ultimately, it's a real problem for you and you can't believe your eyes or your ears anymore.

    You share these pictures. I don't know that they allow you to download them because I did not put my own pictures up there. If these pictures are watermarked. Delete your account. Click that blue link under the big grid text to get started. That's supposed to delete anything anyways. You can figure it out but have a look anyway, it's in my newsletter that comes out on Sunday morning. There'll be a link in there that you can click on and see what they've been able to do.

    Remember. When it comes to particularly things coming up in this next election where it really matters who we vote for, it really matters. Other countries have a very big opinion about who we should be electing to office.

    Look at what happened with Rep Swalwell out in California. Here's a guy who was running for mayor the Chinese socialist government decided they would put a honeypot into his campaign. So they got this woman who was trained in seducing people. They seduced Swalwell and she raised money for him, for his campaign as mayor and stuck with him over the years, all the way until he was in Congress.

    Then in Congress, she helped him get onto the very influential committee in Congress, where he had full access to our government secrets. Certain secrets that are. She apparently was feeding all the information right back to China. That is not a good thing, not a good thing at all. It goes to how much. China is willing to do to directly influence and infiltrate our government and our businesses.

    If they will assign one of their spies to seduce a mayor of a small city in California, and then help elevate him to Congress and to the chairmanship in Congress. By the way, The speaker of the house, Nancy Pelosi has not removed him from that seat. She's got a Chinese spy problem herself. That's another story.

    They're willing to do anything.

    It's going to be a rough little time here going forward. Let me tell you these deep fakes are getting more and more real.

    I'll be right back with a whole lot more.

    You're listening to Craig Peterson.

    I've been talking about this on the radio all week, at least since midweek. I want to talk about it now, and why I am so upset with Microsoft. I can hardly contain myself. This is crazy.

    This is Craig Peterson here. You heard it right. The guy that's very upset with Microsoft. What shall I say? We're going to be getting into that in just a couple of minutes.

    This is a real problem. What are we supposed to do? We have bad guys now doing what is called supply chain attacks.

    The simple way to explain this is you have someone who is supplying software for you. It could be Microsoft. We heard about something, that happened very recently with SolarWinds and how they had software that they were providing their customers, which included government agencies. All kinds of them. It included many businesses. A lot of managed services providers were hacked by this.

    A very, very big problem, because they were trusting the software that came from SolarWinds, and that software had been digitally signed, so they knew it was legitimate. Everything's good. Nothing to worry about here, let's go on with our lives.

    However, the reality was that the SolarWinds software had been hacked many months prior to anybody really noticing. It was hacked in such a way that when SolarWinds provided their software to their customers were now infected.

    Now, you might look at it and say SolarWinds, they should be signing their software. They should be watching the chain of custody for their software. They did, in both cases, they were signing it digitally so that their customers knew, okay, this is legit. This is really from us. You can install it. It's good.

    But you're checking the signature didn't do any good. You were still going to be hacked because it was in SolarWinds software.

    Microsoft has been providing us with software for many years. I helped develop some of the Windows NT code ways back when. Their new technology, that's what the current versions of Windows are based on. I can remember way back then, just what a mess it was I couldn't believe the way they did so many things. It was just absolutely crazy.

    Of course, David Cutler, VMS guy, for those of you who remember all of that, really spearheaded that NT project. There were a lot of VMS systems in it, but then Microsoft ripped them out. They ripped them out because they didn't want to have to support an operating system that enforced security. VMS has been a very secure operating system is written by true programming professionals, not interns, as it was exposed with Microsoft, having interns develop one of their versions of their operating system, like 80% of it. It was crazy. That was only found out because of discovery.

    Yet Microsoft is sitting on cash. A whole lot of cash. It's billions of dollars. Let me see. I'm looking up right now. Microsoft is sitting on $136 billion in cash, right now, according to MacroTrends. Now, were they using that cash, that $136 billion in cash, to make their products more secure? Doesn't look like it does it.

    They had such a huge hole. You could drive a freight train through. The Chinese were able to infiltrate, in fact, many of our machines. This isn't tens of thousands of our machines, this isn't just something like ransomware, where you know about it because Hey, they're asking a ransom, right? They're threatening they're going to release our secrets, our software, our personal information. If we don't pay up it wasn't one of those things.

    What they did is they got onto these machines in education. In other words, school districts. Hospitals, doctor's offices, government agencies, including defense department guys, Homeland security guys. Okay.

    Our businesses all the way across the world. They put back doors on. What a backdoor is. it is something that allows them to go to your machine anytime they want? In this case do pretty much anything they want it to.

    Microsoft comes out with fixes this last week. This is specifically for the Microsoft exchange server. By the way, if you're running Microsoft Exchange server, either locally in your business or in the cloud, you have this bug. They released a patch that supposedly closes the hole. It was used by the Chinese to install permanent back doors and what did they not do? They didn't remove the back doors that the Chinese had put in.

    What's Microsoft saying to us then, are they saying, Hey, listen, you're fools for buying our software. I don't think they're saying that.

    I am at the point now where I'm saying that we are fools for trusting Microsoft. We're fools for trusting these companies that have a product to sell. All they're trying to do is sell the product.

    Look at what's been happening with some of these antivirus products. Look at what's happening with these VPN products. They have the software to sell and they're going to sell it.

    They're not going to tell you the whole truth, nothing but the truth. Forget about it. They're going to do anything they can to sell you the product. So are Microsoft people.

    Are people getting fired for buying Microsoft? It's like IBM in the seventies and the eighties, you never got fired for buying IBM.

    People should be fired for buying Microsoft.

    If you have a Microsoft Exchange server, not only do you need to make sure you install all of the patches. There were four critical Microsoft exchange servers, zero-day vulnerabilities patch.

    In other words, things that they hadn't been able to patch it and know about yet. Supposedly, right? There are articles I've read that say they've known about at least one of these vulnerabilities for a year plus. There are other vulnerabilities Microsoft knows about that they haven't bothered closing the door on.

    They are in our supply chain. They are getting us the software that we need and they're signing it and it's installed in it.

    We're upgrading our machines. Sometimes the upgrades that they provide, the security patches actually work, in this case. It may close the door. What it's not doing is providing us with a way out of this huge mess.

    Velma agrees with me here. Okay. No, she absolutely does.

    They released fixes on March 2nd. Microsoft has been saying they've been used in limited and targeted attacks against law firms, infectious disease researchers, defense contractors, policy think tanks among other victims. Yeah. Yeah.

    How is it a problem? I don't see it.

    Oh, my goodness. Companies are seeing abuses of these Microsoft exchange server problems starting in January. There are reports that I found out there online. There are three clusters of vulnerabilities. Tens of thousands of US-based organizations are running Microsoft exchange servers that have been backdoored by these threat actors, who we are thinking are Chinese. They are stealing administrative passwords. They're exploiting these critical vulnerabilities in the email systems and calendaring application.

    They've done nothing, Microsoft to disinfect the system's already been compromised. Can you believe this?

    I got this from Krebs on security. They were the first ones to report this mass hack and Krebs has got some great stuff they have had for many years now, frankly.

    Brian Krebs put the number of compromised US organizations, at least at 30,000 worldwide. Krebs said that there were at least a hundred thousand hacked organizations. Now, an organization is a government agency. It could be a hospital, could be a doctor's office, could be a business, right? Anything is an organization, tens of thousands in the U. S. This is the real deal. This is a very big deal.

    You have to assume if you are running a Microsoft Exchange server, this is the server that is used for email. This is how small businesses often run. Their email is an exchange server. This is how hospitals and government agencies, et cetera, run their exchange server, which is ridiculous.

    I have never purposely used an exchange server, right? If there's any way around it I've always has gone to something better, a Unix-based system.

    Postfix, almost anything rather than the incredibly buggy software from Microsoft. It is just horrible.

    Anyway, you have to assume that you were compromised between near the end last week of February and the first week of March.

    Absolutely incredible limited targeted attacks. This isn't something that was just absolutely widespread. They went after companies because they knew they could get something out of the companies, a very skilled hacking group from China.

    They're focused primarily on stealing data from US-based infectious disease researchers. As I said, law firms, right? Higher education institutions, defense contractors, policy, think tanks and NGOs. It's absolutely incredible what they've been doing and we cannot put up with it anymore.

    I want to put a little word here. If you are a business and you have been using Microsoft exchange server restore from a backup. I would say in the January timeframe, you'd probably be safe. Probably, didn't have any back doors in January. Hopefully, you've got a backup that goes back that far. Okay.

    Then find something else. Don't use this. Microsoft does not care. You cannot have $136 billion cash on hand, and not spending serious amounts on security. You can't tell me they care. Because frankly, I don't think they do.

    Hey, go online. Craig peterson.com get some of the free training, other things, and I'm offering right there. Craig peterson.com.

    Hey, welcome back everybody we're talking right now about InfoSec, information security. Have you thought about maybe taking up a bit of a new career? Well, there are some estimated 2 million open jobs in this one?

    This is Craig Peterson. Thanks for joining me today.

    This article appeared in dark reading. Now, dark reading is an online magazine, right? It's a website. And they had this article that I absolutely had to read because it reminded me of someone I know. One of our listeners, who decided he needed a new career. He'd lost his job. He'd been out of work for over a year and he had been managing a retail camera shop and they shut it down. He was stuck. What do I do? He'd been listening to the show for a long time. He decided he wanted to go into information security. He took some courses on it and he got himself a job. A full-time job being the chief IT security guy for this company after just a few months.

    So that tells you how desperate these companies are. Kind of jerking his chain a little bit, but not right, because he just barely had any background. If you want me to connect you with him, if you are serious about thinking about one of these careers, I'll be glad to forward your request to him, just to see if he's willing to talk to you. Just email me M [email protected] and make sure you mentioned what this is all about. So I know what's going on.

    Ran Harel, who is security principal and product manager over at Semperis said, when I was growing up, I was quite an introvert, by the way, that sounds like a lot of us in it. I didn't realize until much later on in my career, just how great the security and tech community is looking back. I realize how quickly I could have solved so many issues, by just asking on an IRC channel or forum.

    IRC is an internet relay chat, a bit of a technical thing, but it's an online chat.

    I would tell my former self, the problem you are facing now is probably been dealt with multiple times in the past year alone. Don't be afraid to ask the InfoSec community and then learn from them.

    That's absolutely true. I found an online IRC channel basically, and they were set up just to talk about CMMC is this new standard that department of defense contractors are having to use.

    As you probably know, we have clients that are manufacturers and make things for the Department of Defense and they have to maintain security. It's been interesting going in there answering questions for people and even asking a couple of questions. It is a great resource. This particular kind of IRC is over on discussion.

    You can find them all over the place. Reddit has a bunch of sub- Reddits. It's dealing with these things, including, by the way, getting into an InfoSec career. So keep that in mind.

    There's lots of people like myself that are more than willing to help because some of the stuff can get pretty confusing.

    All right. The next one. Is from Cody Cornell, chief security officer, and co-founder over at swimlane. He said, apply for jobs. You are not qualified for everyone else is.

    Man. I have seen that so many times everybody from PhDs all the way on, down throughout a high school and who have sent me applications that they were not even close to qualified for.

    Now, you can probably guess with me, I don't care if you have a degree. All I care about is can you do the work. Can you get along with the team are you really going to pull your weight and contribute? I have seen many times that the answer to that is no, but I've seen other times where, wow, this person's really impressive.

    So again, apply for jobs you're not qualified for because everybody is. Security changes every day. New skills techniques and the needs of organizations are always shifting. And to be able to check every box from an experience and skills perspective is generally impossible. Looking back at 20 years of jobs in the security space, I don't believe that I was ever a hundred percent qualified for any of them, but felt confident that I could successfully do them.

    So keep that in mind. Okay.

    Again, imposter syndrome, we're all worried about it. This applies to more than just InfoSec. This applies to every job, every part of life, we all feel as though were impostors and that we're not really qualified, but the question is, can you figure it out? Can you really do it?

    Next up here is Chris Robert, a hacker in residence, he calls himself over at Semperis and he says, overall, the most important lessons that I'd tell my younger self are not tech-based. Rather they focus on the human aspect of working in the cybersecurity industry. I think cybersecurity professionals in general, tend to focus on technology and ignore the human element, which is a mistake and something we need to collectively learn from and improve.

    I agree with him on that as well. However, we know humans are going to make mistakes, so make sure you got the technology in place that will help to mitigate those types of problems.

    Next up, who's got, Marlys Rogers. She's CISO over at the CSAA insurance group that's a lot of four-letter acronyms. You are nothing without data. Data is queen. Coming from an insurance person, right? Without hard data, you can only speak to security in more imagined ways or ways. The board and C-suite are aware of in the media cost-benefit is only achievable with related data points. Demonstrating how much we are fighting off and how the tools, processes, and people make that happen.

    Next up we have Edward Frye, he's CSO over at our Aryaka. When I first started out, I was fairly impatient and wanted to get things done right away. While there are some things that need to be done right now, not everything needs to be done. Now have the ability to prioritize and focus on the items that will have the biggest impact.

    I think one of the biggest lessons I've learned along the way is while we may need to move quickly, this race is a marathon, not a sprint.

    Patience is essential for security pros. I can certainly see that one.

    Chris Morgan, senior cyber threat intelligence analyst over at Digital Shadows, despite the way that many in media liked to portray cyber threats, not everything will bring about the end of the world.

    For those getting into incident response and threats, try to have a sense of perspective and establish the facts before allowing your colleagues to push too quickly towards remediation mitigation, et cetera.

    Expectation management amongst senior colleagues is also something you'll frequently have to do to avoid them breaking down over a mere phishing site. The quote, one of my former colleagues try to avoid chicken, little central.

    I've seen that before as well.

    The next one is things are changing daily and the last one is a perception of security is still a challenge.

    So great little article by Joan Goodchild. You'll see it in my newsletter, which we're trying to get out now Sunday mornings.

    You can click through the link if you'd like to read more.

    As you can see. 2 million open jobs while between one and 3 million, depending on whose numbers you're going at in cybersecurity.

    You don't have to be an expert. As I said, one of our listeners went from not knowing much about it at all. He can install windows. That's it. To having a job in cybersecurity in less than six months, stick around. We'll be right back.

    I'm doing a special presentation coming up next month for the New England Society of Physicians and Psychiatrists. We're going to be talking a little bit about what we will talk about right now. What can you do to keep your patient information safe? What can we do as patients to help make sure our data's safe.

    Hi, everybody. You'll also find me on pretty much every podcast platform out there. Just search for my name, Craig Peterson. I have a podcast and it makes it pretty easy. I've found some of them don't understand if you try and search for Craig Peterson, tech talk, some of them do.

    I've been a little inconsistent with my naming over the years, but what the heck you can find me. It's easy enough to do.

    I've got this new kind of purple-ish logo that you can look for to make sure it's the right one. And then you can listen to subscribe, please subscribe. It helps all of our numbers.

    You can also, of course, by listening online with one of these devices, help our numbers too. Cause it's you guys that are important. The more subscribers we have, the way these algorithms work, the more promotion we'll get. I think that's frankly, a very good thing as well.

    What do you do if you need to see a doctor, that question has a different answer today than it did a year ago. I won't be able to say that in about another month, right? Because mid March is when everything changed last year, 2020, man, what a year?

    To see a doctor nowadays, we are typically going online aren't we. You're going to talk to them. So many doctors have been using some of these platforms that are just not secure things like zoom, for instance, which we know isn't secure.

    Now, the fed kind of loosens things up a little bit under the Trump administration saying, Hey. People need to see doctors. The HIPAA PCI rules were loosened up a little bit in order to make things a little bit better. Then there's the whole DSS thing with HIPAA. All of these rules are just across the board are loosened up.

    That has caused us to have more of our information stolen. I'm going to be talking a little bit about this FBI, actually multi-agency warning that came out about the whole medical biz and what we need to be doing. Bottom line, Zoom is not something we should be using when we're talking to our doctors.

    Now, this really bothers me too. Zoom is bad. We know that it's not secure and it should not be used for medical discussions, but Zoom has been private labeling its services so that you can go out and say, Hey, zoom, I want to use you and I'm going to call it my XYZ medical platform.

    People have done that. Businesses have done that. Not really realizing how insecure Zoom is. I'm going to give them the benefit of the doubt here. You go and you use the XYZ medical platform and you have no clue of Zoom. Other than man, this looks a lot like Zoom, that's the dead giveaway.

    Keep an eye out for that because a lot of these platforms just aren't secure. I do use Zoom for basic webinars because everybody has it. Everybody knows how to use it. I have WebEx and the WebEx version of it is secure. In fact, all the basic versions, even of WebEx are secure and I can have a thousand people on a webinar or which is a great way to go. It's all secure end to end.

    Unlike again, what Zoom had been doing, which is it might be secure from your desktop, but it gets to a server where it's no longer secure. That kind of problem that telegram has, frankly.

    If you are talking to your doctor, try and use an approved platform. That's how you can keep it safer.

    If you're a doctor and you have medical records be really careful. Zoom has done some just terrible things from a security standpoint. For instance, installing a complete web server on a Mac and allowing access to the Mac now via the webserver. Are you nuts? What the heck are you doing? That's just crazy. Just so insecure.

    This is all part of a bigger discussion and the discussion has to do with Zero trust architectures. We're seeing this more and more. A couple of you, Danny. I know you reached out to me asking specifically about zero trust architectures. Now Danny owns a chain of. Coffee shops and his family does as well.

    He says, Hey, listen, what should I do to become secure? So I helped them out. I got him a little Cisco platform, and second Cisco go that he can use as much more secure than the stuff you buy the big box retailers or your buying at Amazon, et cetera, and got it all configured for him and running.

    Then he heard me talk about zero-trust and said, Hey, can I do zero-trust with this Cisco go, this Muraki go, is actually what it is and the answer is, well so here's the concept that businesses should be using, not just medical businesses, but businesses in general and zero trust means that you do not trust the devices, even the ones that you own that are on your network. You don't trust them to be secure. You don't trust them to talk to other devices without explicit permission.

    Instead of having a switch that allows everything to talk to everything or a wifi network where everything can talk to everything, you have very narrow, very explicit ways that devices can talk to each other. That's what zero-trust is all about. That's where the businesses are moving.

    There's zero trust architecture, and it doesn't refer to just a specific piece of technology. Obviously, we're talking about the idea that devices, and even on top of that, the users who are using the devices only have the bare minimum access they need in order to perform their job.

    Some businesses look at this and say that's a problem. I'm going to get complaints that someone needs access to this and such. You need that because here's what can happen. You've got this data that's sitting out there might be your intellectual property. You might be a doctor in a doctor's office and you've got patient records. You might have the records from your PCI your credit card records that you have. I put on. Those are sitting there on your network that is in fact a little dangerous because now you've got something the bad guys want. It's dangerous if the bad guys find it and they take it, you could lose your business. It's that simple.

    They are not allowing you to use the excuse anymore because of COVID. That excuse doesn't work anymore. The same thing's true with the credit card numbers that you have the excuse of I'm just a small business. It's not a big deal. Doesn't work anymore. They are taking away your credit card privileges.

    We had an outreach from a client that became a client, that had their ability to take credit cards taken away from them because again, there was a leak.

    So we have to be careful when you're talking and you have private information, or if you don't want your machine to be hacked, do not use things like Zoom. I covered this extensively in my Improving Windows Security course. So keep an eye out for that as well. If you're not on my email list, you won't find out about this stuff.

    Go right now to Craig peterson.com. If you scroll down to the bottom of that homepage and sign up for that newsletter so you can get all of what I talk about here and more.

    Hey, thanks to some hackers out there. Your application for unemployment benefits might've been approved and you didn't apply for it in the first place. Turns out somebody stealing our information again.

    Hi everybody. Craig Peterson here. This is a big concern of mine and I've often wondered because I have not been receiving these stimulus checks. I did not get the first round. I did not get the second round and I contacted the IRS and the IRS says depends on when you filed for 2019.

    Oh my gosh. Of course, I was a little late filing that year. They still haven't caught up. I guess that's good news, right? That the IRS data processing centers are terrible.

    It goes back to aren't you glad we don't get the government we pay for is the bottom line here, but I've been concerned. Did somebody steal my refund?

    Did somebody steal my unemployment benefits, did somebody steal my stimulus checks? It is happening more and more. There is a great little article talking about this, where someone had stolen the author's John personal information again. Now we probably all have had our personal information stolen, whether you're aware of it or not.

    As usual, I recommend that you go to have I been poned.com and pwnd is spelled, pwn, D have I been poned.com and find out whether or not your data has been stolen and is out there on the dark web.

    They have a really good database of a lot of these major hacks. Many of us have been hacked via these credit bureaus and one in particular Equifax who have all kinds of personal information about us, had it all stolen.

    It's easy enough for people to steal our identities file fake tax returns. That's why the IRS is telling you, Hey, file your return as soon as possible. That way when the bad guys file, we'll know it's the bad guys' cause you already filed it. As opposed to you file your tax return and the IRS comes back and says, Oh, you already filed. We already sent you a refund or whatever. You already filed it.

    That is a terrible thing to have to happen because now you have to fight and you have to prove it wasn't you. How do you prove a negative? It's almost impossible. At least in this case, hopefully, the check was sent to some state 50 States away, another side of the world. So you can say, Hey, listen, I never been there, then they can hopefully track where it was deposited.

    Although now the bad guys are using these websites that have banks behind them, or maybe it's a bank with a website that is designed for people to get a debit card and an account just like that. That, in fact, is what was used to hack my buddy. My 75-year-old buddy has been out delivering meals and had his paychecks stolen through one of those.

    These fraudulent job claims are happening more and more. It's really a rampant scam. We've had warnings coming out from the FBI and they have really accelerated during the lockdown because now we've had these jobless benefits increased, people, making more money staying in their home than they made on the job. Disincentives for working, frankly.

    He's saying here the author again, John Wasik, that a third of a million people in his state alone were victims of the scam. This is an Illinois. This is where he lives. A third of the people in the state of Illinois, including several people that he knew.

    We've got some national tallies underway. I don't know if you've seen these. I've seen them on TV and read about them, California. It is crazy. People were applying for California unemployment that didn't live in the state at all, would come into the state and once you're there in the state pick up the check, right? Cause that's all they were doing. Some people have been caught with more than a million dollars worth of California unemployment money.

    Of course, it wasn't a check, it was actually a debit card. The same basic deal and California is estimating that more than $11 billion was stolen. Can you imagine that tens of millions of people could have been scammed because of this?

    This is the third time the author had been a victim of identity theft and fraud. He wanted to know how could they get his information.

    Well, I've told you, check it out on, have I been pwned. It'll tell you which breaches your information was in. It does it based on your email address. It'll also tell what type of data was stolen in those breaches. So it's important stuff. I think you should definitely have a look at it.

    He is very upset and I can understand it. Data breaches last year, more than 737 million data files are ripped off according to act.com. Frankly, that was a digital pandemic, with more and more of us working at home.

    I just talked about the last segment. Your doctor's office and you are talking to your doctor. How now? Cause you don't go into the office. There are so many ways they can steal it.

    The FBI's recording now a 400% increase in cybercrime reports that we had this mega hack of corporate and government systems.

    This whole thing we've talked about before called the SolarWinds hack, although it was really more of a Microsoft hack, and it went out via SolarWinds as well as other things. Be careful everybody out there. If you find yourself in these breach reports, have I been pwned make sure you go to the website. Set yourself up with a new password. At the very least use a password manager.

    I just responded to an email before, when it went on the air today, from a listener who was talking about two-factor authentication. He's worried about what you're to use. I sent him my special report on two-factor authentication, but it is the bottom line, quite a problem.

    Again, Use one password, use two-factor authentication with one password. Don't use SMS as that and you'll be relatively safe.

    I don't know I can't say do this and you'll be safe. I don't think there's any way to be sure your safe.

    Having these organizations, businesses, government agencies hacked all the time that don't seem to care about losing our data, right? Oh, it's a cost of doing business, some of these businesses, and I've talked to them, they'll look at it and say, how much will it cost us in fines if our data is stolen? Versus, how much will it cost us to keep our data relatively safe? For even a larger small company, a hundred employee company, you're talking about something that is going to be costing you about 25 grand a month. That's if it's outsourced.

    If you're trying to do it yourself and a hundred-person company, you can easily be spending a hundred grand a month. It's expensive to do. They'll look at it and say, okay, this is going to cost us a million dollars a year, odds are, it'll be two years, maybe three before we're hacked. That's this statistic, although you're rolling the dice, it might be tomorrow that you get hacked. $3 million versus our fines are going to be about a million dollars. We'll just take the fine.

    That to me is just disgusting. How can these people live with themselves? I don't know. Maybe it's just me. I'm going crazy.

    That leads us to this New York Times article I was talking about on the radio this week. The New York Times article talking about how the United States, really, we are losing control of information warfare. Our warriors have been working at the national security agency and the FBI. They leave those agencies and go to work for private contractors. The tools that we've been using to hack other people have been stolen. The tools that we're paying to be developed, we meaning the US taxpayer, the tools that we have paid to develop aren't even being used, and that mega attack I was just talking about. That's an example of one of these attacks that would have been stopped had we been using the tools that the federal government paid for. It's just crazy. What's going on?

    So here's the bottom line, everybody you can't trust most of these vendors that are out there. They have a product to sell. They don't have the best solution for you, right? They really don't. If they cared about you they would not be selling you antivirus software because it does not work.

    If Microsoft cared about you, they would have come out with their anti-malware stuff. Windows defender, years and years ago. They would have redesigned Microsoft Office and Microsoft Windows, as well, because those were huge security holes.

    Look at Adobe. They've been the source of the most security problems of anything out on the market, bar none. Flash was terrible. Java, another example of something that's been a terrible security hole for years. These businesses are trying to get a product to market as quickly and as inexpensively as possible. Quick is usually the number one goal. It has to be inexpensive for them to develop it. That means now they go out and they sell it because they got it. They're going to sell it. It doesn't matter if it's good. It doesn't matter if it even works overall for you.

    That's why I'm doing these courses, these classes, these emails, I'm recording special stuff for you each week. I've got special emails that are going out for you each week.

    We've got these radio show podcasts. This stuff is all free. All of it.

    Now I charge for some courses, but everything else is absolutely free. Now I hope I have some clients that come from some of this stuff and I do get them, but most of the clients I get are by referrals.

    I really believe in this. I'm putting my time, my money, my energy where my mouth is. But you have to take a step. You have to go to Craig peterson.com and you have to sign up right there. Craig peterson.com. Scroll down to the bottom of this screen. You'll see a little signup thing and I will start sending you my weekly newsletter.

    Some of these little micro pieces of training that only take you a few minutes and information on courses and more. Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 21 min
  • AS HEARD ON: WGAN Mornings News with Matt Gagnon: Microsoft Exchange Server Hack and Russia and Chinese Spying Activities

    Good morning everybody!

    I was on WGAN this morning with Matt Gagnon. Matt asked right off the bat about one of my soapbox subjects, Microsoft! I told him I have had it with them and their reluctance to fix their software when they have the means to do so. Then we discussed Russia and China and their spying and hacking activities. Here we go with Matt.

    And more tech tips, news, and updates visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] China and Russia spying on us. We knew this for a very long time. It's going to take years to unpack. We had the SolarWinds hack. Now we've got this Microsoft exchange server vulnerability. The most incredible drive a freight truck through it, vulnerability possible. I have had it. I think Matt Gagnon figured that out this morning when I was on the radio with him. So here we go with Matt Gagnon.

    Matt Gagnon: [00:00:28] It is 736 on the WGAN morning news, which is a perfect time on a Wednesday to talk to Craig Peterson, our tech guru. He joins us at this time every Wednesday. Also, you can hear him on this very station on Saturdays at one o'clock because he talks about these subjects and more in more depth and detail.

    Craig, how are you this morning?

    Craig Peterson: [00:00:46] I am doing great. My bees were flying yesterday. All of my hives overwintered, which is like a first for me. It is just, wow. This is so great.

    Matt Gagnon: [00:00:56] I'm sorry. I wasn't aware that you were a beekeeper.

    Craig Peterson: [00:00:58] Yeah, bees. I got chickens. I used to have horses, and we got cats and dogs.

    Craig Peterson, you also have technology-related equipment, gadgets galore and we're going to talk about some of that stuff right now.

    Matt Gagnon: [00:01:09] I want to kick things off maybe, if you will, Craig with me, by talking about the ongoing Microsoft exchange hack. What exactly is this?

    Craig Peterson: [00:01:19] This is an absolutely huge deal and it's not that difficult to understand.

    I am, bottom line, fed up with Microsoft. This is just the latest in a long string of major vulnerabilities. In this particular case, we're talking about probably right now, the numbers are over 100,000 businesses that have been hacked. It's just crazy.

    We know of about 30,000 give or take. Here's what the problem is. People in business need email. That's the life of a business. Many people made the mistake of trusting the Microsoft exchange server, which is something that you can get in-house. You run it on a little exchange server and aren't I great cause I got it set up. It's a little confusing. It also is offered in a hosted environment. Then Microsoft also has what used to be called office 365. That's now. Microsoft 365 also has email built-in. Okay. That's one of the core features.

    However, yet again, we had major vulnerabilities. Remember a mail server has to be exposed to the internet to allow it to receive mail and allow it to send email. It should really be one of the most secure machines you have and well protected.

    Many of us use bastion host. That's what I use for all of my clients. So that none of this nasty software or hackers get direct access to a complicated system, like Microsoft exchange server.

    They got into machines. They were able to, at that point, install a backdoor. Which allowed the hackers, and this is almost certainly China based on kind of the fingerprints involved, it allowed them to spread throughout organizations, including government agencies. Major government agencies, our school districts, local government, the retail, small business, you name it have been compromised.

    Microsoft, last week, came up with some patches that they released that kind of closed the door. The problem is the horses are already out of that barn.

    What happened is they've installed the back door and Microsoft didn't close it. Microsoft released patches for this major vulnerability, in the Microsoft exchange server, which you run again for your email and they did not fix the compromised machine.

    My advice to everybody, if you're a small business, if you're running an exchange server, you have to immediately patch it or have your service provider patch it. You should restore from backup from who knows how long ago, because there were backdoors installed.

    There's multiple types. This is a major mess up Matt, absolutely major. It's going to have consequences for years to come. 80% of Americans, now it's expected, about 80% of us have had all of our personal information stolen and in the hands of Russia and China. This is going to bring her closer to a hundred percent.

    Matt Gagnon: [00:04:39] Talking to Craig Peterson, our tech guru, who joins us on Wednesdays at this time to talk over the world of technology.

    I saw a news piece today, actually on China and Russia cooperating to build a moon base of some kind, which is perhaps a subject in and of itself that I could ask you about.

    That's actually not where I was going because China and Russia also in the news for their spying sprees, shall we call them. Where they're engaging in a whole bunch of different spying tactics. I'd love for you to break this down for us a little bit. It's a very interesting story.

    Craig Peterson: [00:05:09] It really is. We had this SolarWinds hack, and I've been talking about that for a couple of months now on this show. This SolarWinds is what's called a supply chain attack where SolarWind software is used by businesses to monitor their networks, to control systems that are within their networks to put this rather simply.

    SolarWinds issued a patch and it was an upgrade, right? It was the new features and some fixes and you got to install this. Apparently, over a year ago their software, SolarWind software had been compromised. SolarWinds then started distributing all of this Russian and Chinese malware to all of its customers. Again, including government agencies, businesses, et cetera.

    Now you have a supply chain risk. In other words, I'm using SolarWind software. I trust it, they signed it. I checked the signature and I got hacked bottom line.

    They have gotten into all kinds of systems, but SolarWinds said, Hey about a third of all of these tens of thousands of companies and agencies that have been hacked about a third of them don't use SolarWinds.

    It turns out now that they came in through Microsoft bugs. In this other third of the cases, almost certainly including this latest one we found out about last week.

    It is going to take years for us to try and figure this out, fix this problem. I am so upset. So upset with Microsoft. They are sitting on billions of dollars in cash, Matt, and they're not spending it to try and protect their customers. Small businesses, what are we supposed to do? It's nuts when our supply chain with our software providers giving us software that is hacked, already. We install it and now they are into all of our systems.

    All the Russians have to do is spray and pray. They just send it all out. We're just sitting there with our fingers crossed. It's not going to hit us. Oh, I trust Microsoft or I trust Apple, whatever it is.

    We have to hold these companies accountable. How about Equifax? They're still out there. They're still in business. They still have all of our information and they gave up about 150 million Americans plus Canadians plus some European data to the bad guys. They sit there and they say it's going to cost us ten to 20 million if we get hacked. To really fix this problem is going to cost us 30, 40, 50 million. We'll just sit here and won't spend the money.

    We have to stop this now.

    Matt Gagnon: [00:08:04] Craig Peterson, you hear his voice here every Wednesday at this time. You also hear it on Saturdays at one, o'clock talking about these issues and more.

    Craig, I appreciate it as always. We will talk to you again next week, sir.

    Craig Peterson: [00:08:15] Take care, Matt.

    Matt Gagnon: [00:08:16] All right.

    Craig Peterson: [00:08:16] Oh me. Oh my. Hey, Karen and I spent a bunch of time. In fact, the whole day, trying to get this membership site all up and running so we can put the courses in there for you. So you have the one place to go. So the free stuff that I'm going to be doing will be in there for you.

    Plus some of the paid courses we are getting close, I know I've been promising this forever, but I've got a business to run. I got eight kids, grandkids, right? My bees, as I mentioned, and chickens and all these other animals running around. So it's just taking me time. I have to apologize for that, but anyhow.

    I am very excited about what we're doing there because this is going to open up a whole new universe for us.

    All right. Everybody take care. We will talk again soon. Probably this weekend.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: MyHeritage Deep Fake Animation App and Microsoft Exchange Server Hack

    Good morning, everybody.

    I was on this morning on WTAG with Jim Polito. We discussed the new deep nostalgia app available from MyHeritage and some of the neat and also scary aspects of it. Then I got in a quick plug about the Microsoft Exchange Server hack that has affected 100,000 businesses. If you are using Microsoft Exchange Server, patch it and then wipe and restore your machine from backup because this hack leaves a back door in your system. Here we go with Jim.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Many of us have these pictures. I have pictures of family, of course, from the 1800s, and lots from then on. There are technologies now that are using a form of artificial intelligence. Right?

    Good morning, everybody. A very cool new, deep fake website that will take your old pictures and animate them. Yes. Those photos you've had for all of these years, you can now put in and it will turn them into a live living person video. It's amazing, but there's some risks. That's what I talked with Jim about this morning. Also, of course, I had to bring up this Microsoft hack.

    I have had it with Microsoft. So here we go with Mr. Jim Pollito.

    Jim Polito: [00:00:48] There is a warning using this could come back to haunt you. Joining us now, the man with all the answers, our tech talk guru friend, Craig Peterson. Good morning.

    Craig Peterson: [00:01:00] Hey, good morning, Mr. Jim. Man, I remember LaVale myself. It's a small world.

    Jim Polito: [00:01:07] You know, Roger LaVale.

    Craig Peterson: [00:01:10] Yes, the name is just crazy familiar. So I'm sure we've met.

    Well, maybe it's another one.

    Jim Polito: [00:01:16] Roger did work in high-tech weather systems, satellite communication systems, weather systems. Your paths may have crossed at one time. He traveled the world. He was a great man and a terrible loss. Thank you. I appreciate that.

    So tell me, people experiencing a loss because say they never met a grandparent. This was a great idea, right? You've warned us about how they can take my face though and make a video of me saying things that I would never say, and that's pretty bad. But this was a nice heartwarming application. No?

    Craig Peterson: [00:01:55] It really is. By the way, it's too late to worry about these things. I see the next election cycle being full of these fake videos.

    My heritage, you can go there. It's a very cool site. Kind of genealogy. There's so many people that are really interested in that. I have a son that is. We've traced our genealogy all the way back on both my mother and my father's side back to the seven-hundreds.

    Jim Polito: [00:02:22] Wow.

    Craig Peterson: [00:02:23] My mother's side, like a nine-hundreds or so. Once you hit a Royal line, it's just really easy. They really keep track.

    Jim Polito: [00:02:33] Royal Peterson. Listen, be careful, because Megan Markle and Harry will be saying terrible things about you. So be careful.

    Craig Peterson: [00:02:45] Well, did you ever seen that TV show Vikings?

    Jim Polito: [00:02:47] Yeah.

    Craig Peterson: [00:02:48] Yeah. Actually, some of those characters are my ancestors. The guy with the bad legs or whatever it is, right. I'm related to him. It's really weird. Now I have a daughter living in Norway, so it's a small world.

    Many of us have these pictures and I have pictures of family, of course, from the 1800s and lots from then on.

    There are technologies now that are using a form of artificial intelligence, that don't just take your photo, and I have software that does this.

    For instance, I use some software that uses artificial intelligence and the machine learning that's built into the Apple devices now in order to really clean up pictures, make them look absolutely amazing beautiful pictures from the thirties and forties.

    What my heritage is doing with their deep nostalgia is taking that to a much higher level and it makes some assumptions. If you've got a picture of someone that's maybe taken a little bit from the side or head-on it doesn't really matter.

    It looks at that picture and it mirrors it because in most cases, our faces are almost the same on both sides. Right. You draw a line down the middle of your face, Jim, the right side is probably pretty similar to the left. The top of your head is probably fairly easy to figure out what's there. What you can do with this deep nostalgia app here, which's available online, is upload a photo and it will have that person come to life. Their head will move around, their eyes blink. They will smile. It does all kinds of amazing things.

    It is, as you said, it's kind of cool to think about what my grandpa or grandma or whoever have looked like back in the day. A little video.

    Jim Polito: [00:04:39] So what's the problem with it.

    Craig Peterson: [00:04:44] Ahh. Well, we've had this problem for a while. Most of these deep fake apps that are available are from, you guessed it. There's this big country, like a billion-plus people. You have an idea, China.

    Jim Polito: [00:04:59] Oh, I know where you're going.

    Craig Peterson: [00:05:05] A lot of these are Chinese-based. They are taking our photos and doing basically whatever they want with them. We've seen this problem more and more, as people have paid more attention, and that is what rights do you have to that photo or video. Then once that photo has been modified, by an AI or something else, what rights do you have to that modified version?

    This is really easy to do. You can upload your picture, you hit the animate button, you set up an account. If you leave it on that website, they have access to it and the rights to it.

    We've seen many times that people there are doing malicious things with some of these pictures. I don't even want to go into that.

    Jim Polito: [00:05:55] So you basically cede ownership of that intellectual and physical property because it's a photo to them to be able to do this.

    Craig Peterson: [00:06:09] Yeah, absolutely.

    Here's the second problem that most people have, and that is they're not using password managers, which means they are reusing passwords.

    You go there, you can set it up using, for instance, in this particular case of MyHeritage. You can use your Google login, in order to log in. They have premium services. Most people are going to be reusing their passwords. They're reusing them across sites and that's been just an absolutely huge problem.

    Then you might've decided to submit even more personal data to my heritage than just the basic information you have to give to create an account. Yeah. You see where it's going, right?

    So it's never a bad idea to reduce your digital footprint. Adding this in. Giving up our photos may be good, may be bad. If you want to try it, it is kind of cool. They say that if you delete that little video off of their website they're not going to use it.

    Jim Polito: [00:07:11] Can we be sure of that?

    You know who we're dealing with, a year ago they were telling us, no, we don't have any problem over here with COVID. With any kind of weird pneumonia or more people die in by all means though, everything is A-okay.

    Well. It's not. Craig. I really appreciate that. I've got a longer final word coming up today. I thought that this was very, very important because you will click on it. You see other people's stuff and you're so thrilled and It's always good to hear from Craig Peterson about these things.

    Craig, in other ways to hear from Craig Peterson, His Highness, his Royal Highness HRH. We're going to have to put HRH in front.

    How do we hear from his Royal Highness Craig Peterson in the future?

    Hey, I sent out something real quick word of warning hundred thousand or more businesses have been hacked apparently by the Chinese because they're using Microsoft exchange server.

    Okay.

    Craig Peterson: [00:08:18] Government agencies have been hacked by this. Retail, education, our schools have been hacked. Hospitals have been hacked. Microsoft just released a patch for it, but it does not remove what it did, which is put a back door on your machine.

    They're taking everything from all of these businesses, government agencies.

    If you're using Microsoft exchange, patch it up now and then restore it from a backup because they may have compromised your machine.

    If you are someone who's been using Microsoft exchange, find options. I've had it with Microsoft. I have had it with them. This is the final straw. Forget it.

    Anyway, Craig peterson.com. You'll find out about this and so much more. There is so many little pieces of training. I have started giving them every week. Multiples. I got big stuff comin' up. Craig peterson.com.

    Jim Polito: [00:09:11] Craig, thank you so much as usual. What a great contribution you make to the show.

    We'll catch up with you next week or who knows maybe before.

    Craig Peterson: [00:09:22] Take care, Jim

    Jim Polito: [00:09:23] Thanks. Craig Peterson. Great guy.

    10 min
  • AS HEARD ON NH Today WGIR-AM 610: Understanding the Microsoft Exchange Hack

    Welcome,

    Craig Peterson here. This morning I was on with Chris Ryan on NH Today. I jumped right into a conversation that he and Justin were having about the Royal Family and because I am from Canada, I had a bit of a different perspective. Then we hopped up on one of my soapbox topics - Microsoft. Here we go with Chris.

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Installing the patches will not get them out. It will not even remove the back door that they've installed on your server. If you can believe this right. Its incompetence is running rampant yet again.

    Hi everybody. Craig Peterson here. We started out by talking about the Royal family because Chris Ryan over on NH today has been talking a lot about that. What's going on with the Royal family? I have a little experience with that. Well, we talked about it.

    Then we got into a soapbox for Craig, which was Microsoft exchange server. I could not be more upset with Microsoft. I have not liked them for decades, now. They are incompetent, if you ask me, in so many ways.

    I'm sitting here pounding on the table. I don't know if you can hear it, but anyhow, We get right into it. I mean the down and dirty of it, because once again, we have had our data stolen this time by the Chinese.

    Chris Ryan: [00:01:07] The queen does not have any power, Justin. These are all ceremonial positions. She has to sign off on the laws. She just does it. She's supposed to sign it.

    Justin McIssac: [00:01:17] If she decided she felt like having some power.

    Chris Ryan: [00:01:20] You can't. The prime minister controls all of the key roles of government. Going to war. Things of that nature. All of her roles at this point are ceremonial. For over the last number hundreds of years the monarchy has diminished and power based upon their incompetence.

    Justin McIssac: [00:01:38] It's time to take the power back.

    Chris Ryan: [00:01:39] The power has been taken back. But maybe she shouldn't sign it. Maybe she shouldn't ceremonial signing things anymore. Is that what you're saying?

    Justin McIssac: [00:01:45] No, just declare war on somebody.

    Chris Ryan: [00:01:47] You can't do that.

    Justin McIssac: [00:01:47] No, I think she can.

    Chris Ryan: [00:01:48] She can't declare war.

    Justin McIssac: [00:01:49] As I understand that she can.

    Chris Ryan: [00:01:51] You don't understand it.

    Justin McIssac: [00:01:53] That may be the case, but as I understand it she declared war.

    Chris Ryan: [00:01:56] She can not declare war, she holds no real power in the British government, none zero.

    Justin McIssac: [00:02:02] You're just trying to minimize her. That's what you're doing. You're hitting on the Royals and I won't stand for it.

    Chris Ryan: [00:02:06] Right now in the program. Is Craig Peterson. Craig, how are you?

    Craig Peterson: [00:02:10] Hey, I'm doing well.

    You know, power in the Commonwealth.

    Chris Ryan: [00:02:14] You have as much power in the United Kingdom as the queen does.

    Craig Peterson: [00:02:19] The queen, she appoints the governor-general in all of the Commonwealth countries.

    The governor-general has the power in the Commonwealth countries like Canada, New Zealand, Australia, et cetera. The governor-general has the power to dissolve parliament effectively firing the prime minister.

    She has quite a bit of power outside of the UK itself. The governor-general is a post that's above all of the elected officials in every Commonwealth country.

    Chris Ryan: [00:02:52] Australia, Canada

    Yes, that is true. In the United Kingdom itself, she does not have the power to declare war, to change the laws that are signed, she is a ceremonial figurehead. However, she maintains that position and influence outside of.

    Craig Peterson: [00:03:06] Yeah, she does. She gets a stipend too from the government.

    Chris Ryan: [00:03:09] It's good to be The Queen

    Justin McIssac: [00:03:10] Sun never sets the British empire, Chris.

    Chris Ryan: [00:03:12] You wonder though, we are going to continue on this Craig since you've indulged me. Which may be the biggest mistake that you make today. The question though is as we start to hear more and more about things that are taking place. Whether it's with Prince Albert and I don't understand why that continues to get brushed under the carpet, while the circumstances with Harry and Megan received this type of attention.

    But appropriately so. Now we're hearing claims that there was racism, within the crown and there were questions about how dark the complexion of their child was going to be, to Harry. That was relayed to Megan. As an individual interested in this, do you see anything changing in regards to less ceremonial roles? The crown diminishing even more with the questions, around Charles, as well and his ability to lead?

    How do you see this affecting the crown as they seem to decrease in terms of what their actual power is but their influence increases? The intrigue in them increases on a continual basis.

    Craig Peterson: [00:04:14] Well, parliament's never particularly liked them because they don't like the budget money going to them.

    But I can tell you that throughout the Commonwealth and the UK, the Royal family is like the center of the conversation. I have an aunt who has passed now, Anna Hanna was her name and she lived for the Royal family. Everything about them. She knew all of the details.

    Chris Ryan: [00:04:38] Right? It's insane.

    Craig Peterson: [00:04:41] I think it's a little crazy, but we got the same thing here.

    People talk every day about these stupid artists that can't even sing. These actors and actresses can act. Follow everything they do. Look at the people that are famous for being famous. The Kardashians, what did they ever do? Well, they built some big empires that's for sure.

    It's the same type of mentality.

    Chris Ryan: [00:05:06] It's true, but I have a lot more respect for it. I have a lot more respect for any actor, musician, or influencer than I have for the crown. Basically, all that you did was be born into a circumstance. That is no reason for me to be interested in you other than the fact that you have a tremendous lineage. That is what upsets me more than anything else about those particular individuals.

    Now, certainly, there has been the benefit of nepotism for some folks in acting and sports and music and all that. Those folks have interest-based upon talent. Whether that's the talent of just drawing attention. Then, therefore, monetizing it, the Kardashians, as an example, there. I have a lot more respect for Kim Kardashian than for the queen of England. I'll just put that right out there.

    Well, let's transition here before we get into more trouble, right?

    We'll get you into trouble.

    Tens of thousands of US organizations hit in an ongoing Microsoft exchange hack. At least 30,000 compromised US organizations as a result of this hack. What took place? What concerns should average Americans have about that?

    Craig Peterson: [00:06:17] This is an extremely big deal. I did a video on this. Everybody who was on my email list, you should have gotten a little copy of this last week when it happened.

    If you are a business, Chris, you have to have email. That's kind of the lifeblood of a business is email. Many companies have made the mistake. I've called it a mistake for decades, of using Microsoft exchange server.

    Microsoft is a company that happens to sell software and usually, it's not particularly good software. I've got a little bit of an opinion on that. For years, I helped develop windows NT early on in Microsoft history. I've used it all. I've developed on it all. I'm talking about the operating systems here.

    Here's what happened recently. Businesses have been using Microsoft exchange server, as have government agencies, as have retail, our educational institutions. No one gets fired for buying Microsoft.

    That just drives me crazy cause they got some really bad stuff. The bottom line and I have a friend who loves the Microsoft stuff because he'll always have a job trying to fix it. That's beside the point.

    Right now, there was such a huge hole that freight trains are driven through. Anyone could easily gain control as the server over any sessions in any data. So last week, Microsoft issued an emergency patch for all of its exchange servers, that kinda sorta fixes the problem.

    The problem is they've gotten into, probably over a hundred thousand computers at this point, and they have put back doors into the computers. They're using the computers now to attack other computers, to grab all of your passwords, all of your history, all of your files and you have no idea.

    Because people are not doing the right stuff, which is blocking outbound connections from things like their exchange server. They're exposing it directly to the internet which you have to do, cause it is your main email gateway. This is just incredible.

    The federal government has jumped on this. Expect congressional investigations, which will solve nothing. By the way, if you install this patch, Chris, you may close the door.

    The problem is the horses are already out of the barn and you may already be infected. The odds are really good. If you're running an exchange server that you have been attacked, that they are inside your network.

    Installing the patches will not get them out and it will not even remove the back door that they've installed on your server. If you can believe this, right.

    Incompetence is running rampant, yet again, and we're losing all of our critical data.

    This is probably China, by the looks of it, and it just a scary, scary thing. Patch right now if you're a business, if you're a school, if you're a nonprofit, right. Patch. You've made the mistake of running a Microsoft exchange server, patch it and look at alternatives.

    Chris Ryan: [00:09:37] I think that there's always a cause for concern and diligence in regards to our information. Let's be honest, we're being a little bit more open with that than we have in past time periods.

    Evolution over, not just the last couple of decades, but over the last few years has been pretty significant. In how frequently we use our credit card information or personal information. You think about the explosion in delivery services and ordering things online with that each time you are putting your personal information there.

    What should it be people's concerns on that?

    Craig Peterson: [00:10:11] Well, things like credit cards, aren't too bad. If you have a visa or MasterCard check with your bank or the issuing company. What I do, if I have to give a credit card online is I have an individual unique credit card number for every website. That's absolutely a free service from all of these credit card companies. Every one of them has it. So check it out, find out more about it. You can install it on your browser. You probably want to use a secure browser. At any rate that's a whole other topic for discussion.

    You've got to give your information nowadays, especially with us being locked in for the last year. Use unique credit card numbers, and you can get those for free from your credit card company. It's just a little plugin for your web browser.

    Businesses, you've got to pull up your socks. Cannot let these people's personal information gets stolen. Remember this includes doctor's offices with your personal health information. Hospitals. It goes on and on. The C levels, Chris, I think are the biggest problem here in all of these companies. You give you a credit card number to a quote to secure server. It's not really a secure server. It's just that your data is encrypted, going to the server. Once that company has your data, is it being stolen?

    Is the CEO looking at this, like Equifax apparently did, from some of the articles I read and said, Oh, well, let's see, it's going to cost us, 10-20 million if we get hacked? It's gonna cost us 30-40 million to fix the problems. We're not going to bother fixing them. We're going to cross our fingers. We can no longer do that.

    Chris Ryan: [00:11:54] All right, Craig. Appreciate your time and look forward to talking again next week.

    Craig Peterson: [00:11:58] Take care.

    Chris Ryan: [00:11:58] All right. That is Craig Peterson with tech talk here on Newsradio 610 and 96.7, Saturdays at 11:30 AM.

    I am Chris Ryan. We shall return with more after this.

    Craig Peterson: [00:12:09] Woo mama. Keep your eyes on your email, because Improving Windows Security is about to launch. I think what I'm going to end up doing is we're going to do a couple of classes live and available for anybody for free before we get into the paid course.

    Keep an eye on your email. Also, I'm going to let you know people who've already signed up for the Improving Windows Security course, I'm going to give you a massive discount. You'll get a coupon for that.

    We'll be back Craig Peterson.com, of course. If you're not on the list better sign up soon because this course is starting.

    Take care, everybody. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Tech Talk with Craig Peterson Podcast: Google Chromebook Outsells Apple - who is the loser?, Vulnerability in Programmable Logic Controllers affecting large Infrastructure providers, Clubhouse and More

    Welcome!

    I am sure that most of you know about the problems Texas experienced with its energy infrastructure well there is more bad news for our nations' infrastructure and that comes from a vulnerability in the programmable logic controllers that many of these large infrastructure providers use to control the flow of product. (i.e., water, electricity, natural gas, etc.). Also this week Google Chromebooks outsold Apple but that is not the whole story. We also dug into processors and the importance of them and how it affects what you do daily. Then we discuss Clubhouse and why it may not be the best platform to get on and there is more so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Embracing a Zero Trust Security Model

    Turns out Most Manufacturing, Water Supply, and Power Companies Use Controllers with a Security Severity Score of 10 out of 10

    Chromebooks outsold Macs worldwide in 2020, cutting into Windows market share

    Clubhouse is the New Up-and-Comer but Security and Privacy Lag Behind Its Explosive Growth

    New York sues to shut down 'fraudulent' Coinseed crypto platform

    Former SolarWinds CEO blames intern for 'solarwinds123' password leak

    WhatsApp will basically stop working if you don't accept the new privacy policy

    TikTok breaching users' rights "on a massive scale", says European Consumer Group

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Apple just got passed by Google's Chromebook. We'll tell you more about that. Clubhouse the app everybody seems to want, and it's invite-only. Sound familiar? That's happened before has got some serious privacy problems.

    Hi everybody. Craig Peterson here. Thanks for joining me today.

    There are a lot of things to talk about and I'm going to start with this article from ARS Technica, talking about programmable logic controllers.

    Now I can see you sitting there saying, what are you talking about, Craig? Who cares? Here's, what's going on. You heard about the solar winds hack? It's been something we've talked about pretty much every week here for the last Oh a month or so since it really happened. And we found out some more stuff about it this week, by the way, we know who the group is that actually did the hack very professional group. This means, of course, nation-state, but.

    They were going after different types of companies, that help the different types of companies, as well as government organizations. In other words, they were targeting MSPs managed services providers. And unfortunately, most of them failed because it's rare, very rare to find an MSP that actually takes care of security.

    And I'm not going to blame them. I'm not going to blame you for using one of these MSPs that got compromised. Because ultimately, security is a long tail thing. It is an industry in and of itself. It's hard to keep up. It's hard to keep moving forward. But I brought this up because I wanted to tie it into something we also talked about a bit for the last two weeks, and that is that water plant in Florida.

    This water plant in Florida had the amount of lye added to water, turned up 100 fold. Not 100%, a hundred times more lye in the water and somebody noticed and all well and good.

    Who did it? We don't really know, but here's the problem I want to talk about today.

    And that is the SCADAs systems, these PLCs, in other words, The computers that are controlling the valves in these various businesses and government agencies, the water plants, the electric plants, et cetera. You had valves. Those were these tubes. Remember that, and then transistors for a little while. Anyhow.

    This is something that's a very real problem because Rockwell automation you've heard of Rockwell before. I am sure of that because Rockwell has been a government contractor forever. They've done a whole lot of stuff in the military space and they do a ton also in the civilian space.

    Rockwell makes hardware that's used to control equipment in factories, a lot of equipment in a lot of factories, as well as all of these other places out there. And it is what's called generically a "programmable logic controller." They're selling them under this logix brand. You'll see them everywhere. They control everything you can think of out there.

    Some of them are very small. There might be a, like a toaster that you'd have on the countertop for instance, or something as big as one of those little pizza ovens you can put on the counter, but then they can be a whole lot bigger than that. But they help control equipment. And. Oh, the manufacturing and the processes on assembly lines and other manufacturing environments.

    You might remember what happened in Iran, where they had these PLCs, programmable logic controllers, that were part of this whole SCADAs system. It's all together. And in Iran, they were using them to control centrifuges and those centrifuges were being used to refine nuclear material eventually to make nuclear bombs. At least that's what we said. That's what the UN said, et cetera, et cetera. And then it makes sense, right? They have to refine the yellowcake. So that's what they were doing. And what did we do?

    Apparently, we got together with this country called Israel. It's over there in that same neck of the woods. And with them, we came up with some software to break into the computers at the Iran facility. Now, these computers were what we call air-gapped. They were not directly connected to the internet. So how did we hack it? We hacked the old-fashioned way. No, we didn't use a little honey bait. What happened with rep Swalwellout in California, who I don't understand how he's still sitting on the number one top secret committee in Congress, even though he spent years with this Chinese spy who obviously would have been feeding all of this information that he got back to China. I don't understand Nancy Pelosi. Sometimes this is just crazy. What's going on in Congress?

    It wasn't that? Okay. It wasn't a honey trap. It was a honey trap. I guess what they did is they developed this piece of malware, knew that they had to get it on to the machines that controlled the manufacturing process there in the plant that did the refining in order to make the nuclear bombs.

    How can you get it in if it's air-gapped, how can you get it in if those machines are not connected to the internet? But it doesn't matter if you break into the firewall because they're not behind the firewall. They're not on a network that is accessible from the outside. However, they were networked and they have to be networked inside the building so that you can have one computer that's monitoring the spin rates of all of these different centrifuges and just kind of keeping tabs on everything. So they went ahead and they put this little virus onto a thumb drive. And then, in fact, they made dozens of these thumb drives. They found out where the engineers who worked at the plant went for coffee, where they went for lunch and they scattered these around.

    And then a coffee spot at the lunch spot. And so now all of this stuff is scattered around these little thumb drives people, pick them up, Oh, a free thumb drive and they take them into the office. And this particular piece of malware was specifically crafted for this programmable logic controller. So if you plugged it into your computer as an accounting puter computer, it would say, Oh, wait a minute this is an accounting computer. I don't care.

    But these guys brought it back into their manufacturing facility and it did work there and it took over control of the machine that controlled all of these centrifuges. And fuges, it keeps saying fuses, centrifuges and it spun them out of control.

    And while it was spinning them out of control, it was showing a perfectly Greenlight status to the people who were trying to monitor it. They resist, it was a stroke of brilliant, but that is the type of system that we're concerned about. That's what we're talking about right now. These kinds of logic controllers that are used all over the place you can use them for almost anything you used on ships. They're used in government facilities. They're used everywhere.

    There was a vulnerability found and it was a, "I can't believe you did this" vulnerability. Now with solar winds, we found out it was a, I can't believe you did this vulnerability because apparently, solar winds had a password of solar winds one, two, three. Who wouldn't guess that perfectly good password? And man, we see these types of passwords all of the time. That's why I use a password manager. That's why you generate passwords or you come up with key phrases. Three or four words strung together with maybe a digit or something else in the middle somewhere and some upper lowercase characters. Right? That's how you generate a password. It's not supposed to be solar winds one, two, three. So that's problem. Number one, that's a big problem.

    This particular vulnerability has a severity score of 10 out of 10. Why? Why is this the worst level it could possibly be? Number one, it requires a very low skill level to be able to exploit it.

    Now that's interesting. Why is that?

    It turns out that these program, programmable logic controllers have a hard-coded key built into them. In other words, whoever programmed these things, and I'm looking at this list, there are a lot of them. Logix is the name of the company, the name of the product, and you'll see Logix in their names. And it is a whole bunch of compact Logix control, Logix drive, Logix a guard, Logix, guard on me. Now that wasn't supposed to provide cybersecurity support. All of those, okay. Then they have a hard-coded password.

    What that means is built right into the software is a back door with a password that can not be changed.

    Now, even if you bought one of those cheap firewalls from the big box retail store, you are going to be safer. Because at least it lets you change the password and you should be changing the password on your firewall. And in some cases, it also lets you change the username and you should change the username as well.

    But no. These Rockwell devices have a hard-coded password and Rockwell apparently is not going to issue a patch that directly addresses the problems that come from having a hard, coded key. So instead of that, they're saying, Oh, use these mitigation techniques.

    Isn't that what Iran did, isn't that? Why they had themselves? Nice little air gap network that was still breached?

    Oh, man. Oh, man. So it's a problem. It's a very big problem and they're just not paying much attention to it.

    Hey, stick around. We're going to talk about Chromebooks versus Mac and Windows right here.

    It looks like the Wintel monopoly continues to die on the vine because of what Apple's been doing, what Google has been doing. In fact, Google is really stepping up their game here, getting rid of Intel.

    Hi everybody. Craig Peterson here. Thanks for joining me.

    We know that Intel's been around for a long time. You probably remember Intel used to brag about it. There were ads where Intel would kick in a couple of bucks if all they'd said was Intel inside. In fact, they are still doing it on machines. You buy a machine it'll probably have a little sticker if it has an Intel processor saying Intel inside. Intel had a problem, they made components that people didn't buy.

    Well, they bought them, but they bought them as part of something else. They did not buy an Intel processor for the fact it's an Intel processor. Makes sense. Some of them did. I certainly looked at them. I bought AMD and some others instead,. Some of the power PC stuff from IBM, just absolutely incredible, as well as others.

    I have done a whole lot over the years when it comes to processors, you've heard already I helped develop operating systems and implement them and the internet protocol. I've got a lot of experience with processors, no doubt about it. A lot of machine coding and assembly work over the years. I wrote C, which is a programming language used largely for a high-speed stuff like operating systems. I did a lot of that.

    I look at this processor from Intel as a massive failure. Marketing-wise. In the industry, it's been really great, but when I get into it from the prospect, or from the side of being an architect, of operating systems, and an architect of user interfaces. I cannot believe Intel. It's just been terrible. Part of the problem with the Intel processors and their instruction sets. The way they do the memory access and the way they do all of their IO to other devices has to do with their legacy code.

    They've tried to remain compatible with all kinds of older processors over the years. I can understand that I can see why they might want to do that. They're afraid that people might leave them. They started out as a memory company and through. I was going to say no fault of their own, but no luck of their own or anything else. I don't know. Another company came to them and said, Hey, can you make a cheap processor?

    Remember IBM looking for a cheap processor to put into this PC right. A personal computer that they didn't think would sell very many, certainly wouldn't be a great business thing. They went and said, okay what are the cheap processors we can get and put into here? Intel, 8080. That's what we'll do. All of a sudden is born the XT and the PC XT and the PC AT came. Some of these others over the years on the 8286 and the other chipsets. Anyhow, I'm getting awfully geeky on ya. Started really falling behind. One of the ways they fell behind was in 64-bit design.

    In fact, Intel is AMD compatible. Now, if you can believe that. Talk about falling behind. I don't think it's the engineers, there's some brilliant people there. It's entirely business decisions that drove them to the point they're at. They continued to increase the price of the processors. They were getting a little faster, but they still had the corner on the market because people bought Wintel they bought Windows. If they're going to get Windows, they're going to get Intel. Make sense. There were some others over the years that competed including AMD, which is Intel-compatible for the most part.

    They really managed to keep people out of the marketplace so they could jack-up the cost. The price structure, just keep jacking up, jacking up, jacking up. Many companies got fed up with it, including some companies that had the ability to do something about it. One of those companies is Apple.

    I mentioned in my newsletter last week, I had an article talking about how Apple is now apparently about to make 6G chips. 6G at the next generation of wireless and Apple's getting rid of Qualcomm and gonna make in themselves. A company like Apple, when they want a million parts, they want them to arrive. They want them to be there on the day they ask for them and they want them to do what they asked for.

    Qualcomm has fallen down on that. They have not been able to meet Apple's demand. Intel has fallen flat on that. They have not been able to meet some of Apple's demands that have to do with the amount of energy they use the temperature they give off of course cause they want them on mobile devices.

    What did Apple do a decade ago? They said fine, forget about it. We're going to not use your Intel processors in our iPhone. They started using some other processors, some arm processors. Apple joined this community like an open-source manufacturing alliance that came up with a chip design that they could use as a basis. Apple took that and ran with it.

    Today it has run so far with it that Apple has an amazing chip. Now you can see these amazing chips in your newest I-phones and your newest iPad. That's what they have in them these new Apple processors, but Apple also now has their new M series processors, which are effectively the same things they've been using in the iPhone, iPad, but beefed up in order to handle the load you'd expect to have on a laptop or a desktop with a Mac mini. I'm just so impressed with these. I was playing with both of those. One of our clients wanted them.

    We had them ordered and shipped to our place. We put them on benches and we loaded them up and got them all running. We played with them a little bit just to see what they were like. Very impressive machines.

    They don't have Intel processors. Apple has switched processors a few times over the years, it went from the Intel or the Motorola over to the power PC then to the Intel, and now to its own chip design. It looks like completely new chipsets for the iPhone 13 hopefully, maybe the 14, hopefully, when that comes out. That'll probably be later this year.

    By the way, the 13 is just going to be an incremental update to the iPhone 12. They're saying is probably going to be like an iPhone 12S, really.

    Processors. Apple doesn't need to pay the Intel tax on these processors out there. I'm going to look right now, purchase price, Intel, a laptop CPU, just to get an idea. I'm on there right now and I see coming right up, here's an Intel core i9 $400. Just for the CPU and that's from B&H photo and B&H has a lot of this sort of thing. Most of these Intel CPUs that are on laptops cost over $400. They're branded as core this, that, or the other things.

    The real expense of one, just start getting into the Xeons. Those Xeon processors can be just through the roof. Here's one here right now an Intel Xeon platinum, 8180 $11,000 while actually, it's 10,995.

    If Apple can make its own processor, do you think they can do it for less than 400 bucks? Of course, they can, and that's going to save them a lot of money in making some of these devices.

    We're going to get into those devices, like the laptops. What do you need in a laptop? Why would you go with Windows, maybe one of these other operating systems, including Mac iOS? We'll talk about that.

    That's going to lead us into the conversation about Chrome. Why is Chrome OS becoming so popular? Why has it surpassed now market share of Apple and where did that market share come from? People have been buying PCs, but what's going on?

    Stick around, you're listening to Craig Peterson and you can find me online. Craig peterson.com.

    We're talking about chips. Yeah we're getting maybe slightly technical, but chips matter nowadays in a way that they haven't before and yet they matter even less. I'm going to explain that.

    Hello everybody. Craig Peterson here. I just said something that might've sounded confusing. Cause I said, CPU's matter more than ever. Yet they matter less than ever. Here's why.

    If you're looking at an Apple computer, you are looking at either an Intel processor, at least for the next couple of years or the Apple processor.

    If you're looking at a Windows machine for a little while Microsoft was really on a bit of a kick, trying to get Windows running on multiple platforms. In fact, it actually did. There were some amazing things they were able to do, but really if you're getting Windows, you are going to be on an Intel platform.

    How about your phone? Do you have a clue as to what kind of processors in your phone? Now, you guys are the best and brightest. So yeah, you, you might, okay. You might know the exact model number and CPU clock rate and everything else about your phone, but the vast majority of people have no idea and you don't need to know. You don't need to know because it is now like a utility. You don't really know how that electron is delivered to your house. Where that came from? How that was produced? You just turn on that light switch and hope it works, right?

    Unlike when there's big wind storms and your power goes out, that's what you're hoping for. That's what's happening now, you buy a phone, you don't care if there's Intel inside. The same thing's true with tablets. You buy a tablet, if it's an Apple tablet guaranteed it doesn't have an Intel CPU. If you buy a Surface tablet, you can get them with Intel or without Intel. A lot of times you can tell just based on the price of the tablet now.

    As we move forward, we're starting to see more and more devices powered by arm chips and others. You see the idea behind Unix, which is this operating system that's underneath all of them. Unix lives underneath MacOS. Unix lives underneath Android. It lives underneath pretty much every cell phone and every device programmable device that exists today has Unix underlayment, which is the main operating system. It's fantastic.

    The whole goal behind that when it was designed by At&T was to make it so that this one operating system could run on anything and it did. Universities adopted it because it would run on anything and universities were getting equipment donated to them from everybody. That was anything, right? This mini-computer, that mainframe, all of these pieces of equipment got donated. They standardized on this Unix platform and the whole thing worked out quite well. Linux is a type of Unix for those who are wondering. The whole idea behind it is that the processor doesn't really matter because there's a version of Unix that will run on really pretty much any processor that's made today or has been made for the last 40, 50 years.

    Now, when you start getting into the useful computers that you and I use every day. What's underneath it? If you run a Mac, I don't think you really care. If you're on a Windows computer, I don't think you really care. What you care about is can I do that task at hand? Can I go ahead and open word, document editor. Even then you don't even care if it's Word for the most part. Word, you're going to get around it a little bit easier, but if you are over on a Mac, you could use pages. It doesn't have to be word and it doesn't have to be Windows and it doesn't have to have Intel inside.

    I am not giving stock advice, but I can tell you, I would not be out there buying Intel right about now. Hopefully, they got some other stuff going on. I know they're looking at some new chip designs that they can provide to people that make it pretty darn simple.

    Now there is another big player we haven't talked about yet and that is Google. Google's got Android, which is underneath again, a Unix operating system. It has also on top of that, this big Java virtual machine, which has been the source of many headaches, a lot of chagrin here for developers. The beauty of it is again, Java was designed so that you can write your program once and run it on anything. You see where I'm going.

    We're getting to the point where the competition is going to be crazy. When it comes to the devices we use to get online or the devices that we are using for work, and it's going to get cheaper and cheaper. I'm not talking about the cloud. The cloud is not cheaper. In most cases, the cloud can present all kinds of additional problems.

    We just got an email from a listener Danny today. In fact, he bought one of the little packages that we'd put together for the listeners. About 18 months ago of a special, it was a little Cisco firewall and Wi-Fi switch with security built into them, something you can't buy off the shelf. It had the firepower basic stuff in it. Anyhow. So Danny was asking because he uses G suite. How does he do a three, two, one backup? You can't with Google's G Suite. With office three 65 or Microsoft three 65, in both cases, they have lost their client's data. So Danny was asking, so what do I do? How do I do a three, two, one backup, like you advise we do?

    Basically what we said is you've got to download all of your data from those cloud services, back them up properly at that point, and do it all in a format so it can be restored. So if it has to go back to the cloud, it can. It keeps your data safe. All of that stuff is, again, just it's everywhere. It's cheap. There are pros and cons to different ways of doing it. Dan is not there thinking I'm using G suite or I'm using Microsoft three 65. What processors behind it, right? You don't care.

    Google has said here's what we're going to do. We make a phone now, the Google smartphone isn't well adopted. It's more of an example of here's a way you can implement the Android operating system. It's a proof of concept for them. It's not a bad phone. They've tied in with some other carriers in order to provide cell phone service.

    They are coming out with a system on a chip. You used to have this big motherboard and if you go way back, I have a very big motherboard with all kinds of discrete components. Nowadays, all of that gets squeezed into one chip and Google has decided that they are going to make their own chip. They call it the white chapel. That's the name of the whole program. It was reportedly made using Samsung's nine millimeter process technology. In other words, it's going to be fast. It's going to be power efficient, and initially, they are going to be putting it into their smartphones. That's not a bad idea. In their pixel smartphone sometime late this year.

    We haven't quite made it yet to Chromebooks, but I promise we'll get to that in just a couple of minutes. I wanted to make sure everybody had a decent understanding so that you can make the right decision for yourself and your business when it comes to what kind of computing to use.

    Stick around.

    So what kind of computer should you get? What's gonna work for you? Should you worry about the chip that's inside of it? What do you do? It just gets so confusing sometimes. That's what we're going to get into finally right now.

    Hi everybody. Craig Peterson here. Thanks for joining me today.

    Now, there are options when you are looking at a computer and I know some people don't even have a regular computer anymore, so let's start there. Really quickly many people are just using their iPad and that's what the goal was behind the iPad. I think that's what Steve Jobs had in mind.

    Apple always wanted it to be a replacement for your computer. It is not as flexible as a computer is by any stretch. Frankly, it's gotten a lot better, especially the iPad pro because of the faster CPU and it has a few more capabilities. It's a good little unit. That's what I use by the way is the iPad pro.

    If you are just going online and you're doing a little browsing, maybe editing a few documents, getting on a zoom call or a WebEx call, whatever it might be, doing all kinds of the regular stuff that iPad's going to work for you. If you have an iPhone, you can link your iPad to the iPhone. If someone calls you on FaceTime, you can actually answer, take the call on your iPad.

    If someone calls you on with a regular phone number, if someone does that anymore you can take that as well, right there on your iPad. iPads are inherently very safe. They have done a great job in trying to keep things pretty tight from the cybersecurity standpoint on the iPad.

    If you need to use Windows applications, then that's where the surface tablet might come in for you. I know some people who like their surface tablets and I know people who really don't like their surface tablets. Personally, I don't think I would buy one. There's not a huge win, but again, some people like them. They're more portable than some laptops.

    Now, you can get laptops in the Windows world that are as small and lightweight as an Apple laptop.

    Now, which would I get the Apple laptop versus a Windows? I would absolutely without a doubt, no question get the Apple. The main reason for that is that it's cheaper. Yes. I said it was cheaper. It's cheaper because that Apple laptop is designed using high-quality components and is manufactured using high-quality stuff versus that PC.

    You might find a laptop PC laptop for maybe 350 bucks, and you look at the Apple laptops and they start at just under a thousand dollars. They're small the Apple ones and they are very functional and they will last. If you get the same component in your windows laptop, the same quality, the same speed, the same buses, IO, everything else, same display. You are going to pay more in the Windows world than you would on a Mac.

    If all you can afford or all you want is something inexpensive then I've got an option and it isn't Windows. Okay.

    Unless you have to have Windows, if there's a specific program you have to use that only runs on Windows while you're stuck aren't you.

    There is another option out there and it is called a Chromebook. It has been doing very well. 2020 was the first year that these Chromebooks outsold Apple Macintoshes. Now, that's a big deal because Apple's always been a kind of a minor player, seven to 10% of the marketplace. To see Chromebooks actually beat Apple is impressive. Now, part of the reason they're beating the Apple is what I just explained to you. They are inexpensive.

    Many kids are at home, right? They're going to school from home virtually and the schools need them to have a computer. What do they say? Get a Chromebook. Here's a $300 Chromebook. Go ahead and get this for your kid or here's $300 and or $300 Chromebook. In some cases, the school just buys it for the kid. Great for that.

    Now, remember it's Google, you're storing most of your documents up in Google's cloud. Depends on how you feel about Google and having Google with full access to all of your information.

    I have a big concern with Google having access to my kids' information, but that's a wholly different story out there. No question about that.

    Chrome is an operating system again, that is based on Unix. It's actually Linux, which is again, a version. It is something that you just won't see. The odds of you directly interacting with the operating system just keeps going down and down.

    Now, Windows, you still got a muck around sometimes you got to get into the registry editor. You got to do weird-ass stuff.

    With your Chromebook or with your Mac, you're not going to have to do that. It's not an antiquated design. It is a very modern design. Very easy to use.

    Now, I started the segment out by saying that CPUs matter more than ever, and yet they matter the least they've ever mattered. Here's why I said that the manufacturers now are able to choose the CPU they want to use. Unless, of course it's a Windows target, but for anything else for Chromebooks, they can use any CPU from any manufacturer. They might have to do some porting and do some work involved in that, but it's moderately minor.

    You can't say the same thing for Windows. Windows is locked into a couple of different architectures and you can bet Microsoft is pretty busy trying to make it so that it will run across even more CPU architectures. It matters more to the manufacturers and matters more to you what CPU they're using, because it keeps costs under control. It gives you longer battery life. It lets them put a smaller battery in and still have longer battery life. Lots of good things.

    It doesn't matter at all anymore because you only care about the web browser. You only care about the text editor, right? What is it that you care about? It isn't, what's underneath all of this.

    Chromebooks, you can find for 150 bucks at a big box retail store and you get what you're paying for. That hardware is not going to be stellar that's for sure. But it's going to work and is going to do a decent job for you. If you don't have any money, really, but you can afford to crack 150 bucks, look at a Chromebook. Chromebooks go all the way up into the $2,000 range.

    Those higher-end ones have more local storage. They're faster. There's a bunch of different benefits to them.

    Now, you've got the options.

    Apple is going to almost certainly stay with its own chipsets. It lets them keep control over the entire investment. Now, you might say that's bad. I don't want to get locked into Apple. Well is not really going to matter that much, but you are going to get locked into Apple. The reason it's not such a bad deal is looking at the marketplace, Apple has a few dozen different designs. They have to maintain the operating system for all of their software, their device drivers, everything has to work across a few different, a few dozen models. Think about it. You've got how far back your iPhones', I know they still put out some patches for iPhone fives and sixes, they might have even older ones. So there you go. Then they had the larger versions of some of the iPhones and they had the ASCE versions. Look at that.

    Compare that to the Android space. Where you have hundreds of manufacturers using Android and building smartphones with it. Thousands of different models of phones each with their own device drivers and all kinds of little things. Some of these manufacturers will go ahead and grab whatever's in the parts bin today and throw that in. Okay.

    This is true too, not just to the smartphone manufacturers, but if some of these PC manufacturers. Dell has been known to do this. Where it's okay, we're making a laptop today. Okay, we promise them this CPU, but this USB controller that we normally put in, we don't have it right now. I'm going to put this other one in there. It gets very confusing when you're trying to repair these things each one of those USB controllers has a different driver for Windows.

    So Apple, the part of the beauty of this is they only have to worry about the security and reliability of just a few dozen different designs versus Google having to worry about again, thousands and thousands of them.

    That's why also with Android you do not get the patches when they come out. If they come out, it can take an easy six months for a patch that's issued by Google to show up available for your phone. It typically takes Apple a matter of a week or so. It's just there. There's no comparison. That means your cybersecurity is going to be better when you can get patches.

    If you have an Android phone, that's more than two years old, forget about it. You're not going to get patches. If you really are insistent, like some people I know in fact, Danny were just talking about it. He really likes his Android. Don't first of all, always buy the top model. It should probably be as Samsung. It should be never any more than two years old. You got to trade it in every one to two years so that you're pretty sure you're going to be getting security updates in a timely fashion.

    There you go. That's the explanation of it. I love my Microsoft stuff for specific Microsoft apps. I really love my Mac for all the graphics and everything. It just works. It doesn't crash. The applications all just work.

    I use my iPad for some just general basic stuff, and Chromebooks are probably the way to go for most home users. As we just talked about for schools as well.

    Hey, visit me online, CraigPeterson.com. You'll find all kinds of great information there. Craig peterson.com,

    Look for my podcasts.

    I guess this is a little bit of good news. If you're a home user, not a business or some other organization, like a state or County or city office, but we've got some breach numbers that have just come out for 2020. We're going to talk about right now.

    Hi, everybody. Thanks for joining me. Of course, you can always go to my website. Yeah. Pick up all of the podcasts in case you missed something today or another week, you'll find them right [email protected]. You can also sign up for my email list and we're going to be doing a couple of different things here.

    I think in the near future, we're going to be sending out some reports that we made as part of the security summer thing I did a couple of years ago, and each one of these reports and there's 30 something of them. Some of them are like five to seven pages long, but it's a checklist of all the security things you should be worrying about.

    Now, if you are a home user, you'll find a lot of these to be interesting. But if you're a business person, you work in an office, you help to run an office. You own a business. You need to make sure you get all of them. So make sure you are signed up Craig peterson.com and we'll be glad to get those out too.

    Plus we're also going to start something new every week. I usually have six to eight, sometimes as many as 10 articles in the week. I spend hours going through finding what I think are the most important things that interest me as well, but that I think will interest you guys.

    I put them in an email, it is it's not very long, but it's just a few sentences from each one of the stories and I have a link to the story as well, right there. I'm going to start sending that out as well to everybody cause some people want my actual show notes.

    We're going to have the newsletter once a week. Then we're also planning on having a little video training as well. So it might just be straight, like straight audio. That's part of a video, but it'll be training on a specific security task or problem that's out there. Then the course improving windows security.

    It's been taking us a long time. Blame it, mostly on me. Karen's also busy with babysitting grandkids at least a couple of days a week, and I'm trying to run a company as well. So it's, forgive us, but it is taking some time, but you're going to love this. I think it's turning out really well.

    I am about halfway done with the final edits. So I'm recording them. We go back and forth. They ended up recording them twice so that we get all of the points I wanted to cover into them. Karen's come up with a whole bunch of great screenshots and other pictures to go in with it so it's not one of these death by PowerPoint things.

    And we've got 21 different talks, if you will, on locking down windows and I go into the why's as well as the hows. I think that's really important, because if you don't understand why you're doing something. You're much less likely to do it. I picked that up from Mr. Tony Robbins, none other, the Anthony Robbins man.

    It's been over 20 years. Karen and I went to an event he had down in Boston and this was one of his firewalk or events. We actually got to walk on hot coals it was the weirdest thing ever. Karen was totally freaking out and I was just, wow, this is going to be weird, but we both did it. It was phenomenal. Cause it of gave you an idea of, even if you have this mental block that you can't do something you probably can. We actually did and nobody's feet were burned or anything. It was real coals. It was really hot. They were really red. It was really something that at the very end they had grass, a little square . Grass, maybe two, three feet by three feet and they had a hose running onto it. So you'd walk over it all. Then you'd just walk in on the grass and the idea there being if you had any hot coals stuck to your foot. You probably didn't want those just to stay on your foot. You'd probably want those, they get put out and taken off, so that's where that did.

    Anyhow. One of the things I learned from Tony was you need to have a strong reason why. We see this all of the time, Stephen Covey, if you read his stuff, you know it as well, you got to know why you're doing something. When it comes to computers and technology and security, you need to understand the why. Because it isn't just a rote thing. There are so many variations on what to do, but if you understand the why you're doing it, then I think it opens up a whole new world. You can explain it to your friends. You can help them understand it because finally you will understand it. You'll be more motivated to do the things that you should be doing because you know why you're doing them, what it involves, what it's going to solve for you.

    This should be a really great course. And I spent some time in it going through the whys, give you some examples of problems people have had and what that solves.

    It's available hopefully here within a couple of weeks, man. I thought I'd be done by the end of January and here it's looking like it'll be the end of February. But be that as it may, keep your eyes out. If you've already emailed me to let me know, you're interested. That's great. I've got you on a list. I'll have to try and send out an email this week or sometime soon to let you guys know it that we've got it ready for you? We will have it already for you, hopefully with the next couple of weeks.

    So that's that I'm told the different way of doing things that's me. I like explaining things I've been told I'm good at it. So let's I think a good thing too.

    I started out the segment by talking about this probably good news for end users. Because in 2020 breaches were down by 19% while the impact of those breaches fell by nearly two-thirds when we're measuring it by the number of people affected.

    Now, of course, if a company is breached and an organization is breached, it's counted as one. One person, if you will affect, obviously it can affect hundreds of thousands, millions of people, depending on what happens like a breach of Equifax. Are you counting that as one or you counting that as 300 million?

    Because that's how many records were stolen? I'm not sure it doesn't say it doesn't go into that much detail, but because the number of data breaches went down and the number of individuals affected by the data breach plummets. It's telling us something, then that is okay. That these hackers have moved away from collecting massive amounts of information and are targeting user credentials as a way to get into corporate networks to install ransomware.

    We've got even more news out this week about the solar winds hack. We talked about this before, and this is a company that makes software that's supposed to help manage networks, which means it's supposed to help make those networks safer. No, as it turns out, they weren't making it safer and it looks like maybe four years bad guys were in these networks.

    We're being managed by solar winds, not with software, right? It's not as though solar winds was managing the network is solar winds sold software services so that you could manage your own networks or in many of these cases, they were actually managing networks of third-party businesses. I do work as well for high valued in value individuals, people who have a high profile that needs to keep all of their data safe and they are constantly being gone after.

    They're trying to hack them all the time and the way they're trying to do it. And I talked about this really the first hour today is by this password stuffing thing. So they're trying to get in and they were successful and now it looks like it wasn't just Russia. Apparently, China knew about this hack potential knew about this bug and was using it.

    And apparently, it also was not. Just solar wind software. Now they're blaming some of this stuff on Microsoft office. If you have an office three 65 subscriptions, apparently they were using that to get in. So the bad guys are getting very selective. They want to go against companies and organizations like government agencies that have information there's really going to help them out.

    That is absolutely phenomenal. So these are stats from the identity theft resource center. And I was thumbing through as I was talking here. So it's saying that more than 300 million individuals were affected by data breaches in 2020, which means they must be counting the people whose.

    Information was stolen, not just the people that were hacked but it is a huge drop of 66% over 2019. And the number of reported data breaches dropped to about 1100, which is about. 20% less than 2019. So it's good. It's bad. I think the mass data collection thing is over with now.

    They're not as interested in it, but they are very interested in strategic attacks as opposed to just these blankets. Let's grab as much data as we can because they want to get it into these government networks, which now we've, we know they've gotten into. And then you've got this double extortion thing going on with the ransomware, where again, the going after businesses and people who they know can pay.

    So that's good news for the rest of us, right? The home users. It's not good news so much for some of my clients, that's what we take care of. That's why we get paid the big bucks. Now how that works. Downright stick around. When we get back, we're going to be talking more about the news this week in particular, of course, security, Facebook, and their Supreme court.

    Stick around.

    The United States has a Supreme court. Our States each have their own Supreme courts. In fact, there's probably Supreme courts all over the world. But did you know that Facebook now has something that people are calling a Supreme court? This is interesting.

    Craig Peterson here. Thanks for joining me.

    People have been complaining about Facebook and what they've been doing for years. One of the things people have really been complaining about lately is how Facebook has been censoring people, particularly according to them anyways, conservatives. I've certainly seen evidence of that. No question don't get me wrong, but there's also left-wingers who are complaining about being censored.

    Facebook decided it needed to have its kind of its own version of the Supreme court. You see what happened? Bins are you have a post on Facebook that is questioned. And usually what has to happen is somebody reports it to Facebook as being off-color or whatever it is, the reporting it as. And if two or three people report it, then it goes to the moderators.

    That same thing is true for some of the artificial intelligence. Some of it's reviewed by moderators as well. Here's your problem. Particularly when it comes to conservatives because you post something conservative on Facebook. And if you are noticed by some of these liberal hacks that are watching Facebook accounts, they will gang up on you.

    And they use these bots to pretend that there is an incredible rage that there are hundreds of people who are very upset by what you just had on Facebook. When in reality, no, one's upset and they're just trying to shut you down. And there might only be two or three people who actually know about it, but they'll use these kinds of artificial intelligence, bots to flood Facebook with complaints.

    And they're doing that on Twitter. The left is doing it all over the place. So what happens next? The big challenge for Facebook is there are 2.7 billion users. Can you even wrap your head around a number like that? That is just massive. So they've got 2.7 billion users, and now, obviously, not everybody's on every day.

    But some percentage of them. And I've seen it's in the hundreds of millions of posts every day on Facebook and they log in and look around. Facebook only has 15,000 moderators. So for 2.7 billion people, 15,000 moderators just isn't a lot. And the other problem is that the moderators are suing Facebook.

    And they came up. This was about a year ago. With a $52 million settlement with moderators and the moderators are saying, Hey, first of all, we're crazy overworked. And then secondarily, we've got PTSD. Post-traumatic stress disorder. And they're saying that they have this because of the stuff that they've had to see, they alleged that reviewing violent and graphic images, sometimes stuff.

    My gosh, I might've gotten mentioned here on the air, but they had to view these. For Facebook. And they said, this just led us to PTSD. I can see that particularly since they have to have so many every day. So many of these different posts that they have to look at. And they are clocked and they are third-party contractors.

    They're just, all this stuff adds up. Doesn't it? Moderators who worked in California, Arizona, Texas, and Florida from 2015 until last year, every moderator will receive a minimum of a thousand dollars as well as additional funds if they are diagnosed with PTSD or related conditions. So they're saying there's about 11,000 moderators that were eligible for this compensation.

    But this is a very big deal. It's difficult. How do you deal with that? They've got now 15,000 moderators who are reviewing the posts of these 2.7 billion users. There is a little bit of an escalation procedure, although it's a very difficult and because there are so many people who are. Complaining and trying to take care of everything.

    It is a very tough situation, really for everybody involved. So they've decided what Facebook needs Facebook's decided this themselves is they've got to moderate themselves a little bit better, and the way they are going to do all of this moderation is they're going to have this kind of Supreme court that supervises.

    All of the moderation going on within Facebook. So they call him the new to an oversight board and. Obviously with just one board, without very many people on it, it is only going to be able to handle a small number of cases. So they have been paying attention to some of the cases. And they're trying to set precedents that will be followed by the moderators and millions of other cases.

    It's basically the same thing that the U S Supreme court does, where they review cases that come up from the federal district court. They can have cases that are coming up from individual States as well. And then they set standards and, without going into all of the detail of disputes between district courts, et cetera, we'll see what happens in Facebook, but lower courts are treating these us Supreme court.

    Rulings and dicta as binding precedents for everything in the future. So it's not easy to do in our courts. We're certainly not great at it. And there are a lot of complex procedures. And even if you're talking about moderation where you bring a moderator in. And there are some standards for that in disputes between businesses where you'll pull in a neutral third party.

    And they'll just usually split things down the middle. But those are going to be difficult for Facebook to put in how they reviewed five decisions. These are pretty substantive. Sixth case apparently became moot after the user deleted the post.

    We have an uprising and Miramar right now. You might've seen it on TV. If you're paying attention. I know a couple of channels have been talking about it. But this is an interesting problem because the military has overthrown the potentially properly democratically elected government.

    What do you do if there is massive cheating going on in the election? We faced that question here ourselves.

    In Miramar, they went ahead and the military took over and imprisoned the president. There was a post talking about that and talking about Muslims in France and China.

    Another one about Azerbaijanis. I don't know if you've seen what happened with Armenia and Azerbaijan and lots of history going back there with the Soviets and they created this whole problem because they didn't like the Armenians, but anyways, of all of these five, they disagreed with the lower moderators opinions and they overturned them. I think it's really good.

    I looked at these cases and I was shocked. I think they're doing the right thing here. Isn't that weird?

    Hey, you're listening to Craig Peterson.

    Visit me online Craig peterson.com.

    Hey, did you know, there is a war, if you will, between Facebook and Apple? It is getting nasty. What's going on over there. That's what we're going to talk about right now. Your privacy, Facebook, Apple, and Android.

    Craig Peterson here. Thanks for joining me.

    My golly. You know what I think about Facebook when it comes to privacy, right? Facebook and Google. I think Facebook is worse than Google, frankly. They just don't respect your privacy. They will go ahead and look at anything that they can get their hands on.

    We'll at that point, just go ahead and pull it together and sell it to anybody that's willing to pay. I am not fond of that. And I think you can probably guess why, and I doubt your fond of that at as well. You're not fond of that either. Apple did something. If that has really upset.

    Facebook and Zuckerberg have been making a lot of noise about this, but Apple announced plans about a week ago to finally roll out a change that they were putting into place in iOS 14, which is the operating system for the iPhones and iPads that Apple has. They had announced that they were going to add it the late last year.

    And there was huge pushback from Facebook and a few others as well. What's going on here? Bottom line is that Apple is trying to force. Apps to be transparent. What privacy do you have? What data are they taking? And in the case of iOS, as well as Android and windows, and Macs, there has been the ability for certain applications to be able to look at other apps that are on the device.

    And by doing that, it can get data from it. They can figure out who you are. They can give a unique fingerprint based on what apps you have and what versions they are. They're pretty clever about what they've been doing in order to harvest your information. Now you might have noticed if you go in.

    To the app store that there's been actually a big change already. This is the Apple app store. If you go in there and you pull up an app, any app, so let's pull up Facebook and then in the app store, and then you click, obviously on Facebook, you scroll down the app store page about Facebook. And partway down, it already has privacy information.

    You want to click on more info project early if it's Facebook because it doesn't fit on that homepage for the Facebook app. And it will tell you everything. Everything that Facebook wants access to. Now, some of it's self-reported by the app developers. Some of it is the stuff that happened. Figure it out either electronically or by getting people involved.

    I would like to think that when it comes to something as big as Facebook, they really are going that extra mile. And making sure that yes, indeed, this information is valid, it is what it is. They may not, and I'm not quite sure, but look at all of the stuff Facebook is gaining access to with you.

    So that was a bit of a hit people were pretty excited. Oh, wow. This is great. And although Google doesn't do what we're talking about here quite yet, I'm sure they will be not in the way that Apple is doing it, but because remember Google makes money off of you and your information, Facebook makes money off of you and your information.

    So if you want privacy, you cannot use Google products like Android or. Chrome. And if you want privacy, you can't use Facebook. So it's as simple as that. Of course, the big question, and we talked about this earlier in the show is how much privacy can you expect? How much do you want? What's legitimate, right?

    All of those types of questions. So what Apple's doing now is they said that in early spring of 2021, they are going to release this new version of iOS. And here's what happens. They've added something and this is according to a white paper and Q and a that Apple sent out. They added something called app tracking transparency, and this is going to require apps to get the user's permission before tracking their data across apps or websites owned by other companies.

    Under settings users will be able to see which apps have requested permission to track so they can make changes. As they see fit. You might have noticed that already under settings as you can look at the microphone settings, it'll tell you. Okay. Here's the apps that I have asked about the microphone and you can turn them off.

    Here's the apps that have asked about the camera. You can turn them off. So they're adding more functionality. They also, in the FAQ, they said that app developers will not be able to require users to allow tracking in order for those users to gain access to the full capabilities of the app. Now, you know how I've talked before extensively about how, if it's free your, the product.

    So what Apple is doing is they're saying, Hey guys if the user says, no, you can't try it. Track me across apps. No, you can't get it. This privacy information, which Apple's letting you do, they cannot Labatt automize. The app is what it comes right down to. So it was in September last year that they first said they were going to do that.

    Then they delayed the implementation of this tracking policy. So the businesses and app developers could get more time to figure this out. One of the things that I think is fascinating here is what Facebook's doing with fighting back. Oh, and by the way, Apple has not just gotten complaints from Facebook.

    There are other marketers and tech companies that frankly it makes Apple more vulnerable to some of these antitrust investigations that have been. Started really against some of these big tech companies. Although, I don't really expect much to happen under the current administration in Washington because frankly, big companies love big regulations.

    Because they can afford to comply with them, but startup little companies who are competitors of theirs cannot afford the lawyers for the paperwork and everything out. I look at the CMMC, we do a lot of work for the DOD, department of defense contractors, where we secure their networks. We secure their computers, we secure everything.

    We put it all together. And we also, for some of them there's guys, there's a 50, $50,000 upcharge for this. And that's because we're cheap. Believe it or not, it is a lot higher for other companies to do it, but we do all of the paperwork, putting together all of the policies, all of the procedures, what they have and.

    Auditing everything for them. And we're talking about a case and a half of paper thinking of the big cases of paper, right? 500 sheets and the ream and how many reams in a box? 10 20. I'm not even sure, but literally cases. And we. Printed it up, we wrote it all up, printed it all up, delivered it to a client just a few weeks ago.

    And it was a huge box of three-inch ring binders. It was all in and they didn't all fit in there. They're the big guys in the department of defense probably love this because they pay a million bucks to the people, the generate the paperwork for them internally. And they know the little guys can't afford to have full-time paper pushers.

    And so that's why, even though we're talking about months worth of work, why we charge 50 grand, which is a heck of a lot cheaper, believe it or not. And it's a huge discount for us. So I don't expect that the fed you're going to come up with a solution. That's truly going to help the little guy here, but Apple's announcement praised by privacy advocate nonprofits as well.

    And Facebook apparently has been buying full-page newspaper ads claiming it's going to hurt small businesses in a way it will cause it can make advertising. Just a little bit harder. And apparently, also Facebook has decided to rewrite its apps. So no longer even requests to access, cross-app access to your personal information.

    We're going to wrap up, talk a little bit about Comcast data cap, and some of these SolarWinds hack victims that didn't use SolarWinds, and ransomware payoffs have surged, even though the number of people affected has gone down.

    Make sure you get on my email list so that you get all of the important news. You're going to get some of this little training I'm doing and the courses that we've developed. The only way to do that is to go to Craig Peterson.com/subscribe. That's how you get on those lists and I'm not sitting there and pounding you or anything else, but I want to keep you informed. So there you go.

    We're probably going to increase our volume from one email a week to three so that we can provide you with a little bit more training. I want to keep these down to something that just takes you a few minutes to go through, but could save you millions of your business and tens of thousands, your retirement, if you are a home user. So make sure you are on that list. Craigpeterson.com/subscribe.

    Comcast. I know many of us have Comcast, I certainly do, is imposing data caps on many people in many parts of the country. That includes people to the South here, Massachusetts residents.

    What do you think they're doing down there? The state lawmakers have proposed a ban on data caps, a ban on new fees, and a ban on price increases for home internet services.

    The idea from their standpoint is we have a lot of people who are working at home because of a lockdown. What are they supposed to be doing?

    I'll take my daughter, one of my daughters, as an example, she's working at home. She used to work in a call center she'd go to every day. Now she's working at home. Are they paying a wage differential for her? Are they paying for the electric bill? They're not even paying for the phone bill or the phone. She has to provide her own phone. She takes inbound calls for a call center.

    Can you believe that? It's just amazing what's happened. The company is saving just a ton of money because people don't have to go into work. You can bet they're going to dispose of some of this space that they've been. What's happening here, we are using more bandwidth than we've ever used because more people are at home and it isn't all business related many are watching Netflix or you've got Netflix on in the background while you're working on stuff. It's just so common to do that.

    What data caps are doing is they say you can only use so much data a month. Then there's usually a penalty of some sort. In Comcast's case, they said for the first quarter of 2021, I believe is what they had come up with. We'll just warn you that you go over your data cap then they'll charge extra. I have a friend who has Comcast and he said, I think it took him like three days before he went over the data cap. That's not long. It's because they're streaming TV. They've got kids working from home.

    Then you've got meetings that they're going to, that are now streaming. So I can see this, but from Comcast side, they now have to handle more data than they've ever had to handle before.

    Because we are using it, like for my daughter, she actually has a cell phone, but all of the calls are routed over the internet. Cause her cell phone hooks up to the wifi in the house and the calls come in and go out via that wifi. It goes through the internet, it goes to her phone carrier's network. Then it goes to the call centers network. So there you go.

    What does that need? That needs to make sure there's no jitter. You don't want voice packets to be dropped because then it sounds terrible. It's very obvious when audio is dropped. I don't know if you've noticed if you're streaming something from one of these online streaming video services, but sometimes. It will hiccup a little bit, but have you noticed that with the smaller hiccups, the audio is fine and the problem is in the video. Now they do that for a couple of reasons, obviously video uses more bandwidth than audio uses, but the other reason is people tend to get more annoyed by audio fallout and audio problems.

    Comcast is saying, Hey guys, look at what we have to do with our networks. We have to expand them. We have to increase them.

    Now I've got to bring up again the Biden administration because of what they're planning on doing with this fairness doctrine on the internet. What they're planning on doing is saying, Hey, Comcast, just because this person uses five terabytes of data a month, you should not be charging them more than grandma that uses 10 gigabytes a month. Thousands of times more bandwidth requirements, you're not allowed to bill them differently. Cause a bit is a bit which is absolutely insane. I don't know how they can justify this sort of thing.

    So what's going to happen is you get companies like Comcast or other internet providers who are going to say. We are not going to invest any money into expanding our capacity because we can't charge for it. Doesn't that make sense to you? It makes perfect sense to me. By getting the FCC involved, it's just going to be crazy.

    Ajit Pi resigned when President Trump was leaving, he used to be the chairman. He actually had a head on his shoulders, but these new people President Biden put in there, it's insanity what they're trying to do with our networks. It's going to make it much worse.

    Comcast is putting data caps in. You hit the data cap it, they're just going to slow you way down. That happens too, with a lot of our cell phones, our cell phone carriers, if you use more data than they've allotted to you, they'll drop you back. So most people have 4g. Yeah. Okay. Your phone's 5g, but really guess what? You're not getting 5g. It's very rare unless you are on the T-Mobile slash Sprint plan. T-Mobile more specifically because nobody else has the coverage that T-Mobile has for 5g.

    So you're using 4g LTE, you hit your data cap. They're going to drop you back to 3g, which is really slow comparing the two together, all the three of them, frankly, but it's very slow compared to a 4g LTE. In mass, by the way, I should mention Verizon files and RCN. Do not impose the data caps. It's just our friends at Comcast that are doing that Vargas and Rogers.

    They let a group of 71 different Massachusetts lawmakers urged Comcast to halt the enforcement. By the way, the data cap is 1.2 terabytes per month, which is actually quite a bit of data. You'd have to spend a lot of time streaming TV. The cap does hurt low-income people is no question about it. If you are being forced to work from home because of the lockdown, the government's forcing you to work from home. They put their fingers in anything, and that just never seems to work out anyhow. We'll see what happens down in mass with Comcast and these guys.

    Let's see here, SolarWinds hack.

    I mentioned this just in passing a little bit earlier in the show today, but CISA, which is the US cybersecurity and infrastructure agency said that nearly a third of the organizations that were attacked by these Russian and Chinese hackers had no direct connection to SolarWinds. Apparently, many of the attacks got in by using password spraying to compromise individual email accounts at targeted organizations.

    There's your tie into Microsoft. Obviously major flaws in Microsoft's cloud services. Another one of the targets was CrowdStrike, which is another company that does security. They do remediation after the fact, as well, which we've had to do for many companies over the years too. We'll see, it looks like these Microsoft flaws may have been these bad guys first vector into some of these systems. That's pretty bad.

    Ransomware, things have changed because they figured out a better way to do it. Nowadays we're calling it double extortion. Payments to ransomware gangs that are using cryptocurrency now, more than quadrupled in 2020. Isn't that something? Less than 200 cryptocurrency wallets received 80% of the funds. 80% of the payments went to 200 wallets, which may or may not represent individual ransomware gangs. It's just incredible. The payments using this cryptocurrency stuff, surged 311% last year, the total volume of $350 million.

    Cyber criminals are moving to crypto locking is the easiest way to turn compromised computers into cash. Then the other thing that they're doing this double whammy is before they encrypt your files and then demand you pay up in order to get the encryption key or decryption key, they're double whamming. They're saying, Oh, Yeah, by the way, we grabbed a bunch of your files, and if you don't want us to, and they'd try and figure out what's the most what's the best way for them to sneak the files out and then tell you which ones are the most valuable, right?

    They have people look at it, which is really bad. If you don't want us to release them out onto the open internet or onto the dark web, you have to pay us. They'll sometimes pretend they're a different company. That's where I was saying. When you look at the 200 different crypto wallets that are used, they will often go in, at first it'll look like a ransomware attack. People will pay the ransom, much less so in the United States than any other country. Then they will use a different crypto wallet, pretending they're somebody else saying, we have your files, you better pay up. Law enforcement, by the way, can target these deposit addresses here for the crypto wallets. They've done it before. We'll see what happens. About half of all of the funds went to 25 different crypto wallets. That's not a lot.

    Make sure you sign up. You'll be getting some of the new newsletter stuff. Some of the free training, the courses, and other things. I'm really devoting myself here 2021's going to be the year that we really help you stop the bad guys.

    Take care and make sure you sign up @craigpeterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 21 min
  • Tech Talk with Craig Peterson Podcast: Google Chromebook Outsells Apple - who is the loser?, Vulnerability in Programmable Logic Controllers affecting large Infrastructure providers, Clubhouse and More

    Welcome!ย ย 

    I am sure that most of you know about the problems Texas experienced with its energy infrastructure well there is more bad news for our nations' infrastructure and that comes from a vulnerability in the programmable logic controllers that many of these large infrastructure providers use to control the flow of product. (i.e., water, electricity, natural gas, etc.). Also this week Google Chromebooks outsold Apple but that is not the whole story.ย  We also dug into processors and the importance of them and how it affects what you do daily. Then we discuss Clubhouse and why it may not be the best platform to get on and there is more so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Embracing a Zero Trust Security Model

    Turns out Most Manufacturing, Water Supply, and Power Companies Use Controllers with a Security Severity Score of 10 out of 10

    Chromebooks outsold Macs worldwide in 2020, cutting into Windows market share

    Clubhouse is the New Up-and-Comer butย  Security and Privacy Lag Behind Its Explosive Growth

    New York sues to shut down 'fraudulent' Coinseed crypto platform

    Former SolarWinds CEO blames intern for 'solarwinds123' password leak

    WhatsApp will basically stop working if you don't accept the new privacy policy

    TikTok breaching usersโ€™ rights โ€œon a massive scaleโ€, says European Consumer Group

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Apple just got passed by Google's Chromebook. We'll tell you more about that. Clubhouse the app everybody seems to want, and it's invite-only. Sound familiar? That's happened before has got some serious privacy problems.

    Hi everybody. Craig Peterson here. Thanks for joining me today.

    There are a lot of things to talk about and I'm going to start with this article from ARS Technica, talking about programmable logic controllers.

    Now I can see you sitting there saying, what are you talking about, Craig? Who cares? Here's, what's going on. You heard about the solar winds hack? It's been something we've talked about pretty much every week here for the last Oh a month or so since it really happened. And we found out some more stuff about it this week, by the way, we know who the group is that actually did the hack very professional group. This means, of course, nation-state, but.

    They were going after different types of companies, that help the different types of companies, as well as government organizations. In other words, they were targeting MSPs managed services providers. And unfortunately, most of them failed because it's rare, very rare to find an MSP that actually takes care of security.

    And I'm not going to blame them. I'm not going to blame you for using one of these MSPs that got compromised. Because ultimately, security is a long tail thing. It is an industry in and of itself. It's hard to keep up. It's hard to keep moving forward. But I brought this up because I wanted to tie it into something we also talked about a bit for the last two weeks, and that is that water plant in Florida.

    This water plant in Florida had the amount of lye added to water, turned up 100 fold. Not 100%, a hundred times more lye in the water and somebody noticed and all well and good.

    Who did it? We don't really know, but here's the problem I want to talk about today.

    And that is the SCADAs systems, these PLCs, in other words, The computers that are controlling the valves in these various businesses and government agencies, the water plants, the electric plants, et cetera. You had valves. Those were these tubes. Remember that, and then transistors for a little while. Anyhow.

    This is something that's a very real problem because Rockwell automation you've heard of Rockwell before. I am sure of that because Rockwell has been a government contractor forever. They've done a whole lot of stuff in the military space and they do a ton also in the civilian space.

    Rockwell makes hardware that's used to control equipment in factories, a lot of equipment in a lot of factories, as well as all of these other places out there. And it is what's called generically a "programmable logic controller." They're selling them under this logix brand. You'll see them everywhere. They control everything you can think of out there.

    Some of them are very small. There might be a, like a toaster that you'd have on the countertop for instance, or something as big as one of those little pizza ovens you can put on the counter, but then they can be a whole lot bigger than that. But they help control equipment. And. Oh, the manufacturing and the processes on assembly lines and other manufacturing environments.

    You might remember what happened in Iran, where they had these PLCs, programmable logic controllers, that were part of this whole SCADAs system. It's all together. And in Iran, they were using them to control centrifuges and those centrifuges were being used to refine nuclear material eventually to make nuclear bombs. At least that's what we said. That's what the UN said, et cetera, et cetera. And then it makes sense, right? They have to refine the yellowcake. So that's what they were doing. And what did we do?

    Apparently, we got together with this country called Israel. It's over there in that same neck of the woods. And with them, we came up with some software to break into the computers at the Iran facility. Now, these computers were what we call air-gapped. They were not directly connected to the internet. So how did we hack it? We hacked the old-fashioned way. No, we didn't use a little honey bait. What happened with rep Swalwellout in California, who I don't understand how he's still sitting on the number one top secret committee in Congress, even though he spent years with this Chinese spy who obviously would have been feeding all of this information that he got back to China. I don't understand Nancy Pelosi. Sometimes this is just crazy. What's going on in Congress?

    It wasn't that? Okay. It wasn't a honey trap. It was a honey trap. I guess what they did is they developed this piece of malware, knew that they had to get it on to the machines that controlled the manufacturing process there in the plant that did the refining in order to make the nuclear bombs.

    How can you get it in if it's air-gapped, how can you get it in if those machines are not connected to the internet? But it doesn't matter if you break into the firewall because they're not behind the firewall. They're not on a network that is accessible from the outside. However, they were networked and they have to be networked inside the building so that you can have one computer that's monitoring the spin rates of all of these different centrifuges and just kind of keeping tabs on everything. So they went ahead and they put this little virus onto a thumb drive. And then, in fact, they made dozens of these thumb drives. They found out where the engineers who worked at the plant went for coffee, where they went for lunch and they scattered these around.

    And then a coffee spot at the lunch spot. And so now all of this stuff is scattered around these little thumb drives people, pick them up, Oh, a free thumb drive and they take them into the office. And this particular piece of malware was specifically crafted for this programmable logic controller. So if you plugged it into your computer as an accounting puter computer, it would say, Oh, wait a minute this is an accounting computer. I don't care.

    But these guys brought it back into their manufacturing facility and it did work there and it took over control of the machine that controlled all of these centrifuges. And fuges, it keeps saying fuses, centrifuges and it spun them out of control.

    And while it was spinning them out of control, it was showing a perfectly Greenlight status to the people who were trying to monitor it. They resist, it was a stroke of brilliant, but that is the type of system that we're concerned about. That's what we're talking about right now. These kinds of logic controllers that are used all over the place you can use them for almost anything you used on ships. They're used in government facilities. They're used everywhere.

    There was a vulnerability found and it was a, "I can't believe you did this" vulnerability. Now with solar winds, we found out it was a, I can't believe you did this vulnerability because apparently, solar winds had a password of solar winds one, two, three. Who wouldn't guess that perfectly good password? And man, we see these types of passwords all of the time. That's why I use a password manager. That's why you generate passwords or you come up with key phrases. Three or four words strung together with maybe a digit or something else in the middle somewhere and some upper lowercase characters. Right? That's how you generate a password. It's not supposed to be solar winds one, two, three. So that's problem. Number one, that's a big problem.

    This particular vulnerability has a severity score of 10 out of 10. Why? Why is this the worst level it could possibly be? Number one, it requires a very low skill level to be able to exploit it.

    Now that's interesting. Why is that?

    It turns out that these program, programmable logic controllers have a hard-coded key built into them. In other words, whoever programmed these things, and I'm looking at this list, there are a lot of them. Logix is the name of the company, the name of the product, and you'll see Logix in their names. And it is a whole bunch of compact Logix control, Logix drive, Logix a guard, Logix, guard on me. Now that wasn't supposed to provide cybersecurity support. All of those, okay. Then they have a hard-coded password.

    What that means is built right into the software is a back door with a password that can not be changed.

    Now, even if you bought one of those cheap firewalls from the big box retail store, you are going to be safer. Because at least it lets you change the password and you should be changing the password on your firewall. And in some cases, it also lets you change the username and you should change the username as well.

    But no. These Rockwell devices have a hard-coded password and Rockwell apparently is not going to issue a patch that directly addresses the problems that come from having a hard, coded key. So instead of that, they're saying, Oh, use these mitigation techniques.

    Isn't that what Iran did, isn't that? Why they had themselves? Nice little air gap network that was still breached?

    Oh, man. Oh, man. So it's a problem. It's a very big problem and they're just not paying much attention to it.

    Hey, stick around.ย  We're going to talk about Chromebooks versus Mac and Windows right here.

    It looks like the Wintel monopoly continues to die on the vine because of what Apple's been doing, what Google has been doing. In fact, Google is really stepping up their game here, getting rid of Intel.

    Hi everybody. Craig Peterson here. Thanks for joining me.

    We know that Intel's been around for a long time. You probably remember Intel used to brag about it. There were ads where Intel would kick in a couple of bucks if all they'd said was Intel inside. In fact, they are still doing it on machines. You buy a machine it'll probably have a little sticker if it has an Intel processor saying Intel inside. Intel had a problem, they made components that people didn't buy.

    Well, they bought them, but they bought them as part of something else. They did not buy an Intel processor for the fact it's an Intel processor. Makes sense. Some of them did. I certainly looked at them. I bought AMD and some others instead,. Some of the power PC stuff from IBM, just absolutely incredible, as well as others.

    I have done a whole lot over the years when it comes to processors, you've heard already I helped develop operating systems and implement them and the internet protocol. I've got a lot of experience with processors, no doubt about it. A lot of machine coding and assembly work over the years. I wrote C, which is a programming language used largely for a high-speed stuff like operating systems. I did a lot of that.

    I look at this processor from Intel as a massive failure. Marketing-wise. In the industry, it's been really great, but when I get into it from the prospect, or from the side of being an architect, of operating systems, and an architect of user interfaces. I cannot believe Intel. It's just been terrible. Part of the problem with the Intel processors and their instruction sets. The way they do the memory access and the way they do all of their IO to other devices has to do with their legacy code.

    They've tried to remain compatible with all kinds of older processors over the years. I can understand that I can see why they might want to do that. They're afraid that people might leave them. They started out as a memory company and through. I was going to say no fault of their own, but no luck of their own or anything else. I don't know. Another company came to them and said, Hey, can you make a cheap processor?

    Remember IBM looking for a cheap processor to put into this PC right. A personal computer that they didn't think would sell very many, certainly wouldn't be a great business thing. They went and said, okay what are the cheap processors we can get and put into here? Intel, 8080. That's what we'll do. All of a sudden is born the XT and the PC XT and the PC AT came. Some of these others over the years on the 8286 and the other chipsets. Anyhow, I'm getting awfully geeky on ya. Started really falling behind.ย  One of the ways they fell behind was in 64-bit design.

    In fact, Intel is AMD compatible. Now, if you can believe that. Talk about falling behind.ย  I don't think it's the engineers, there's some brilliant people there. It's entirely business decisions that drove them to the point they're at. They continued to increase the price of the processors. They were getting a little faster, but they still had the corner on the market because people bought Wintel they bought Windows. If they're going to get Windows, they're going to get Intel. Make sense. There were some others over the years that competed including AMD, which is Intel-compatible for the most part.

    They really managed to keep people out of the marketplace so they could jack-up the cost. The price structure, just keep jacking up, jacking up, jacking up. Many companies got fed up with it, including some companies that had the ability to do something about it. One of those companies is Apple.

    I mentioned in my newsletter last week, I had an article talking about how Apple is now apparently about to make 6G chips. 6G at the next generation of wireless and Apple's getting rid of Qualcomm and gonna make in themselves.ย  A company like Apple, when they want a million parts, they want them to arrive. They want them to be there on the day they ask for them and they want them to do what they asked for.

    Qualcomm has fallen down on that. They have not been able to meet Apple's demand. Intel has fallen flat on that. They have not been able to meet some of Apple's demands that have to do with the amount of energy they use the temperature they give off of course cause they want them on mobile devices.

    What did Apple do a decade ago? They said fine, forget about it. We're going to not use your Intel processors in our iPhone. They started using some other processors, some arm processors. Apple joined this community like an open-source manufacturing alliance that came up with a chip design that they could use as a basis.ย  Apple took that and ran with it.

    Today it has run so far with it that Apple has an amazing chip. Now you can see these amazing chips in your newest I-phones and your newest iPad. That's what they have in them these new Apple processors, but Apple also now has their new M series processors, which are effectively the same things they've been using in the iPhone, iPad, but beefed up in order to handle the load you'd expect to have on a laptop or a desktop with a Mac mini. I'm just so impressed with these. I was playing with both of those. One of our clients wanted them.

    We had them ordered and shipped to our place.ย  We put them on benches and we loaded them up and got them all running.ย  We played with them a little bit just to see what they were like. Very impressive machines.ย 

    They don't have Intel processors. Apple has switched processors a few times over the years, it went from the Intel or the Motorola over to the power PC then to the Intel, and now to its own chip design. It looks like completely new chipsets for the iPhone 13 hopefully, maybe the 14, hopefully, when that comes out. That'll probably be later this year.

    By the way, the 13 is just going to be an incremental update to the iPhone 12. They're saying is probably going to be like an iPhone 12S, really.

    Processors.ย  Apple doesn't need to pay the Intel tax on these processors out there.ย  I'm going to look right now, purchase price, Intel, a laptop CPU, just to get an idea.ย  I'm on there right now and I see coming right up, here's an Intel core i9 $400. Just for the CPU and that's from B&H photo and B&H has a lot of this sort of thing. Most of these Intel CPUs that are on laptops cost over $400. They're branded as core this, that, or the other things.

    The real expense of one, just start getting into the Xeons. Those Xeon processors can be just through the roof. Here's one here right now an Intel Xeon platinum, 8180 $11,000 while actually, it's 10,995.

    If Apple can make its own processor, do you think they can do it for less than 400 bucks? Of course, they can, and that's going to save them a lot of money in making some of these devices.

    We're going to get into those devices, like the laptops. What do you need in a laptop? Why would you go with Windows, maybe one of these other operating systems, including Mac iOS? We'll talk about that.

    That's going to lead us into the conversation about Chrome. Why is Chrome OS becoming so popular? Why has it surpassed now market share of Apple and where did that market share come from? People have been buying PCs, but what's going on?

    Stick around, you're listening to Craig Peterson and you can find me online. Craig peterson.com.

    We're talking about chips. Yeah we're getting maybe slightly technical, but chips matter nowadays in a way that they haven't before and yet they matter even less. I'm going to explain that.

    Hello everybody. Craig Peterson here.ย  I just said something that might've sounded confusing. Cause I said, CPU's matter more than ever. Yet they matter less than ever. Here's why.

    If you're looking at an Apple computer, you are looking at either an Intel processor, at least for the next couple of years or the Apple processor.

    If you're looking at a Windows machine for a little while Microsoft was really on a bit of a kick, trying to get Windows running on multiple platforms. In fact, it actually did.ย  There were some amazing things they were able to do, but really if you're getting Windows, you are going to be on an Intel platform.

    How about your phone? Do you have a clue as to what kind of processors in your phone? Now, you guys are the best and brightest. So yeah, you, you might, okay. You might know the exact model number and CPU clock rate and everything else about your phone, but the vast majority of people have no idea and you don't need to know. You don't need to know because it is now like a utility. You don't really know how that electron is delivered to your house. Where that came from? How that was produced? You just turn on that light switch and hope it works, right?

    Unlike when there's big wind storms and your power goes out, that's what you're hoping for. That's what's happening now, you buy a phone, you don't care if there's Intel inside. The same thing's true with tablets. You buy a tablet, if it's an Apple tablet guaranteed it doesn't have an Intel CPU. If you buy a Surface tablet, you can get them with Intel or without Intel. A lot of times you can tell just based on the price of the tablet now.

    As we move forward, we're starting to see more and more devices powered by arm chips and others. You see the idea behind Unix, which is this operating system that's underneath all of them. Unix lives underneath MacOS. Unix lives underneath Android. It lives underneath pretty much every cell phone and every device programmable device that exists today has Unix underlayment, which is the main operating system. It's fantastic.

    The whole goal behind that when it was designed by At&T was to make it so that this one operating system could run on anything and it did. Universities adopted it because it would run on anything and universities were getting equipment donated to them from everybody. That was anything, right? This mini-computer, that mainframe, all of these pieces of equipment got donated. They standardized on this Unix platform and the whole thing worked out quite well.ย  Linux is a type of Unix for those who are wondering.ย  The whole idea behind it is that the processor doesn't really matter because there's a version of Unix that will run on really pretty much any processor that's made today or has been made for the last 40, 50 years.

    Now, when you start getting into the useful computers that you and I use every day. What's underneath it? If you run a Mac, I don't think you really care. If you're on a Windows computer, I don't think you really care. What you care about is can I do that task at hand? Can I go ahead and open word, document editor. Even then you don't even care if it's Word for the most part. Word, you're going to get around it a little bit easier, but if you are over on a Mac, you could use pages. It doesn't have to be word and it doesn't have to be Windows and it doesn't have to have Intel inside.

    I am not giving stock advice, but I can tell you, I would not be out there buying Intel right about now. Hopefully, they got some other stuff going on. I know they're looking at some new chip designs that they can provide to people that make it pretty darn simple.

    Now there is another big player we haven't talked about yet and that is Google. Google's got Android, which is underneath again, a Unix operating system.ย  It has also on top of that, this big Java virtual machine, which has been the source of many headaches, a lot of chagrin here for developers. The beauty of it is again, Java was designed so that you can write your program once and run it on anything. You see where I'm going.

    We're getting to the point where the competition is going to be crazy. When it comes to the devices we use to get online or the devices that we are using for work, and it's going to get cheaper and cheaper.ย  I'm not talking about the cloud. The cloud is not cheaper. In most cases, the cloud can present all kinds of additional problems.

    We just got an email from a listener Danny today. In fact, he bought one of the little packages that we'd put together for the listeners. About 18 months ago of a special, it was a little Cisco firewall and Wi-Fi switch with security built into them, something you can't buy off the shelf. It had the firepower basic stuff in it. Anyhow. So Danny was asking because he uses G suite. How does he do a three, two, one backup? You can't with Google's G Suite.ย  With office three 65 or Microsoft three 65, in both cases, they have lost their client's data. So Danny was asking, so what do I do? How do I do a three, two, one backup, like you advise we do?

    Basically what we said is you've got to download all of your data from those cloud services, back them up properly at that point, and do it all in a format so it can be restored. So if it has to go back to the cloud, it can. It keeps your data safe. All of that stuff is, again, just it's everywhere. It's cheap. There are pros and cons to different ways of doing it. Dan is not there thinking I'm using G suite or I'm using Microsoft three 65. What processors behind it, right? You don't care.

    Google has said here's what we're going to do. We make a phone now, the Google smartphone isn't well adopted. It's more of an example of here's a way you can implement the Android operating system. It's a proof of concept for them. It's not a bad phone. They've tied in with some other carriers in order to provide cell phone service.

    They are coming out with a system on a chip. You used to have this big motherboard and if you go way back, I have a very big motherboard with all kinds of discrete components. Nowadays, all of that gets squeezed into one chip and Google has decided that they are going to make their own chip. They call it the white chapel. That's the name of the whole program.ย  It was reportedly made using Samsung's nine millimeter process technology. In other words, it's going to be fast. It's going to be power efficient, and initially, they are going to be putting it into their smartphones. That's not a bad idea. In their pixel smartphone sometime late this year.

    We haven't quite made it yet to Chromebooks, but I promise we'll get to that in just a couple of minutes. I wanted to make sure everybody had a decent understanding so that you can make the right decision for yourself and your business when it comes to what kind of computing to use.

    Stick around.

    So what kind of computer should you get? What's gonna work for you? Should you worry about the chip that's inside of it? What do you do? It just gets so confusing sometimes. That's what we're going to get into finally right now.

    Hi everybody. Craig Peterson here. Thanks for joining me today.

    Now, there are options when you are looking at a computer and I know some people don't even have a regular computer anymore, so let's start there. Really quickly many people are just using their iPad and that's what the goal was behind the iPad. I think that's what Steve Jobs had in mind.

    Apple always wanted it to be a replacement for your computer. It is not as flexible as a computer is by any stretch. Frankly, it's gotten a lot better, especially the iPad pro because of the faster CPU and it has a few more capabilities.ย  It's a good little unit.ย  That's what I use by the way is the iPad pro.

    If you are just going online and you're doing a little browsing, maybe editing a few documents, getting on a zoom call or a WebEx call, whatever it might be, doing all kinds of the regular stuff that iPad's going to work for you.ย  If you have an iPhone, you can link your iPad to the iPhone.ย  If someone calls you on FaceTime, you can actually answer, take the call on your iPad.

    If someone calls you on with a regular phone number, if someone does that anymore you can take that as well, right there on your iPad. iPads are inherently very safe. They have done a great job in trying to keep things pretty tight from the cybersecurity standpoint on the iPad.

    If you need to use Windows applications, then that's where the surface tablet might come in for you. I know some people who like their surface tablets and I know people who really don't like their surface tablets. Personally, I don't think I would buy one. There's not a huge win, but again, some people like them. They're more portable than some laptops.

    Now, you can get laptops in the Windows world that are as small and lightweight as an Apple laptop.

    Now, which would I get the Apple laptop versus a Windows? I would absolutely without a doubt, no question get the Apple. The main reason for that is that it's cheaper. Yes. I said it was cheaper.ย  It's cheaper because that Apple laptop is designed using high-quality components and is manufactured using high-quality stuff versus that PC.

    You might find a laptop PC laptop for maybe 350 bucks, and you look at the Apple laptops and they start at just under a thousand dollars. They're small the Apple ones and they are very functional and they will last. If you get the same component in your windows laptop, the same quality, the same speed, the same buses, IO, everything else, same display. You are going to pay more in the Windows world than you would on a Mac.

    If all you can afford or all you want is something inexpensive then I've got an option and it isn't Windows. Okay.

    Unless you have to have Windows, if there's a specific program you have to use that only runs on Windows while you're stuck aren't you.

    There is another option out there and it is called a Chromebook. It has been doing very well. 2020 was the first year that these Chromebooks outsold Apple Macintoshes. Now, that's a big deal because Apple's always been a kind of a minor player, seven to 10% of the marketplace. To see Chromebooks actually beat Apple is impressive. Now, part of the reason they're beating the Apple is what I just explained to you. They are inexpensive.

    Many kids are at home, right? They're going to school from home virtually and the schools need them to have a computer. What do they say? Get a Chromebook. Here's a $300 Chromebook. Go ahead and get this for your kid or here's $300 and or $300 Chromebook. In some cases, the school just buys it for the kid. Great for that.

    Now, remember it's Google, you're storing most of your documents up in Google's cloud. Depends on how you feel about Google and having Google with full access to all of your information.

    I have a big concern with Google having access to my kids' information, but that's a wholly different story out there. No question about that.

    Chrome is an operating system again, that is based on Unix. It's actually Linux, which is again, a version. It is something that you just won't see. The odds of you directly interacting with the operating system just keeps going down and down.

    Now, Windows, you still got a muck around sometimes you got to get into the registry editor. You got to do weird-ass stuff.

    With your Chromebook or with your Mac, you're not going to have to do that. It's not an antiquated design. It is a very modern design. Very easy to use.

    Now, I started the segment out by saying that CPUs matter more than ever, and yet they matter the least they've ever mattered. Here's why I said that the manufacturers now are able to choose the CPU they want to use. Unless, of course it's a Windows target, but for anything else for Chromebooks, they can use any CPU from any manufacturer. They might have to do some porting and do some work involved in that, but it's moderately minor.

    You can't say the same thing for Windows. Windows is locked into a couple of different architectures and you can bet Microsoft is pretty busy trying to make it so that it will run across even more CPU architectures.ย  It matters more to the manufacturers and matters more to you what CPU they're using, because it keeps costs under control. It gives you longer battery life. It lets them put a smaller battery in and still have longer battery life. Lots of good things.

    It doesn't matter at all anymore because you only care about the web browser. You only care about the text editor, right? What is it that you care about? It isn't, what's underneath all of this.

    Chromebooks, you can find for 150 bucks at a big box retail store and you get what you're paying for. That hardware is not going to be stellar that's for sure. But it's going to work and is going to do a decent job for you.ย  If you don't have any money, really, but you can afford to crack 150 bucks, look at a Chromebook. Chromebooks go all the way up into the $2,000 range.

    Those higher-end ones have more local storage. They're faster. There's a bunch of different benefits to them.

    Now, you've got the options.

    Apple is going to almost certainly stay with its own chipsets. It lets them keep control over the entire investment. Now,ย  you might say that's bad. I don't want to get locked into Apple. Well is not really going to matter that much, but you are going to get locked into Apple. The reason it's not such a bad deal is looking at the marketplace, Apple has a few dozen different designs. They have to maintain the operating system for all of their software, their device drivers, everything has to work across a few different, a few dozen models. Think about it. You've got how far back your iPhones', I know they still put out some patches for iPhone fives and sixes, they might have even older ones. So there you go. Then they had the larger versions of some of the iPhones and they had the ASCE versions. Look at that.

    Compare that to the Android space. Where you have hundreds of manufacturers using Android and building smartphones with it. Thousands of different models of phones each with their own device drivers and all kinds of little things. Some of these manufacturers willย  go ahead and grab whatever's in the parts bin today and throw that in. Okay.

    This is true too, not just to the smartphone manufacturers, but if some of these PC manufacturers. Dell has been known to do this. Where it's okay, we're making a laptop today. Okay, we promise them this CPU, but this USB controller that we normally put in, we don't have it right now. I'm going to put this other one in there. It gets very confusing when you're trying to repair these things each one of those USB controllers has a different driver for Windows.

    So Apple, the part of the beauty of this is they only have to worry about the security and reliability of just a few dozen different designs versus Google having to worry about again, thousands and thousands of them.

    That's why also with Android you do not get the patches when they come out. If they come out, it can take an easy six months for a patch that's issued by Google to show up available for your phone. It typically takes Apple a matter of a week or so. It's just there. There's no comparison. That means your cybersecurity is going to be better when you can get patches.

    If you have an Android phone, that's more than two years old, forget about it. You're not going to get patches.ย  If you really are insistent, like some people I know in fact, Danny were just talking about it. He really likes his Android. Don't first of all, always buy the top model. It should probably be as Samsung.ย  It should be never any more than two years old. You got to trade it in every one to two years so that you're pretty sure you're going to be getting security updates in a timely fashion.

    There you go. That's the explanation of it. I love my Microsoft stuff for specific Microsoft apps. I really love my Mac for all the graphics and everything. It just works. It doesn't crash. The applications all just work.

    I use my iPad for some just general basic stuff, and Chromebooks are probably the way to go for most home users.ย  As we just talked about for schools as well.

    Hey, visit me online, CraigPeterson.com. You'll find all kinds of great information there. Craig peterson.com,

    Look for my podcasts.

    I guess this is a little bit of good news. If you're a home user, not a business or some other organization, like a state or County or city office, but we've got some breach numbers that have just come out for 2020. We're going to talk about right now.

    Hi, everybody. Thanks for joining me.ย  Of course, you can always go to my website. Yeah. Pick up all of the podcasts in case you missed something today or another week, you'll find them right [email protected]. You can also sign up for my email list and we're going to be doing a couple of different things here.

    I think in the near future, we're going to be sending out some reports that we made as part of the security summer thing I did a couple of years ago, and each one of these reports and there's 30 something of them. Some of them are like five to seven pages long, but it's a checklist of all the security things you should be worrying about.

    Now, if you are a home user, you'll find a lot of these to be interesting. But if you're a business person, you work in an office, you help to run an office. You own a business. You need to make sure you get all of them. So make sure you are signed up Craig peterson.com and we'll be glad to get those out too.

    Plus we're also going to start something new every week. I usually have six to eight, sometimes as many as 10 articles in the week. I spend hours going through finding what I think are the most important things that interest me as well, but that I think will interest you guys.

    I put them in an email, it is it's not very long, but it's just a few sentences from each one of the stories and I have a link to the story as well, right there.ย  I'm going to start sending that out as well to everybody cause some people want my actual show notes.

    We're going to have the newsletter once a week. Then we're also planning on having a little video training as well. So it might just be straight, like straight audio. That's part of a video, but it'll be training on a specific security task or problem that's out there.ย  Then the course improving windows security.

    It's been taking us a long time. Blame it, mostly on me. Karen's also busy with babysitting grandkids at least a couple of days a week, and I'm trying to run a company as well. So it's, forgive us, but it is taking some time, but you're going to love this. I think it's turning out really well.

    I am about halfway done with the final edits. So I'm recording them. We go back and forth. They ended up recording them twice so that we get all of the points I wanted to cover into them. Karen's come up with a whole bunch of great screenshots and other pictures to go in with it so it's not one of these death by PowerPoint things.

    And we've got 21 different talks, if you will, on locking down windows and I go into the why's as well as the hows. I think that's really important, because if you don't understand why you're doing something. You're much less likely to do it. I picked that up from Mr. Tony Robbins, none other, the Anthony Robbins man.

    It's been over 20 years. Karen and I went to an event he had down in Boston and this was one ofย  his firewalk or events.ย  We actually got to walk on hot coals it was the weirdest thing ever. Karen was totally freaking out and I was just, wow, this is going to be weird, but we both did it. It was phenomenal. Cause it of gave you an idea of, even if you have this mental block that you can't do something you probably can. We actually did and nobody's feet were burned or anything. It was real coals. It was really hot. They were really red. It was really something that at the very end they had grass, a little square . Grass, maybe two, three feet by three feet and they had a hose running onto it. So you'd walk over it all. Then you'd just walk in on the grass and the idea there being if you had any hot coals stuck to your foot. You probably didn't want those just to stay on your foot. You'd probably want those, they get put out and taken off, so that's where that did.

    Anyhow. One of the things I learned from Tony was you need to have a strong reason why. We see this all of the time, Stephen Covey, if you read his stuff, you know it as well, you got to know why you're doing something. When it comes to computers and technology and security, you need to understand the why. Because it isn't just a rote thing. There are so many variations on what to do, but if you understand the why you're doing it, then I think it opens up a whole new world. You can explain it to your friends. You can help them understand it because finally you will understand it.ย  You'll be more motivated to do the things that you should be doing because you know why you're doing them, what it involves, what it's going to solve for you.

    This should be a really great course. And I spent some time in it going through the whys, give you some examples of problems people have had and what that solves.

    It's available hopefully here within a couple of weeks, man. I thought I'd be done by the end of January and here it's looking like it'll be the end of February. But be that as it may, keep your eyes out. If you've already emailed me to let me know, you're interested. That's great. I've got you on a list. I'll have to try and send out an email this week or sometime soon to let you guys know it that we've got it ready for you?ย  We will have it already for you, hopefully with the next couple of weeks.

    So that's that I'm told the different way of doing things that's me. I like explaining things I've been told I'm good at it. So let's I think a good thing too.

    I started out the segment by talking about this probably good news for end users. Because in 2020 breaches were down by 19% while the impact of those breaches fell by nearly two-thirds when we're measuring it by the number of people affected.

    Now, of course, if a company is breached and an organization is breached, it's counted as one. One person, if you will affect, obviously it can affect hundreds of thousands, millions of people, depending on what happens like a breach of Equifax. Are you counting that as one or you counting that as 300 million?

    Because that's how many records were stolen? I'm not sure it doesn't say it doesn't go into that much detail, but because the number of data breaches went down and the number of individuals affected by the data breach plummets. It's telling us something, then that is okay. That these hackers have moved away from collecting massive amounts of information and are targeting user credentials as a way to get into corporate networks to install ransomware.

    We've got even more news out this week about the solar winds hack. We talked about this before, and this is a company that makes software that's supposed to help manage networks, which means it's supposed to help make those networks safer. No, as it turns out, they weren't making it safer and it looks like maybe four years bad guys were in these networks.

    We're being managed by solar winds, not with software, right? It's not as though solar winds was managing the network is solar winds sold software services so that you could manage your own networks or in many of these cases, they were actually managing networks of third-party businesses. I do work as well for high valued in value individuals, people who have a high profile that needs to keep all of their data safe and they are constantly being gone after.

    They're trying to hack them all the time and the way they're trying to do it. And I talked about this really the first hour today is by this password stuffing thing. So they're trying to get in and they were successful and now it looks like it wasn't just Russia. Apparently, China knew about this hack potential knew about this bug and was using it.

    And apparently, it also was not. Just solar wind software. Now they're blaming some of this stuff on Microsoft office. If you have an office three 65 subscriptions, apparently they were using that to get in. So the bad guys are getting very selective. They want to go against companies and organizations like government agencies that have information there's really going to help them out.

    That is absolutely phenomenal. So these are stats from the identity theft resource center. And I was thumbing through as I was talking here. So it's saying that more than 300 million individuals were affected by data breaches in 2020, which means they must be counting the people whose.

    Information was stolen, not just the people that were hacked but it is a huge drop of 66% over 2019. And the number of reported data breaches dropped to about 1100, which is about. 20% less than 2019. So it's good. It's bad. I think the mass data collection thing is over with now.

    They're not as interested in it, but they are very interested in strategic attacks as opposed to just these blankets. Let's grab as much data as we can because they want to get it into these government networks, which now we've, we know they've gotten into. And then you've got this double extortion thing going on with the ransomware, where again, the going after businesses and people who they know can pay.

    So that's good news for the rest of us, right? The home users. It's not good news so much for some of my clients, that's what we take care of. That's why we get paid the big bucks. Now how that works. Downright stick around. When we get back, we're going to be talking more about the news this week in particular, of course, security, Facebook, and their Supreme court.

    Stick around.

    The United States has a Supreme court. Our States each have their own Supreme courts. In fact, there's probably Supreme courts all over the world. But did you know that Facebook now has something that people are calling a Supreme court? This is interesting.

    Craig Peterson here. Thanks for joining me.

    People have been complaining about Facebook and what they've been doing for years. One of the things people have really been complaining about lately is how Facebook has been censoring people, particularly according to them anyways, conservatives.ย  I've certainly seen evidence of that. No question don't get me wrong, but there's also left-wingers who are complaining about being censored.

    Facebook decided it needed to have its kind of its own version of the Supreme court. You see what happened? Bins are you have a post on Facebook that is questioned. And usually what has to happen is somebody reports it to Facebook as being off-color or whatever it is, the reporting it as. And if two or three people report it, then it goes to the moderators.

    That same thing is true for some of the artificial intelligence. Some of it's reviewed by moderators as well. Here's your problem. Particularly when it comes to conservatives because you post something conservative on Facebook. And if you are noticed by some of these liberal hacks that are watching Facebook accounts, they will gang up on you.

    And they use these bots to pretend that there is an incredible rage that there are hundreds of people who are very upset by what you just had on Facebook. When in reality, no, one's upset and they're just trying to shut you down. And there might only be two or three people who actually know about it, but they'll use these kinds of artificial intelligence, bots to flood Facebook with complaints.

    And they're doing that on Twitter. The left is doing it all over the place. So what happens next? The big challenge for Facebook is there are 2.7 billion users. Can you even wrap your head around a number like that? That is just massive. So they've got 2.7 billion users, and now, obviously, not everybody's on every day.

    But some percentage of them. And I've seen it's in the hundreds of millions of posts every day on Facebook and they log in and look around. Facebook only has 15,000 moderators. So for 2.7 billion people, 15,000 moderators just isn't a lot. And the other problem is that the moderators are suing Facebook.

    And they came up. This was about a year ago. With a $52 million settlement with moderators and the moderators are saying, Hey, first of all, we're crazy overworked. And then secondarily, we've got PTSD. Post-traumatic stress disorder. And they're saying that they have this because of the stuff that they've had to see, they alleged that reviewing violent and graphic images, sometimes stuff.

    My gosh, I might've gotten mentioned here on the air, but they had to view these. For Facebook. And they said, this just led us to PTSD. I can see that particularly since they have to have so many every day. So many of these different posts that they have to look at. And they are clocked and they are third-party contractors.

    They're just, all this stuff adds up. Doesn't it? Moderators who worked in California, Arizona, Texas, and Florida from 2015 until last year, every moderator will receive a minimum of a thousand dollars as well as additional funds if they are diagnosed with PTSD or related conditions. So they're saying there's about 11,000 moderators that were eligible for this compensation.

    But this is a very big deal. It's difficult. How do you deal with that? They've got now 15,000 moderators who are reviewing the posts of these 2.7 billion users. There is a little bit of an escalation procedure, although it's a very difficult and because there are so many people who are. Complaining and trying to take care of everything.

    It is a very tough situation, really for everybody involved. So they've decided what Facebook needs Facebook's decided this themselves is they've got to moderate themselves a little bit better, and the way they are going to do all of this moderation is they're going to have this kind of Supreme court that supervises.

    All of the moderation going on within Facebook. So they call him the new to an oversight board and. Obviously with just one board, without very many people on it, it is only going to be able to handle a small number of cases. So they have been paying attention to some of the cases. And they're trying to set precedents that will be followed by the moderators and millions of other cases.

    It's basically the same thing that the U S Supreme court does, where they review cases that come up from the federal district court. They can have cases that are coming up from individual States as well. And then they set standards and, without going into all of the detail of disputes between district courts, et cetera, we'll see what happens in Facebook, but lower courts are treating these us Supreme court.

    Rulings and dicta as binding precedents for everything in the future. So it's not easy to do in our courts. We're certainly not great at it. And there are a lot of complex procedures. And even if you're talking about moderation where you bring a moderator in. And there are some standards for that in disputes between businesses where you'll pull in a neutral third party.

    And they'll just usually split things down the middle. But those are going to be difficult for Facebook to put in how they reviewed five decisions. These are pretty substantive. Sixth case apparently became moot after the user deleted the post.

    We have an uprising and Miramar right now. You might've seen it on TV. If you're paying attention. I know a couple of channels have been talking about it. But this is an interesting problem because the military has overthrown the potentially properly democratically elected government.

    What do you do if there is massive cheating going on in the election? We faced that question here ourselves.

    In Miramar, they went ahead and the military took over and imprisoned the president. There was a post talking about that and talking about Muslims in France and China.

    Another one about Azerbaijanis. I don't know if you've seen what happened with Armenia and Azerbaijan and lots of history going back there with the Soviets and they created this whole problem because they didn't like the Armenians, but anyways, of all of these five, they disagreed with the lower moderators opinions and they overturned them. I think it's really good.

    I looked at these cases and I was shocked. I think they're doing the right thing here. Isn't that weird?

    Hey, you're listening to Craig Peterson.

    Visit me online Craig peterson.com.

    Hey, did you know, there is a war, if you will, between Facebook and Apple? It is getting nasty. What's going on over there. That's what we're going to talk about right now. Your privacy, Facebook, Apple, and Android.

    Craig Peterson here. Thanks for joining me.

    My golly. You know what I think about Facebook when it comes to privacy, right? Facebook and Google. I think Facebook is worse than Google, frankly. They just don't respect your privacy. They will go ahead and look at anything that they can get their hands on.

    We'll at that point, just go ahead and pull it together and sell it to anybody that's willing to pay. I am not fond of that. And I think you can probably guess why, and I doubt your fond of that at as well. You're not fond of that either. Apple did something. If that has really upset.

    Facebook and Zuckerberg have been making a lot of noise about this, but Apple announced plans about a week ago to finally roll out a change that they were putting into place in iOS 14, which is the operating system for the iPhones and iPads that Apple has. They had announced that they were going to add it the late last year.

    And there was huge pushback from Facebook and a few others as well. What's going on here? Bottom line is that Apple is trying to force. Apps to be transparent. What privacy do you have? What data are they taking? And in the case of iOS, as well as Android and windows, and Macs, there has been the ability for certain applications to be able to look at other apps that are on the device.

    And by doing that, it can get data from it. They can figure out who you are. They can give a unique fingerprint based on what apps you have and what versions they are. They're pretty clever about what they've been doing in order to harvest your information. Now you might have noticed if you go in.

    To the app store that there's been actually a big change already. This is the Apple app store. If you go in there and you pull up an app, any app, so let's pull up Facebook and then in the app store, and then you click, obviously on Facebook, you scroll down the app store page about Facebook. And partway down, it already has privacy information.

    You want to click on more info project early if it's Facebook because it doesn't fit on that homepage for the Facebook app. And it will tell you everything. Everything that Facebook wants access to. Now, some of it's self-reported by the app developers. Some of it is the stuff that happened. Figure it out either electronically or by getting people involved.

    I would like to think that when it comes to something as big as Facebook, they really are going that extra mile. And making sure that yes, indeed, this information is valid, it is what it is. They may not, and I'm not quite sure, but look at all of the stuff Facebook is gaining access to with you.

    So that was a bit of a hit people were pretty excited. Oh, wow. This is great. And although Google doesn't do what we're talking about here quite yet, I'm sure they will be not in the way that Apple is doing it, but because remember Google makes money off of you and your information, Facebook makes money off of you and your information.

    So if you want privacy, you cannot use Google products like Android or. Chrome. And if you want privacy, you can't use Facebook. So it's as simple as that. Of course, the big question, and we talked about this earlier in the show is how much privacy can you expect? How much do you want? What's legitimate, right?

    All of those types of questions. So what Apple's doing now is they said that in early spring of 2021, they are going to release this new version of iOS. And here's what happens. They've added something and this is according to a white paper and Q and a that Apple sent out. They added something called app tracking transparency, and this is going to require apps to get the user's permission before tracking their data across apps or websites owned by other companies.

    Under settings users will be able to see which apps have requested permission to track so they can make changes. As they see fit. You might have noticed that already under settings as you can look at the microphone settings, it'll tell you. Okay. Here's the apps that I have asked about the microphone and you can turn them off.

    Here's the apps that have asked about the camera. You can turn them off. So they're adding more functionality. They also, in the FAQ, they said that app developers will not be able to require users to allow tracking in order for those users to gain access to the full capabilities of the app. Now, you know how I've talked before extensively about how, if it's free your, the product.

    So what Apple is doing is they're saying, Hey guys if the user says, no, you can't try it. Track me across apps. No, you can't get it. This privacy information, which Apple's letting you do, they cannot Labatt automize. The app is what it comes right down to. So it was in September last year that they first said they were going to do that.

    Then they delayed the implementation of this tracking policy. So the businesses and app developers could get more time to figure this out. One of the things that I think is fascinating here is what Facebook's doing with fighting back. Oh, and by the way, Apple has not just gotten complaints from Facebook.

    There are other marketers and tech companies that frankly it makes Apple more vulnerable to some of these antitrust investigations that have been. Started really against some of these big tech companies. Although, I don't really expect much to happen under the current administration in Washington because frankly, big companies love big regulations.

    Because they can afford to comply with them, but startup little companies who are competitors of theirs cannot afford the lawyers for the paperwork and everything out. I look at the CMMC, we do a lot of work for the DOD, department of defense contractors, where we secure their networks. We secure their computers, we secure everything.

    We put it all together. And we also, for some of them there's guys, there's a 50, $50,000 upcharge for this. And that's because we're cheap. Believe it or not, it is a lot higher for other companies to do it, but we do all of the paperwork, putting together all of the policies, all of the procedures, what they have and.

    Auditing everything for them. And we're talking about a case and a half of paper thinking of the big cases of paper, right? 500 sheets and the ream and how many reams in a box? 10 20. I'm not even sure, but literally cases. And we. Printed it up, we wrote it all up, printed it all up, delivered it to a client just a few weeks ago.

    And it was a huge box of three-inch ring binders. It was all in and they didn't all fit in there. They're the big guys in the department of defense probably love this because they pay a million bucks to the people, the generate the paperwork for them internally. And they know the little guys can't afford to have full-time paper pushers.

    And so that's why, even though we're talking about months worth of work, why we charge 50 grand, which is a heck of a lot cheaper, believe it or not. And it's a huge discount for us. So I don't expect that the fed you're going to come up with a solution. That's truly going to help the little guy here, but Apple's announcement praised by privacy advocate nonprofits as well.

    And Facebook apparently has been buying full-page newspaper ads claiming it's going to hurt small businesses in a way it will cause it can make advertising. Just a little bit harder. And apparently, also Facebook has decided to rewrite its apps. So no longer even requests to access, cross-app access to your personal information.

    We're going to wrap up, talk a little bit about Comcast data cap, and some of these SolarWinds hack victims that didn't use SolarWinds, and ransomware payoffs have surged, even though the number of people affected has gone down.

    Make sure you get on my email list so that you get all of the important news. You're going to get some of this little training I'm doing and the courses that we've developed. The only way to do that is to go to Craig Peterson.com/subscribe. That's how you get on those lists and I'm not sitting there and pounding you or anything else, but I want to keep you informed. So there you go.

    We're probably going to increase our volume from one email a week to three so that we can provide you with a little bit more training. I want to keep these down to something that just takes you a few minutes to go through, but could save you millions of your business and tens of thousands, your retirement, if you are a home user. So make sure you are on that list. Craigpeterson.com/subscribe.

    Comcast. I know many of us have Comcast, I certainly do, is imposing data caps on many people in many parts of the country. That includes people to the South here, Massachusetts residents.

    What do you think they're doing down there? The state lawmakers have proposed a ban on data caps, a ban on new fees, and a ban on price increases for home internet services.

    The idea from their standpoint is we have a lot of people who are working at home because of a lockdown. What are they supposed to be doing?

    I'll take my daughter, one of my daughters, as an example, she's working at home. She used to work in a call center she'd go to every day. Now she's working at home. Are they paying a wage differential for her? Are they paying for the electric bill? They're not even paying for the phone bill or the phone. She has to provide her own phone. She takes inbound calls for a call center.

    Can you believe that? It's just amazing what's happened. The company is saving just a ton of money because people don't have to go into work. You can bet they're going to dispose of some of this space that they've been. What's happening here, we are using more bandwidth than we've ever used because more people are at home and it isn't all business related many are watching Netflix or you've got Netflix on in the background while you're working on stuff. It's just so common to do that.

    What data caps are doing is they say you can only use so much data a month. Then there's usually a penalty of some sort. In Comcast's case, they said for the first quarter of 2021, I believe is what they had come up with. We'll just warn you that you go over your data cap then they'll charge extra. I have a friend who has Comcast and he said, I think it took him like three days before he went over the data cap. That's not long.ย  It's because they're streaming TV. They've got kids working from home.

    Then you've got meetings that they're going to, that are now streaming. So I can see this, but from Comcast side, they now have to handle more data than they've ever had to handle before.

    Because we are using it, like for my daughter, she actually has a cell phone, but all of the calls are routed over the internet. Cause her cell phone hooks up to the wifi in the house and the calls come in and go out via that wifi.ย  It goes through the internet, it goes to her phone carrier's network. Then it goes to the call centers network. So there you go.

    What does that need? That needs to make sure there's no jitter. You don't want voice packets to be dropped because then it sounds terrible. It's very obvious when audio is dropped. I don't know if you've noticed if you're streaming something from one of these online streaming video services, but sometimes. It will hiccup a little bit, but have you noticed that with the smaller hiccups, the audio is fine and the problem is in the video. Now they do that for a couple of reasons, obviously video uses more bandwidth than audio uses, but the other reason is people tend to get more annoyed by audio fallout and audio problems.

    Comcast is saying, Hey guys, look at what we have to do with our networks. We have to expand them. We have to increase them.

    Now I've got to bring up again the Biden administration because of what they're planning on doing with this fairness doctrine on the internet. What they're planning on doing is saying, Hey, Comcast, just because this person uses five terabytes of data a month, you should not be charging them more than grandma that uses 10 gigabytes a month. Thousands of times more bandwidth requirements, you're not allowed to bill them differently. Cause a bit is a bit which is absolutely insane. I don't know how they can justify this sort of thing.

    So what's going to happen is you get companies like Comcast or other internet providers who are going to say. We are not going to invest any money into expanding our capacity because we can't charge for it. Doesn't that make sense to you? It makes perfect sense to me. By getting the FCC involved, it's just going to be crazy.

    Ajit Pi resigned when President Trump was leaving, he used to be the chairman. He actually had a head on his shoulders, but these new people President Biden put in there, it's insanity what they're trying to do with our networks. It's going to make it much worse.

    Comcast is putting data caps in. You hit the data cap it, they're just going to slow you way down. That happens too, with a lot of our cell phones, our cell phone carriers, if you use more data than they've allotted to you, they'll drop you back. So most people have 4g. Yeah. Okay. Your phone's 5g, but really guess what? You're not getting 5g. It's very rare unless you are on the T-Mobile slash Sprint plan. T-Mobile more specifically because nobody else has the coverage that T-Mobile has for 5g.

    So you're using 4g LTE, you hit your data cap. They're going to drop you back to 3g, which is really slow comparing the two together, all the three of them, frankly, but it's very slow compared to a 4g LTE. In mass, by the way, I should mention Verizon files and RCN. Do not impose the data caps. It's just our friends at Comcast that are doing that Vargas and Rogers.

    They let a group of 71 different Massachusetts lawmakers urged Comcast to halt the enforcement. By the way, the data cap is 1.2 terabytes per month, which is actually quite a bit of data. You'd have to spend a lot of time streaming TV. The cap does hurt low-income people is no question about it. If you are being forced to work from home because of the lockdown, the government's forcing you to work from home. They put their fingers in anything, and that just never seems to work out anyhow. We'll see what happens down in mass with Comcast and these guys.

    Let's see here, SolarWinds hack.

    I mentioned this just in passing a little bit earlier in the show today, but CISA, which is the US cybersecurity and infrastructure agency said that nearly a third of the organizations that were attacked by these Russian and Chinese hackers had no direct connection to SolarWinds. Apparently, many of the attacks got in by using password spraying to compromise individual email accounts at targeted organizations.

    There's your tie into Microsoft. Obviously major flaws in Microsoft's cloud services. Another one of the targets was CrowdStrike, which is another company that does security. They do remediation after the fact, as well, which we've had to do for many companies over the years too. We'll see, it looks like these Microsoft flaws may have been these bad guys first vector into some of these systems. That's pretty bad.

    Ransomware, things have changed because they figured out a better way to do it. Nowadays we're calling it double extortion. Payments to ransomware gangs that are using cryptocurrency now, more than quadrupled in 2020. Isn't that something? Less than 200 cryptocurrency wallets received 80% of the funds. 80% of the payments went to 200 wallets, which may or may not represent individual ransomware gangs. It's just incredible. The payments using this cryptocurrency stuff, surged 311% last year, the total volume of $350 million.

    Cyber criminals are moving to crypto locking is the easiest way to turn compromised computers into cash. Then the other thing that they're doing this double whammy is before they encrypt your files and then demand you pay up in order to get the encryption key or decryption key, they're double whamming. They're saying, Oh, Yeah, by the way, we grabbed a bunch of your files, and if you don't want us to, and they'd try and figure out what's the most what's the best way for them to sneak the files out and then tell you which ones are the most valuable, right?

    They have people look at it, which is really bad. If you don't want us to release them out onto the open internet or onto the dark web, you have to pay us. They'll sometimes pretend they're a different company. That's where I was saying. When you look at the 200 different crypto wallets that are used, they will often go in, at first it'll look like a ransomware attack. People will pay the ransom, much less so in the United States than any other country. Then they will use a different crypto wallet, pretending they're somebody else saying, we have your files, you better pay up. Law enforcement, by the way, can target these deposit addresses here for the crypto wallets. They've done it before. We'll see what happens. About half of all of the funds went to 25 different crypto wallets. That's not a lot.

    Make sure you sign up. You'll be getting some of the new newsletter stuff. Some of the free training, the courses, and other things. I'm really devoting myself here 2021's going to be the year that we really help you stop the bad guys.

    Take care and make sure you sign up @craigpeterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 21 min
  • AS HEARD ON: WGAN Mornings News with Matt Gagnon: Why You Should Consider A Zero Trust Security Model and Is there a Chromebook in your Future?

    Good morning everybody!

    I was on WGAN this morning with Matt Gagnon. I went into a little detail about what a Zero Trust Security Model is and how it differs from a traditional network design and why you should be considering this type of system. Then we discussed the future of computing and why Chromebooks are so popular. Here we go with Matt.

    And more tech tips, news, and updates visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Morning, Craig Peterson here.

    Hey, if you've ever wondered about Chromebooks and if you should get one, talked with Matt about that. Matt Gagnon, of course, I'm on every Wednesday morning with him. Also zero trust. Why is the national security agency pushing a whole new way of thinking? When we're talking about our computers. So here we go.

    Matt Gagnon: [00:00:26] Seven 36 WGAN morning news on a Wednesday morning. That means it's time to talk to Craig Peterson, our tech guru. You hear him on this very station on Saturdays at one o'clock to hear more depth of detail about these very stories we'll be talking to him about right now. Craig, how are you this morning, sir?

    Craig Peterson: [00:00:41] Hey, I am doing really quite well. I'm looking forward to spring. It's been actually a nice winter.

    Matt Gagnon: [00:00:48] What are you doing, man? You're tomorrow, there's going to be some sort of blizzard because you just said that you are now tempting fate. I already had to walk outside yesterday.

    I got gas in my car. Sadly, I had to, I had no choice. The wind hurt my face. Okay. That happened yesterday,

    Craig Peterson: [00:01:03] We were outside pouring diesel into our generator because there was no power and it was really cold.

    Matt Gagnon: [00:01:10] It really was. It was frozen. Terrible. I was actually reminded of my old college days. March in from the perimeter parking lot and the wind and the cold just beating me to death on my way in. It was not good yesterday.

    Craig Peterson: [00:01:24] I keep reminding people where that comes from. It comes from Russia. They blow it over the North pole in order to destroy our economy.

    Matt Gagnon: [00:01:31] Yes, they do. And there's so many things that those Russians do, those pesky Russians.

    Craig Peterson: [00:01:34] Canada gets caught in the cross hairs. It's just not fair to them,

    Matt Gagnon: [00:01:38] You might say, Craig, that I have zero trust in Russia. See where I'm going with this one. Could you tell me what a zero-trust security model is and why it perhaps should be something that people embrace?

    Craig Peterson: [00:01:50] This is a concept that's relatively new, at least to most people. The whole idea behind it is we have. To assume in this day and age that our systems have already been compromised. Not just that they might get compromised, but they have.

    So when we're setting up networks for businesses, we look at things in a much different way. It's no longer about the perimeter. Trying to keep people out. The NSA, the national security agency, used to call it no such agency. The NSA has come out with a warning to be bold and also a description of what to do.

    The idea is you've got things inside your network. You've got a printer, that's connected to the network. You've got laptops, desktops, a server. None of them should be able to talk to anything else on the network that it doesn't absolutely need to talk to. It's like the lowest privilege type thing.

    So for instance what I do on my office network is the printers are on a completely different network that is firewalled from the servers, which are firewalled from the desktop which are firewalled from the laptops. The printers can not get to anything else on the network unless first someone's trying to send them a print job. It's just an example of it. You don't want the laptops to be able to scan.

    We have a customer who just this week, he has a little SonicWall firewall and SonicWall's are okay, but he hasn't been updating it for three years. It hasn't been supported in years either. That little SonicWall firewall was then used to get into his network and start spreading. It got around the firewall because he was using it for a VPN controller. Then it started crawling all the way through this network and playing all kinds of havoc, internally. Again. If that firewall couldn't have gotten to a machine and then that machine starts probing everything else, it couldn't have spread.

    In other words, the zero-trust only allows machines to talk to each other that absolutely need to talk to each other and only using the protocols that they're supposed to. I've seen many times, which is the sales guy is tinkering around and is getting into the accounting data. Why are you doing that? They should not be allowed to, so that's the bottom line.

    This is a real big deal. We've got to start building our networks with the assumption that they have already been compromised. How are we going to control it? If it's compromised?

    Matt Gagnon: [00:04:34] Craig Peterson tech guru joins us at this time on Wednesdays going over to the world of technology.

    Another interesting story that I saw here this morning, Craig, was that Chromebooks apparently outsold Macs worldwide in 2020. That's something that surprised me a little bit here. I didn't realize that the market penetration, if you will, of the Chromebook, was that deep, but apparently, it is. What does this mean for the industry?

    Craig Peterson: [00:04:54] Yeah, it's interesting because you're talking about it surpassing the Mac and it sounds like maybe Chromebooks are leaning into Apple. In fact, these things are very lightweight computers. They're typically a tablet, maybe a laptop and they're running an operating system that comes from our friends at Google called Chrome OS.

    It is really designed for being online, although you can store files locally. Where it's been eating into is people that have been running Windows for years. Those Windows machines have been getting more and more expensive. Intel is just not keeping up with everything, particularly from the price standpoint. Putting a chip into Chromebook that is a non-Intel chip. It is way cheaper than Intel, we're talking to 10th or less of the price allows them to make these devices very inexpensive. You can go to a big-box retailer. You can get a little Chromebook device for 150 bucks at the low end. Now you've got a computer that can go online, get edit word documents, or spreadsheets, whatever you might want to do. Can talk to the grandkids or get on a business call, all right there from the Chromebook.

    It is hurting the Wintel monopoly, which is the Windows-Intel, a monopoly, if you will, that has been around for so long. It's a direction that Apple is following the Apple's computers will all be using non-Intel chips within the next two years, all of them. They already have computers out with these new chipsets.

    That's the bottom line, they really have gained some significant market share. People love them. I've got also mentioned here, not just regular people security researchers love the Chromebooks. They are very secure, but remember, we're talking about Google, their business is selling your information. They're not going to sell your files, but they're going to keep track of you.

    The other big driver of the Chromebook sales is schools because now we have so many kids at home going to school, the school says, Hey, you got to buy a $300 Chromebook for your kid for school. That's much easier to swallow than a thousand-dollar Mac or a $700 Windows laptop.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    8 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who justโ€ฆ