Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • AS HEARD ON NH Today WGIR-AM 610: Anti-Trust Legislation for Big Tech and Facial Recognition

    Welcome,

    Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about some of the misguided legislation being pushed by Amy Klobacher regarding big tech with her regulatory solution to anti-trust.  Then we got into Facial recognition and expose.ai. Here we go with Chris. 

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Now we also see that many other companies have entered into that marketplace without our permission to use our faces. So if you want to check right now, this is a great thing that the New York Times did. They have exposed this a little bit, but go to exposing.ai. Senator Amy Klobuchar has introduced some legislation to try and hold big tech a little bit more accountable.

    I'm afraid I have to disagree with her approach. Also, we talked about an article in New York about facial recognition and some of the things we're doing that we probably shouldn't be doing. So here we go with Mr. Chris Ryan.

    Chris Ryan: [00:00:44] Joining us right now in the program is Craig Peterson from Tech Talk you hear on Saturdays at 11:30 AM. Craig, how are you?

    Craig Peterson: [00:00:52] Hey, good morning. Doing well

    Chris Ryan: [00:00:54] Appreciate you joining us for the show.

    I want to talk to you a little about some of the legislation I was reading from Amy Klobuchar, as she looks to get anti-trust legislation to take away some of the security of entities like Facebook and other large tech companies. It doesn't appear there's a tremendous amount of appetite for this type of antitrust legislation at this point. In your view, does there need to be a look at this?

    Craig Peterson: [00:01:22] Yeah, there's two different sides to this whole anti-trust activity. Of course, it had started way back in the 18 hundreds. Then you had all of these massive barrons, and they wanted to stop them from controlling the economy effectively is what they were doing at the time.

    Now we're looking at these almost oligarchs. We've got these people running these huge corporations like Facebook and Google, and Amazon, although there's been a bit of a shakeup at Amazon. Those guys and gals have an incredible amount of market power. That's one side of it. We understand that because if there's no competition, we're not going to be able to get a good value for our dollar.

    The other side of that is how about if there's really only one buyer for your goods? You've got the one side where there's only one seller of particular interest, but what if there's one buyer. We see that more and more, particularly with companies like Amazon.

    People complained about Walmart with that years ago. When Walmart just had such a monopoly and frankly still does in many cases. Walmart beats their suppliers over the head and shoulders to get the price down to a point where the supplier basically can't support it anymore. 

    What we're looking at now is a situation we haven't had in a long time.  She's looking at having more and more regulations, adding more regulators to the various entities and the federal government that regulate business.

    I look at this as saying I've had so many friends who have been destroyed their businesses that are destroyed by these big tech companies and their market manipulation to drive competitors out of business. That really bothers me.

    I see a real big problem here because we do not allow the big guys to fail anymore. There's this concept of too big to fail. When we're talking about a free market, the idea is, if you want to buy some other companies, knock yourself out, but you're going to reach a point where you are not going to be able to afford to survive anymore. We've seen that many times look at the car industry.

    We've seen bailouts now twice of Chrysler in my life as well as GM. There are serious problems with having more and more regulations because it will make it difficult for more competition to enter the market. That could potentially drive these big guys out of business. That's where I really start getting concerned.

    Chris Ryan: [00:03:59] We focus a lot here in this segment about how, whether it's Facebook or other social media mechanisms and the usage of our phones as well, that we're spying on ourselves. It's a fascinating article in the New York Times last week. Actually, I think it was the weekend before, about facial recognition systems being used on our phones. What are they, and how are they used?

    Craig Peterson: [00:04:21] There are a few companies out there you've probably heard of. I've talked about Clearview before, which is this clearview.ai company. This computer vision for a safer world. I love the way they put this. Actually couldn't have written it any better.

    Clearview has raped all of our pictures on the internet. What that means is any publicly available picture, Clearview downloaded and started to look at. We also see that many other companies have entered into that marketplace without our permission to use our faces.

    If you want to check right now, and this is a great thing that the New York times did, they've exposed this a little bit, but go to exposing.ai. Online, exposing.ai as artificial intelligence. It'll let you check to see if the photos you uploaded to flicker are now being sold and used online.

    Our faces. We are uploading our Pictures. We're getting these free photo services, but all your photos on flicker, back in the day, nowadays upload them to Amazon photos or Google photos or Apple photos.

    We know Apple does not make money off of our personal information. Google sure does and so do some of these others.  If you go to exposing.ai, you can type in your flicker username or a photo URL that it'll compare. It'll show you if they're using the pictures that you posted for facial recognition systems.

    This is where we're starting to see arrests coming out of Washington, DC. Where they are scanning the internet for photos or using companies like Clearview and others. We even have had the FBI issue, a legal document here. I don't remember exactly how far I got along the line. The FBI using a big photo that they found online that had been doctored.

    Is your face online? Are they using it for nefarious purposes? Like this guy who ended up getting charged by the FBI for this January in Washington, DC, and he had nothing to do with it.

    Chris Ryan: [00:06:39] Craig, as always appreciate you joining us for the show. I look forward to chatting again next week.

    Craig Peterson: [00:06:43] All right. Take care. Chris.

    Chris Ryan: [00:06:44] Craig Peterson, joining us here in New Hampshire today from Tech Talk. You hear at Saturday's on news radio 610 and 96.7 at 11:30 AM.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    7 min
  • Tech Talk with Craig Peterson Podcast: Drones, Military and AI, Ransomware, Comcast Data Caps and more

    Welcome!

    It is another busy week on the technology front. We delve into the Military's use of drones and AI. We will discuss why Facebook thinks Apple has declared war. Ransomware is up. It turns out that many of those who were victims of the SolarWinds hack did not use their software. They were breached because they had misconfiguration. Well, just a taste of today's topics, and there is even more, so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Drone Swarms Are Getting Too Fast For Humans To Fight, U.S. General Warns

    Building Your Personal Privacy Risk Tolerance Profile

    Breach Data Highlights a Pivot to Orgs Over Individuals

    Facebook "Supreme Court" overrules company in 4 of its first 5 decisions

    State reps try to ban Comcast data cap and price hikes until pandemic is over

    Every crazy thing that happened in Apple and Facebook's privacy feud today

    30% of "SolarWinds hack" victims didn't actually use SolarWinds

    Ransomware Payoffs Surge by 311% to Nearly $350 Million

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hi everybody. Of course, Craig Peterson here. We're going to talk today about these drone swarms, your personal privacy risk tolerance breach highlights here over org's not individuals. What's going on? Ransomware is way up.

    As usual, a lot to talk about. Hey, if you miss part of my show, you can always go online to Craig peterson.com. You'll find it there if you're a YouTube fan CraigPeterson.com/youtube.

    This is really an interesting time to be alive. Is that a good way to put it right? There used to be a curse "May you live in interesting times" Least that was the rumor.

    One of the listeners pointed this out, there was a TV show that was on about five years ago, apparently, and it used this as a premise. I also saw a great movie that used this as a premise, and it was where the President was under attack. He was under attack by drones.

    The Biden administration has a policy now where they're calling for research into artificial intelligence, think the Terminator, where you can have these fighting machines.

    These things should be outlawed, but I also understand the other side where if we don't have that tech and our enemies end up having that tech, we are left at a major disadvantage.

    Don't get me wrong here. I just don't like the idea of anybody doing Terminators, Skynet type of technology. They have called for it to be investigated.

    What we're talking about right now are the drone swarms. Have you seen some of these really cool drones that these people called influencers? Man, the term always bothers me. So many people don't know what they're doing. They just make these silly videos that people watch, and then they make millions, tens of millions. I guess it's not silly after all.

    These influencers make these videos. There are drones that they can use if they're out hiking, you might've noticed, or mountain biking or climbing. They have drones now that will follow them around automatically. They are on camera. It's following them. It focuses on their face. They can make the drone get a little closer or further away. As long as the sky is clear, there's no tree branches or anything in the way that drone is going to be able to follow them, see what they're doing and just really do some amazing shots. I've been just stunned by how good they are.

    Those drones are using a form of artificial intelligence, and I'm not going to really get into it right now, but there are differences between machine learning and artificial intelligence, but at the very least here, it's able to track their faces.

    Now, this is where I start getting really concerned. That's one thing. But they are apparently, right now, training. When I say they, the Chinese and probably us, too, are designing drones that not only have cameras on them but are military drones. They have without them having to have a central computer system controlling them or figuring out targets. They're able to figure out where there's a human and take them out.

    These small drones, they're not going to take them out by firing a 50 caliber round at them. These drones can't carry that kind of firepower. It's just too heavy, the barrels and everything else -- it's a part of that type of a firearm. We're talking about small drones again. So obviously, they're not going to have a missile on them either.

    What they do is they put a small amount, just a fraction of an ounce, of high explosives on the drone. The idea is if that drone crashes into you and sets off its explosives, you're dead, particularly if it crashes into and sets off explosives right there by your head. Now that's pretty bad when you get down to it.

    I don't like the whole Skynet Terminator part of this, which is that the drones are able to find that human and then kill them.

    Think of a simple scenario where there is, let's say there's a war going on. Let's use the worst-case scenario and, enemy troops are located approximately here. You send the drones out, and the drone has, of course, GPS built into it, or some other inertial guidance system or something in case GPS gets jammed.

    That drone then goes to that area.

    It can recognize humans, and it says, Oh, there's a human, and it goes and kills the human. Now that human might be an innocent person. Look at all of the problems we've had with our aerial drones, the manually controlled ones, just the ones that we've been using in the last 10 years where we say, okay, there's a terrorist here. Now they fly it in from. They've got somebody controlling it in Nevada or wherever it might be, and they get their strike orders and their kill orders. They go in, and they'd take it out. There are collateral damages. Now that's always been true.

    Every war.

    Look at Jimmy Stewart. For example, younger kids probably don't know who it is. Mr. Smith Goes to Washington was one of his movies. He had some great Christmas movies and stuff too. Anyhow, Jimmy Stewart was a bomber. I think he was a pilot actually in World War II. He flew combat missions over Germany. Think of what we did in Germany, in Japan, where we killed thousands, tens of thousands, hundreds, probably of thousands of civilians.

    We now think, Oh, we're much better than that. We don't do that anymore. We're careful about civilian casualties. Sometimes to the point where some of our people end up getting in harm's way and killed. For the most part, we try and keep it down.

    A drone like this that goes into an area, even if it's a confined area, and we say, kill any humans in this area, there are going to be innocent casualties. It might even be "friendly fire." You might even be taking out some of your own people.

    They've said, okay, we've got a way around this. What we're going to do is we're going to use artificial intelligence. The drone doesn't just pick out, Oh, this is a human. I'm going to attack that person. It looks at the uniform. It looks at the helmet. It determines which side they're on. If they're wearing an American or Chinese uniform, whatever, it might be programmed for it again. It goes into the area, it finds a human and identifies them as the enemy. Then it goes in and hits them and blows up, killing that person. That's one way that they are looking to use drones.

    The other way is pretty scary. It's, you can defend yourself against a drone, like that. You've got a drone coming. You're probably going to be able to hear it. Obviously, it depends. That drone gets close. I don't know if you've ever had the kids playing with drones, flying them around you, or you've done the same thing. You can always hit it out of the air, can't you?

    If you're military and you have a rifle in your arm, you can just use the rifle and play a little baseball with that drone. There's some interesting stories of people who've been doing that already.

    What happens if we're not talking about a drone, we're talking about a drone swarm. I don't know that you could defend against something like that. There have been studies that have been done. So think, you think there nobody's really working this suit? No, they sure are.

    What's going to happen? Well, the Indian army is one that has admitted to doing tests, and they had a swarm of 75 drones. If you have 75 drones coming after you, let's say you're a high-value target. There is no way you're going to be able to defend yourself against them unless you can duck and cover, and they can't get anywhere near you with their high explosives. The Indian army had these Kamikaze-attack drones. They don't necessarily have to even have high explosives on them.

    This is a new interpretation under Joseph Biden. Mr. President of the Pentagon's rules of use of autonomous weapons. We've always had to have "meaningful human control." That's the wording that the Pentagon uses meaningful human control over any lethal system. Now that could be in a supervisory role rather than direct control. So they call it "human on the loop" rather than "human in the loop." But this is very difficult to fight against.

    The US army is spending now billions of dollars on new air defense vehicles. These air defense vehicles have cannons, two types of missiles, jammers. They're also looking at lasers and interceptor drones, so they can use the right weapon against the right target at the right time.

    That's going to be absolutely vital here because it's so cheap to use a drone. Look what happened. What was a year plus ago now? I'm trying to remember, Central America, Venezuela, somewhere in there where El Presidente for life was up giving a speech. I'm sorry. I didn't mean that to be insulting, but that often is what ends up happening. A drone comes up, and everybody's thinking: Oh, it's a camera drone, wave to the camera thing. It got very close to the President and then blew up. On purpose, right? They were trying to murder the president. That's a bad thing. He was okay. I guess some of the people got minor injuries, relatively speaking.

    When we're looking at having large numbers of incoming threats, not just one drone, but many drones, many of those drones may be decoys.

    How cheap is it to buy one of these drones? Just like the ones that were used in China over the Olympic stadium, where they were all controlled by a computer. You just have these things, decoys. All you need is a few of them that can blow up and kill the people you want to kill very concerning if you ask me.

    We're paying attention to this, as are other countries as they're going forward.

    We're going to talk about building your privacy risk tolerance profile because if you're going to defend yourself, you have to know what you're going to defend against and how much defense do you need?

    Hey, we take risks every day. We take risks when we're going online. But we're still getting out of bed. We're still going into the bathroom. We're still driving cars. How about your online privacy risk tolerance? What is it?

    Hi everybody. Thanks for joining me.

    We all take risks, and it's just part of life. You breathe in air, which you need. You're taking the risk of catching a cold or the flu, or maybe of having some toxic material inhaled. We just don't know, do we?

    Well, on any given day, when we go online, we're also facing risks. And the biggest question I have with clients when I'm bringing businesses on or high-value individuals who need to protect themselves and their information is: okay... what information do you have that you want to try and protect? And what is your personal privacy risk tolerance? So we build a bit of her profile from that, and you guys are going to get the advantage of doing that right now without having to pay me, my team. How's that for simple?

    First of all, we got to understand that nothing is ever completely safe. When you're going online, you are facing real risks, and no matter what people tell you, there is no way to be a hundred percent sure that your data is going to be safe online or that your individual personal, private information is going to be safe while you're online. And there's a few reasons for this.

    The most obvious one, and the one we think about, I think the most has to do with advertising. There are a lot of marketers out there that want to send a message to us at exactly the right time. The right message, too, obviously? So how can they do that? They do that by tracking you via Google. So Google that's their whole business model to know everything they can about you and then sell that information.

    Facebook, same thing. Both of those companies are trying to gather your information. They're doing it when you are not just on their sites, but when you are on other people's sites. Third-party sites are tracking you. In fact, if you go to my website @ craigpeterson.com, you'll see that I do set a Facebook cookie. So I know that you're on Facebook and you visited my site, and you might be interested in this or that.

    Now I'm not a good marketer. Because I'm not using that information for anything, at least not right now, hopefully in the future, we'll start to do some stuff. But that's what they're doing. And the reason why I don't think it's a terrible thing don't know about you.

    I don't think it's bad that they know that I'm trying to go ahead and buy a car right now. Because if I'm trying to buy a car, I want advertisements about cars and I don't want to advertisements about the latest Bugatti or Ferrari, whatever it might be. I want a Ford truck, right? Just simple something I can haul stuff around. You already know I have a small farm, and I need a truck because you need one. I'd love to have a front loader and everything too. Those costs money, and I ain't got it. So that makes sense to me.

    And now there's the other side, which is the criminal side. And then there's really a third side, which is the government side.

    So let's go with the government side here. In the United States, our government is not supposed to track us. Now I say "supposed to," because we have found out through Edward Snowden and many other means that they have been tracking us against the law. And then they put in some laws to let them do some of it, but our government has been tracking us.

    And one of the ways it tracks us is through the "five eyes" program, and now that's been expanded and then expanded again. But the five eyes program is where the United States asks the United Kingdom. Hey, listen. Hey bro. Hey, we can't, and we're not allowed to track our citizens, but you not us. How about we have you track Trump and his team? Yeah, that's what we'll do.

    So there's an example of what evidence is showing has happened. So they go to a third-party country that's part of this agreement,d where all of these countries have gotten together, how signed papers and said, yeah, we'll track each other citizens for each other.

    And that way, the United States could say, Hey, we're not tracking you. And yet they're tracking because they're going to a third-party country. And the United States, if you are going out of the country, then again, they can track you. Any communications are going out of the country. So that's the government side.

    And then, of course, there's governments that track everything. You look at China and how they control all of the media. They control all of the social networking sites. They basically control everything out there.

    We have to be careful with all of that stuff because it can and will be used. And we've seen it has been used to really not just harass people, but do things like throwing them in prison disappear them. Look at what just happened in China, with the head of China's biggest company, basically the Amazon competitor over there. And he disappeared for months and then came back, just praising the Chinese Communist government and how great it is to have all of these people over there. Just telling them what to do and how to do it.

    We obviously don't live in China. We obviously, I think, have oligarchs nowadays. We have people who are rich, who are running the country. They're giving money to campaigns. They get the ear. You have seen all of the bribery allegations against the Biden crime family, or his brother, his son, other members, himself as well, based on a hundred Biden's laptop.

    So I don't trust the government for those very reasons.

    The hackers, let's get into the hackers here. When it comes to hackers, there are, again, a few different types. You've got hackers that are working for governments. And what they're doing is in the case of a small government, like North Korea, they're trying to get their hands on foreign currencies so that they can use those currencies to buy grain, to buy oil, coal, whatever it is they might need to buy.

    You have governments like China and Russia that are trying to basically run World War three. And they're out there with their hacking teams and groups and trying to figure out how do we get into the critical infrastructure in the United States? Okay. So this is how we get in. Okay. We're in over there. So if we ever want to shut down all of the power to New York City, this is what we do.

    Now, remember, that's what happened back in, in when was that 2004, I guess that was, yeah. I remember I was down in, I was heading actually to New York City and then all of a sudden, all of the power went out.

    That apparently was an accident, but it didn't need to be an accident. There are all kinds of allegations about what actually happened there. But that's why China and Russia are trying to get into our systems. And then they obviously want to play havoc. Look at the havoc that was caused in the US economy by this China virus that came obviously from China for Huan. If they wanted to shut down our economy, they now have proof that's all it takes. And they are working on the genetics of some of these viruses over there in China. And they're trying to modify the genes, and they are running experiments on their troops to enhance them, to make these super soldiers that maybe, need less sleep or less food are stronger or et cetera, et cetera, they are doing that.

    So China is a real threat in just a number of different ways. What would it be like if they could shut down our banking system or make it, so we don't trust it anymore?

    Okay. That's part one of your Personal Privacy Risk Tolerance Profile. Stick around because we're going to talk more about this and what you can do to help you have privacy.

    What is your online personal privacy risk tolerance? It's going to vary. I help high-value individuals. I help businesses with this, and now I'm helping you as well. So let's get into part two.

    Craig Peterson here.

    When people ask me, what should I do? That is a very nuanced question. At least it's very nuanced to answer because you could say something like: if you want to be private, use Signal for messaging and use Tor for web browsing, that's fine. And it works in some ways and not in others. For instance, Tor is a web browser that is like a super VPN. It is set up so that you're not just coming from one exit point, you're coming from a whole bunch of different points on the internet. So it's hard to track you down. The problem, however, with Tor is the same problem that you have with VPN services. And I talk about this all the time.

    VPN services do not make your data secure. It does not keep it private. And in the case of VPN services that you might get for free or even buy, and also the case with Tor. Using those VPN services that can make you less secure again. Why did Sutton rob banks? He robbed banks because that's where the money was, where he is a bad guy going to go. If they want easy and quick access to lots of peoples. Private information?

    They're going to hack a VPN server aren't they? Yeah. And if they can't hack the VPN server, why not just have server space in the same data center that VPN provider is renting their space from and then hack it from there, try and get in from there. Or maybe get into the service; the data centers will logs or the VPN servers logs, because even when they say they don't log, they all log, they have to log, they have to have your information otherwise, how can they bill you? And the ones that say we don't log, which are those people are "lieing" by the way. But those guys that have these VPN servers and they're trying not to log, they're trying not to log where you're going. They get fooled all of the time as well. Because their servers have logs, even if they're deleted and disappear.

    So I just wanted to make it clear that you, I, if you have a low risk tolerance, when it comes to your privacy, Tor is not going to do it for you. VPN services are not going to do it for you. You have to look at all of the individual things you're doing online and then decide based on those. What is it that is the most. Beneficial for you in that particular case. Okay.

    So Signal, I brought it up. So let's talk about it for a minute. Signal is the messaging app to use bar none. Signal is encrypted and do, and it is known to be highly secure, which again, Doesn't mean it's a hundred percent, but with Signal, you can talk to people on other platforms. You can have a Mac and talk to somebody on a, on an Android or a windows device.

    But another consideration is who are you talking to? If you're talking to other people that have Macs and you don't want your information to get out, but you're not horrifically worried about it, right? You want it to be private. You want end to end encryption. You're better off using iMessage on your Mac.

    If you're on Windows or Android, there are not any great built-in messaging apps. WhatsApp. If you listened last week and I've got it up on my website, WhatsApp is not great. They claim it's not horrible, but why would you use it if there's a question use Signal instead.

    All right. So there's just a lot to consider when we're talking about it, but here is your big bang for the buck thing. That you can do. And that is use password manager. Now we talked about how Google Chromium Google's Chrome and of course now Microsoft edge. Actually it was the other way around Microsoft edge came up with it first and now Google's adding it.

    But Edge has this password manager built-in. That's all well and good, but I don't know, trust those. I use a third party password manager that is designed for password management and that's all the company does. They're focused on the security behind it, which is why I recommend 1Password and lLastPass. 1Password being my absolute favorite. Use those password managers. That's the biggest bang for your buck if you have a low tolerance for your information, getting out. All right?

    Now that will help to enforce good password habits. It will generate passwords for you, both of those, and it'll generate good passwords and it'll keep them for you, which is really great.

    If you don't want to be tracked while you're browsing online, you can use an ad blocker. I have a couple of webinars I've done on that. If you want a video of one of those webinars to go through that talks about these different blockers ad blockers and others. I'd be glad to send you a link to one of them, but you're going to have to email [email protected].

    And I will send you a link to one of those webinars I did on that stuff. No problem. But some websites are going to break when you use an ad blocker. So sometimes you have to turn it off and you have to turn it back on. The ones I tell you how to use and how to configure, I actually show you a step-by-step we walked through it. Those allow you to turn off that particular ad blocker on an individual site that was broken because of the ad blocker. So pretty straightforward. You don't have to remember to turn it all on and all off. All right.

    Now studies are showing that people are concerned about their privacy. In fact, I believe last I saw said that I think it was about 70% of Americans believe that their smart phones are being tracked by advertisers, and the tech companies provide them with the information. May, 2020 Pew research report talked about this, but 85% of consumers worry, they can trust corporations with their data. So what do you do? Because. Most people don't have the support or the tools. They don't have. I have the money, they didn't get a big inheritance. They're not a high value individual that needs my help and can afford it -- where we go through everything that they do and make sure they have the best solution for each thing, including banking, including going online and trading stocks, all of that stuff.

    You gotta be very careful with all of that stuff. I'm really sad that I have to say this here, but there are no online privacy solutions that will work for everybody. And there are no solutions that work in every situation either.

    So what you need to do is understand what you care the most about. And I think for all of us, what we should care the most about is our financial situation and anything associated with that: our intellectual property, if we're businesses, our bank accounts, all of that sort of stuff is stuff we really should be concerned about. And that means you need to watch it. Make sure you're not sharing stuff that you really don't want to share.

    Okay?

    So even privacy experts like myself, don't lock everything down. We locked most of it down. Particularly since we have department of defense clients, we have to maintain a very high standard.

    All right. Stick around and visit me online. CraigPeterson.com. Make sure you sign up for my newsletter.

    You'll get all of the latest news and the tips I send out every week.

    I don't want to leave you hanging. We're going to get into a few more things to consider here, because obviously we are going to share some of our personal information. So I'm going to tell you how I share my personal information and it might be a bit of a surprise.

    Hello everybody. Thanks for listening.

    We all enjoy products and services, and that's what I'm saying. When when I talk about security experts, we don't lock everything down. I've used 23 in me. I did that thing, of course, I'm sending in my DNA. That's been an issue in some cases, but that's what I did.

    I use these online map programs. I use Google maps. I use weighs more than Google maps. I use Apple maps cause I'm trying to figure out how do I get to where I want to go in a reasonable amount of time. But what I do is I lie about the answer to the security questions. Okay. I don't want them to know my dad's name.

    My mother's maiden name, the street. I was, I grew up on my first school, my first car, none of their business. Because it's a lot of that information is actually publicly available. How many of us on LinkedIn have right there in our profile? Yeah I went to McGill university or I w I grew up here's pictures of my childhood home, and that picture has GPS coordinates in it.

    So if we use the real information. We are giving away way too much. I use a little phrase I coined here, which is lie to your bank. And you might remember. I did a show on that sometime ago. And the idea here is in your line to the bank about your financial situation, it's nothing like that. You're lying to your bank about this personal information.

    They don't need to know these personal questions. They give you for their security questions. It's really important to understand all of this stuff. Okay. For instance, this is Jennifer Granick, she's at the ACL, you and she said her dad died recently. And the accountant said it's really important to report the death to credit companies because the answers to many of the security questions are on the public death certificate.

    So answers to security questions really can be a nightmare, but that doesn't mean you have to give them the right answers. So for instance, I found a site online. I should try and dig that up again, but it generated fake identities. And I had a generate like 5,000 of them for me thinking, okay, they might go at some point and it even generated fake social security numbers, fake phone numbers, names, addresses, everything, everything you'd need for a fake identity. And the idea here isn't to cheat anybody out of anything. The idea is, Hey, Mr. Website, you don't know, you don't need to know who I really am. So on some websites, I'm female some websites I've, I'm only 30 years old on other websites. I'm 80 years old. It doesn't matter.

    You can call it a lie if you want. But in reality, you're just trying to keep your information straight not and another advantage. Of these password managers. Cause you're trying to keep your information straight, right? It's hard to remember a lie and you have to tell a lie to enforce a lie. You're not, all that stuff your mother told you.

    And she's right about that too, by the way. But if you're using a password manager, what I do is I create a unique email address. In fact, my email addresses are extremely unique, so I'll use a plus sign as part of my email address and my mail server knows. Oh, okay. That's just Craig trying to track who is using.

    That email address. So I'll have Craig plus YouTube for instance, [email protected]. I actually have a whole bunch of domains that I use as well. And if you want a secure email service have look at proton mail. They're actually very good from a security standpoint. So there's nothing illegal about giving them this information.

    Yeah. You're lying to them, but you gotta keep your lies straight. Another reason to use a password manager because I have the password manager generate my. My password I put in the email, which is unique for every website I go to, I never use that same email address twice if I can avoid it. And then I, and I use aliases too in my email server.

    And then I go and in my notes section for that website in my password manager, I put in the answers to the security questions and I just make stuff up nonsensical stuff. So it's asking what my first car, it might be a transformational snooze. There you go. I just made something up. So I'll put those notes into my notes in my password manager and save them.

    So if I ever have to do some sort of a recovery with those guys, it's going to be simple. Because I just look in my password manager, I got to go in there anyways to get my password right. And my email address or username to login. And there it is, there's my security questions. And then the password manager, cause I'm using one password.

    It has a little database, it keeps and everything in there is encrypted. And the only way to decrypted is with my password, my one password, that's it. You only have to remember one password and that's the password to one password so that you can decrypt that little vault of a database of all of your information.

    So I have, I bought a, I think it's a 30 plus character password I use for one password because yeah, I'm a little bit paranoid about all that sort of stuff. So that's a really good way to be able to keep your information safe. I talked last week about a friend of mine. Whose wife went on Facebook to get some help, some tips on selling her investments investment anyways, and the disaster.

    That was okay. So a lot of people have regrets about what they've posted on Facebook, and there's a really cool thing out of CMU. Carnegie Mellon university, where these, how many, it's six guys and gals. They put together this special report. I regretted the minute I pressed share a qualitative study of regrets on Facebook.

    Very interesting. So they looked at all of this stuff as best they possibly could. And what did they find? Some examples, just think for yourself what regrets you might have. I know friends of mine in the grads that they have had. But there are a lot, so they go through privacy risk. I can send you a copy of this article if you're interested.

    It talks about their methodology. They analyze comments on the New York times website and others Craig's list to regroup people. They, so they've got all of the stuff. Here you go sensitive content. Number one. So alcohol and illegal drug use. Think about that. Think about your employer, your next employer or the police.

    They got a report on you. Oh my, this is a bad person. So they go onto your Facebook page and they find. Oh, photos posted from a party with some very non unflattering photos in it. And even maybe mentioning a illegal drug use, what it thinks is going to happen. How about if you get stopped at the border coming back from Canada, Mexico, Europe.

    And they decide to do a little deeper look into you and they find this stuff online. The next one sexual content, you can imagine what that is. Think of a Congressman from New York, in fact, religion and politics apparently is one of the things people have regretted posting online, profanity and obscenities, personal and family issues.

    Working company here, negative or offensive comments it's arguments, lies and secrets, venting frustration, good intentions intended purposes. I didn't think about it. Hot. State. Yeah. Oh, my this thing just goes on and on, but keep all of this in mind, when you are trying to keep your information private, whether you are a business or an individual, you have to have eternal vigilant watch when your emotions are high, right.

    It's like drunk dialing. Don't do it. Or your emotions are high. Something's been going on. Don't put it online. So that's I think a real good bottom line about your. Personal privacy, risk tolerance profile. Okay. Be very careful. , don't put stuff that you don't want other people to see. It's not true that once it's out on the internet, it's there forever.

    It's not true that once you've posted it, it's there for anyone to discover. None of that's true. Not at all. Okay. But be very careful cover up your laptop cameras. In fact, in the improving windows security course, I go into this in quite a bit of detail, what you can do, what kind of cameras you can and should use, what sort of microphones you can or should use.

    Many people just cover up the laptop cameras with the sticky note. When they're not using it disable automatic image loading in your mail program. That's important. I do that as well, because that image that's in the email is usually being used to track you. It's really that simple. You've got new privacy laws in many States and in Europe, they are really not going to work or help you with your privacy, except with the really big companies out there.

    So keep all of that in mind. All right, everybody. I want to encourage you go to Craig peterson.com. You'll see all kinds of great information there. You're going to be able to also listen to my whole show, pick up all the little training tips and even find out about the courses that I'm offering. Craig peterson.com

    I guess this is a little bit of good news. If you're a home user, not a business or some other organization, like a state or County or city office, but we've got some breach numbers that have just come out for 2020. We're going to talk about right now.

    Hi, everybody. Thanks for joining me. Of course you can always go to my website. Yeah. Pick up all of the podcast in case you missed something today or another week, you'll find them right [email protected]. You can also sign up for my email list and we're going to be doing a couple of different things here.

    I think in the near future, we're going to be sending out some reports that we made as part of the security summer thing I did a couple of years ago and each one of these reports and there's 30 something of them. Some of them are like five to seven pages long, but it's checklists of all the security things you should be worrying about.

    Now, if you are home user, you'll find a lot of these to be interesting. But if you're a business person, you work in an office, you help to run an office. You own a business. You need to make sure you get all of them. So make sure you are signed up Craig peterson.com and we'll be glad to get those out too.

    Plus we're also going to start something new every week. I usually have six to eight, sometimes as many as 10 articles in the week. I spend hours going through finding what I think are the most important things that interest me as well, but that I think will interest you guys.

    I put them in an email, it is it's not very long, but it's just a few sentences from each one of the stories and I have a link to the story as well, right there. I'm going to start sending that out as well to everybody cause some people want my actual show notes.

    We're going to have the newsletter once a week. Then we're also planning on having a little video training as well. So it might just be straight, like straight audio. That's part of a video, but it'll be training on a specific security task or problem that's out there. Then the course improving windows security.

    It's been taking us a long time. Blame it, mostly on me. Karen's also busy with babysitting grandkids at least a couple of days a week, and I'm trying to run a company as well. So it's, forgive us, but it is taking some time, but you're going to love this. I think it's turning out really well.

    I am about halfway done with the final edits. So I'm recording them. We go back and forth. They ended up recording them twice so that we get all of the points I wanted to cover into them. Karen's come up with a whole bunch of great screenshots and other pictures to go in with it so it's not one of these death by PowerPoint things.

    And we've got 21 different talks, if you will, on locking down windows and I go into the why's as well as the hows. I think that's really important, because if you don't understand why you're doing something. You're much less likely to do it. I picked that up from Mr. Tony Robbins, none other, the Anthony Robbins man.

    It's been over 20 years. Karen and I went to an event he had down in Boston and this was one of his firewalk or events. We actually got to walk on hot coals it was the weirdess thing ever. Karen was totally freaking out and I was just, wow, this is going to be weird, but we both did it. It was phenomenal. Cause it of gave you an idea of, even if you have this mental block that you can't do something you probably can. We actually did and nobody's feet were burned or anything. It was real coals. It was real hot. They were really red. It was really something that at the very end they had a grass, a little square. Grass, maybe two, three feet by three feet and they had a hose running onto it. So you'd walk over it all. Then you'd just walk in on the grass and the idea there being, if you had any hot coals stuck to your foot. You probably didn't want those just stay on your foot. You'd probably want those, they get put out and taken off, so that's where that did.

    Anyhow. One of the things I learned from Tony was you need to have a strong reason why. We see this all of the time, Stephen Covey, if you read his stuff, you know it as well, you got to know why you're doing something. When it comes to computers and technology and security, you need to understand the why. Because it isn't just a rote thing. There are so many variations on what to do, but if you understand the why you're doing it, then I think it opens up a whole new world. You can explain it to your friends. You can help them understand it because finally you will understand it. You'll be more motivated to do the things that you should be doing because you know why you're doing them, what it involves, what it's going to solve for you.

    This should be a really great course. And I spent some time in it going through the whys, give you some examples of problems people have had and what that solves.

    It's available hopefully here within a couple of weeks, man. I thought I'd be done by the end of January and here it's looking like it'll be the end of February. But be that as it may, keep your eyes out. If you've already emailed me to let me know, you're interested. That's great. I've got you on a list. I'll have to try and send out an email this week or sometime soon to let you guys know about it that we've got it ready for you? We will have already for you, hopefully with the next couple of weeks.

    So that's that I'm told different way of doing things that's me. I like explaining things I've been told I'm good at it. So let's I think a good thing too.

    I started out the segment by talking about this probably good news for end users. Because in 2020 breaches were down by 19% while the impact of those breaches fell by nearly two thirds when we're measuring it by the number of people affected.

    Now, of course, if a company is breached and organization is breached, it's counted as one. One person, if you will affected, obviously it can affect a hundreds of thousands, millions of people, depending on what happens like a breach of Equifax. Are you counting that as one or you counting that as 300 million?

    Because that's how many records were stolen? I'm not sure it doesn't say it doesn't go into that much detail, but because the number of data breaches went down and the number of individuals affected by the data breach is plummeted. It's telling us something, then that is okay. That these hackers have moved away from collecting massive amounts of information and are targeting user credentials as a way to get into corporate networks to install ransomware.

    We've got even more news out this week about the solar winds hack. We talked about this before, and this is a company that makes software that's supposed to help manage networks, which means it's supposed to help make those networks safer. No, as it turns out, they weren't making it safer and it looks like maybe four years bad guys were in these networks that.

    We're being managed by solar winds, not with software, right? It's not as though solar winds was managing the network is solar winds sold software services so that you could manage your own networks or in many of these cases, they were actually managing networks of third-party businesses. I do work as well for high valued in value individuals, people who have a high profile that need to keep all of their data safe and they are constantly being gone after.

    They're trying to hack them all the time and the way they're trying to do it. And I talked about this really the first hour today is by this password stuffing thing. So they're trying to get in and they were successful and now it looks like it wasn't just Russia. Apparently China knew about this hack potential knew about this bug and was using it.

    And apparently it also was not. Just solar wind software. Now they're blaming some of this stuff on Microsoft office. If you have an office three 65 subscription, apparently they were using that to get in. So the bad guys are getting very selective. They want to go against companies and organizations like government agencies that have information there's really going to help them out.

    That is absolutely phenomenal. So these are stats from the identity theft resource center. And I was thumbing through as I was talking here. So it's saying that more than 300 million individuals were affected by data breaches in 2020, which means they must be counting the people whose.

    Information was stolen, not just the people that were hacked but it is a huge drop 66% over 2019. And the number of reported data breaches dropped to about 1100, which is about. 20% less than 2019. So it's good. It's bad. I think the mass data collection thing is over with now.

    They're not as interested in it, but they are very interested in strategic attacks as opposed to just these blanket. Let's grab as much data as we can because they want to get it into these government networks, which now we've, we know they've gotten into. And then you've got this double extortion thing going on with the ransomware, where again, the going after businesses and people who they know can pay.

    So that's good news for the rest of us, right? The home users. It's not good news so much for some of my clients, that's what we take care of. That's why we get paid the big bucks. Now how that works. Downright stick around. When we get back, we're going to be talking more about the news this week in particular, of course, security, Facebook and their Supreme court stick around.

    We'll be right back.

    The United States has a Supreme court. Our States each have their own Supreme courts. In fact, there's probably Supreme courts all over the world. But did you know that Facebook now has something that people are calling a Supreme court. This is interesting.

    Craig Peterson here. Thanks for joining me.

    I'm not sure if you've seen this or not, it's very small and it's designed to go into your car and then it will hook up like Bluetooth to your car. It'll use your phone for data. So the data is going back and forth from your phone over to them. They're a little device and that way you can talk to it and you can play music, whatever you'd like to listen to right there from your Alexa.

    People have been complaining about Facebook and what they've been doing for years. One of the things people have really been complaining about lately is how Facebook has been censoring people, particularly according to them anyways, conservatives. I've certainly seen evidence of that. No question don't get me wrong, but there's also left-wingers who are complaining about being censored.

    Facebook decided it needed to have its kind of its own version of Supreme court. You see what happened? Bins is you have a post on Facebook that is questioned. And usually what has to happen is somebody reports it to Facebook as being off color or whatever it is, the reporting it as. And if two or three people report it, then it goes to the moderators.

    That same thing is true for some of the artificial intelligence. Some of it's reviewed by moderators as well. Here's your problem. Particularly when it comes to conservatives because you post something conservative on Facebook. And if you are noticed by some of these liberal hacks that are watching Facebook accounts, they will gang up on you.

    And they use these bots to pretend that there is incredible. Rage that there are hundreds of people who are very upset by what you just had on Facebook. When in reality, no, one's upset and they're just trying to shut you down. And there might only be two or three people who actually know about it, but they'll use these kind of artificial intelligence, bots to flood Facebook with complaints.

    And they're doing that on Twitter. The left is doing it all over the place. So what happens next? The big challenge for Facebook is there are 2.7 billion users. Can you even wrap your head around a number like that? That is just massive. So they've got 2.7 billion users, and now, obviously not everybody's on every day.

    But some percentage of them. And I've seen it's in the hundreds of millions posts every day on Facebook and they log in and look around. Facebook only has 15,000 moderators. So for 2.7 billion people, 15,000 moderators just isn't a lot. And the other problem is that the moderators are suing Facebook.

    And they came up. This was about a year ago. With a $52 million settlement with moderators and the moderators are saying, Hey, first of all, we're crazy overworked. And then secondarily, we've got PTSD. Post-traumatic stress disorder. And they're saying that they have this because of the stuff that they've had to see, they alleged that reviewing violent and graphic images, sometimes stuff.

    My gosh, I might've gotten mentioned here on the air, but they had to view these. For Facebook. And they said, this just led us to PTSD. I can see that particularly since they have to have so many every day. So many of these different posts that they have to look at. And they are clocked and they are third-party contractors.

    They're just, all this stuff adds up. Doesn't it? Moderators who worked in California, Arizona, Texas, and Florida from 2015 until last year, every moderator will receive a minimum of a thousand dollars as well as additional funds if they are diagnosed with PTSD or related conditions. So they're saying there's about 11,000 moderators that were eligible for this compensation.

    But this is a very big deal. It's difficult. How do you deal with that? They've got now 15,000 moderators who are reviewing the posts of these 2.7 billion users. There is a little bit of an escalation procedure, although it's a very difficult and because there are so many people who are. Complaining and trying to take care of everything.

    It is a very tough situation, really for everybody involved. So they've decided what Facebook needs Facebook's decided this themselves is they've got to moderate themselves a little bit better, and the way they are going to do all of this moderation is they're going to have this kind of Supreme court that supervises.

    All of the moderation going on within Facebook. So they call him the new to an oversight board and. Obviously with just one board, without very many people on it, it is only going to be able to handle a small number of cases. So they have been paying attention to some of the cases. And they're trying to set precedents that will be followed by the moderators and millions of other cases.

    It's basically the same thing that the U S Supreme court does, where they review cases that come up from the federal district court. They can have cases that are coming up from individual States as well. And then they set standards and, without going into all of the detail of disputes between district courts, et cetera, we'll see what happens in Facebook, but lower courts are treating these us Supreme court.

    Rulings and dicta as binding precedents for everything in the future. So it's not easy to do in our courts. We're certainly not great at it. And there are a lot of complex procedures. And even if you're talking about moderation where you bring a moderator in. And there are some standards for that in disputes between businesses where you'll pull in a neutral third party.

    And they'll just usually split things down the middle. But those are going to be difficult for Facebook to put in how they reviewed five decisions. These are pretty substantive. Sixth case apparently became moot after the user deleted the post.

    We have an uprising and Miramar right now. You might've seen it on TV. If you're paying attention. I know a couple of channels have been talking about it. But this is an interesting problem because the military has overthrown the potentially properly democratically elected government.

    What do you do if there is massive cheating going on in the election? We faced that question here ourselves.

    In Miramar, they went ahead and the military took over and imprisoned the president. There was a post talking about that and talking about Muslims in France and China.

    Another one about Azerbaijanis. I don't know if you've seen what happened with Armenia and Azerbaijan and lots of history going back there with the Soviets and they created this whole problem because they didn't like the Armenians, but anyways, of all of these five, they disagreed with the lower moderators opinions and they overturned them. I think it's really good.

    I looked at these cases and I was shocked. I think they're doing the right thing here. Isn't that weird?

    Hey, you're listening to Craig Peterson right here on news radio.

    Visit me online craig peterson.com.

    Hey, did you know, there is a war, if you will, between Facebook and Apple? It is getting nasty. What's going on over there. That's what we're going to talk about right now. Your privacy, Facebook, Apple, and Android.

    Craig Peterson here. Thanks for joining me. My golly. You know what I think about Facebook when it comes to privacy, right? Facebook and Google. I think Facebook is worse than Google, frankly. They just don't respect your privacy. They will go ahead and look at anything that they can get their hands on.

    We'll at that point, just go ahead and pull it together and sell it to anybody that's willing to pay. I am not fond of that. And I think you can probably guess why, and I doubt your fond of that at as well. You're not fond of that either. Apple did something. If that has really upset.

    Facebook and Zuckerberg has been making a lot of noise about this, but Apple announced plans about a week ago to finally roll out a change that they were putting into place in iOS 14, which is the operating system for the iPhones and iPads that Apple has. They had announced that they were going to add it the late last year.

    And there was huge pushback from Facebook and a few others as well. What's going on here? Bottom line is that Apple is trying to force. Apps to be transparent. What privacy do you have? What data are they taking? And in the case of iOS, as well as Android and windows and Macs, there has been the ability for certain applications to be able to look at other apps that are on the device.

    And by doing that, it can get data from it. They can figure out who you are. They can give a unique fingerprint based on what apps you have and what versions they are. They're pretty clever what they've been doing in order to harvest your information. Now you might have noticed if you go in.

    To the app store that there's been actually a big change already. This is the Apple app store. If you go in there and you pull up an app, any app, so let's pull up Facebook and then in the app store, and then you click, obviously on Facebook, you scroll down the app store page about Facebook. And partway down, it already has privacy information.

    You want to click on more info project early if it's Facebook, because it doesn't fit on that homepage for the Facebook app. And it will tell you everything. Everything that Facebook wants access to. Now, some of it's self-reported by the app developers. Some of it is stuff that happened. Figure it out either electronically or by getting people involved.

    I would like to think that when it comes to something as big as Facebook, they really are going that extra mile. And making sure that yes, indeed, this information is valid, it is what it is. They may not, and I'm not quite sure, but look at all of the stuff Facebook is gaining access to with you.

    So that was a bit of a hit people were pretty excited. Oh, wow. This is great. And although Google doesn't do what we're talking about here quite yet, I'm sure they will be not in the way that Apple is doing it, but because remember Google makes money off of you and your information, Facebook makes money off of you and your information.

    So if you want privacy, you cannot use Google products like Android or. Chrome. And if you want privacy, you can't use Facebook. So it's as simple as that. Of course, the big question, and we talked about this earlier in the show is how much privacy can you expect? How much do you want? What's legitimate, right?

    All of those types of questions. So what Apple's doing now is they said that in early spring of 2021, they are going to release this new version of iOS. And here's what happens. They've added something and this is according to a white paper and Q and a that Apple sent out. They added something called app tracking transparency, and this is going to require apps to get the user's permission before tracking their data across apps or websites owned by other companies.

    Under settings user will be able to see which apps have requested permission to track so they can make changes. As they see fit. You might have noticed that already under settings, like you can look at the microphone settings, it'll tell you. Okay. Here's the apps that I have asked about microphone and you can turn them off.

    Here's the apps that have asked about the camera. You can turn them off. So they're adding more functionality. They also, in the FAQ, they said that app developers will not be able to require users to allow tracking in order for those users to gain access to the full capabilities of the app. Now, you know how I've talked before extensively about how, if it's free your, the product.

    So what Apple is doing is they're saying, Hey guys if the user says, no, you can't try it. Track me across apps. No, you can't get it. This privacy information, which Apple's letting you do, they cannot Labatt automize. The app is what it comes right down to. So it was in September last year that they first said they were going to do that.

    Then they delayed the implementation of this tracking policy. So the businesses and app developers could get more time to figure this out. One of the things that I think is fascinating here is what Facebook's doing with fighting back. Oh, and by the way, Apple has not just gotten complaints from Facebook.

    There are other marketers and tech companies that frankly it makes Apple more vulnerable to some of these antitrust investigations that have been. Started really against some of these big tech companies. Although, I don't really expect much to happen under the current administration in Washington because frankly, big companies love big regulations.

    Because they can afford to comply with them, but startup little companies who are competitors of theirs cannot afford the lawyers for the paperwork and everything out. I look at the CMMC, we do a lot of work for DOD department of defense contractors, where we secure their networks. We secure their computers, we secure everything.

    We put it all together. And we also, for some of them there's guys, there's a 50, $50,000 upcharge for this. And that's because we're cheap. Believe it or not, it is a lot higher for other companies do it, but we do all of the paperwork, putting together all of the policies, all of the procedures, what they have and.

    Auditing everything for them. And we're talking about a case and a half of paper thinking of the big cases of paper, right? 500 sheets and the ream and how many reams in a box? 10 20. I'm not even sure, but literally cases. And we. Printed it up, we wrote it all up, printed it all up, delivered it to a client just a few weeks ago.

    And it was a huge box of three inch ring binders. It was all in and they didn't all fit in there. They're the big guys in the department of defense probably love this because they, they pay a million million bucks to the people, the generate the paperwork for them internally. And they know the little guys can't afford to have full-time paper pushers.

    And so that's why, even though we're talking about months worth of work, why we charge 50 grand, which is a heck of a lot cheaper, believe it or not. And it's a huge discount for us. So I don't expect that the fed you're going to come up with a solution. That's truly going to help the little guy here, but Apple's announcement praised by privacy advocate nonprofits as well.

    And Facebook apparently has been buying full page newspaper ads claiming it's going to hurt small businesses in a way it will cause it can make advertising. Just a little bit harder. And apparently also Facebook has decided to rewrite its apps. So no longer even requests to access, cross app access to your personal information.

    Welcome back. We're going to wrap up, talk a little bit about Comcast data cap, and some of these SolarWinds hack victims that didn't use SolarWinds, and ransomware payoffs have surged, even though the number of people affected has gone down.

    Make sure you get on my email list so that you get all of the important news. You're going to get some of this little training I'm doing and the courses that we've developed. The only way to do that is to go to Craig Peterson.com/subscribe. That's how you get on those lists and I'm not sitting there and pounding you or anything else, but I want to keep you informed. So there you go.

    We're probably going to increase our volume from one email a week to three, so that we can provide you with a little bit more training. I want to keep these down to something that just takes you a few minutes to go through, but could save you millions of your business and tens of thousands, your retirement, if you are a home user. So make sure you are on that list. Craigpeterson.com/subscribe.

    Comcast. I know many of us have Comcast, I certainly do, is imposing data caps on many people in many parts of the country. That includes people to the South here, Massachusetts residents.

    What do you think they're doing down there? The state lawmakers have proposed a ban on data caps, a ban on new fees, and a ban on price increases for home internet services.

    The idea from their standpoint is we have a lot of people who are working at home because of a lockdown. What are they supposed to be doing?

    I'll take my daughter, one of my daughters, as an example, she's working at home. She used to work in a call center she'd go in every day. Now she's working at home. Are they paying a wage differential for her? Are they paying for electric bill? They're not even paying for the phone bill or the phone. She has to provide her own phone. She takes inbound calls for a call center.

    Can you believe that? It's just amazing what's happened. The company is saving just a ton of money because people don't have to go into work. You can bet they're going to dispose of some of this space that they've been. What's happening here, we are using more bandwidth than we've ever used because more people are at home and it isn't all business related many are watching Netflix or you've got Netflix on in the background while you're working on stuff. It's just so common to do that.

    What data caps are doing is they say you can only use so much data a month. Then there's usually a penalty of some sort. In Comcast case, they said for the first quarter of 2021, I believe is what they had come up with. We'll just warn you that you go over your data cap then they'll charge extra. I have a friend who has Comcast and he said, I think it took him like three days before he went over the data cap. That's not long. It's because they're streaming TV. They've got kids working from home.

    Then you've got meetings that they're going to, that are now streaming. So I can see this, but from Comcast side, they now have to handle more data than they've ever had to handle before.

    Because we are using it, like for my daughter, she actually has a cell phone, but all of the calls are routed over the internet. Cause her cell phone hooks up to the wifi in the house and the calls come in and go out via that wifi. It goes through the internet, it goes to her phone carriers network. Then it goes to the call centers network. So there you go.

    What does that need? That needs to make sure there's no jitter. You don't want voice packets to be dropped because then it sounds terrible. It's very obvious when audio is dropped. I don't know if you've noticed if you're streaming something from one of these online streaming video services, but sometimes. It will hiccup a little bit, but have you noticed that with the smaller hiccups, the audio is fine and the problem is in the video. Now they do that for a couple of reasons, obviously video uses more bandwidth than audio uses, but the other reason is people tend to get more annoyed by audio fallout and audio problems.

    Comcast is saying, Hey guys, look at what we have to do with our networks. We have to expand them. We have to increase them.

    Now I've got to bring up again the Biden administration because of what they're planning on doing with this fairness doctrine on the internet. What they're planning on doing is saying, Hey, Comcast, just because this person uses five terabytes of data a month, you should not be charging them more than grandma that uses 10 gigabytes a month. Thousands of times more bandwidth requirement, you're not allowed to bill them differently. Cause a bit is a bit which is absolutely insane. I don't know how they can justify this sort of thing.

    So what's going to happen is you get companies like Comcast or other internet providers who are going to say. We are not going to invest any money into expanding our capacity because we can't charge for it. Doesn't that make sense to you? It makes perfect sense to me. By getting the FCC involved, it's just going to be crazy.

    Ajit Pi resigned when President Trump was leaving, he used to be the chairman. He actually had a head on his shoulders, but these new people President Biden put in there, it's insanity what they're trying to do with our networks. It's going to make it much worse.

    Comcast is putting data caps in. You hit the data cap it, they're just going to slow you way down. That happens too, with a lot of our cell phones, our cell phone carriers, if you use more data than they've allotted to you, they'll drop you back. So most people have 4g. Yeah. Okay. Your phone's 5g, but really guess what? You're not getting 5g. It's very rare unless you are on on the T-Mobile slash Sprint plan. T-Mobile more specifically because nobody else has the coverage that T-Mobile has for 5g.

    So you're using 4g LTE, you hit your data cap. They're going to drop you back to 3g, which is really slow comparing the two together, all the three of them, frankly, but it's very slow compared to a 4g LTE. In mass, by the way, I should mention Verizon files and RCN. Do not impose the data caps. It's just our friends at Comcast that are doing that Vargas and Rogers.

    They let a group of 71 different Massachusetts lawmakers who urged Comcast to halt the enforcement. By the way, the data cap is 1.2 terabytes per month, which is actually quite a bit of data. You'd have to spend a lot of time streaming TV. The cap does hurt low-income people is no question about it. If you are being forced to work from home because of the lockdown, government's forcing you to work from home. They put their fingers in anything, and that just never seems to work out anyhow. We'll see what happens down in mass with Comcast and these guys.

    Let's see here, SolarWinds hack.

    I mentioned this just in passing a little bit earlier in the show today, but CISA, which is the US cybersecurity and infrastructure agency said that nearly a third of the organizations that were attacked by these Russian and Chinese hackers had no direct connection to SolarWinds. Apparently many of the attacks got in by using password spraying to compromise individual email accounts at targeted organizations.

    There's your tie into Microsoft. Obviously major flaws in Microsoft's cloud services. Another one of the targets was CrowdStrike, which is another company that does security. They do remediation after the fact, as well, which we've had to do for many companies over the years too. We'll see, it looks like these Microsoft flaws may have been these bad guys first vector into some of these systems. That's pretty bad.

    Ransomware, things have changed because they figured out a better way to do it. Nowadays we're calling it a double extortion. Payments to ransomware gangs that are using cryptocurrency now, more than quadrupled in 2020. Isn't that something. Less than 200 cryptocurrency wallets received 80% of the funds. 80% of the payments went to 200 wallets, which may or may not represent individual ransomware gangs. It's just incredible. The payments using this cryptocurrency stuff, surged 311% last year, total volume $350 million.

    Cyber criminals are moving to cryptolocking is the easiest way to turn compromised computers into cash. Then the other thing that they're doing this double whammy is before they encrypt your files and then demand you pay up in order to get the encryption key or decryption key, they're double whamming. They're saying, Oh, Yeah, by the way, we grabbed a bunch of your files and if you don't want us to, and they'd try and figure out what's the most what's the best way for them to sneak the files out and then tell you which ones are the most valuable, right?

    They have people look at it, which is really bad. If you don't want us to release them out onto the open internet or onto the dark web, you have to pay us. They'll sometimes pretend they're a different company. That's where I was saying. When you look at the 200 different crypto wallets that are used, they will often go in, at first it'll look like a ransomware attack. People will pay the ransom, much less so in the United States than any other country. Then they will use a different crypto wallet, pretending they're somebody else saying, we have your files, you better pay up. Law enforcement, by the way, can target these deposit addresses here for the crypto wallets. They've done it before. We'll see what happens. About half of all of the funds went to 25 different crypto wallets. That's not a lot.

    Make sure you sign up. You'll be getting some of the new newsletter stuff. Some of the free training, the courses and other things. I'm really devoting myself here 2021's going to be the year that we really help you stop the bad guys.

    Take care and make sure you sign up @craigpeterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553.

    1 hr 23 min
  • Tech Talk with Craig Peterson Podcast: Drones, Military and AI, Ransomware, Comcast Data Caps and more

    Welcome!  

    It is another busy week on the technology front.  We delve into the Military's use of drones and AI.  We will discuss why Facebook thinks Apple has declared war.  Ransomware is up. It turns out that many of those who were victims of the SolarWinds hack did not use their software. They were breached because they had misconfiguration. Well, just a taste of today's topics, and there is even more, so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Drone Swarms Are Getting Too Fast For Humans To Fight, U.S. General Warns

    Building Your Personal Privacy Risk Tolerance Profile

    Breach Data Highlights a Pivot to Orgs Over Individuals

    Facebook “Supreme Court” overrules company in 4 of its first 5 decisions

    State reps try to ban Comcast data cap and price hikes until pandemic is over

    Every crazy thing that happened in Apple and Facebook’s privacy feud today

    30% of “SolarWinds hack” victims didn’t actually use SolarWinds

    Ransomware Payoffs Surge by 311% to Nearly $350 Million

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hi everybody. Of course, Craig Peterson here. We're going to talk today about these drone swarms, your personal privacy risk tolerance breach highlights here over org's not individuals. What's going on? Ransomware is way up.

    As usual, a lot to talk about. Hey, if you miss part of my show, you can always go online to Craig peterson.com. You'll find it there if you're a YouTube fan CraigPeterson.com/youtube.

    This is really an interesting time to be alive. Is that a good way to put it right? There used to be a curse "May you live in interesting times" Least that was the rumor.

    One of the listeners pointed this out, there was a TV show that was on about five years ago, apparently, and it used this as a premise. I also saw a great movie that used this as a premise, and it was where the President was under attack. He was under attack by drones.

    The Biden administration has a policy now where they're calling for research into artificial intelligence, think the Terminator, where you can have these fighting machines.

    These things should be outlawed, but I also understand the other side where if we don't have that tech and our enemies end up having that tech, we are left at a major disadvantage.

    Don't get me wrong here. I just don't like the idea of anybody doing Terminators, Skynet type of technology. They have called for it to be investigated.

    What we're talking about right now are the drone swarms. Have you seen some of these really cool drones that these people called influencers? Man, the term always bothers me. So many people don't know what they're doing. They just make these silly videos that people watch, and then they make millions, tens of millions. I guess it's not silly after all.

    These influencers make these videos. There are drones that they can use if they're out hiking, you might've noticed, or mountain biking or climbing. They have drones now that will follow them around automatically. They are on camera. It's following them. It focuses on their face. They can make the drone get a little closer or further away. As long as the sky is clear, there's no tree branches or anything in the way that drone is going to be able to follow them, see what they're doing and just really do some amazing shots. I've been just stunned by how good they are.

    Those drones are using a form of artificial intelligence, and I'm not going to really get into it right now, but there are differences between machine learning and artificial intelligence, but at the very least here, it's able to track their faces.

    Now, this is where I start getting really concerned. That's one thing. But they are apparently, right now, training. When I say they, the Chinese and probably us, too, are designing drones that not only have cameras on them but are military drones.  They have without them having to have a central computer system controlling them or figuring out targets. They're able to figure out where there's a human and take them out.

    These small drones, they're not going to take them out by firing a 50 caliber round at them. These drones can't carry that kind of firepower. It's just too heavy, the barrels and everything else -- it's a part of that type of a firearm.  We're talking about small drones again. So obviously, they're not going to have a missile on them either.

    What they do is they put a small amount, just a fraction of an ounce, of high explosives on the drone.  The idea is if that drone crashes into you and sets off its explosives, you're dead, particularly if it crashes into and sets off explosives right there by your head. Now that's pretty bad when you get down to it.

    I don't like the whole Skynet Terminator part of this, which is that the drones are able to find that human and then kill them.

    Think of a simple scenario where there is, let's say there's a war going on. Let's use the worst-case scenario and, enemy troops are located approximately here. You send the drones out, and the drone has, of course, GPS built into it, or some other inertial guidance system or something in case GPS gets jammed.

    That drone then goes to that area.

    It can recognize humans, and it says, Oh, there's a human, and it goes and kills the human. Now that human might be an innocent person. Look at all of the problems we've had with our aerial drones, the manually controlled ones, just the ones that we've been using in the last 10 years where we say, okay, there's a terrorist here. Now they fly it in from. They've got somebody controlling it in Nevada or wherever it might be, and they get their strike orders and their kill orders. They go in, and they'd take it out. There are collateral damages. Now that's always been true.

    Every war.

    Look at Jimmy Stewart. For example, younger kids probably don't know who it is. Mr. Smith Goes to Washington was one of his movies.  He had some great Christmas movies and stuff too. Anyhow, Jimmy Stewart was a bomber. I think he was a pilot actually in World War II.  He flew combat missions over Germany. Think of what we did in Germany, in Japan, where we killed thousands, tens of thousands, hundreds, probably of thousands of civilians.

    We now think, Oh, we're much better than that. We don't do that anymore. We're careful about civilian casualties. Sometimes to the point where some of our people end up getting in harm's way and killed.  For the most part, we try and keep it down.

    A drone like this that goes into an area, even if it's a confined area, and we say, kill any humans in this area, there are going to be innocent casualties.  It might even be "friendly fire." You might even be taking out some of your own people.

    They've said, okay, we've got a way around this. What we're going to do is we're going to use artificial intelligence. The drone doesn't just pick out, Oh, this is a human. I'm going to attack that person. It looks at the uniform. It looks at the helmet.  It determines which side they're on.  If they're wearing an American or Chinese uniform, whatever, it might be programmed for it again. It goes into the area, it finds a human and identifies them as the enemy. Then it goes in and hits them and blows up, killing that person. That's one way that they are looking to use drones.

    The other way is pretty scary. It's, you can defend yourself against a drone, like that. You've got a drone coming. You're probably going to be able to hear it. Obviously, it depends. That drone gets close. I don't know if you've ever had the kids playing with drones, flying them around you, or you've done the same thing. You can always hit it out of the air, can't you?

    If you're military and you have a rifle in your arm, you can just use the rifle and play a little baseball with that drone. There's some interesting stories of people who've been doing that already.

    What happens if we're not talking about a drone, we're talking about a drone swarm. I don't know that you could defend against something like that. There have been studies that have been done. So think, you think there nobody's really working this suit? No, they sure are.

    What's going to happen? Well, the Indian army is one that has admitted to doing tests, and they had a swarm of 75 drones. If you have 75 drones coming after you, let's say you're a high-value target. There is no way you're going to be able to defend yourself against them unless you can duck and cover, and they can't get anywhere near you with their high explosives. The Indian army had these Kamikaze-attack drones. They don't necessarily have to even have high explosives on them.

    This is a new interpretation under Joseph Biden. Mr. President of the Pentagon's rules of use of autonomous weapons. We've always had to have "meaningful human control." That's the wording that the Pentagon uses meaningful human control over any lethal system. Now that could be in a supervisory role rather than direct control. So they call it "human on the loop" rather than "human in the loop." But this is very difficult to fight against.

    The US army is spending now billions of dollars on new air defense vehicles. These air defense vehicles have cannons, two types of missiles, jammers.  They're also looking at lasers and interceptor drones, so they can use the right weapon against the right target at the right time.

    That's going to be absolutely vital here because it's so cheap to use a drone. Look what happened. What was a year plus ago now? I'm trying to remember, Central America, Venezuela, somewhere in there where El Presidente for life was up giving a speech. I'm sorry. I didn't mean that to be insulting, but that often is what ends up happening. A drone comes up, and everybody's thinking: Oh, it's a camera drone, wave to the camera thing. It got very close to the President and then blew up. On purpose, right? They were trying to murder the president. That's a bad thing. He was okay. I guess some of the people got minor injuries, relatively speaking.

    When we're looking at having large numbers of incoming threats, not just one drone, but many drones, many of those drones may be decoys.

    How cheap is it to buy one of these drones? Just like the ones that were used in China over the Olympic stadium, where they were all controlled by a computer. You just have these things, decoys. All you need is a few of them that can blow up and kill the people you want to kill very concerning if you ask me.

    We're paying attention to this, as are other countries as they're going forward.

    We're going to talk about building your privacy risk tolerance profile because if you're going to defend yourself, you have to know what you're going to defend against and how much defense do you need?

    Hey, we take risks every day. We take risks when we're going online. But we're still getting out of bed. We're still going into the bathroom. We're still driving cars. How about your online privacy risk tolerance? What is it?

    Hi everybody. Thanks for joining me.

    We all take risks, and it's just part of life. You breathe in air, which you need. You're taking the risk of catching a cold or the flu, or maybe of having some toxic material inhaled. We just don't know, do we?

    Well, on any given day, when we go online, we're also facing risks. And the biggest question I have with clients when I'm bringing businesses on or high-value individuals who need to protect themselves and their information is: okay... what information do you have that you want to try and protect? And what is your personal privacy risk tolerance? So we build a bit of her profile from that, and you guys are going to get the advantage of doing that right now without having to pay me, my team. How's that for simple?

    First of all, we got to understand that nothing is ever completely safe. When you're going online, you are facing real risks, and no matter what people tell you, there is no way to be a hundred percent sure that your data is going to be safe online or that your individual personal, private information is going to be safe while you're online. And there's a few reasons for this.

    The most obvious one, and the one we think about, I think the most has to do with advertising. There are a lot of marketers out there that want to send a message to us at exactly the right time. The right message, too, obviously? So how can they do that? They do that by tracking you via Google. So Google that's their whole business model to know everything they can about you and then sell that information.

    Facebook, same thing. Both of those companies are trying to gather your information. They're doing it when you are not just on their sites, but when you are on other people's sites. Third-party sites are tracking you. In fact, if you go to my website @ craigpeterson.com, you'll see that I do set a Facebook cookie. So I know that you're on Facebook and you visited my site, and you might be interested in this or that.

    Now I'm not a good marketer. Because I'm not using that information for anything, at least not right now, hopefully in the future, we'll start to do some stuff. But that's what they're doing. And the reason why I don't think it's a terrible thing don't know about you.

    I don't think it's bad that they know that I'm trying to go ahead and buy a car right now. Because if I'm trying to buy a car, I want advertisements about cars and I don't want to advertisements about the latest Bugatti or Ferrari, whatever it might be. I want a Ford truck, right? Just simple something I can haul stuff around. You already know I have a small farm, and I need a truck because you need one. I'd love to have a front loader and everything too. Those costs money, and I ain't got it. So that makes sense to me.

    And now there's the other side, which is the criminal side. And then there's really a third side, which is the government side.

    So let's go with the government side here. In the United States, our government is not supposed to track us. Now I say "supposed to," because we have found out through Edward Snowden and many other means that they have been tracking us against the law. And then they put in some laws to let them do some of it, but our government has been tracking us.

    And one of the ways it tracks us is through the "five eyes" program, and now that's been expanded and then expanded again. But the five eyes program is where the United States asks the United Kingdom. Hey, listen. Hey bro. Hey, we can't, and we're not allowed to track our citizens, but you not us.  How about we have you track Trump and his team? Yeah, that's what we'll do.

    So there's an example of what evidence is showing has happened. So they go to a third-party country that's part of this agreement,d where all of these countries have gotten together, how signed papers and said, yeah, we'll track each other citizens for each other.

    And that way, the United States could say, Hey, we're not tracking you. And yet they're tracking because they're going to a third-party country. And the United States, if you are going out of the country, then again, they can track you. Any communications are going out of the country. So that's the government side.

    And then, of course, there's governments that track everything. You look at China and how they control all of the media. They control all of the social networking sites. They basically control everything out there.

    We have to be careful with all of that stuff because it can and will be used. And we've seen it has been used to really not just harass people, but do things like throwing them in prison disappear them. Look at what just happened in China, with the head of China's biggest company, basically the Amazon competitor over there. And he disappeared for months and then came back, just praising the Chinese Communist government and how great it is to have all of these people over there. Just telling them what to do and how to do it.

    We obviously don't live in China. We obviously, I think, have oligarchs nowadays. We have people who are rich, who are running the country. They're giving money to campaigns. They get the ear. You have seen all of the bribery allegations against the Biden crime family, or his brother, his son, other members, himself as well, based on a hundred Biden's laptop.

    So I don't trust the government for those very reasons.

    The hackers, let's get into the hackers here. When it comes to hackers, there are, again, a few different types. You've got hackers that are working for governments. And what they're doing is in the case of a small government, like North Korea, they're trying to get their hands on foreign currencies so that they can use those currencies to buy grain, to buy oil, coal, whatever it is they might need to buy.

    You have governments like China and Russia that are trying to basically run World War three. And they're out there with their hacking teams and groups and trying to figure out how do we get into the critical infrastructure in the United States? Okay. So this is how we get in. Okay. We're in over there. So if we ever want to shut down all of the power to New York City, this is what we do.

    Now, remember, that's what happened back in, in when was that 2004, I guess that was, yeah. I remember I was down in, I was heading actually to New York City and then all of a sudden, all of the power went out.

    That apparently was an accident, but it didn't need to be an accident. There are all kinds of allegations about what actually happened there. But that's why China and Russia are trying to get into our systems. And then they obviously want to play havoc. Look at the havoc that was caused in the US economy by this China virus that came obviously from China for Huan. If they wanted to shut down our economy, they now have proof that's all it takes. And they are working on the genetics of some of these viruses over there in China. And they're trying to modify the genes, and they are running experiments on their troops to enhance them, to make these super soldiers that maybe, need less sleep or less food are stronger or et cetera, et cetera, they are doing that.

    So China is a real threat in just a number of different ways. What would it be like if they could shut down our banking system or make it, so we don't trust it anymore?

    Okay. That's part one of your Personal Privacy Risk Tolerance Profile. Stick around because we're going to talk more about this and what you can do to help you have privacy.

    What is your online personal privacy risk tolerance? It's going to vary. I help high-value individuals. I help businesses with this, and now I'm helping you as well. So let's get into part two.

    Craig Peterson here.

    When people ask me, what should I do? That is a very nuanced question. At least it's very nuanced to answer because you could say something like: if you want to be private, use Signal for messaging and use Tor for web browsing, that's fine. And it works in some ways and not in others. For instance, Tor is a web browser that is like a super VPN.  It is set up so that you're not just coming from one exit point, you're coming from a whole bunch of different points on the internet. So it's hard to track you down. The problem, however, with Tor is the same problem that you have with VPN services. And I talk about this all the time.

    VPN services do not make your data secure. It does not keep it private. And in the case of VPN services that you might get for free or even buy, and also the case with Tor. Using those VPN services that can make you less secure again. Why did Sutton rob banks? He robbed banks because that's where the money was, where he is a bad guy going to go. If they want easy and quick access to lots of peoples. Private information?

    They're going to hack a VPN server aren't they? Yeah. And if they can't hack the VPN server, why not just have server space in the same data center that VPN provider is renting their space from and then hack it from there, try and get in from there. Or maybe get into the service; the data centers will logs or the VPN servers logs, because even when they say they don't log, they all log, they have to log, they have to have your information otherwise, how can they bill you? And the ones that say we don't log, which are those people are "lieing" by the way. But those guys that have these VPN servers and they're trying not to log, they're trying not to log where you're going. They get fooled all of the time as well. Because their servers have logs, even if they're deleted and disappear.

    So I just wanted to make it clear that you, I, if you have a low risk tolerance, when it comes to your privacy, Tor is not going to do it for you. VPN services are not going to do it for you. You have to look at all of the individual things you're doing online and then decide based on those. What is it that is the most. Beneficial for you in that particular case. Okay.

    So Signal, I brought it up. So let's talk about it for a minute. Signal is the messaging app to use bar none. Signal is encrypted and do, and it is known to be highly secure, which again, Doesn't mean it's a hundred percent, but with Signal, you can talk to people on other platforms. You can have a Mac and talk to somebody on a, on an Android or a windows device.

    But another consideration is who are you talking to? If you're talking to other people that have Macs and you don't want your information to get out, but you're not horrifically worried about it, right? You want it to be private. You want end to end encryption. You're better off using iMessage on your Mac.

    If you're on Windows or Android, there are not any great built-in messaging apps. WhatsApp. If you listened last week and I've got it up on my website, WhatsApp is not great. They claim it's not horrible, but why would you use it if there's a question use Signal instead.

    All right. So there's just a lot to consider when we're talking about it, but here is your big bang for the buck thing. That you can do. And that is use password manager. Now we talked about how Google Chromium Google's Chrome and of course now Microsoft edge. Actually it was the other way around Microsoft edge came up with it first and now Google's adding it.

    But Edge has this password manager built-in. That's all well and good, but I don't know, trust those. I use a third party password manager that is designed for password management and that's all the company does. They're focused on the security behind it, which is why I recommend 1Password and lLastPass. 1Password being my absolute favorite. Use those password managers. That's the biggest bang for your buck if you have a low tolerance for your information, getting out. All right?

    Now that will help to enforce good password habits. It will generate passwords for you, both of those, and it'll generate good passwords and it'll keep them for you, which is really great.

    If you don't want to be tracked while you're browsing online, you can use an ad blocker. I have a couple of webinars I've done on that. If you want a video of one of those webinars to go through that talks about these different blockers ad blockers and others. I'd be glad to send you a link to one of them, but you're going to have to email [email protected].

    And I will send you a link to one of those webinars I did on that stuff. No problem. But some websites are going to break when you use an ad blocker. So sometimes you have to turn it off and you have to turn it back on. The ones I tell you  how to use and how to configure, I actually show you a step-by-step we walked through it. Those allow you to turn off that particular ad blocker on an individual site that was broken because of the ad blocker. So pretty straightforward. You don't have to remember to turn it all on and all off. All right.

    Now studies are showing that people are concerned about their privacy. In fact, I believe last I saw said that I think it was about 70% of Americans believe that their smart phones are being tracked by advertisers, and the tech companies provide them with the information.  May, 2020 Pew research report talked about this, but 85% of consumers worry, they can trust corporations with their data. So what do you do? Because. Most people don't have the support or the tools. They don't have. I have the money, they didn't get a big inheritance. They're not a high value individual that needs my help and can afford it -- where we go through everything that they do and make sure they have the best solution for each thing, including banking, including going online and trading stocks, all of that stuff.

    You gotta be very careful with all of that stuff.  I'm really sad that I have to say this here, but there are no online privacy solutions that will work for everybody. And there are no solutions that work in every situation either.

    So what you need to do is understand what you care the most about. And I think for all of us, what we should care the most about is our financial situation and anything associated with that: our intellectual property, if we're businesses, our bank accounts, all of that sort of stuff is stuff we really should be concerned about. And that means you need to watch it. Make sure you're not sharing stuff that you really don't want to share.

    Okay?

    So even privacy experts like myself, don't lock everything down. We locked most of it down. Particularly since we have department of defense clients, we have to maintain a very high standard.

    All right. Stick around and visit me online. CraigPeterson.com. Make sure you sign up for my newsletter.

    You'll get all of the latest news and the tips I send out every week.

    I don't want to leave you hanging. We're going to get into a few more things to consider here, because obviously we are going to share some of our personal information. So I'm going to tell you how I share my personal information and it might be a bit of a surprise.

    Hello everybody. Thanks for listening.

    We all enjoy products and services, and that's what I'm saying. When when I talk about security experts, we don't lock everything down. I've used 23 in me. I did that thing, of course, I'm sending in my DNA. That's been an issue in some cases, but that's what I did.

    I use these online map programs. I use Google maps. I use weighs more than Google maps. I use Apple maps cause I'm trying to figure out how do I get to where I want to go in a reasonable amount of time. But what I do is I lie about the answer to the security questions. Okay. I don't want them to know my dad's name.

    My mother's maiden name, the street. I was, I grew up on my first school, my first car, none of their business. Because it's a lot of that information is actually publicly available. How many of us on LinkedIn have right there in our profile? Yeah I went to McGill university or I w I grew up here's pictures of my childhood home, and that picture has GPS coordinates in it.

    So if we use the real information. We are giving away way too much. I use a little phrase I coined here, which is lie to your bank. And you might remember. I did a show on that sometime ago. And the idea here is in your line to the bank about your financial situation, it's nothing like that. You're lying to your bank about this personal information.

    They don't need to know these personal questions. They give you for their security questions. It's really important to understand all of this stuff. Okay. For instance, this is Jennifer Granick, she's at the ACL, you and she said her dad died recently. And the accountant said it's really important to report the death to credit companies because the answers to many of the security questions are on the public death certificate.

    So answers to security questions really can be a nightmare, but that doesn't mean you have to give them the right answers. So for instance, I found a site online. I should try and dig that up again, but it generated fake identities. And I had a generate like 5,000 of them for me thinking, okay, they might go at some point and it even generated fake social security numbers, fake phone numbers, names, addresses, everything, everything you'd need for a fake identity. And the idea here isn't to cheat anybody out of anything. The idea is, Hey, Mr. Website, you don't know, you don't need to know who I really am. So on some websites, I'm female some websites I've, I'm only 30 years old on other websites. I'm 80 years old. It doesn't matter.

    You can call it a lie if you want. But in reality, you're just trying to keep your information straight not and another advantage. Of these password managers. Cause you're trying to keep your information straight, right? It's hard to remember a lie and you have to tell a lie to enforce a lie. You're not, all that stuff your mother told you.

    And she's right about that too, by the way. But if you're using a password manager, what I do is I create a unique email address. In fact, my email addresses are extremely unique, so I'll use a plus sign as part of my email address and my mail server knows. Oh, okay. That's just Craig trying to track who is using.

    That email address. So I'll have Craig plus YouTube for instance, [email protected]. I actually have a whole bunch of domains that I use as well. And if you want a secure email service have look at proton mail. They're actually very good from a security standpoint. So there's nothing illegal about giving them this information.

    Yeah. You're lying to them, but you gotta keep your lies straight. Another reason to use a password manager because I have the password manager generate my. My password I put in the email, which is unique for every website I go to, I never use that same email address twice if I can avoid it. And then I, and I use aliases too in my email server.

    And then I go and in my notes section for that website in my password manager, I put in the answers to the security questions and I just make stuff up nonsensical stuff. So it's asking what my first car, it might be a transformational snooze. There you go. I just made something up. So I'll put those notes into my notes in my password manager and save them.

    So if I ever have to do some sort of a recovery with those guys, it's going to be simple. Because I just look in my password manager, I got to go in there anyways to get my password right. And my email address or username to login. And there it is, there's my security questions. And then the password manager, cause I'm using one password.

    It has a little database, it keeps and everything in there is encrypted. And the only way to decrypted is with my password, my one password, that's it. You only have to remember one password and that's the password to one password so that you can decrypt that little vault of a database of all of your information.

    So I have, I bought a, I think it's a 30 plus character password I use for one password because yeah, I'm a little bit paranoid about all that sort of stuff. So that's a really good way to be able to keep your information safe. I talked last week about a friend of mine. Whose wife went on Facebook to get some help, some tips on selling her investments investment anyways, and the disaster.

    That was okay. So a lot of people have regrets about what they've posted on Facebook, and there's a really cool thing out of CMU. Carnegie Mellon university, where these, how many, it's six guys and gals. They put together this special report. I regretted the minute I pressed share a qualitative study of regrets on Facebook.

    Very interesting. So they looked at all of this stuff as best they possibly could. And what did they find? Some examples, just think for yourself what regrets you might have. I know friends of mine in the grads that they have had. But there are a lot, so they go through privacy risk. I can send you a copy of this article if you're interested.

    It talks about their methodology. They analyze comments on the New York times website and others Craig's list to regroup people. They, so they've got all of the stuff. Here you go sensitive content. Number one. So alcohol and illegal drug use. Think about that. Think about your employer, your next employer or the police.

    They got a report on you. Oh my, this is a bad person. So they go onto your Facebook page and they find. Oh, photos posted from a party with some very non unflattering photos in it. And even maybe mentioning a illegal drug use, what it thinks is going to happen. How about if you get stopped at the border coming back from Canada, Mexico, Europe.

    And they decide to do a little deeper look into you and they find this stuff online. The next one sexual content, you can imagine what that is. Think of a Congressman from New York, in fact, religion and politics apparently is one of the things people have regretted posting online, profanity and obscenities, personal and family issues.

    Working company here, negative or offensive comments it's arguments, lies and secrets, venting frustration, good intentions intended purposes. I didn't think about it. Hot. State. Yeah. Oh, my this thing just goes on and on, but keep all of this in mind, when you are trying to keep your information private, whether you are a business or an individual, you have to have eternal vigilant watch when your emotions are high, right.

    It's like drunk dialing. Don't do it. Or your emotions are high. Something's been going on. Don't put it online. So that's I think a real good bottom line about your. Personal privacy, risk tolerance profile. Okay. Be very careful. , don't put stuff that you don't want other people to see. It's not true that once it's out on the internet, it's there forever.

    It's not true that once you've posted it, it's there for anyone to discover. None of that's true. Not at all. Okay. But be very careful cover up your laptop cameras. In fact, in the improving windows security course, I go into this in quite a bit of detail, what you can do, what kind of cameras you can and should use, what sort of microphones you can or should use.

    Many people just cover up the laptop cameras with the sticky note. When they're not using it disable automatic image loading in your mail program. That's important. I do that as well, because that image that's in the email is usually being used to track you. It's really that simple. You've got new privacy laws in many States and in Europe, they are really not going to work or help you with your privacy, except with the really big companies out there.

    So keep all of that in mind. All right, everybody.  I want to encourage you go to Craig peterson.com. You'll see all kinds of great information there. You're going to be able to also listen to my whole show, pick up all the little training tips and even find out about the courses that I'm offering. Craig peterson.com

    I guess this is a little bit of good news. If you're a home user, not a business or some other organization, like a state or County or city office, but we've got some breach numbers that have just come out for 2020. We're going to talk about right now.

    Hi, everybody. Thanks for joining me.  Of course you can always go to my website. Yeah. Pick up all of the podcast in case you missed something today or another week, you'll find them right [email protected]. You can also sign up for my email list and we're going to be doing a couple of different things here.

    I think in the near future, we're going to be sending out some reports that we made as part of the security summer thing I did a couple of years ago and each one of these reports and there's 30 something of them. Some of them are like five to seven pages long, but it's checklists of all the security things you should be worrying about.

    Now, if you are home user, you'll find a lot of these to be interesting. But if you're a business person, you work in an office, you help to run an office. You own a business. You need to make sure you get all of them. So make sure you are signed up Craig peterson.com and we'll be glad to get those out too.

    Plus we're also going to start something new every week. I usually have six to eight, sometimes as many as 10 articles in the week. I spend hours going through finding what I think are the most important things that interest me as well, but that I think will interest you guys.

    I put them in an email, it is it's not very long, but it's just a few sentences from each one of the stories and I have a link to the story as well, right there.  I'm going to start sending that out as well to everybody cause some people want my actual show notes.

    We're going to have the newsletter once a week. Then we're also planning on having a little video training as well. So it might just be straight, like straight audio. That's part of a video, but it'll be training on a specific security task or problem that's out there.  Then the course improving windows security.

    It's been taking us a long time. Blame it, mostly on me. Karen's also busy with babysitting grandkids at least a couple of days a week, and I'm trying to run a company as well. So it's, forgive us, but it is taking some time, but you're going to love this. I think it's turning out really well.

    I am about halfway done with the final edits. So I'm recording them. We go back and forth. They ended up recording them twice so that we get all of the points I wanted to cover into them. Karen's come up with a whole bunch of great screenshots and other pictures to go in with it so it's not one of these death by PowerPoint things.

    And we've got 21 different talks, if you will, on locking down windows and I go into the why's as well as the hows. I think that's really important, because if you don't understand why you're doing something. You're much less likely to do it. I picked that up from Mr. Tony Robbins, none other, the Anthony Robbins man.

    It's been over 20 years. Karen and I went to an event he had down in Boston and this was one of his firewalk or events.  We actually got to walk on hot coals it was the weirdess thing ever. Karen was totally freaking out and I was just, wow, this is going to be weird, but we both did it. It was phenomenal. Cause it of gave you an idea of, even if you have this mental block that you can't do something you probably can. We actually did and nobody's feet were burned or anything. It was real coals. It was real hot. They were really red. It was really something that at the very end they had a grass, a little square. Grass, maybe two, three feet by three feet and they had a hose running onto it. So you'd walk over it all. Then you'd just walk in on the grass and the idea there being, if you had any hot coals stuck to your foot. You probably didn't want those just stay on your foot. You'd probably want those, they get put out and taken off, so that's where that did.

    Anyhow. One of the things I learned from Tony was you need to have a strong reason why. We see this all of the time, Stephen Covey, if you read his stuff, you know it as well, you got to know why you're doing something. When it comes to computers and technology and security, you need to understand the why. Because it isn't just a rote thing. There are so many variations on what to do, but if you understand the why you're doing it, then I think it opens up a whole new world. You can explain it to your friends. You can help them understand it because finally you will understand it.  You'll be more motivated to do the things that you should be doing because you know why you're doing them, what it involves, what it's going to solve for you.

    This should be a really great course. And I spent some time in it going through the whys, give you some examples of problems people have had and what that solves.

    It's available hopefully here within a couple of weeks, man. I thought I'd be done by the end of January and here it's looking like it'll be the end of February. But be that as it may, keep your eyes out. If you've already emailed me to let me know, you're interested. That's great. I've got you on a list. I'll have to try and send out an email this week or sometime soon to let you guys know about it that we've got it ready for you?  We will have already for you, hopefully with the next couple of weeks.

    So that's that I'm told different way of doing things that's me. I like explaining things I've been told I'm good at it. So let's I think a good thing too.

    I started out the segment by talking about this probably good news for end users. Because in 2020 breaches were down by 19% while the impact of those breaches fell by nearly two thirds when we're measuring it by the number of people affected.

    Now, of course, if a company is breached and organization is breached, it's counted as one. One person, if you will affected, obviously it can affect a hundreds of thousands, millions of people, depending on what happens like a breach of Equifax. Are you counting that as one or you counting that as 300 million?

    Because that's how many records were stolen? I'm not sure it doesn't say it doesn't go into that much detail, but because the number of data breaches went down and the number of individuals affected by the data breach is plummeted. It's telling us something, then that is okay. That these hackers have moved away from collecting massive amounts of information and are targeting user credentials as a way to get into corporate networks to install ransomware.

    We've got even more news out this week about the solar winds hack. We talked about this before, and this is a company that makes software that's supposed to help manage networks, which means it's supposed to help make those networks safer. No, as it turns out, they weren't making it safer and it looks like maybe four years bad guys were in these networks that.

    We're being managed by solar winds, not with software, right? It's not as though solar winds was managing the network is solar winds sold software services so that you could manage your own networks or in many of these cases, they were actually managing networks of third-party businesses. I do work as well for high valued in value individuals, people who have a high profile that need to keep all of their data safe and they are constantly being gone after.

    They're trying to hack them all the time and the way they're trying to do it. And I talked about this really the first hour today is by this password stuffing thing. So they're trying to get in and they were successful and now it looks like it wasn't just Russia. Apparently China knew about this hack potential knew about this bug and was using it.

    And apparently it also was not. Just solar wind software. Now they're blaming some of this stuff on Microsoft office. If you have an office three 65 subscription, apparently they were using that to get in. So the bad guys are getting very selective. They want to go against companies and organizations like government agencies that have information there's really going to help them out.

    That is absolutely phenomenal. So these are stats from the identity theft resource center. And I was thumbing through as I was talking here. So it's saying that more than 300 million individuals were affected by data breaches in 2020, which means they must be counting the people whose.

    Information was stolen, not just the people that were hacked but it is a huge drop 66% over 2019. And the number of reported data breaches dropped to about 1100, which is about. 20% less than 2019. So it's good. It's bad. I think the mass data collection thing is over with now.

    They're not as interested in it, but they are very interested in strategic attacks as opposed to just these blanket. Let's grab as much data as we can because they want to get it into these government networks, which now we've, we know they've gotten into. And then you've got this double extortion thing going on with the ransomware, where again, the going after businesses and people who they know can pay.

    So that's good news for the rest of us, right? The home users. It's not good news so much for some of my clients, that's what we take care of. That's why we get paid the big bucks. Now how that works. Downright stick around. When we get back, we're going to be talking more about the news this week in particular, of course, security, Facebook and their Supreme court stick around.

    We'll be right back.

    The United States has a Supreme court. Our States each have their own Supreme courts. In fact, there's probably Supreme courts all over the world. But did you know that Facebook now has something that people are calling a Supreme court. This is interesting.

    Craig Peterson here. Thanks for joining me.

    I'm not sure if you've seen this or not, it's very small and it's designed to go into your car and then it will hook up like Bluetooth to your car. It'll use your phone for data. So the data is going back and forth from your phone over to them. They're a little device and that way you can talk to it and you can play music, whatever you'd like to listen to right there from your Alexa.

    People have been complaining about Facebook and what they've been doing for years. One of the things people have really been complaining about lately is how Facebook has been censoring people, particularly according to them anyways, conservatives.  I've certainly seen evidence of that. No question don't get me wrong, but there's also left-wingers who are complaining about being censored.

    Facebook decided it needed to have its kind of its own version of Supreme court. You see what happened? Bins is you have a post on Facebook that is questioned. And usually what has to happen is somebody reports it to Facebook as being off color or whatever it is, the reporting it as. And if two or three people report it, then it goes to the moderators.

    That same thing is true for some of the artificial intelligence. Some of it's reviewed by moderators as well. Here's your problem. Particularly when it comes to conservatives because you post something conservative on Facebook. And if you are noticed by some of these liberal hacks that are watching Facebook accounts, they will gang up on you.

    And they use these bots to pretend that there is incredible. Rage that there are hundreds of people who are very upset by what you just had on Facebook. When in reality, no, one's upset and they're just trying to shut you down. And there might only be two or three people who actually know about it, but they'll use these kind of artificial intelligence, bots to flood Facebook with complaints.

    And they're doing that on Twitter. The left is doing it all over the place. So what happens next? The big challenge for Facebook is there are 2.7 billion users. Can you even wrap your head around a number like that? That is just massive. So they've got 2.7 billion users, and now, obviously not everybody's on every day.

    But some percentage of them. And I've seen it's in the hundreds of millions posts every day on Facebook and they log in and look around. Facebook only has 15,000 moderators. So for 2.7 billion people, 15,000 moderators just isn't a lot. And the other problem is that the moderators are suing Facebook.

    And they came up. This was about a year ago. With a $52 million settlement with moderators and the moderators are saying, Hey, first of all, we're crazy overworked. And then secondarily, we've got PTSD. Post-traumatic stress disorder. And they're saying that they have this because of the stuff that they've had to see, they alleged that reviewing violent and graphic images, sometimes stuff.

    My gosh, I might've gotten mentioned here on the air, but they had to view these. For Facebook. And they said, this just led us to PTSD. I can see that particularly since they have to have so many every day. So many of these different posts that they have to look at. And they are clocked and they are third-party contractors.

    They're just, all this stuff adds up. Doesn't it? Moderators who worked in California, Arizona, Texas, and Florida from 2015 until last year, every moderator will receive a minimum of a thousand dollars as well as additional funds if they are diagnosed with PTSD or related conditions. So they're saying there's about 11,000 moderators that were eligible for this compensation.

    But this is a very big deal. It's difficult. How do you deal with that? They've got now 15,000 moderators who are reviewing the posts of these 2.7 billion users. There is a little bit of an escalation procedure, although it's a very difficult and because there are so many people who are. Complaining and trying to take care of everything.

    It is a very tough situation, really for everybody involved. So they've decided what Facebook needs Facebook's decided this themselves is they've got to moderate themselves a little bit better, and the way they are going to do all of this moderation is they're going to have this kind of Supreme court that supervises.

    All of the moderation going on within Facebook. So they call him the new to an oversight board and. Obviously with just one board, without very many people on it, it is only going to be able to handle a small number of cases. So they have been paying attention to some of the cases. And they're trying to set precedents that will be followed by the moderators and millions of other cases.

    It's basically the same thing that the U S Supreme court does, where they review cases that come up from the federal district court. They can have cases that are coming up from individual States as well. And then they set standards and, without going into all of the detail of disputes between district courts, et cetera, we'll see what happens in Facebook, but lower courts are treating these us Supreme court.

    Rulings and dicta as binding precedents for everything in the future. So it's not easy to do in our courts. We're certainly not great at it. And there are a lot of complex procedures. And even if you're talking about moderation where you bring a moderator in. And there are some standards for that in disputes between businesses where you'll pull in a neutral third party.

    And they'll just usually split things down the middle. But those are going to be difficult for Facebook to put in how they reviewed five decisions. These are pretty substantive. Sixth case apparently became moot after the user deleted the post.

    We have an uprising and Miramar right now. You might've seen it on TV. If you're paying attention. I know a couple of channels have been talking about it. But this is an interesting problem because the military has overthrown the potentially properly democratically elected government.

    What do you do if there is massive cheating going on in the election? We faced that question here ourselves.

    In Miramar, they went ahead and the military took over and imprisoned the president. There was a post talking about that and talking about Muslims in France and China.

    Another one about Azerbaijanis. I don't know if you've seen what happened with Armenia and Azerbaijan and lots of history going back there with the Soviets and they created this whole problem because they didn't like the Armenians, but anyways, of all of these five, they disagreed with the lower moderators opinions and they overturned them. I think it's really good.

    I looked at these cases and I was shocked. I think they're doing the right thing here. Isn't that weird?

    Hey, you're listening to Craig Peterson right here on news radio.

    Visit me online craig peterson.com.

    Hey, did you know, there is a war, if you will, between Facebook and Apple? It is getting nasty. What's going on over there. That's what we're going to talk about right now. Your privacy, Facebook, Apple, and Android.

    Craig Peterson here. Thanks for joining me. My golly. You know what I think about Facebook when it comes to privacy, right? Facebook and Google. I think Facebook is worse than Google, frankly. They just don't respect your privacy. They will go ahead and look at anything that they can get their hands on.

    We'll at that point, just go ahead and pull it together and sell it to anybody that's willing to pay. I am not fond of that. And I think you can probably guess why, and I doubt your fond of that at as well. You're not fond of that either. Apple did something. If that has really upset.

    Facebook and Zuckerberg has been making a lot of noise about this, but Apple announced plans about a week ago to finally roll out a change that they were putting into place in iOS 14, which is the operating system for the iPhones and iPads that Apple has. They had announced that they were going to add it the late last year.

    And there was huge pushback from Facebook and a few others as well. What's going on here? Bottom line is that Apple is trying to force. Apps to be transparent. What privacy do you have? What data are they taking? And in the case of iOS, as well as Android and windows and Macs, there has been the ability for certain applications to be able to look at other apps that are on the device.

    And by doing that, it can get data from it. They can figure out who you are. They can give a unique fingerprint based on what apps you have and what versions they are. They're pretty clever what they've been doing in order to harvest your information. Now you might have noticed if you go in.

    To the app store that there's been actually a big change already. This is the Apple app store. If you go in there and you pull up an app, any app, so let's pull up Facebook and then in the app store, and then you click, obviously on Facebook, you scroll down the app store page about Facebook. And partway down, it already has privacy information.

    You want to click on more info project early if it's Facebook, because it doesn't fit on that homepage for the Facebook app. And it will tell you everything. Everything that Facebook wants access to. Now, some of it's self-reported by the app developers. Some of it is stuff that happened. Figure it out either electronically or by getting people involved.

    I would like to think that when it comes to something as big as Facebook, they really are going that extra mile. And making sure that yes, indeed, this information is valid, it is what it is. They may not, and I'm not quite sure, but look at all of the stuff Facebook is gaining access to with you.

    So that was a bit of a hit people were pretty excited. Oh, wow. This is great. And although Google doesn't do what we're talking about here quite yet, I'm sure they will be not in the way that Apple is doing it, but because remember Google makes money off of you and your information, Facebook makes money off of you and your information.

    So if you want privacy, you cannot use Google products like Android or. Chrome. And if you want privacy, you can't use Facebook. So it's as simple as that. Of course, the big question, and we talked about this earlier in the show is how much privacy can you expect? How much do you want? What's legitimate, right?

    All of those types of questions. So what Apple's doing now is they said that in early spring of 2021, they are going to release this new version of iOS. And here's what happens. They've added something and this is according to a white paper and Q and a that Apple sent out. They added something called app tracking transparency, and this is going to require apps to get the user's permission before tracking their data across apps or websites owned by other companies.

    Under settings user will be able to see which apps have requested permission to track so they can make changes. As they see fit. You might have noticed that already under settings, like you can look at the microphone settings, it'll tell you. Okay. Here's the apps that I have asked about microphone and you can turn them off.

    Here's the apps that have asked about the camera. You can turn them off. So they're adding more functionality. They also, in the FAQ, they said that app developers will not be able to require users to allow tracking in order for those users to gain access to the full capabilities of the app. Now, you know how I've talked before extensively about how, if it's free your, the product.

    So what Apple is doing is they're saying, Hey guys if the user says, no, you can't try it. Track me across apps. No, you can't get it. This privacy information, which Apple's letting you do, they cannot Labatt automize. The app is what it comes right down to. So it was in September last year that they first said they were going to do that.

    Then they delayed the implementation of this tracking policy. So the businesses and app developers could get more time to figure this out. One of the things that I think is fascinating here is what Facebook's doing with fighting back. Oh, and by the way, Apple has not just gotten complaints from Facebook.

    There are other marketers and tech companies that frankly it makes Apple more vulnerable to some of these antitrust investigations that have been. Started really against some of these big tech companies. Although, I don't really expect much to happen under the current administration in Washington because frankly, big companies love big regulations.

    Because they can afford to comply with them, but startup little companies who are competitors of theirs cannot afford the lawyers for the paperwork and everything out. I look at the CMMC, we do a lot of work for DOD department of defense contractors, where we secure their networks. We secure their computers, we secure everything.

    We put it all together. And we also, for some of them there's guys, there's a 50, $50,000 upcharge for this. And that's because we're cheap. Believe it or not, it is a lot higher for other companies do it, but we do all of the paperwork, putting together all of the policies, all of the procedures, what they have and.

    Auditing everything for them. And we're talking about a case and a half of paper thinking of the big cases of paper, right? 500 sheets and the ream and how many reams in a box? 10 20. I'm not even sure, but literally cases. And we. Printed it up, we wrote it all up, printed it all up, delivered it to a client just a few weeks ago.

    And it was a huge box of three inch ring binders. It was all in and they didn't all fit in there. They're the big guys in the department of defense probably love this because they, they pay a million million bucks to the people, the generate the paperwork for them internally. And they know the little guys can't afford to have full-time paper pushers.

    And so that's why, even though we're talking about months worth of work, why we charge 50 grand, which is a heck of a lot cheaper, believe it or not. And it's a huge discount for us. So I don't expect that the fed you're going to come up with a solution. That's truly going to help the little guy here, but Apple's announcement praised by privacy advocate nonprofits as well.

    And Facebook apparently has been buying full page newspaper ads claiming it's going to hurt small businesses in a way it will cause it can make advertising. Just a little bit harder. And apparently also Facebook has decided to rewrite its apps. So no longer even requests to access, cross app access to your personal information.

    Welcome back. We're going to wrap up, talk a little bit about Comcast data cap, and some of these SolarWinds hack victims that didn't use SolarWinds, and ransomware payoffs have surged, even though the number of people affected has gone down.

    Make sure you get on my email list so that you get all of the important news. You're going to get some of this little training I'm doing and the courses that we've developed. The only way to do that is to go to Craig Peterson.com/subscribe. That's how you get on those lists and I'm not sitting there and pounding you or anything else, but I want to keep you informed. So there you go.

    We're probably going to increase our volume from one email a week to three, so that we can provide you with a little bit more training. I want to keep these down to something that just takes you a few minutes to go through, but could save you millions of your business and tens of thousands, your retirement, if you are a home user. So make sure you are on that list. Craigpeterson.com/subscribe.

    Comcast. I know many of us have Comcast, I certainly do, is imposing data caps on many people in many parts of the country. That includes people to the South here, Massachusetts residents.

    What do you think they're doing down there? The state lawmakers have proposed a ban on data caps, a ban on new fees, and a ban on price increases for home internet services.

    The idea from their standpoint is we have a lot of people who are working at home because of a lockdown. What are they supposed to be doing?

    I'll take my daughter, one of my daughters, as an example, she's working at home. She used to work in a call center she'd go in every day. Now she's working at home. Are they paying a wage differential for her? Are they paying for electric bill? They're not even paying for the phone bill or the phone. She has to provide her own phone. She takes inbound calls for a call center.

    Can you believe that? It's just amazing what's happened. The company is saving just a ton of money because people don't have to go into work. You can bet they're going to dispose of some of this space that they've been. What's happening here, we are using more bandwidth than we've ever used because more people are at home and it isn't all business related many are watching Netflix or you've got Netflix on in the background while you're working on stuff. It's just so common to do that.

    What data caps are doing is they say you can only use so much data a month. Then there's usually a penalty of some sort. In Comcast case, they said for the first quarter of 2021, I believe is what they had come up with. We'll just warn you that you go over your data cap then they'll charge extra. I have a friend who has Comcast and he said, I think it took him like three days before he went over the data cap. That's not long.  It's because they're streaming TV. They've got kids working from home.

    Then you've got meetings that they're going to, that are now streaming. So I can see this, but from Comcast side, they now have to handle more data than they've ever had to handle before.

    Because we are using it, like for my daughter, she actually has a cell phone, but all of the calls are routed over the internet. Cause her cell phone hooks up to the wifi in the house and the calls come in and go out via that wifi.  It goes through the internet, it goes to her phone carriers network. Then it goes to the call centers network. So there you go.

    What does that need? That needs to make sure there's no jitter. You don't want voice packets to be dropped because then it sounds terrible. It's very obvious when audio is dropped. I don't know if you've noticed if you're streaming something from one of these online streaming video services, but sometimes. It will hiccup a little bit, but have you noticed that with the smaller hiccups, the audio is fine and the problem is in the video. Now they do that for a couple of reasons, obviously video uses more bandwidth than audio uses, but the other reason is people tend to get more annoyed by audio fallout and audio problems.

    Comcast is saying, Hey guys, look at what we have to do with our networks. We have to expand them. We have to increase them.

    Now I've got to bring up again the Biden administration because of what they're planning on doing with this fairness doctrine on the internet. What they're planning on doing is saying, Hey, Comcast, just because this person uses five terabytes of data a month, you should not be charging them more than grandma that uses 10 gigabytes a month. Thousands of times more bandwidth requirement, you're not allowed to bill them differently. Cause a bit is a bit which is absolutely insane. I don't know how they can justify this sort of thing.

    So what's going to happen is you get companies like Comcast or other internet providers who are going to say. We are not going to invest any money into expanding our capacity because we can't charge for it. Doesn't that make sense to you? It makes perfect sense to me. By getting the FCC involved, it's just going to be crazy.

    Ajit Pi resigned when President Trump was leaving, he used to be the chairman. He actually had a head on his shoulders, but these new people President Biden put in there, it's insanity what they're trying to do with our networks. It's going to make it much worse.

    Comcast is putting data caps in. You hit the data cap it, they're just going to slow you way down. That happens too, with a lot of our cell phones, our cell phone carriers, if you use more data than they've allotted to you, they'll drop you back. So most people have 4g. Yeah. Okay. Your phone's 5g, but really guess what? You're not getting 5g. It's very rare unless you are on on the T-Mobile slash Sprint plan. T-Mobile more specifically because nobody else has the coverage that T-Mobile has for 5g.

    So you're using 4g LTE, you hit your data cap. They're going to drop you back to 3g, which is really slow comparing the two together, all the three of them, frankly, but it's very slow compared to a 4g LTE. In mass, by the way, I should mention Verizon files and RCN. Do not impose the data caps. It's just our friends at Comcast that are doing that Vargas and Rogers.

    They let a group of 71 different Massachusetts lawmakers who urged Comcast to halt the enforcement. By the way, the data cap is 1.2 terabytes per month, which is actually quite a bit of data. You'd have to spend a lot of time streaming TV. The cap does hurt low-income people is no question about it. If you are being forced to work from home because of the lockdown, government's forcing you to work from home. They put their fingers in anything, and that just never seems to work out anyhow. We'll see what happens down in mass with Comcast and these guys.

    Let's see here, SolarWinds hack.

    I mentioned this just in passing a little bit earlier in the show today, but CISA, which is the US cybersecurity and infrastructure agency said that nearly a third of the organizations that were attacked by these Russian and Chinese hackers had no direct connection to SolarWinds. Apparently many of the attacks got in by using password spraying to compromise individual email accounts at targeted organizations.

    There's your tie into Microsoft. Obviously major flaws in Microsoft's cloud services. Another one of the targets was CrowdStrike, which is another company that does security. They do remediation after the fact, as well, which we've had to do for many companies over the years too. We'll see, it looks like these Microsoft flaws may have been these bad guys first vector into some of these systems. That's pretty bad.

    Ransomware, things have changed because they figured out a better way to do it. Nowadays we're calling it a double extortion. Payments to ransomware gangs that are using cryptocurrency now, more than quadrupled in 2020. Isn't that something. Less than 200 cryptocurrency wallets received 80% of the funds. 80% of the payments went to 200 wallets, which may or may not represent individual ransomware gangs. It's just incredible. The payments using this cryptocurrency stuff, surged 311% last year, total volume $350 million.

    Cyber criminals are moving to cryptolocking is the easiest way to turn compromised computers into cash. Then the other thing that they're doing this double whammy is before they encrypt your files and then demand you pay up in order to get the encryption key or decryption key, they're double whamming. They're saying, Oh, Yeah, by the way, we grabbed a bunch of your files and if you don't want us to, and they'd try and figure out what's the most what's the best way for them to sneak the files out and then tell you which ones are the most valuable, right?

    They have people look at it, which is really bad. If you don't want us to release them out onto the open internet or onto the dark web, you have to pay us. They'll sometimes pretend they're a different company. That's where I was saying. When you look at the 200 different crypto wallets that are used, they will often go in, at first it'll look like a ransomware attack. People will pay the ransom, much less so in the United States than any other country. Then they will use a different crypto wallet, pretending they're somebody else saying, we have your files, you better pay up. Law enforcement, by the way, can target these deposit addresses here for the crypto wallets. They've done it before. We'll see what happens. About half of all of the funds went to 25 different crypto wallets. That's not a lot.

    Make sure you sign up. You'll be getting some of the new newsletter stuff. Some of the free training, the courses and other things. I'm really devoting myself here 2021's going to be the year that we really help you stop the bad guys.

    Take care and make sure you sign up @craigpeterson.com.

     

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553.

    1 hr 23 min
  • AS HEARD ON: WGAN Mornings News with Matt Gagnon: Swarms of Armed Drones, Ransomware, Autonomous Vehicles, and Amazon

    Good morning everybody!

    I was on WGAN this morning with Matt Gagnon. I started this morning talking about Drone swarms and how the military in different countries are considering using it, and the concerns about this technology. Then we talked about Hyundai and Apples' electric autonomous vehicles. We discussed the problem with Ransomware. Then we talked about Amazon and my thoughts on the transition. Here we go with Matt.

    And more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] We survived the nor'easter well, actually it came from the West. The big snowstorm, good news, maybe more snow on the way I use, shouldn't have been complaining about the fact that we didn't have much of a winter this year because it sure did hit us. Here, up in New Hampshire, we can get snow, even in early April, which is not something to look forward to. It does go away quickly if it comes at the time of year.

    Hey, I was on with Mr. Matt Gagnon this morning. He and I talked about a number of subjects, including what's going to happen with Jeff Bezos stepping down and on day-to-day operations over there at Amazon. So here we go.

    Matt Gagnon: [00:00:46] It's all things technology tech talk with Craig Peterson right now on News Radio 98.5 FM and AM 560 WGAN.

    Craig Peterson joins us on Wednesdays at this time to go over the world of technology, and today being no exception to that. We welcome Craig onto the program. How are you, sir?

    Craig Peterson: [00:01:06] Hey, good morning. Rowe, of course, one of the sponsors. They have the Hyundai dealership. Did you hear about it? Apple and the Hyundai actually they're Kia brand, and it looks like they might be coming out with one of these smart self-driving cars. Electric, of course.

    Matt Gagnon: [00:01:23] I did not see that. That's the future, though. Isn't it, right? We're going to be having 10, 20, 30 years from now. I'm not driving my car anymore. Am I right about that?

    Craig Peterson: [00:01:31] Yeah, I like that. I'll be old enough at that point that if I'm smart, I won't be driving myself.

    Matt Gagnon: [00:01:38] Take a nap behind the wheel. It'd be great.

    Craig Peterson: [00:01:40] Yeah, exactly. I'll be able to look between the dashboard and the steering wheel as I'm driving down the road.

    But yeah, and the new cars too, that have come out now from Tesla, they've got brand new models. They don't even have a steering wheel anymore. It's got a yoke. They almost like an airplane. I don't know if you've seen those too, but they're starting to really move fast. Although Tesla they're saying maybe not the winner that everyone's been predicting, they're so far ahead with some of these technologies.

    There's a lot of reasons they're concerned about the fact that they don't have LIDAR on the cars, which gives a really great view of what's ahead on the road. They're also looking at it saying you've got those cameras, isn't that wonderful, but when Ford and GM and. Hyundai Et cetera, et cetera, really go forward on this they say, they're just going to swamp, and Tesla is going to be left on the road behind them.

    Matt Gagnon: [00:02:41] We're speaking with Craig Peterson, the tech guru that joins us every Wednesday. You also hear him on Saturdays on this very network, doing a show where he goes into all of these stories in detail in depth here.

    Now I do want to touch on this one, which I find fascinating envisioning these swarms of drones and whether or not they're getting too fast now. And whether or not we're going to be able to deal with this whole swarm issue in the future. So what is a drone swarm, and how does this impact us?

    Craig Peterson: [00:03:07] You might've seen this at the Olympics over in China. Where they had the opening ceremonies and overhead, normally they're shooting up all kinds of fireworks, which they did do, of course, but they had all of a sudden this display in the sky. It was all of these drones, it was thousands of drones that were synchronously flying, and they had lights on them. So they could put up all this different optics, basically, almost like a screen, a computer screen in the sky.

    We've got these types of drones right now. They are used in these types of events, like the Olympics or big games like this weekend. I'm sure there'll be something going on, but there's another side of this.

    That's the darker side that you're referring to, which is you've got these drones. Now, a lot of these drones can fly by themselves without any human input or computer external computer input. They have cameras in them. Of course, we know that. We've seen all kinds of beautiful photos of the forest or cities from these drones with cameras, but they're building artificial intelligence into them now. Where concern really comes in is that this artificial intelligence is able to determine if someone is an enemy soldier or if their face matches someone that they want to attack.

    Now, it's one thing to have one little drone come after you, excuse me, with a small amount of high explosives, right? Because you can just bat it out of the way and get out of there.

    Where they're really concerned about is a swarm of like 75 drones coming at you, kamikaze style. The Indian army just generated this, and they're coming up with these thousand drones, strong little armies. If they're aiming at you, if they're coming for you and they have just a fraction less than an ounce of high explosive on them, there is no avoiding them.

    A US Navy has also looked at some of this. They've been demonstrated numerous times, and this is really scary. Especially the whole autonomous idea where they identify someone that might be a suspect, a terrorist, or whatever. Instead of bringing them in and having even a military trial. The drone recognized you, and they attack you and kill you right there. Even if it's not a battlefield,

    Matt Gagnon: [00:05:42] We're speaking with Craig Peterson, our tech guru here. He joins us every Wednesday at this time to talk a little bit about the world of technology.

    Ransomware payoffs are now surging and are nearing 350 million. From what I understand about these ransomware things and you've been talking about this for quite some time on this very program. Basically, companies are held hostage by ransomware, and people that are held hostage by ransomware essentially paying off the people holding them hostage. This is a crazy story.

    Craig Peterson: [00:06:08] Yeah, it is. If you look at the different countries out there, these different countries, different payoff amounts, and the percentages of businesses that will payout, the US is the lowest in the nation when it comes to will we payout. Of course, the US says we don't pay for hostages. We don't. We don't have the trade of hostages very often. We can talk about some really bad trades, but at any rate, we just don't pay ransoms.

    We now know that the federal government might come after us as a business if we do pay a ransom because we're supporting terrorism. Other countries, like in Europe, many of the countries versus the US, will pay two to three times more than us, but now we're seeing huge payoffs that are just surging right now. Three times plus over the last year. They're doing it because that's where the money is. People are paying the ransoms more and more. That is the main reason that these Bitcoin and other blockchain currencies have been surging over the last 10 years. It really is because of ransomware payments.

    We're not protecting our systems. They're getting in. The other side is this, Matt, is they're holding our data hostage. It isn't enough that they go onto the computers, encrypt everything and say, I hope I have a good backup.

    What they're doing now is first, before you even know anything's going on, they take all of your stuff. They steal your files, your spreadsheets, your documents, and then they hold it ransom. Then after that, they say, Oh, and by the way, here's some samples of some of the files of yours we have, unless you pay us even more, we're going to release those out there, which of course includes the family jewels, your intellectual property, and other things.

    So these bad guys have gotten very bad, and countries like North Korea are using it to get hard currency. To get the money that they can spend in other places. Iran doing the same thing.

    So it's not just some little kid in the basement of their parents' home over in Eastern Europe. It is countries that are coming for us, and we're just not protecting ourselves.

    Matt Gagnon: [00:08:32] Craig, before we let you go, one really quick question here for you before you sign off Amazon is now making a transition. Jeff

    Craig Peterson: [00:08:39] Bezos

    Matt Gagnon: [00:08:40] is no longer going to be the CEO moving forward. Obviously, the company will go on and just like Apple, as I was joking with earlier with Danny on the program here, just like when Apple was Steve jobs, it's not as if one human being is that important to the success of the company. But I would like you to reflect really quickly on the legacy of Bezos. He was pretty much there from the very beginning when they had a really terrible garage-based office, right? All the way to the point where he's got $185 billion and is the most the wealthiest person in the world. Just reflect a little bit on what it means that he's stepping away.

    Craig Peterson: [00:09:12] I looked at some statistics on comparing what's happening with Amazon and with Google, both of them have. Cloud services, right? Amazon had to build up all of this computing infrastructure in order to support their stores, which started, of course, like a bookstore. They had massive infrastructure, and they designed it themselves. Did just a marvelous job. The guy that's taking over from Bezos is the guy that's in charge of cloud services over there at Amazon.

    Compare that to our friends at Google, who also have cloud services, and Google, on about $13 billion of revenue for cloud services, lost about $6 billion. That is crazy. It's terrible. Google just is not doing the cloud well. The guy that's taken over from Bezos has defined cloud services in the entire industry.

    Amazon has about 60% of the marketplace. So I think things are just going to continue. Frankly, this guy knows what he's doing, and he ran a huge division of Amazon.

    Matt Gagnon: [00:10:25] All right. That is Craig Peterson, our tech guru. Again, you can hear him on Saturdays at one. O'clock here to get more in-depth on many of these same topics.

    Thanks a lot, Craig. Appreciate it. We'll talk to you again.

    Craig Peterson: [00:10:34] At that point, I was cut off. So, Matt, you're welcome. All right, everybody, have a great day.

    We'll be back this weekend. Take care. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min
  • AS HEARD ON: WGAN Mornings News with Matt Gagnon: Swarms of Armed Drones, Ransomware, Autonomous Vehicles, and Amazon

    Good morning everybody! 

    I was on WGAN this morning with Matt Gagnon. I started this morning talking about Drone swarms and how the military in different countries are considering using it, and the concerns about this technology.  Then we talked about Hyundai and Apples' electric autonomous vehicles.  We discussed the problem with Ransomware. Then we talked about Amazon and my thoughts on the transition.   Here we go with Matt.

    And more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] We survived the nor'easter well, actually it came from the West. The big snowstorm, good news, maybe more snow on the way I use, shouldn't have been complaining about the fact that we didn't have much of a winter this year because it sure did hit us. Here, up in New Hampshire, we can get snow, even in early April, which is not something to look forward to. It does go away quickly if it comes at the time of year.

    Hey, I was on with Mr. Matt Gagnon this morning. He and I talked about a number of subjects, including what's going to happen with Jeff Bezos stepping down and on day-to-day operations over there at Amazon. So here we go.

    Matt Gagnon: [00:00:46] It's all things technology tech talk with Craig Peterson right now on News Radio 98.5 FM and AM 560 WGAN.

    Craig Peterson joins us on Wednesdays at this time to go over the world of technology, and today being no exception to that. We welcome Craig onto the program. How are you, sir?

    Craig Peterson: [00:01:06] Hey, good morning. Rowe, of course, one of the sponsors. They have the Hyundai dealership. Did you hear about it? Apple and the Hyundai actually they're Kia brand, and it looks like they might be coming out with one of these smart self-driving cars. Electric, of course.

    Matt Gagnon: [00:01:23] I did not see that. That's the future, though. Isn't it, right? We're going to be having 10, 20, 30 years from now. I'm not driving my car anymore. Am I right about that?

    Craig Peterson: [00:01:31] Yeah, I like that. I'll be old enough at that point that if I'm smart, I won't be driving myself.

    Matt Gagnon: [00:01:38] Take a nap behind the wheel. It'd be great.

    Craig Peterson: [00:01:40] Yeah, exactly. I'll be able to look between the dashboard and the steering wheel as I'm driving down the road.

    But yeah, and the new cars too, that have come out now from Tesla, they've got brand new models. They don't even have a steering wheel anymore. It's got a yoke. They almost like an airplane. I don't know if you've seen those too, but they're starting to really move fast. Although Tesla they're saying maybe not the winner that everyone's been predicting, they're so far ahead with some of these technologies.

    There's a lot of reasons they're concerned about the fact that they don't have LIDAR on the cars, which gives a really great view of what's ahead on the road. They're also looking at it saying you've got those cameras, isn't that wonderful, but when Ford and GM and. Hyundai Et cetera, et cetera, really go forward on this they say, they're just going to swamp, and Tesla is going to be left on the road behind them.

    Matt Gagnon: [00:02:41] We're speaking with Craig Peterson, the tech guru that joins us every Wednesday. You also hear him on Saturdays on this very network, doing a show where he goes into all of these stories in detail in depth here.

    Now I do want to touch on this one, which I find fascinating envisioning these swarms of drones and whether or not they're getting too fast now. And whether or not we're going to be able to deal with this whole swarm issue in the future. So what is a drone swarm, and how does this impact us?

    Craig Peterson: [00:03:07] You might've seen this at the Olympics over in China. Where they had the opening ceremonies and overhead, normally they're shooting up all kinds of fireworks, which they did do, of course, but they had all of a sudden this display in the sky. It was all of these drones, it was thousands of drones that were synchronously flying, and they had lights on them. So they could put up all this different optics, basically, almost like a screen, a computer screen in the sky.

    We've got these types of drones right now. They are used in these types of events, like the Olympics or big games like this weekend. I'm sure there'll be something going on, but there's another side of this.

    That's the darker side that you're referring to, which is you've got these drones. Now, a lot of these drones can fly by themselves without any human input or computer external computer input. They have cameras in them. Of course, we know that. We've seen all kinds of beautiful photos of the forest or cities from these drones with cameras, but they're building artificial intelligence into them now. Where concern really comes in is that this artificial intelligence is able to determine if someone is an enemy soldier or if their face matches someone that they want to attack.

    Now, it's one thing to have one little drone come after you, excuse me, with a small amount of high explosives, right? Because you can just bat it out of the way and get out of there.

    Where they're really concerned about is a swarm of like 75 drones coming at you, kamikaze style. The Indian army just generated this, and they're coming up with these thousand drones, strong little armies. If they're aiming at you, if they're coming for you and they have just a fraction less than an ounce of high explosive on them, there is no avoiding them.

    A US Navy has also looked at some of this. They've been demonstrated numerous times, and this is really scary. Especially the whole autonomous idea where they identify someone that might be a suspect, a terrorist, or whatever. Instead of bringing them in and having even a military trial. The drone recognized you, and they attack you and kill you right there. Even if it's not a battlefield,

    Matt Gagnon: [00:05:42] We're speaking with Craig Peterson, our tech guru here. He joins us every Wednesday at this time to talk a little bit about the world of technology.

    Ransomware payoffs are now surging and are nearing 350 million. From what I understand about these ransomware things and you've been talking about this for quite some time on this very program. Basically, companies are held hostage by ransomware, and people that are held hostage by ransomware essentially paying off the people holding them hostage. This is a crazy story.

    Craig Peterson: [00:06:08] Yeah, it is.  If you look at the different countries out there, these different countries, different payoff amounts, and the percentages of businesses that will payout, the US is the lowest in the nation when it comes to will we payout.  Of course, the US says we don't pay for hostages. We don't. We don't have the trade of hostages very often. We can talk about some really bad trades, but at any rate, we just don't pay ransoms. 

    We now know that the federal government might come after us as a business if we do pay a ransom because we're supporting terrorism. Other countries, like in Europe, many of the countries versus the US, will pay two to three times more than us, but now we're seeing huge payoffs that are just surging right now. Three times plus over the last year.  They're doing it because that's where the money is. People are paying the ransoms more and more. That is the main reason that these Bitcoin and other blockchain currencies have been surging over the last 10 years. It really is because of ransomware payments.

    We're not protecting our systems. They're getting in. The other side is this, Matt,  is they're holding our data hostage. It isn't enough that they go onto the computers, encrypt everything and say, I hope I have a good backup.

    What they're doing now is first, before you even know anything's going on, they take all of your stuff. They steal your files, your spreadsheets, your documents, and then they hold it ransom. Then after that, they say, Oh, and by the way, here's some samples of some of the files of yours we have, unless you pay us even more, we're going to release those out there, which of course includes the family jewels, your intellectual property, and other things.

    So these bad guys have gotten very bad, and countries like North Korea are using it to get hard currency. To get the money that they can spend in other places. Iran doing the same thing.

    So it's not just some little kid in the basement of their parents' home over in Eastern Europe. It is countries that are coming for us, and we're just not protecting ourselves.

    Matt Gagnon: [00:08:32] Craig, before we let you go, one really quick question here for you before you sign off Amazon is now making a transition. Jeff

    Craig Peterson: [00:08:39] Bezos

    Matt Gagnon: [00:08:40] is no longer going to be the CEO moving forward. Obviously, the company will go on and just like Apple, as I was joking with earlier with Danny on the program here, just like when Apple was Steve jobs, it's not as if one human being is that important to the success of the company. But I would like you to reflect really quickly on the legacy of Bezos. He was pretty much there from the very beginning when they had a really terrible garage-based office, right? All the way to the point where he's got $185 billion and is the most the wealthiest person in the world.  Just reflect a little bit on what it means that he's stepping away.

    Craig Peterson: [00:09:12] I looked at some statistics on comparing what's happening with Amazon and with Google, both of them have. Cloud services, right? Amazon had to build up all of this computing infrastructure in order to support their stores, which started, of course, like a bookstore. They had massive infrastructure, and they designed it themselves. Did just a marvelous job.  The guy that's taking over from Bezos is the guy that's in charge of cloud services over there at Amazon.

    Compare that to our friends at Google, who also have cloud services, and Google, on about $13 billion of revenue for cloud services, lost about $6 billion. That is crazy. It's terrible. Google just is not doing the cloud well.  The guy that's taken over from Bezos has defined cloud services in the entire industry.

    Amazon has about 60% of the marketplace. So I think things are just going to continue. Frankly, this guy knows what he's doing, and he ran a huge division of Amazon.

    Matt Gagnon: [00:10:25] All right. That is Craig Peterson, our tech guru. Again, you can hear him on Saturdays at one. O'clock here to get more in-depth on many of these same topics.

    Thanks a lot, Craig. Appreciate it. We'll talk to you again.

    Craig Peterson: [00:10:34] At that point, I was cut off. So, Matt, you're welcome. All right, everybody, have a great day.

    We'll be back this weekend. Take care. Bye-bye.

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min
  • AS HEARD ON NH Today WGIR-AM 610: Using Online Trading Apps Safely to Protect Your Privacy

    Welcome,

    Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about how you can stay secure and private while using the Cloud and then we talked about Contact Tracing, privacy, compliance, and government tracking. Here we go with Chris.

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Hey, good morning. I was on with Mr. Chris Ryan this morning and I gave, I thought it was a pretty good explanation of the risks when it comes to online trading. I'm not really a trading expert, obviously, and I'm not talking about which platforms to use. I think it was a bit of an eye-opener. I got a lot of time to talk this morning. I did a decent job. Anyways, here it goes. I gave a couple of examples too, from close friends and family and how they got messed up.

    Chris Ryan: [00:00:32] Craig Peterson joins us right now on the program. The host of tech talk. Craig, how are you?

    Craig Peterson: [00:00:38] Hey, I am doing well this morning.

    I'm not going to resign, anymore.

    Chris Ryan: [00:00:41] Nor am I going to ask you to resign? I like your spot in the show here. Enjoy talking to you. So there you're not in that consideration at this point, we'll see how the segment goes. So let's start with this.

    Craig Peterson: [00:00:53] Is it, Justin?

    Chris Ryan: [00:00:54] No, I've already no, you don't get to ask me. He will just, it will be another process which will take place there, which will be outside of a resignation.

    So let's start with this. There's been a lot of discussion about, online trading and, getting involved with different aspects of trading outside the traditional methods.

    I'm curious as to what you think of that from a safety perspective, when you're thinking about using apps, you're thinking about using entities that are the non-traditional trading mechanisms, in light of the game stop situation. What should individuals be cognizant of?

    Craig Peterson: [00:01:32] There's two different parts of this.

    Chris. I want to tell you two stories, personal stories, friends, and family members of mine. And we'll start by just saying, this is a new technology and when you get right into it, I've looked at the analysis of some of these trading apps, including some of the big ones, including Robinhood and others.

    And many of them are not encrypting our data. And that's just crazy. Like some of its encrypted account balances might not be encrypted, but here's the bottom line on this, frankly, there's always going to be security problems. If you are going to be doing online banking trading, doesn't matter. Make sure you're using, what we would call a secure platform or a more secure platform. This means, do not ever root your phone.

    People are using their iPhones or Androids all of the time, Androids, particularly people try and gain master control if you will, over that phone. So they can do anything at that point, you've gotten around even the most basic security measures. So don't do that.

    The other thing that you can and must do with these online trading apps is using two-factor authentication. Now there's a few different types.

    The most simple is to have it send you a text message when you go to log in, but I have to warn you that is not safe. It's not safe because it's sending it to your phone and your phone number is attached to that.

    We've now seen. Because so many people are trading everything from Bitcoin through stock, that they have very large portfolios. What'll happen is it's worth it to them to steal a hundred thousand dollars from you or even 50 or 20,000. In some cases we've seen it as low as. 5,000 it's worth it for them to go to the trouble to get the phone company to switch your phone number to the bad guy's burner phone. Now when they go to log into your account.

    Guess what people aren't doing the basics, they're not using unique passwords, in many cases.

    What will happen is they'll go to your account online and it'll ask for the username. They'll try to use a name they found on the dark web for you. They'll try the password they found on the dark web for you. Maybe they'll try a few different passwords. They've compromised other machines so they can try different passwords in different places. So they don't get caught. Now it sends a text message, but it's not coming to your phone. It's going to the bad guy's phone.

    Use an authenticator app, or use a hardware token. Some of these online trading places and banks, including Chase, is a good example. They've been doing this for 15 years.

    They'll send you a little key fob, a little thing that goes on your key chain and it has a display with a number on it. That number continually changes it's every 30 seconds and you have to type that number in, that's much, much safer. That's real two-factor authentication.

    Now real quickly, two people in my life have been affected by this right now. One of them had an account, an online brokerage account and her stock had gone way up and she decided that she needed to sell her stock.

    She didn't ask me, she didn't ask her husband. He's a bit of a techie guy. She was going to do it herself. She went to a Facebook group. She went to a Facebook group that she found online about how to go ahead now and cash out. They asked her, in the Facebook group, there's a few things we're going to need to do in order to help you out.

    First of all, what's your account number? Secondly, what's your password? She gave it to them. She instantly lost $6,000 from her account by just doing something. I'm sorry here, but dude, you don't go to Facebook to get help with training. Don't ask how do I get Robin hood? What do I do with it and all that? It is not the right place.

    Go directly to the company. Picked up a phone. You can't trust some of this stuff online.

    Another example is a friend, family member, a close friend where he had been using Robinhood for trading. He had bought a bunch of stock and it included AMC. Of course, this is a movie theater chain and it had been targeted if you will, by these people on this subreddit. AMC had finally gotten up to breakeven point and so he decided to sell. He sold and okay, great, fine. He now regrets it. That's a big problem. I've seen him before. Now, he's a millennial and nothing personal guys, but.

    Chris Ryan: [00:06:33] I'm going to take it personally. I'm gen X.

    Craig Peterson: [00:06:35] So he trusts these platforms. He trusts what they're saying on the subreddit and he's putting money he cannot afford to lose into this Robinhood app that lets him buy and sell a stock. That to me is a huge concern.

    So, Chris, there's a couple of examples. Make sure you know what you're doing. Day traders, lose money. Most of them lose money. It's that simple. Maybe buy and hold long, maybe follow what the real professionals do. Do check out the basics. Don't just buy it because it's going up.

    Also, just basic security stuff guys use a password manager. Unique passwords for every site and full two-factor authentication. These apps are not completely to be trusted, so don't use it on a computer that you use for everything else.

    If you're running windows great. Okay. There's a lot of problems with windows and I've got a course coming up on improving windows security. That's one thing.

    Try and have a machine that you don't use for anything else, and if you can.

    I don't make a dime by saying this but use Apple equipment. They don't make money off of you. They're trying to keep you safe.

    Get an iPhone, get an old iPhone. If he can't afford a new one there rather than inexpensive, usually free. Get a Mac and don't use the same computer for online trading that you use for going to Facebook and everywhere else online, because it might be compromised.

    Chris Ryan: [00:08:08] Craig, I appreciate your time and encourage folks to check out tech, talk on Saturdays at 11:30 AM here on news radio six, 10 and 96, seven. We'll chat again on Monday.

    Craig Peterson: [00:08:17] All right. Take care guys.

    I should have mentioned this, but in case you were wondering he was talking about asking someone to resign. He said I never asked anyone to resign. So that's what that was all about. What does it mean? Is it Justin?

    Anyways, everybody, take care. Have a great day.

    We'll talk later. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    9 min
  • AS HEARD ON NH Today WGIR-AM 610: Using Online Trading Apps Safely to Protect Your Privacy

    Welcome,

    Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about how you can stay secure and private while using the Cloud and then we talked about Contact Tracing, privacy, compliance, and government tracking. Here we go with Chris. 

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Hey, good morning. I was on with Mr. Chris Ryan this morning and I gave, I thought it was a pretty good explanation of the risks when it comes to online trading. I'm not really a trading expert, obviously, and I'm not talking about which platforms to use. I think it was a bit of an eye-opener. I got a lot of time to talk this morning. I did a decent job. Anyways, here it goes. I gave a couple of examples too, from close friends and family and how they got messed up.

    Chris Ryan: [00:00:32] Craig Peterson joins us right now on the program. The host of tech talk. Craig, how are you?

    Craig Peterson: [00:00:38] Hey, I am doing well this morning.

    I'm not going to resign, anymore.

    Chris Ryan: [00:00:41] Nor am I going to ask you to resign? I like your spot in the show here. Enjoy talking to you. So there you're not in that consideration at this point, we'll see how the segment goes. So let's start with this.

    Craig Peterson: [00:00:53] Is it, Justin?

    Chris Ryan: [00:00:54] No, I've already no, you don't get to ask me. He will just, it will be another process which will take place there, which will be outside of a resignation.

    So let's start with this. There's been a lot of discussion about, online trading and, getting involved with different aspects of trading outside the traditional methods.

    I'm curious as to what you think of that from a safety perspective, when you're thinking about using apps, you're thinking about using entities that are the non-traditional trading mechanisms, in light of the game stop situation. What should individuals be cognizant of?

    Craig Peterson: [00:01:32] There's two different parts of this.

    Chris. I want to tell you two stories, personal stories, friends, and family members of mine. And we'll start by just saying, this is a new technology and when you get right into it, I've looked at the analysis of some of these trading apps, including some of the big ones, including Robinhood and others.

    And many of them are not encrypting our data. And that's just crazy. Like some of its encrypted account balances might not be encrypted, but here's the bottom line on this, frankly, there's always going to be security problems. If you are going to be doing online banking trading, doesn't matter. Make sure you're using, what we would call a secure platform or a more secure platform. This means, do not ever root your phone.

    People are using their iPhones or Androids all of the time, Androids, particularly people try and gain master control if you will, over that phone. So they can do anything at that point, you've gotten around even the most basic security measures. So don't do that.

    The other thing that you can and must do with these online trading apps is using two-factor authentication. Now there's a few different types.

    The most simple is to have it send you a text message when you go to log in, but I have to warn you that is not safe.  It's not safe because it's sending it to your phone and your phone number is attached to that.

    We've now seen. Because so many people are trading everything from Bitcoin through stock, that they have very large portfolios.  What'll happen is it's worth it to them to steal a hundred thousand dollars from you or even 50 or 20,000. In some cases we've seen it as low as. 5,000 it's worth it for them to go to the trouble to get the phone company to switch your phone number to the bad guy's burner phone. Now when they go to log into your account.

    Guess what people aren't doing the basics, they're not using unique passwords, in many cases.

    What will happen is they'll go to your account online and it'll ask for the username. They'll try to use a name they found on the dark web for you. They'll try the password they found on the dark web for you. Maybe they'll try a few different passwords. They've compromised other machines so they can try different passwords in different places. So they don't get caught. Now it sends a text message, but it's not coming to your phone. It's going to the bad guy's phone.

    Use an authenticator app, or use a hardware token. Some of these online trading places and banks, including Chase, is a good example. They've been doing this for 15 years.

    They'll send you a little key fob, a little thing that goes on your key chain and it has a display with a number on it. That number continually changes it's every 30 seconds and you have to type that number in, that's much, much safer. That's real two-factor authentication.

    Now real quickly, two people in my life have been affected by this right now. One of them had an account, an online brokerage account and her stock had gone way up and she decided that she needed to sell her stock.

    She didn't ask me, she didn't ask her husband. He's a bit of a techie guy. She was going to do it herself. She went to a Facebook group.  She went to a Facebook group that she found online about how to go ahead now and cash out. They asked her, in the Facebook group, there's a few things we're going to need to do in order to help you out.

    First of all, what's your account number? Secondly, what's your password?  She gave it to them. She instantly lost $6,000 from her account by just doing something. I'm sorry here, but dude, you don't go to Facebook to get help with training. Don't ask how do I get Robin hood? What do I do with it and all that? It is not the right place.

    Go directly to the company. Picked up a phone. You can't trust some of this stuff online.

    Another example is a friend, family member, a close friend where he had been using Robinhood for trading.  He had bought a bunch of stock and it included AMC. Of course, this is a movie theater chain and it had been targeted if you will, by these people on this subreddit.  AMC had finally gotten up to breakeven point and so he decided to sell. He sold and okay, great, fine. He now regrets it. That's a big problem. I've seen him before. Now, he's a millennial and nothing personal guys, but.

    Chris Ryan: [00:06:33] I'm going to take it personally. I'm gen X.

    Craig Peterson: [00:06:35] So he trusts these platforms.  He trusts what they're saying on the subreddit and he's putting money he cannot afford to lose into this  Robinhood app that lets him buy and sell a stock. That to me is a huge concern.

    So, Chris, there's a couple of examples. Make sure you know what you're doing. Day traders, lose money. Most of them lose money. It's that simple. Maybe buy and hold long, maybe follow what the real professionals do. Do check out the basics. Don't just buy it because it's going up.

    Also, just basic security stuff guys use a password manager. Unique passwords for every site and full two-factor authentication. These apps are not completely to be trusted, so don't use it on a computer that you use for everything else.

    If you're running windows great. Okay. There's a lot of problems with windows and I've got a course coming up on improving windows security. That's one thing.

    Try and have a machine that you don't use for anything else, and if you can.

    I don't make a dime by saying this but use Apple equipment. They don't make money off of you. They're trying to keep you safe.

    Get an iPhone, get an old iPhone. If he can't afford a new one there rather than inexpensive, usually free. Get a Mac and don't use the same computer for online trading that you use for going to Facebook and everywhere else online, because it might be compromised.

    Chris Ryan: [00:08:08] Craig, I appreciate your time and encourage folks to check out tech, talk on Saturdays at 11:30 AM here on news radio six, 10 and 96, seven. We'll chat again on Monday.

    Craig Peterson: [00:08:17] All right. Take care guys.

    I should have mentioned this, but in case you were wondering he was talking about asking someone to resign. He said I never asked anyone to resign. So that's what that was all about. What does it mean? Is it Justin?

    Anyways, everybody, take care. Have a great day.

    We'll talk later. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    9 min
  • Tech Talk with Craig Peterson Podcast: Cloud Jacking, Browser Password Protection, Subliminal Messages on White House Website and more

    Welcome!

    With the rapid pace of change unleashed this past week through Executive Orders, we are now a lot less secure than we were just a month ago and it is going to get a lot worse. But there are somethings you can do technologically to protect your privacy and stay a little more secure. Cloudjacking is possible mainly due to the failure to use secure passwords and a different password for every site and every application you use. Just doing that makes it almost impossible for hackers to carry out their trade. Chrome and by default Microsoft's Edge Browser have put something in their browser to help -- not alleviate but help with this problem. You can do better by using a true Password Manager and we will get into that as well. Speaking of privacy, the US government is going around its own requirements and buying your location data and other personal information they are not allowed to collect from Data aggregators. We will get into that as well. Then did you know that the new administration has put subliminal messaging into the White House website -- Yes they have. Well, just a taste of today's topics and there is even more so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Cloud Jacking: The Bold New World of Enterprise Cybersecurity

    Chrome and Edge want to help with that password problem of yours

    Military intelligence buys location data instead of getting warrants, memo shows

    US administration adds "subliminal" ad to White House website

    Why North Korea Excels in Cybercrime

    Speed of Digital Transformation May Lead to Greater App Vulnerabilities

    Waymo CEO dismisses Tesla self-driving plan: "This is not how it works"

    What's the technology behind a five-minute charge battery?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, there is a new company out there on the forefront of passwords. We're going to talk about that and a few weather things. Of course today.

    Hi everybody. Craig Peterson here.

    The biggest problem, pretty much all of us have, has to do with our passwords, what we're doing with them, how often we're changing them, how we are storing them. It is being used for quite a few things out there right now. We're seeing a real emphasis on a term you might not have heard before it's cloud jacking.

    This is where someone gained access to your cloud services and then does nefarious things with them. What do you expect them to do now? What does this all mean? It means if you are using something thing, like maybe you're using salesforce.com, maybe you have online banking with your bank.

    Most people do. There are so many cloud services that we use nowadays. And cloud jacking is where someone gained access to that online account. You might ask, how do they do that? How do they gain access to it? The simplest and most common way of doing it is something called password stuffing. Now, I know I'm throwing a lot of terms out there for everybody, but basically, cloud jacking means that cloud service is being used without your permission, your cloud service.

    So again, think about clouds as just a word for somebody else's computer that you have no control over. Cloud services. Generally speaking, are dangerous. Now I know a whole lot of people who think I don't know much about computers. I'm probably a lot better off having some third party manage my computers for me.

    And so I'll just go to Amazon or I'll go to Microsoft or IBM or whomever and have them run my server for me. And in fact, that's what most companies are doing nowadays. Initially, it looked like it was going to save them money. It was going to be a big saving because you didn't have to maintain that data center anymore.

    You didn't have to have the personnel who know the systems who did the updates and stuff. In reality, that's turned out not to be true. Most of the slightly bigger businesses, those smaller to mid midsize are moving their stuff. Out of the cloud because of cloud jacking, because of all of the supposedly expenses that we're going to be saved, not only not being saved but because they don't have control over their computer anymore and they don't have control over the network because remember the cloud is somebody else's their computer it's their network. it's something you have very little control over, so they're moving it back into their business. I think that makes a whole lot of sense. In the meantime, we have many more businesses that are saying you cannot buy our software anymore. You have to use it in the cloud.

    You have to use our cloud license, which to me is just frankly, mind-boggling. Now I can see how it makes it simpler for them because they only have to have one version of the software, maybe two or three as working on the development and they can roll it out a little bit more slowly. They don't have to worry about it.

    People having problems with windows, which is always a nightmare. And we'll try and do support because when it comes to windows, Microsoft, themselves tell you don't run more than one app, one service on that machine. We can't guarantee it. It's not going to work. And then you have to pay them 300 bucks when there's a problem.

    And that 300 bucks don't go very far because they don't guarantee they'll solve that problem. So all of these things have led us to move to the cloud and now some moving back away from the cloud and our cloud servers and our cloud services that we're using on our businesses. Are being hijacked.

    Now I mentioned that one of the things that these hijackers are doing to take over is something called credential stuffing. Another one is fishing. We're not going to talk a lot about fishing right now, but you probably know this already. It's where you get in the email that looks legitimate. It's from somebody that looks legitimate.

    But in fact, it's trying to get you to do something that is going to now give them access to your systems. And in fact, that's what happened to a buddy of mine. I've talked about him before, just a couple of weeks ago. Yeah, he lost his whole paycheck. It's gone and he's not getting it back. And the company is not going to reimburse him for it, which is really a shame, frankly.

    So once credential stuffing, it's something that's been used for cradle quite a while. In fact, way back when. They used to use credential stuffing to try like a thousand, 10,000 most recent passwords, or, most popular passwords. Now that's a problem. Isn't it? What is it? Why are they doing it?

    Back when life was simpler and people use password as their password, or, ABC one, two, three, or the whole top of the keyboard. There were only a few thousand, maybe 10, 20,000 passwords that were in common use, and we've gotten way smarter since then. Haven't we. No, we haven't.

    And I would ask right now that you just take a minute and you go online to have I been poned.com and you can type into, have I been poned your email address? And it'll tell you if it found it anywhere. On the internet. So not just on the internet, but more or less on the dark web on the dark internet, but there's another feature on, have I been poned is spelled P w N E D.

    Have I been poned and that's in the passwords tab. So if you click the password. Tab here. It's saying that right now they have a database of 613 million real-world passwords that have been previously exposed in data breaches. And obviously, this exposure makes them unsuitable for ongoing use. Why does it make it unsuitable?

    Let's type in right now. We're going to type in P an actually we're going to get fancy P at Sein S w zero R D. So it's a great password, right? Because it's a password with an additional sign instead of an eight and a zero instead of an O. So we're going to type this in and they hit return and let's see what it says.

    Oh my gosh. This password has been seen almost 55,000 times before. Okay. So it's not such a great password out there. It has been breached in data breaches and should never be used if you've ever used it anywhere before change it. And it's going through giving you this list. There are a lot of places.

    Yeah. 55,000 times it's been used. So check it out, go there, check it out. Make sure your password that you're using. Hasn't been used before. And the question is why? That's where we get into. Okay. Problem with credential stuffing. What they'll do is they will use your email address and your passwords that they found online.

    And then they'll try and log in to critical websites like your bank, for instance, we mentioned the bank, so they will try and break into your bank account because they've got your email address and they've got, or password that's what credential stuffing is all about. So they'll just try it on across all kinds of different websites until they can get in.

    So this ties back into our cloud jacking problem. And with cloud jacking, they just go to these online services. Again, it's like your bank or might be Salesforce to get access to your client information or QuickBooks. Maybe there's a whole lot of them are out there and they'll try and log in as you know, most of these websites have.

    Controls on this. So they limit the number of times you can try and log in. So the bad guys know this and they know the ways around it. And some of the ways are just to do it really fast. One of the ways are to do it from different IP addresses. And they do that using, of course, hijacked computers. We called botnets people's home computers, business computers.

    They use them to do their dirty work for them. And now they have control over your systems. Multifactor authentication. That's something I go into in some detail. In my improving windows security course, that's coming up. So if you need more information, that's the place to get it. If you want to find out how to sign up, make sure you just go to Craig peterson.com and sign up for the newsletter.

    I'll let you know when that course is ready. Karen and I are finishing it up now. There's just been too much stuff going on. So I apologize. It's been taken a little longer than I had hoped it would take. But it'll be out pretty soon, but multifactor authentication or two-factor authentication is really becoming a standard and you're foolish if you don't need it.

    Microsoft, Google, and others have been trying to do away with passwords entirely with some whole new technology, which is. Going back and forth. It may come into play. It might not. We'll see how it all goes. There's been some adoption, but it certainly has not been universal, but multifactor authentication absolutely.

    Is universally adopted. So when we get back, we'll talk a little bit more about this. What does it mean? This two-factor authentication multi-factor authentication. How can it stop our cloud accounts from getting hijacked, which is really big? Then we're going to get into Chrome and edge a brand new feature designed to help you with this very problem.

    You're listening to Craig Peterson and of course, that's all you will find me online. Craig peterson.com.

    We know about credential stuffing and cloud jacking, and we mentioned multi-factor authentication. So we're going to talk a little more about it, but now

    hi everybody. Craig Peterson here.

    There are a lot of things that we have to understand and take care of when it comes to our computers. But frankly, one of the things that we have to be the most concerned about, and yet, so many of us just haven't been paying that much attention. Is our password. We are hearing stories every week of people who have had their accounts hijacked, who have had people take their bank account money right out.

    We've seen that for a couple of years, but it's getting worse and worse. I'm not exactly sure why you guys are not using unique passwords. For every one of your accounts, I really don't get it. It's easy enough to do use 1password. I don't have any money invested in these companies unless you buy 1password through me which I don't sell.

    I'm not going to make a dime off of it. Use 1password or LastPass, same thing there. I know the CEO of LastPass had him on the show before I don't make a dime off of it. So use them. It's just so easy to do, but yeah. Two-factor authentication. That's a little bit of a different thing. And we want to get into here in just a minute and how you can use that, how to tie it in.

    As I mentioned, I do go into it quite a bit of detail in my course. So if you are interested in that, the improving windows security course, we talk a lot about it. Our friends over at Google have decided they're going to help us out. And here's what they're doing. Number one, they are tying into, have I been poned.com, which you can go to yourself.

    You can get an alert from them. If your account shows up in any of these password dumps that are out there on the internet, very handy. So Google is going to have I been poned on your behalf. And if they notice that your account has shown up on the dark web, they're going to tell you, and they're going to recommend that you change your password.

    So the easy thing to do right now is. Go to Google. If you're using Chrome that is and check your security preferences. And once you're new security preferences, it'll tell you about the accounts that it knows about that you have that have been hacked. Now, when I say it's been hacked, it doesn't mean your account has been hacked, but your information has been stolen usually via some form of a hack.

    If you're using 1password, it has something called Watchtower, which does the same thing. I've got about 2,500 user accounts in my 1password vault. There's actually multiple vaults it's across all of those vaults. So we have some for the business person we have some other stuff that we use for our business clients because we have to maintain the highest levels of security for ourselves, because we have clients that have to have that level of security as well.

    So we in fact have better security than most of our clients do, frankly. And that's a little bit sad, many how. 1password will remind me as well. When one of my accounts, email addresses of passwords show up on the dark web. And it'll also tell me, for instance, if I've got my Craig peterson.com to log in and it shows up somewhere on the dark web, it will tell me that.

    They found Craig peterson.com out of the dark web, whether or not my password was stolen. So it's really nice. 1password can help you with that and it can generate new passwords and you can use it as well for keeping private notes. And when you are generating. Passcodes for two-factor authentication.

    Many times it'll give you a one-time pad. So it'll be a number of single-use passwords that you can use in the event that you don't have your two-factor device with you, as I said, but go into that in a lot of detail in my improving windows security course. But Chrome has done something else and I have to apply them for doing this.

    I am not a big fan, already of Google and Chrome, they make their money, their whole living off of you and your information. And I think that a little bit on the dishonest side, frankly. But that's what they do. Okay. They have added now something that's really quite nice and because Google has added it to Chrome, that means that these Chrome-based browsers will also be picking it up.

    What are the chromium based browsers? Of course, Google Chrome itself is a chromium-based browser, which means it's a certain codebase Microsoft's Edge browser. The latest version of Edge is not a Microsoft product anymore. They're using Google Chrome as its base. They're using chromium. So in both cases, you now have a strong password generator that you can use when you're signing up for a new account or account, or when you're changing an existing password, again, If you've heard me talk about this before that I'm not fond of having a web browser, remember your passwords because who knows, it's not designed for security. Google Chrome usually does a pretty good job. That's why it's such a popular web browser, but I much prefer an application that's specifically designed for security and they know what they're doing. And that's why I recommend the whole 1password thing. So here's what happens when you are on a web page and you are entering in a username and a password, or you're putting in a new password for your account, how it pops up and says, do you want me to save this password?

    Now it is giving you another option here. So rather than having to think up a password, that's really unique. That's a difficult one to guess that is not used anywhere else on the internet. You can now have the generator. Do it for you and generate a very good password. So you're going to look for the browser, suggested password dropdown in the password field, and you can select that and it's going to automatically save your new password to the browser, sync it across all of your other devices.

    If you are signed in to your Google account from all of those other devices so that you can use it in the future. There's another feature called password monitor and it's being added to adjuncts already there in Chrome. And it is a password monitor. Again, most of these guys are using, have I been poned would nothing wrong with that?

    Although have I been poned isn't being paid by these guys for doing it, but checking your passwords can be difficult. But have I been poned has free signup that you can use that will let you know if your username has shown up on any of these hacks out there. And frankly, that's all of these other people are using.

    They've got some very good encryption by the way, for keeping track of your passwords in Epic, they're using homomorphic encryption is what it's called. It's. Pretty new, but it allows computing on encrypted data without decrypting the data first. So that's really cool. It has this hash function that only the server knows they're doing a lot of neat stuff here and Google Chrome team.

    Unveiled their own version of this as well. And they've got a fuller featured password manager now built into the browser. So keep an eye out for those on your chromium based browsers. And have a look at, have I been poned P w N d.com online, if you want some more help on passwords, just drop me an email. [email protected] or sign up for my improving windows security course.

    You can keep up to date with all of the latest news courses, little training, webinars, by going to Craig peterson.com and signing up right there.

    Hey, I got a quick update here on secure communications. You might've heard about what happened. What's going on there and let's talk about alternatives.

    Hi everybody. Craig Peterson here.

    You might've heard about WhatsApp, WhatsApp used to be really popular. I've had a listener before, ask me about using WhatsApp overseas. It was a family member who was serving in the military and they wanted something that was secure. They asked about WhatsApp and I said, I don't know. A little bit of moaning and groaning there that I, I don't like WhatsApp because of Facebook.

    Facebook, our friends over there decided that they were a couple of weeks ago going to come out with new terms of use. And that new terms of use have language that made it sound like maybe they'd be spying on us. Now that Facebook has come out and said, no, we're not going to break the end to end encryption.

    In other words, we won't be able to decrypt your conversations. However, we are going to start sharing your information with advertisers, et cetera. Sharing your information about using WhatsApp, which is an encrypted, supposedly secure chat app might cause some problems, right? You can imagine someone knocking on your door and saying, why are you using encrypted communications?

    And in fact, you have every right to, it is the best thing to do. You don't want bad guys getting their hands on it. And in some parts of the world, the governments just can not be trusted and they are trying to monitor everything that's going on. So that's why I've never been a fan of WhatsApp. And why so many people have migrated off of WhatsApp.

    Facebook finally realized what a mistake it was to send out that press release w wasn't as the press release, actually, it was something that came up when you used WhatsApp became right up on your screen. You hadn't to accept it. So it is concerning. Where do we go? Now I think that I suggest you use signal and we cover this quite a bit in a bit of detail in the improving windows security course.

    So in the course, we talk about all these different types of messengers, which ones are the best ones to use and when and why, but I want to point out something about Telegram. Telegram has picked up. I'm looking at some numbers right now, but tens they're saying tens of millions. Wow. Of people have moved over to telegram.

    They said that earlier in January, telegram announced it had hit a milestone of 500 million active. Monthly users and pointed to a single 72 hour period, one 25 million people had joined the service. Now, obviously, this is people who are fleeing some of these censored services that are out there. People who are fleeing from WhatsApp, because who knows where it's going.

    Ultimately. But I want to point out something about Telegram. So first of all, don't use it. All right. Not if you want to be secure, but here are the problems with Telegram. First of all. End-to-end encryption is what you want. So if you are talking to someone over one of these encrypted apps, you want that message, that voice conversation, that video to be encrypted from the time it leaves your device.

    Until it arrives on the person you're talking to his device. It's almost certainly going to go through a server or two or three or four. It's going to go through routers. There are ways to intercept it, but if it's encrypted end to end, it won't do much good to intercept in the middle. Our encryption today is really quite good.

    Now, if the government wants to get its hands on it, they're on your communications. There are ways around it. However, when it comes to just cast casting, a big fishing net, nothing's going to happen. And they're just going to cast a net. They're going to catch all of this stuff and there's nothing in it.

    We know that various intelligence agencies around the world try and keep copies of everything in case, later on, they want to go back and examine it and see what was said after the fact. Whatever, more power to them, Telegram by default does not have an end to end encryption. So by default, yes, it has encryption, but the encryption goes from your phone to their server.

    And once it's on the server, it is no longer encrypted. And then on the remote side for the person you're talking to, it's encrypted from the server to that person that you're talking to on the far end. See where the problem can come in here. Particularly if you are in a country that does not treat its citizens, residents, whatever you might want to call these people from serfs on up, that doesn't treat them well. They can potentially force telegram to give them a complete copy of everything that was said or done. That is a problem. That is a very big problem. You are not going to get by default end encryption. However, you can turn it on. On telegram now on Signal. It is by default.

    It is end to end. It's always end-to-end. Okay. So telegram only encrypt by default messages between your device and the telegram server and the telegram server and the other person on the other end. However, the group messaging feature that telegram has offers no end to end encryption at all. None. So we have a group of people.

    Who've got family members that you're talking, or maybe it's some investors, and you're talking about buying some more real estate for your investment trust, or you are talking with your accountant about, bank numbers and things, and yeah. You've got the attorney on, or maybe you're just talking to some friends and you don't have anything you want to share with those prying intelligence agencies in some of these countries out there, you are not secure because right in the middle, you have your messages in cleartext.

    So where is Telegram located? It is based in the United Arab Emirates. That is scary. When they have servers over in the United Arab Emirates, you already know that you don't have much of a sense of security over there. And you certainly don't have privacy. So don't use Telegram. If you want to be secure, we've got tens of millions of WhatsApp users who flee the service.

    Many of them went to Telegram. No doubt. They were attracted by Telegrams claims of heavily encrypted messaging. But in fact, it's not true. Okay. People do not want to exchange privacy for free services. Now the nice thing about Signal is it is open source and they are not trying to make money off of signal it's available freely.

    Anyone can grab the source code and the signal encryption methodology. Is used by WhatsApp as well, but we already expressed some of my concerns about WhatsApp.

    Hey, if you want to learn more about this, more about improving windows security, more about communicating securely, I've got it all covered in my improving windows security course that's coming up in a couple of weeks.

    Make sure you sign up. Just go to craigpeterson.com. You can sign up anywhere on that website or go to Craig peterson.com/subscribe. And you'll get my weekly newsletter as well.

    Shortly after Joe Biden took office, we started seeing some subliminal messages right there on the White House home page.

    Hi everybody. Craig Peterson here. Thanks for joining me.

    Let me tell you I'm not trying to start some sort of a rumor here. This is absolutely true. You might've heard about Easter eggs before? No, I'm not talking about the type that you know, that little bunny comes with the colored dyed hard-boiled eggs, or maybe they're little plastic aides with candy inside. Some of that Candy's kind of yummy. Of it's just horrific it's at least it's not as bad as mean with those little corn things that are nasty.

    Anyhow Easter eggs are in movies. Have you seen them in the Marvel movies? For instance, they use them quite a bit. These are little things that are hidden away so that people who are watching super fans can find them. It might be just something on a shelf. Behind in one of the movies. So it's on a set and it's something from another movie.

    It might be a movie that the director loves, or maybe it's another movie. That's part of the series. Those are Easter eggs are hidden away. They're there, but they're hidden. I think those are cool to try and spot sometimes. The White House added an Easter egg, this subliminal ad to the White House website shortly after president Biden took office.

    It's really just absolutely amazing, but one of the most famous Easter eggs in software history and this was pretty complex as well as in Microsoft Excel 97, Microsoft Excel, that's their spreadsheet software. And this is from 20 plus years ago, 23, 24, whatever it is back in 97. You could open a new workbook, hit F five type in L 97, colon X 97, enter and then tab and then control shift, click on the chart, wizard icon.

    And all of a sudden you are in to. Flight simulator. You didn't have to buy a flight simulator pretty cool. And you flew using the mouse and then when you were done, you hit escape. And that was cool. I thought it was phenomenal, frankly, but this wasn't. Just a hidden, a game is hidden inside of some commercial software.

    There was a version of Tetris that was hidden in a spreadsheet as an Easter egg. They had something called boss mode control B. So it was quick to type and it. Popped it up, it a dubious sort of Easter egg intended as decoys, coy. And it had a spreadsheet app as well. She could pop back and forth as the boss is looking over your shoulder.

    No, just pop, hit a button and it's a spreadsheet. In this particular case, what happened. Someone at the White House, decided that they would add in some job information isn't this is cool. So if you were looking at the source code for the website, you would see hidden away in there, a job application, Google's done something similar before they have had some.

    Coded messages up on billboards, out in the San Jose area, out in California, and people that we're able to decipher it. They, it told you how to apply for a job. Obviously, they want to have a little bit of fun Microsoft edge, by the way, if you go to edge colon slash. Surf as you are AF and it's only available over on the Microsoft edge thing.

    You have a surfing theme game when you're offline. All you have to do is type in edge colon slash surf. And it's like the windows game ski free. And it challenges you to ride through the water while avoiding islands. Those can be tricky. Very easy to do. Marvel has an interesting one too.

    If you're really totally geeky, you can grab the headers from Marvel.com's website. And the hatters will have a server nickname, field, and call like she helped. Cause I don't know if or not, but Marvel is coming out with a female Hulk. And so this is a. A promotion Ford very geeky stuff.

    Here's another one you can go to naked security.sofos.com. And again, if you look at the headers, which you're not going to see just by going there regularly, there is a header in there. It says, if you're reading this, you should visit blah and apply to join the fund. Mention this header. This 2021 White House website added a job ad as well.

    Presumably they're trying to get some publicity and to attract job applicants to the US digital service. Done it. And it describes itself this USDS as part of the public service, that quote aims to use design and technology to deliver better services to the American people and its goal is to attract some of these technophiles.

    Yeah. That might otherwise be alerted to join the commercial big stuff out there, but you can go there online, directly at usds.gov. And there's a picture there. Fascinating picture. If you ask me because out of one, two, three, four, five, six, seven, eight, nine, 10, 11, 12, people that are in this picture, there is one white male.

    Half of them are females and of the males. And about half are males and of the males. Five of them are not white, which is, it's just interesting. It's such a change from what you normally see advertised online. So it's fun. Cobalt call in an older language, something, I wrote a lot of code in back in the day and you've got new.

    Languages out there like rust. I don't want to get into all of this right now, but it's geeky kind of fun. I also, by the way, wanted to point out going back to Telegram, which we talked about a little bit earlier in the show today. If you want to use end-to-end encryption with Telegram, you have to turn it on for each and every individual you are going to talk to. Okay. That's a real big deal here. It's what they call their secret chats feature. Every individual has to turn it on. So be very careful in order to do what you have to. Tap the contacts name then hit more and then hit start secret chat, and then confirm one prompt asks whether you're sure. So the conversation history from the default chat does not carry over to the secret one. You have to initiate that encryption option. Every time you pick a conversation with a contact. So it isn't like you can set it once and forget it. This isn't a romp appeal thing. It's if you're using telegram every time you have to you want to start a conversation with someone, you have to go into that more menu than the secret menu, and then are you sure?

    Okay. Not good at all. I love this. This comparison saying that this is a guy named. Would you rather go for the car where airbags work every time you get into a crash or going to go for a car where every time you have to turn it on by typing in a pin to enable airbags, why not have them on by default?

    I think the idea is. Pretty obvious why they're doing that right. UAE. They're not trying to really keep secure. And speaking of security here, before the hour's up, I wanted to mention this military intelligence is buying location data instead of getting warrants. Now, this is from a memo that came out. We know Homeland security has been doing that.as well, the DIA, the defense intelligence agency, it's like the CIA, but they provide military intelligence to the department of defense confirmed in this memo that it purchases commercially available smartphone location, data to gather the information that would otherwise require the use of a research warrant.

    How's that for? Interesting. So they have the ability to get information on you just because you are giving it for free. He just gave it right to these app developers, to Google, et cetera. And Google has decided because of what Apple has done. Apple now has said, if you are an app and you are going to be tracking people.

    Apple is going to pop up a permission screen where it informs you that this Google app or whichever app it is asking for permission to track you even across other apps. And you have the ability to say no. Apparently, that really scared Google off. So Google has decided. That they're not going to play that game at all.

    And they changed their code Google maps and some of these others, they change their code so that it does not gather that data, but only on iOS, only on Apple devices, because they were concerned, afraid, whatever word you might want to use, that Apple's disclosure of the fact that they are tracking you.

    Would turn people off from Google. I think that people should have been turned off from Google a very long time ago. I go into search engines as well in my improving windows security course and how to set the right search engines for your browsers and stuff. But bottom line, I like duckduckGo. They have gotten to be very good.

    I've had their founder on the show before it has been, I think, a bit of a godsend because you don't have to use Bing, which of course tracks you. That's Microsoft's search engine. You don't have to use the Google search engine. Just use duck go. It's just harder to say.

    Yeah, I'm going to duck duck go that.

    Okay. Media also, by the way, found out that customs and border patrol buys, license plate, scanner data to track individual movements. They buy cell phone location, data, they all get it. So remember if you have a smartphone or even a cell phone, that data can be sold and used by whoever cares to use it, it's really that simple.

    You might be in for a bit of a shock if you have been working remotely due to this whole lockdown thing. In fact, millions of us are going to have a bit of a shock coming up soon.

    We have been busy here for the first hour. Talking a little bit about the Amazon bait and switch reviews. What I do when I'm online shopping and how you can help keep yourself not just safer, but make sure you don't get ripped off.

    We went through an article from ARS Technica about how he did get ripped off for gifts this season. We also talked a little bit about mobile endpoint security, some of the problems that frankly we've had with our mobile devices. How Jeff Bezos in fact got a massive problem. I got involved with his divorce and everything else because of his mobile device and denial of service attacks. What that is all about?

    We're going to talk this hour a bit about our remote. Workforce the tax implications. We've got another arrest and jail time. So we're going to talk about bad facial recognition and what's going on there. Cyber resilience. And what can we do this year? I really want to get into these hacked home cameras used to live stream police, weight raids in what is called swatting attacks.

    Then Solar winds there are so many ways this massive hack could have been avoided. Our federal agencies have been compromised. Microsoft now says that due to these SolarWinds, hack somebody God into Microsoft source code. Those are the key to the kingdom.

    And one of the ways Microsoft realizes to stay secure is by keeping its source code secret. And of course we, no, that's work. Microsoft has never had any vulnerabilities. So we'll get into that a lot to talk about this hour. First off, let's talk about this problem with taxes. Many of us have problems, if you work in Maine and you work in Massachusetts, you could have a little bit of a tax problem, but there is a reciprocal agreement that's in place.

    So if you had been working in mass and you live in Maine, Okay. I can see that you're driving down to mass every day and you're living in Maine. So the reciprocity agreement covers that. But how about if you have never stepped foot in Massachusetts? How about if you started working for a company out of New York or a company out of California?

    Did you realize that many of these, all of them, by the way, Democrat administrations are now going to require you to pay state taxes, Connecticut, you name it. All of these, it is very concerning to me. And when we get right down to workforces and the fact that this whole lockdown has really accelerated this trend of working from home.

    And because of that, we've got employers who are letting their workers perform their jobs remotely from home most, if not all of the time. So where does illegal nexus tie in? So they're saying, Hey, listen, your employer. And you both knew exactly where you live and work, but the state departments of taxation can have some very different ideas about where here is.

    So as a result, Texas, Utah, Arkansas workers who are working for New York or Massachusetts based companies will have income taxes with health in the paychecks, even if they've never set foot in the home office. Or never set foot in this state. How about that one? The thing for New Hampshire if you live in Maine, of course.

    Yeah. A lot of these states that have state income taxes, will go ahead and say, okay you don't have to worry about paying our state income tax as well. Or in some cases, they look at it and say, Oh, you pay less state income tax. Then we charge our residents. I don't want to call them citizens because we are not being treated like true citizens anymore, but you pay less in your home state than our were residents pay.

    So you don't have to make up the difference as well. So we've gotten dozens of major companies out there all the way through little guys who have been increasing their support from working from home permanently. And I think that's great. We have businesses closing offices. Thank goodness. I don't own business space.

    We've lent our leases laps counting on physical distance, flexible workforce was going to reduce real estate needs. I know one of my daughters is in that boat right now. And in many ways it can be a win-win employers can save overhead costs on those expensive square footage and high-demand cities look at what's happened right now in San Francisco.

    For instance, they are a great example of San Francisco. The city has lost 43% of its tax revenue. So you look at it until K while they've lost a lot of tax revenue because of the lockdown and people aren't going out shopping. They're not buying stuff. No. According to the San Francisco economist and yes, indeed the city of San Francisco has its own economists.

    Know that a 43% drop in revenue is due to people moving out of the city. New York, San Francisco, Los Angeles, all expensive,, and people are moving to Maine, to Montana, dial in from the woods, or get a nice little place down in Florida for instance. But as far as the state's concerned, your beachside can banner might.

    Just as well be right in the middle of downtown Manhattan and you're going to be taxed as such. So we've had these problems for a long time, but living in one state, working in another, but typically it's been adjacent States, just like again, Maine and Massachusetts, right? DC, Maryland, Virginia, maybe Pennsylvania, West Virginia, Delaware.

    Kansas City itself goes across two States. You've got Kansas City, Kansas, and Kansas City, Missouri. So traveling across city limits can mean crossing state lines as well. So any major city near a border has lots of workers that go over the lines back and forth every day. And that's always been tricky from a tax perspective.

    Because both the state where you work and the state where you live is going to want to try and tax your income, but still typically only one state at a time has been able to tax you for your income. And most jurisdictions with a lot of overlaps have agreements, as I said, main and mass and New Hampshire doesn't really have that agreement because they don't have any state income tax or of course sales tax on almost anything.

    But. This is really going to be a problem, frankly. So keep in mind that if you are working for a company that is headquartered or even just has a presence in Arkansas, Connecticut, Delaware, Massachusetts, Nebraska, New York, and Pennsylvania. All of those States have convenient rules on the books that require any work performed for an employer based in their state.

    That it be taxed as if the worker performing the job is actually. In the state, no matter where the employee is actually located now, New Hampshire is one of the nine states that does not have an income tax. And it's right now in the process of suing Massachusetts over its convenience rules and for other States, by the way, New Jersey, Connecticut, Hawaii, and Iowa are supporting the suit.

    So we'll see what happens there in federal courts. As you probably already know going to court doesn't mean the right thing is going to happen. It's gotten really bad, but at any rate, something to be careful about, if you are working remotely for a company, many of these States are going to become an after you for tax dollars.

    We got a couple of things to get in. I want to talk right now about facial recognition. We what a year, maybe more ago talked about this company called clear view AI Clearview. And what they've been doing has been questionable. They've gone online and done searches. They've combed through social media.

    And they've found and downloaded every picture. They can get the grubby little paws on, and then what they've done is they've put together some facial recognition software. So they've violated laws. They've violated platform rules. It's almost like Facebook when it got started, where apparently Zuckerberg went ahead and stole.

    All of the records of all of the kids that were there, going to school at Harvard and including their photographs and put together this little Facebook thing, the Facebook, and had people rating other people by their looks, et cetera, and just basically stole. To get his business started Facebook. That's the allegation that's been out there.

    There'd been a whole movie by this, about what he did. So that's what Clearview did too. They went ahead and decided we'll just steal all of the photos we can of people. They tied facial recognition software into it, and they perform scans of these images that were scraped from the internet and created a biometric database of the images.

    We're going to talk about that and how we now have people being only wrongly accused, but arrested, spent jail time. It's a crazy world out there.

    The allegations are that Clearview stole your picture without your consent and without the consent of the websites you put them on. Now they are being used in this biometric database by the police and others with wrongful arrests.

    Hey, if you want to hear the whole show or an older show, you can find them, just go online to Craig peterson.com. You'll see the podcasts there. I podcast the whole radio show, as well as my appearances on radio and television right there. So you can listen to them as podcasts there or on your favorite podcast app. There you go.

    So we were talking about Clearview using these images that were scraped from the internet illegally. In some cases against obvious usage agreement, as well.

    Now is that they've got this biometric database of the images and they can use that database to match an image of one person to one of these preexisting images that have been analyzed and scanned and maybe stolen, right? Depending on how you want to look at it, the allegations are all the way across the board.

    Now neither you nor anybody else whose image was scraped from the internet, even know that it happened. Let alone give Clearview permission to use your image, right? They didn't get permission to take it, and they're not going to get permission to use it.

    So the details of these practices are not well-received by anybody out there. Even the New York Times came out about it last January, which is when I really started talking about it as well. Within three days of the New York times talking about what this Clearview company did, there was a federal class-action suit that was filed.

    And the complaint opened with a quote from justice Brandice that the greatest, dangerous to Liberty lurk in insidious encroachment by men of zeal well-meaning, but without understanding. So it's very interesting. There's a whole bunch of cases. I'm looking at the list of them right now. These will take a while before everything is finalized on them, but here's something we absolutely.

    Do know for a fact. And that is that there have been arrests that have been made due to this database. Anyone who identifies as a policeman can go ahead and download the app onto their iPhone or other devices. And can then just take a picture of someone casually on the street. There are people who are making police cameras that are constantly streaming video.

    And on the backend are trying to do facial recognition. I've had a couple of them on my radio show a few years back, and it's cool because it gives the policemen an idea of, is this a bad guy or not? There is this somebody who we should trust somebody we could trust. I'm not really that worried about it.

    Just. Think about the most dangerous thing most pleased officers do, which is a traffic stop. They have no idea who's in the car. If that person's going to try and attack them, et cetera. So having a live stream, thinking about Robocop, which didn't end that well, and what was happening there with the ed two Oh nines as well as Robocop himself, being able to see a person and be able to tell right away what this person's background is if there's any wants or warrants, et cetera, out there.

    That's all well and good to a certain degree, but we just had another man. This is a New Jersey man who was accused of shoplifting and trying to hit a police officer with a car. He was wrongfully arrested based on facial recognition. Now, in this case, it's a black man and these facial recognition software programs that are available.

    Tend to do poorly with any minority, frankly. And or do terribly with some and do poorly with any of them and also do rather poorly with the good old, regular Caucasian in phases like mine. Okay. So this is a third person who's arrested for a crime. He did not commit. He spent 10 days in jail and paid around $5,000 to defend himself.

    So this is a guy that had nothing to do with it. The police got lazy, they said, Oh, we got a facial recognition match. It's this guy because they ran it through some software that had scraped some photos from the internet. Do you see where I'm going with this? And those photos from the internet say it's probably this guy, Nigeria parks.

    And we know his social media is saying it's Nigeria parks. This is where he lives. This is where he posts most of his pictures because you remember our pictures. When we take them, Arthur smartphones have embedded GPS information. Oh, my gosh. And in this particular case, he was apparently 30 miles away from the scene of the crime.

    Okay. Pretty sad. Pretty sad. They dismissed the case because of a lack of evidence. Isn't that wonderful? But the department is now getting sued along with the prosecutor in the city of Woodbridge for false arrest, false imprisonment, and violation of his civil rights. I think he should absolutely win on that.

    2019. And this is an article that came from the New York Times. They're saying a national study of over a hundred facial recognition algorithms found that they didn't work as well on black and Asian. Faces, as I said a little bit earlier see an ACL or attorney named Wessler believes that police should stop using facial recognition technology.

    I am okay with it to a degree. I don't think you should be issuing any sort of an arrest warrant based on facial recognition. I think you might get a clue from that and. From that clue, you can look at the phases and decide for yourself and interview the suspect, do some good old fashioned police work, but this facial recognition arresting people, putting them in jail and then costing them thousands of dollars plus their time and their reputation and what it does to your nerves and everything else is just absolutely insane.

    And bad arrests. So this article in the New York times goes through what happened. Apparently, the officers had been presented with a fraudulent driver's license, one of the officer's reports or did that. They saw a big bag of suspected marijuana in the man's prof pocket. They tried to handcuff him and that's when he ran, he had a rental car just goes on and on, but.

    It was a problem. And even though Mr. Parks had been arrested twice and incarcerated for selling drugs release back in 2016, doesn't mean that he's the guy that did all of this. So let's be careful. I'm not fond of what Clearview has done, obviously, just based on how I described it and who I quoted. And I don't like the idea of using this facial recognition technology to arrest people.

    Bottom line. So speaking about arresting people, when we get back, we're going to talk about what is called swatting attacks. I don't know if you've heard of these before. They're pretty common, unfortunately, and some of the technology that we've been bringing into our homes to keep us safer is now being used to put our lives in danger if you can believe that.

    Yeah, absolutely true. We'll be talking about that.

    You can also follow me online. Just go to Craig peterson.com. You can subscribe to my newsletter. I'm not an active poster in Facebook or anywhere else, so the newsletter is the best place to get my weekly show summaries.

    We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up in killing people. Yeah. Yeah. Death by police officer. Here we go.

    If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information. That I have available my podcasts and a few articles that we've written, and you'll also have the opportunity to subscribe to my newsletter. So I'll keep you up to date with the latest, most important articles of the week. I don't send all of my show notes anymore.

    I found that a lot of people. Just don't open them cause it's overwhelming. So I've been lately trying to focus on one tip in particular. So we'll see how this all goes in the future and you can always let me know what you think. Just email me [email protected]. I'd love to know, do prefer to get all of my show notes every week, or do you prefer what I've been doing lately, which is a deeper dive into one topic. That seems to be pretty popular, but I'm getting about a 40% interaction rate, which is really good on such a large list.

    I just want to get the message out is my bottom line.

    We have these home cameras that we have welcomed into our homes. And one of the ones that has been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

    And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings to the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

    There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them a live, real-time access to all of the Ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

    And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring, doorbell cameras.

    Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because of why. Does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate, the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

    And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened on a number of occasions and far more than we like to talk about is that there are.

    The bad guys or people who don't like their neighbors and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting a prank led police to shoot dead 28-year-old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

    After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth.

    You can have teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. Apparently, they believe the report was an act of swatting where somebody makes a false report to a police department that causes the police to respond with a SWAT team.

    Now the audio of this emergency call had been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

    The color also said he had a handgun and had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

    When Mr. Finch came to the door, they said one round was released by the officers after the 28-year-old failed to comply with verbal orders to keep his hands up. Why would he, what did he do wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

    They said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them were dead, injured or taken hostage. His family told local media, he was not involved online gaming.

    Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that the hackers are out there who do this swatting maneuver on somebody. Then they have the hacked Ring camera at that house and they watch the SWAT team respond. Can you believe that?

    The FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices.

    How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that His revenue, his pay from the work he was doing, delivering food to people's homes was stolen by a hacker because he was using the same email address.

    Yes, to log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells that have allowed hackers to steal pet network passwords, et cetera.

    In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, it causes death, many examples of that, and we're still reusing passwords. Give me a break.

    We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

    But anyway our businesses and government got broken that's what we're going to talk about right now.

    Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly, since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

    Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

    And in fact, That's a big problem still, but we'll talk about this right now. SolarWinds is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWinds. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

    We dropped SolarWinds as a vendor, and the reason we dropped them and we made it very clear to them as we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWinds a couple of years ago, and they wouldn't do anything about it.

    So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWinds. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

    Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presume now to be the hand of a Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

    He said SolarWinds, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it an easy target with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWinds websites stopped offering the client the compromised programs.

    Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached too, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

    This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because I, I didn't tell you guys this, but I do love the fact that I was right again.

    How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce.

    Schneider. You've probably seen him before. He is also, I think he writes for the Washington post. But remember when this came out the word about the SolarWindss hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

    Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just the North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

    In other words, going out after other countries in the cyber security realm. And we benefit from the lack of norms that are in cybersecurity, but here's what I really liked. The Bruce said. And I agree with entirely. I'm glad he must listen to the show. The fundamental problem is one of the economic incentives.

    The market rewards, quick development of products. It rewards new features. It rewards spying on customers, end-users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram, or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

    It doesn't reward reliability past a bare minimum, and it does not reward resilience at all. And this is what happened with SolarWinds. SolarWinds ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

    It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure it.

    It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

    I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely in excusable, right. Inexcusable. So this is happening with SolarWindss right now, but it's going to be happening with other places out there.

    We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWinds is a Puerto Rican born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

    The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from Tech Beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the US treasury department was hacked the US Department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cybersecurity, and infrastructure.

    Agency. SISA the department of Homeland security, the U S department of state, the department of justice, the national nuclear security administration, the US Department of energy, three US state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others. I use two of those.

    We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem. How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody - use a password manager and I will have a course on that this year.

    Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

    The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an IT security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

    Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have 1.4 email coming in and going out SMTP Imam.

    They should be controlled and controlled pretty tightly. According to the department of justice, apparently their email accounts were compromised about 4,000 dish. People's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

    It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

    Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email [email protected] and let me know, be glad to send you stuff.

    ME@Craig peterson.com.

    Take care guys.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553.

    1 hr 23 min
  • Tech Talk with Craig Peterson Podcast: Cloud Jacking, Browser Password Protection, Subliminal Messages on White House Website and more

    Welcome!  

    With the rapid pace of change unleashed this past week through Executive Orders, we are now a lot less secure than we were just a month ago and it is going to get a lot worse. But there are somethings you can do technologically to protect your privacy and stay a little more secure. Cloudjacking is possible mainly due to the failure to use secure passwords and a different password for every site and every application you use. Just doing that makes it almost impossible for hackers to carry out their trade. Chrome and by default Microsoft's Edge Browser have put something in their browser to help -- not alleviate but help with this problem.  You can do better by using a true Password Manager and we will get into that as well. Speaking of privacy, the US government is going around its own requirements and buying your location data and other personal information they are not allowed to collect from Data aggregators. We will get into that as well.  Then did you know that the new administration has put subliminal messaging into the White House website -- Yes they have. Well, just a taste of today's topics and there is even more so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Cloud Jacking: The Bold New World of Enterprise Cybersecurity

    Chrome and Edge want to help with that password problem of yours

    Military intelligence buys location data instead of getting warrants, memo shows

    US administration adds “subliminal” ad to White House website

    Why North Korea Excels in Cybercrime

    Speed of Digital Transformation May Lead to Greater App Vulnerabilities

    Waymo CEO dismisses Tesla self-driving plan: “This is not how it works”

    What’s the technology behind a five-minute charge battery?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, there is a new company out there on the forefront of passwords. We're going to talk about that and a few weather things. Of course today.

    Hi everybody. Craig Peterson here. 

    The biggest problem, pretty much all of us have, has to do with our passwords, what we're doing with them, how often we're changing them, how we are storing them. It is being used for quite a few things out there right now. We're seeing a real emphasis on a term you might not have heard before it's cloud jacking.

    This is where someone gained access to your cloud services and then does nefarious things with them. What do you expect them to do now? What does this all mean? It means if you are using something thing, like maybe you're using salesforce.com, maybe you have online banking with your bank.

    Most people do. There are so many cloud services that we use nowadays. And cloud jacking is where someone gained access to that online account. You might ask, how do they do that? How do they gain access to it? The simplest and most common way of doing it is something called password stuffing. Now, I know I'm throwing a lot of terms out there for everybody, but basically, cloud jacking means that cloud service is being used without your permission, your cloud service.

    So again, think about clouds as just a word for somebody else's computer that you have no control over. Cloud services. Generally speaking, are dangerous. Now I know a whole lot of people who think I don't know much about computers. I'm probably a lot better off having some third party manage my computers for me.

    And so I'll just go to Amazon or I'll go to Microsoft or IBM or whomever and have them run my server for me. And in fact, that's what most companies are doing nowadays. Initially, it looked like it was going to save them money. It was going to be a big saving because you didn't have to maintain that data center anymore.

    You didn't have to have the personnel who know the systems who did the updates and stuff. In reality, that's turned out not to be true. Most of the slightly bigger businesses, those smaller to mid midsize are moving their stuff. Out of the cloud because of cloud jacking, because of all of the supposedly expenses that we're going to be saved, not only not being saved but because they don't have control over their computer anymore and they don't have control over the network because remember the cloud is somebody else's their computer it's their network. it's something you have very little control over, so they're moving it back into their business. I think that makes a whole lot of sense. In the meantime, we have many more businesses that are saying you cannot buy our software anymore. You have to use it in the cloud.

    You have to use our cloud license, which to me is just frankly, mind-boggling. Now I can see how it makes it simpler for them because they only have to have one version of the software, maybe two or three as working on the development and they can roll it out a little bit more slowly. They don't have to worry about it.

    People having problems with windows, which is always a nightmare. And we'll try and do support because when it comes to windows, Microsoft, themselves tell you don't run more than one app, one service on that machine. We can't guarantee it. It's not going to work. And then you have to pay them 300 bucks when there's a problem.

    And that 300 bucks don't go very far because they don't guarantee they'll solve that problem. So all of these things have led us to move to the cloud and now some moving back away from the cloud and our cloud servers and our cloud services that we're using on our businesses. Are being hijacked.

    Now I mentioned that one of the things that these hijackers are doing to take over is something called credential stuffing. Another one is fishing. We're not going to talk a lot about fishing right now, but you probably know this already. It's where you get in the email that looks legitimate. It's from somebody that looks legitimate.

    But in fact, it's trying to get you to do something that is going to now give them access to your systems. And in fact, that's what happened to a buddy of mine. I've talked about him before, just a couple of weeks ago. Yeah, he lost his whole paycheck. It's gone and he's not getting it back. And the company is not going to reimburse him for it, which is really a shame, frankly.

    So once credential stuffing, it's something that's been used for cradle quite a while. In fact, way back when. They used to use credential stuffing to try like a thousand, 10,000 most recent passwords, or, most popular passwords. Now that's a problem. Isn't it? What is it? Why are they doing it?

    Back when life was simpler and people use password as their password, or, ABC one, two, three, or the whole top of the keyboard. There were only a few thousand, maybe 10, 20,000 passwords that were in common use, and we've gotten way smarter since then. Haven't we. No, we haven't.

    And I would ask right now that you just take a minute and you go online to have I been poned.com and you can type into, have I been poned your email address? And it'll tell you if it found it anywhere. On the internet. So not just on the internet, but more or less on the dark web on the dark internet, but there's another feature on, have I been poned is spelled P w N E D.

    Have I been poned and that's in the passwords tab. So if you click the password. Tab here. It's saying that right now they have a database of 613 million real-world passwords that have been previously exposed in data breaches. And obviously, this exposure makes them unsuitable for ongoing use.  Why does it make it unsuitable?

    Let's type in right now. We're going to type in P an actually we're going to get fancy P at Sein S w zero R D. So it's a great password, right? Because it's a password with an additional sign instead of an eight and a zero instead of an O. So we're going to type this in and they hit return and let's see what it says.

    Oh my gosh. This password has been seen almost 55,000 times before. Okay. So it's not such a great password out there. It has been breached in data breaches and should never be used if you've ever used it anywhere before change it. And it's going through giving you this list. There are a lot of places.

    Yeah. 55,000 times it's been used. So check it out, go there, check it out. Make sure your password that you're using. Hasn't been used before. And the question is why? That's where we get into. Okay. Problem with credential stuffing. What they'll do is they will use your email address and your passwords that they found online.

    And then they'll try and log in to critical websites like your bank, for instance, we mentioned the bank, so they will try and break into your bank account because they've got your email address and they've got, or password that's what credential stuffing is all about. So they'll just try it on across all kinds of different websites until they can get in.

    So this ties back into our cloud jacking problem. And with cloud jacking, they just go to these online services. Again, it's like your bank or might be Salesforce to get access to your client information or QuickBooks. Maybe there's a whole lot of them are out there and they'll try and log in as you know, most of these websites have.

    Controls on this. So they limit the number of times you can try and log in. So the bad guys know this and they know the ways around it. And some of the ways are just to do it really fast. One of the ways are to do it from different IP addresses. And they do that using, of course, hijacked computers. We called botnets people's home computers, business computers.

    They use them to do their dirty work for them. And now they have control over your systems. Multifactor authentication. That's something I go into in some detail. In my improving windows security course, that's coming up. So if you need more information, that's the place to get it. If you want to find out how to sign up, make sure you just go to Craig peterson.com and sign up for the newsletter.

    I'll let you know when that course is ready. Karen and I are finishing it up now. There's just been too much stuff going on. So I apologize. It's been taken a little longer than I had hoped it would take. But it'll be out pretty soon, but multifactor authentication or two-factor authentication is really becoming a standard and you're foolish if you don't need it.

    Microsoft, Google, and others have been trying to do away with passwords entirely with some whole new technology, which is. Going back and forth. It may come into play. It might not. We'll see how it all goes. There's been some adoption, but it certainly has not been universal, but multifactor authentication absolutely.

    Is universally adopted. So when we get back, we'll talk a little bit more about this. What does it mean? This two-factor authentication multi-factor authentication. How can it stop our cloud accounts from getting hijacked, which is really big? Then we're going to get into Chrome and edge a brand new feature designed to help you with this very problem. 

     You're listening to Craig Peterson and of course, that's all you will find me online. Craig peterson.com. 

    We know about credential stuffing and cloud jacking, and we mentioned multi-factor authentication. So we're going to talk a little more about it, but now

    hi everybody. Craig Peterson here. 

    There are a lot of things that we have to understand and take care of when it comes to our computers. But frankly, one of the things that we have to be the most concerned about, and yet, so many of us just haven't been paying that much attention. Is our password.  We are hearing stories every week of people who have had their accounts hijacked, who have had people take their bank account money right out.

    We've seen that for a couple of years, but it's getting worse and worse.  I'm not exactly sure why you guys are not using unique passwords. For every one of your accounts, I really don't get it. It's easy enough to do use 1password. I don't have any money invested in these companies unless you buy 1password through me which I don't sell.

    I'm not going to make a dime off of it. Use 1password or LastPass, same thing there. I know the CEO of LastPass had him on the show before I don't make a dime off of it. So use them. It's just so easy to do, but yeah. Two-factor authentication. That's a little bit of a different thing. And we want to get into here in just a minute and how you can use that, how to tie it in.

    As I mentioned, I do go into it quite a bit of detail in my course. So if you are interested in that, the improving windows security course, we talk a lot about it. Our friends over at Google have decided they're going to help us out. And here's what they're doing. Number one, they are tying into, have I been poned.com, which you can go to yourself.

    You can get an alert from them. If your account shows up in any of these password dumps that are out there on the internet, very handy. So Google is going to have I been poned on your behalf. And if they notice that your account has shown up on the dark web, they're going to tell you, and they're going to recommend that you change your password.

    So the easy thing to do right now is. Go to Google. If you're using Chrome that is and check your security preferences. And once you're new security preferences, it'll tell you about the accounts that it knows about that you have that have been hacked. Now, when I say it's been hacked, it doesn't mean your account has been hacked, but your information has been stolen usually via some form of a hack.

    If you're using 1password, it has something called Watchtower, which does the same thing. I've got about 2,500 user accounts in my 1password vault. There's actually multiple vaults it's across all of those vaults. So we have some for the business person we have some other stuff that we use for our business clients because we have to maintain the highest levels of security for ourselves, because we have clients that have to have that level of security as well.

    So we in fact have better security than most of our clients do, frankly. And that's a little bit sad, many how. 1password will remind me as well. When one of my accounts, email addresses of passwords show up on the dark web. And it'll also tell me, for instance, if I've got my Craig peterson.com to log in and it shows up somewhere on the dark web, it will tell me that.

    They found Craig peterson.com out of the dark web, whether or not my password was stolen. So it's really nice. 1password can help you with that and it can generate new passwords and you can use it as well for keeping private notes. And when you are generating. Passcodes for two-factor authentication.

    Many times it'll give you a one-time pad. So it'll be a number of single-use passwords that you can use in the event that you don't have your two-factor device with you, as I said, but go into that in a lot of detail in my improving windows security course. But Chrome has done something else and I have to apply them for doing this.

    I am not a big fan, already of Google and Chrome, they make their money, their whole living off of you and your information. And I think that a little bit on the dishonest side, frankly. But that's what they do. Okay. They have added now something that's really quite nice and because Google has added it to Chrome, that means that these Chrome-based browsers will also be picking it up.

    What are the chromium based browsers? Of course, Google Chrome itself is a chromium-based browser, which means it's a certain codebase Microsoft's Edge browser. The latest version of Edge is not a Microsoft product anymore. They're using Google Chrome as its base. They're using chromium. So in both cases, you now have a strong password generator that you can use when you're signing up for a new account or account, or when you're changing an existing password, again, If you've heard me talk about this before that I'm not fond of having a web browser, remember your passwords because who knows, it's not designed for security. Google Chrome usually does a pretty good job. That's why it's such a popular web browser, but I much prefer an application that's specifically designed for security and they know what they're doing. And that's why I recommend the whole 1password thing. So here's what happens when you are on a web page and you are entering in a username and a password, or you're putting in a new password for your account, how it pops up and says, do you want me to save this password?

    Now it is giving you another option here. So rather than having to think up a password, that's really unique. That's a difficult one to guess that is not used anywhere else on the internet. You can now have the generator. Do it for you and generate a very good password. So you're going to look for the browser, suggested password dropdown in the password field, and you can select that and it's going to automatically save your new password to the browser, sync it across all of your other devices.

    If you are signed in to your Google account from all of those other devices so that you can use it in the future. There's another feature called password monitor and it's being added to adjuncts already there in Chrome. And it is a password monitor. Again, most of these guys are using, have I been poned would nothing wrong with that?

    Although have I been poned isn't being paid by these guys for doing it, but checking your passwords can be difficult. But have I been poned has free signup that you can use that will let you know if your username has shown up on any of these hacks out there. And frankly, that's all of these other people are using.

    They've got some very good encryption by the way, for keeping track of your passwords in Epic, they're using homomorphic encryption is what it's called. It's. Pretty new, but it allows computing on encrypted data without decrypting the data first. So that's really cool. It has this hash function that only the server knows they're doing a lot of neat stuff here and Google Chrome team.

    Unveiled their own version of this as well. And they've got a fuller featured password manager now built into the browser. So keep an eye out for those on your chromium based browsers. And have a look at, have I been poned P w N d.com online, if you want some more help on passwords, just drop me an email. [email protected] or sign up for my improving windows security course. 

    You can keep up to date with all of the latest news courses, little training, webinars, by going to Craig peterson.com and signing up right there.

    Hey, I got a quick update here on secure communications. You might've heard about what happened. What's going on there and let's talk about alternatives.

    Hi everybody. Craig Peterson here. 

    You might've heard about WhatsApp, WhatsApp used to be really popular. I've had a listener before, ask me about using WhatsApp overseas. It was a family member who was serving in the military and they wanted something that was secure. They asked about WhatsApp and I said, I don't know. A little bit of moaning and groaning there that I, I don't like WhatsApp because of Facebook.

    Facebook, our friends over there decided that they were a couple of weeks ago going to come out with new terms of use. And that new terms of use have language that made it sound like maybe they'd be spying on us. Now that Facebook has come out and said, no, we're not going to break the end to end encryption.

    In other words, we won't be able to decrypt your conversations. However, we are going to start sharing your information with advertisers, et cetera. Sharing your information about using WhatsApp, which is an encrypted, supposedly secure chat app might cause some problems, right? You can imagine someone knocking on your door and saying, why are you using encrypted communications?

    And in fact, you have every right to, it is the best thing to do. You don't want bad guys getting their hands on it. And in some parts of the world, the governments just can not be trusted and they are trying to monitor everything that's going on. So that's why I've never been a fan of WhatsApp. And why so many people have migrated off of WhatsApp.

    Facebook finally realized what a mistake it was to send out that press release w wasn't as the press release, actually, it was something that came up when you used WhatsApp became right up on your screen. You hadn't to accept it. So it is concerning. Where do we go? Now I think that I suggest you use signal and we cover this quite a bit in a bit of detail in the improving windows security course.

    So in the course, we talk about all these different types of messengers, which ones are the best ones to use and when and why, but I want to point out something about Telegram. Telegram has picked up. I'm looking at some numbers right now, but tens they're saying tens of millions. Wow. Of people have moved over to telegram.

    They said that earlier in January, telegram announced it had hit a milestone of 500 million active. Monthly users and pointed to a single 72 hour period, one 25 million people had joined the service. Now, obviously, this is people who are fleeing some of these censored services that are out there. People who are fleeing from WhatsApp, because who knows where it's going.

    Ultimately. But I want to point out something about Telegram. So first of all, don't use it. All right. Not if you want to be secure, but here are the problems with Telegram. First of all. End-to-end encryption is what you want. So if you are talking to someone over one of these encrypted apps, you want that message, that voice conversation, that video to be encrypted from the time it leaves your device.

    Until it arrives on the person you're talking to his device. It's almost certainly going to go through a server or two or three or four. It's going to go through routers. There are ways to intercept it, but if it's encrypted end to end, it won't do much good to intercept in the middle. Our encryption today is really quite good.

    Now, if the government wants to get its hands on it, they're on your communications. There are ways around it. However, when it comes to just cast casting, a big fishing net, nothing's going to happen. And they're just going to cast a net. They're going to catch all of this stuff and there's nothing in it.

    We know that various intelligence agencies around the world try and keep copies of everything in case, later on, they want to go back and examine it and see what was said after the fact. Whatever, more power to them, Telegram by default does not have an end to end encryption. So by default, yes, it has encryption, but the encryption goes from your phone to their server.

    And once it's on the server, it is no longer encrypted. And then on the remote side for the person you're talking to, it's encrypted from the server to that person that you're talking to on the far end. See where the problem can come in here. Particularly if you are in a country that does not treat its citizens, residents, whatever you might want to call these people from serfs on up, that doesn't treat them well. They can potentially force telegram to give them a complete copy of everything that was said or done. That is a problem. That is a very big problem. You are not going to get by default end encryption. However, you can turn it on. On telegram now on Signal. It is by default.

    It is end to end. It's always end-to-end. Okay. So telegram only encrypt by default messages between your device and the telegram server and the telegram server and the other person on the other end. However, the group messaging feature that telegram has offers no end to end encryption at all. None. So we have a group of people.

    Who've got family members that you're talking, or maybe it's some investors, and you're talking about buying some more real estate for your investment trust, or you are talking with your accountant about, bank numbers and things, and yeah. You've got the attorney on, or maybe you're just talking to some friends and you don't have anything you want to share with those prying intelligence agencies in some of these countries out there, you are not secure because right in the middle, you have your messages in cleartext.

    So where is Telegram located? It is based in the United Arab Emirates. That is scary. When they have servers over in the United Arab Emirates, you already know that you don't have much of a sense of security over there. And you certainly don't have privacy. So don't use Telegram. If you want to be secure, we've got tens of millions of WhatsApp users who flee the service.

    Many of them went to Telegram. No doubt. They were attracted by Telegrams claims of heavily encrypted messaging. But in fact, it's not true. Okay. People do not want to exchange privacy for free services. Now the nice thing about Signal is it is open source and they are not trying to make money off of signal it's available freely.

    Anyone can grab the source code and the signal encryption methodology. Is used by WhatsApp as well, but we already expressed some of my concerns about WhatsApp. 

    Hey, if you want to learn more about this, more about improving windows security, more about communicating securely, I've got it all covered in my improving windows security course that's coming up in a couple of weeks. 

    Make sure you sign up. Just go to craigpeterson.com. You can sign up anywhere on that website or go to Craig peterson.com/subscribe. And you'll get my weekly newsletter as well. 

    Shortly after Joe Biden took office, we started seeing some subliminal messages right there on the White House home page.

    Hi everybody. Craig Peterson here. Thanks for joining me.

    Let me tell you I'm not trying to start some sort of a rumor here. This is absolutely true. You might've heard about Easter eggs before? No, I'm not talking about the type that you know, that little bunny comes with the colored dyed hard-boiled eggs, or maybe they're little plastic aides with candy inside. Some of that Candy's kind of yummy.  Of it's just horrific it's at least it's not as bad as mean with those little corn things that are nasty. 

    Anyhow Easter eggs are in movies. Have you seen them in the Marvel movies? For instance, they use them quite a bit. These are little things that are hidden away so that people who are watching super fans can find them. It might be just something on a shelf. Behind in one of the movies. So it's on a set and it's something from another movie.

    It might be a movie that the director loves, or maybe it's another movie. That's part of the series. Those are Easter eggs are hidden away. They're there, but they're hidden. I think those are cool to try and spot sometimes. The White House added an Easter egg, this subliminal ad to the White House website shortly after president Biden took office.

    It's really just absolutely amazing, but one of the most famous Easter eggs in software history and this was pretty complex as well as in Microsoft Excel 97, Microsoft Excel, that's their spreadsheet software. And this is from 20 plus years ago, 23, 24, whatever it is back in 97. You could open a new workbook, hit F five type in L 97, colon X 97, enter and then tab and then control shift, click on the chart, wizard icon.

    And all of a sudden you are in to. Flight simulator. You didn't have to buy a flight simulator pretty cool. And you flew using the mouse and then when you were done, you hit escape. And that was cool. I thought it was phenomenal, frankly, but this wasn't. Just a hidden, a game is hidden inside of some commercial software.

    There was a version of Tetris that was hidden in a spreadsheet as an Easter egg. They had something called boss mode control B. So it was quick to type and it. Popped it up, it a dubious sort of Easter egg intended as decoys, coy. And it had a spreadsheet app as well. She could pop back and forth as the boss is looking over your shoulder.

    No, just pop, hit a button and it's a spreadsheet. In this particular case, what happened. Someone at the White House, decided that they would add in some job information isn't this is cool. So if you were looking at the source code for the website, you would see hidden away in there, a job application, Google's done something similar before they have had some.

    Coded messages up on billboards, out in the San Jose area, out in California, and people that we're able to decipher it. They, it told you how to apply for a job. Obviously, they want to have a little bit of fun Microsoft edge, by the way, if you go to edge colon slash. Surf as you are AF and it's only available over on the Microsoft edge thing.

    You have a surfing theme game when you're offline. All you have to do is type in edge colon slash surf. And it's like the windows game ski free. And it challenges you to ride through the water while avoiding islands. Those can be tricky. Very easy to do. Marvel has an interesting one too.

    If you're really totally geeky, you can grab the headers from Marvel.com's website. And the hatters will have a server nickname, field, and call like she helped. Cause I don't know if or not, but Marvel is coming out with a female Hulk. And so this is a. A promotion Ford very geeky stuff.

    Here's another one you can go to naked security.sofos.com. And again, if you look at the headers, which you're not going to see just by going there regularly, there is a header in there. It says, if you're reading this, you should visit blah and apply to join the fund. Mention this header. This 2021 White House website added a job ad as well.

    Presumably they're trying to get some publicity and to attract job applicants to the US digital service. Done it. And it describes itself this USDS as part of the public service, that quote aims to use design and technology to deliver better services to the American people and its goal is to attract some of these technophiles.

    Yeah. That might otherwise be alerted to join the commercial big stuff out there, but you can go there online, directly at usds.gov. And there's a picture there. Fascinating picture. If you ask me because out of one, two, three, four, five, six, seven, eight, nine, 10, 11, 12, people that are in this picture, there is one white male.

    Half of them are females and of the males. And about half are males and of the males. Five of them are not white, which is, it's just interesting. It's such a change from what you normally see advertised online. So it's fun. Cobalt call in an older language, something, I wrote a lot of code in back in the day and you've got new.

    Languages out there like rust. I don't want to get into all of this right now, but it's geeky kind of fun. I also, by the way, wanted to point out going back to Telegram, which we talked about a little bit earlier in the show today. If you want to use end-to-end encryption with Telegram, you have to turn it on for each and every individual you are going to talk to. Okay. That's a real big deal here. It's what they call their secret chats feature. Every individual has to turn it on.  So be very careful in order to do what you have to. Tap the contacts name then hit more and then hit start secret chat, and then confirm one prompt asks whether you're sure. So the conversation history from the default chat does not carry over to the secret one. You have to initiate that encryption option. Every time you pick a conversation with a contact. So it isn't like you can set it once and forget it. This isn't a romp appeal thing. It's if you're using telegram every time you have to you want to start a conversation with someone, you have to go into that more menu than the secret menu, and then are you sure?

    Okay. Not good at all. I love this. This comparison saying that this is a guy named. Would you rather go for the car where airbags work every time you get into a crash or going to go for a car where every time you have to turn it on by typing in a pin to enable airbags, why not have them on by default?

    I think the idea is. Pretty obvious why they're doing that right. UAE. They're not trying to really keep secure. And speaking of security here, before the hour's up, I wanted to mention this military intelligence is buying location data instead of getting warrants. Now, this is from a memo that came out. We know Homeland security has been doing that.as well, the DIA, the defense intelligence agency, it's like the CIA, but they provide military intelligence to the department of defense confirmed in this memo that it purchases commercially available smartphone location, data to gather the information that would otherwise require the use of a research warrant.

    How's that for? Interesting. So they have the ability to get information on you just because you are giving it for free. He just gave it right to these app developers, to Google, et cetera. And Google has decided because of what Apple has done. Apple now has said, if you are an app and you are going to be tracking people.

    Apple is going to pop up a permission screen where it informs you that this Google app or whichever app it is asking for permission to track you even across other apps. And you have the ability to say no. Apparently, that really scared Google off. So Google has decided. That they're not going to play that game at all.

    And they changed their code Google maps and some of these others, they change their code so that it does not gather that data, but only on iOS, only on Apple devices, because they were concerned, afraid, whatever word you might want to use, that Apple's disclosure of the fact that they are tracking you.

    Would turn people off from Google. I think that people should have been turned off from Google a very long time ago. I go into search engines as well in my improving windows security course and how to set the right search engines for your browsers and stuff. But bottom line, I like duckduckGo. They have gotten to be very good.

    I've had their founder on the show before it has been, I think, a bit of a godsend because you don't have to use Bing, which of course tracks you. That's Microsoft's search engine. You don't have to use the Google search engine. Just use duck go. It's just harder to say.

    Yeah, I'm going to duck duck go that.

     Okay. Media also, by the way, found out that customs and border patrol buys, license plate, scanner data to track individual movements. They buy cell phone location, data, they all get it. So remember if you have a smartphone or even a cell phone, that data can be sold and used by whoever cares to use it, it's really that simple.

    You might be in for a bit of a shock if you have been working remotely due to this whole lockdown thing. In fact, millions of us are going to have a bit of a shock coming up soon.

     We have been busy here for the first hour. Talking a little bit about the Amazon bait and switch reviews. What I do when I'm online shopping and how you can help keep yourself not just safer, but make sure you don't get ripped off.

    We went through an article from ARS Technica about how he did get ripped off for gifts this season. We also talked a little bit about mobile endpoint security, some of the problems that frankly we've had with our mobile devices. How Jeff Bezos in fact got a massive problem. I got involved with his divorce and everything else because of his mobile device and denial of service attacks. What that is all about? 

    We're going to talk this hour a bit about our remote. Workforce the tax implications. We've got another arrest and jail time. So we're going to talk about bad facial recognition and what's going on there. Cyber resilience. And what can we do this year? I really want to get into these hacked home cameras used to live stream police, weight raids in what is called swatting attacks.

    Then Solar winds there are so many ways this massive hack could have been avoided. Our federal agencies have been compromised. Microsoft now says that due to these SolarWinds, hack somebody God into Microsoft source code. Those are the key to the kingdom.

    And one of the ways Microsoft realizes to stay secure is by keeping its source code secret. And of course we, no, that's work. Microsoft has never had any vulnerabilities. So we'll get into that a lot to talk about this hour. First off, let's talk about this problem with taxes. Many of us have problems, if you work in Maine and you work in Massachusetts, you could have a little bit of a tax problem, but there is a reciprocal agreement that's in place.

    So if you had been working in mass and you live in Maine, Okay. I can see that you're driving down to mass every day and you're living in Maine. So the reciprocity agreement covers that. But how about if you have never stepped foot in Massachusetts? How about if you started working for a company out of New York or a company out of California?

    Did you realize that many of these, all of them, by the way, Democrat administrations are now going to require you to pay state taxes, Connecticut, you name it. All of these, it is very concerning to me. And when we get right down to workforces and the fact that this whole lockdown has really accelerated this trend of working from home.

    And because of that, we've got employers who are letting their workers perform their jobs remotely from home most, if not all of the time. So where does illegal nexus tie in? So they're saying, Hey, listen, your employer. And you both knew exactly where you live and work, but the state departments of taxation can have some very different ideas about where here is.

    So as a result, Texas, Utah, Arkansas workers who are working for New York or Massachusetts based companies will have income taxes with health in the paychecks, even if they've never set foot in the home office. Or never set foot in this state. How about that one? The thing for New Hampshire if you live in Maine, of course.

    Yeah. A lot of these states that have state income taxes, will go ahead and say, okay you don't have to worry about paying our state income tax as well. Or in some cases, they look at it and say, Oh, you pay less state income tax. Then we charge our residents. I don't want to call them citizens because we are not being treated like true citizens anymore, but you pay less in your home state than our were residents pay.

    So you don't have to make up the difference as well. So we've gotten dozens of major companies out there all the way through little guys who have been increasing their support from working from home permanently. And I think that's great. We have businesses closing offices. Thank goodness. I don't own business space.

    We've lent our leases laps counting on physical distance, flexible workforce was going to reduce real estate needs. I know one of my daughters is in that boat right now. And in many ways it can be a win-win employers can save overhead costs on those expensive square footage and high-demand cities look at what's happened right now in San Francisco.

    For instance, they are a great example of San Francisco. The city has lost 43% of its tax revenue. So you look at it until K while they've lost a lot of tax revenue because of the lockdown and people aren't going out shopping. They're not buying stuff. No. According to the San Francisco economist and yes, indeed the city of San Francisco has its own economists.

    Know that a 43% drop in revenue is due to people moving out of the city. New York, San Francisco, Los Angeles, all expensive,, and people are moving to Maine, to Montana, dial in from the woods, or get a nice little place down in Florida for instance. But as far as the state's concerned, your beachside can banner might.

    Just as well be right in the middle of downtown Manhattan and you're going to be taxed as such. So we've had these problems for a long time, but living in one state, working in another, but typically it's been adjacent States, just like again, Maine and Massachusetts, right? DC, Maryland, Virginia, maybe Pennsylvania, West Virginia, Delaware.

    Kansas City itself goes across two States. You've got Kansas City, Kansas, and Kansas City, Missouri. So traveling across city limits can mean crossing state lines as well. So any major city near a border has lots of workers that go over the lines back and forth every day. And that's always been tricky from a tax perspective.

    Because both the state where you work and the state where you live is going to want to try and tax your income, but still typically only one state at a time has been able to tax you for your income. And most jurisdictions with a lot of overlaps have agreements, as I said, main and mass and New Hampshire doesn't really have that agreement because they don't have any state income tax or of course sales tax on almost anything.

    But. This is really going to be a problem, frankly. So keep in mind that if you are working for a company that is headquartered or even just has a presence in Arkansas, Connecticut, Delaware, Massachusetts, Nebraska, New York, and Pennsylvania. All of those States have convenient rules on the books that require any work performed for an employer based in their state.

    That it be taxed as if the worker performing the job is actually. In the state, no matter where the employee is actually located now, New Hampshire is one of the nine states that does not have an income tax. And it's right now in the process of suing Massachusetts over its convenience rules and for other States, by the way, New Jersey, Connecticut, Hawaii, and Iowa are supporting the suit.

    So we'll see what happens there in federal courts. As you probably already know going to court doesn't mean the right thing is going to happen. It's gotten really bad, but at any rate, something to be careful about, if you are working remotely for a company, many of these States are going to become an after you for tax dollars.

    We got a couple of things to get in. I want to talk right now about facial recognition. We what a year, maybe more ago talked about this company called clear view AI Clearview. And what they've been doing has been questionable. They've gone online and done searches. They've combed through social media.

    And they've found and downloaded every picture. They can get the grubby little paws on, and then what they've done is they've put together some facial recognition software. So they've violated laws. They've violated platform rules. It's almost like Facebook when it got started, where apparently Zuckerberg went ahead and stole.

    All of the records of all of the kids that were there, going to school at Harvard and including their photographs and put together this little Facebook thing, the Facebook, and had people rating other people by their looks, et cetera, and just basically stole. To get his business started Facebook. That's the allegation that's been out there.

    There'd been a whole movie by this, about what he did. So that's what Clearview did too. They went ahead and decided we'll just steal all of the photos we can of people. They tied facial recognition software into it, and they perform scans of these images that were scraped from the internet and created a biometric database of the images.

    We're going to talk about that and how we now have people being only wrongly accused, but arrested, spent jail time. It's a crazy world out there. 

    The allegations are that Clearview stole your picture without your consent and without the consent of the websites you put them on. Now they are being used in this biometric database by the police and others with wrongful arrests.

    Hey, if you want to hear the whole show or an older show, you can find them, just go online to Craig peterson.com. You'll see the podcasts there. I podcast the whole radio show, as well as my appearances on radio and television right there. So you can listen to them as podcasts there or on your favorite podcast app. There you go. 

    So we were talking about Clearview using these images that were scraped from the internet illegally. In some cases against obvious usage agreement, as well. 

     Now is that they've got this biometric database of the images and they can use that database to match an image of one person to one of these preexisting images that have been analyzed and scanned and maybe stolen, right? Depending on how you want to look at it, the allegations are all the way across the board. 

    Now neither you nor anybody else whose image was scraped from the internet, even know that it happened. Let alone give Clearview permission to use your image, right? They didn't get permission to take it, and they're not going to get permission to use it.

    So the details of these practices are not well-received by anybody out there. Even the New York Times came out about it last January, which is when I really started talking about it as well. Within three days of the New York times talking about what this Clearview company did, there was a federal class-action suit that was filed.

    And the complaint opened with a quote from justice Brandice that the greatest, dangerous to Liberty lurk in insidious encroachment by men of zeal well-meaning, but without understanding. So it's very interesting. There's a whole bunch of cases. I'm looking at the list of them right now. These will take a while before everything is finalized on them, but here's something we absolutely.

    Do know for a fact. And that is that there have been arrests that have been made due to this database. Anyone who identifies as a policeman can go ahead and download the app onto their iPhone or other devices. And can then just take a picture of someone casually on the street. There are people who are making police cameras that are constantly streaming video.

    And on the backend are trying to do facial recognition. I've had a couple of them on my radio show a few years back, and it's cool because it gives the policemen an idea of, is this a bad guy or not? There is this somebody who we should trust somebody we could trust. I'm not really that worried about it.

    Just. Think about the most dangerous thing most pleased officers do, which is a traffic stop. They have no idea who's in the car. If that person's going to try and attack them, et cetera. So having a live stream, thinking about Robocop, which didn't end that well, and what was happening there with the ed two Oh nines as well as Robocop himself, being able to see a person and be able to tell right away what this person's background is if there's any wants or warrants, et cetera, out there.

    That's all well and good to a certain degree, but we just had another man. This is a New Jersey man who was accused of shoplifting and trying to hit a police officer with a car. He was wrongfully arrested based on facial recognition. Now, in this case, it's a black man and these facial recognition software programs that are available.

    Tend to do poorly with any minority, frankly. And or do terribly with some and do poorly with any of them and also do rather poorly with the good old, regular Caucasian in phases like mine. Okay. So this is a third person who's arrested for a crime. He did not commit. He spent 10 days in jail and paid around $5,000 to defend himself.

    So this is a guy that had nothing to do with it. The police got lazy, they said, Oh, we got a facial recognition match. It's this guy because they ran it through some software that had scraped some photos from the internet. Do you see where I'm going with this? And those photos from the internet say it's probably this guy, Nigeria parks.

    And we know his social media is saying it's Nigeria parks. This is where he lives. This is where he posts most of his pictures because you remember our pictures. When we take them, Arthur smartphones have embedded GPS information. Oh, my gosh. And in this particular case, he was apparently 30 miles away from the scene of the crime.

    Okay. Pretty sad. Pretty sad. They dismissed the case because of a lack of evidence. Isn't that wonderful? But the department is now getting sued along with the prosecutor in the city of Woodbridge for false arrest, false imprisonment, and violation of his civil rights. I think he should absolutely win on that.

    2019. And this is an article that came from the New York Times. They're saying a national study of over a hundred facial recognition algorithms found that they didn't work as well on black and Asian. Faces, as I said a little bit earlier see an ACL or attorney named Wessler believes that police should stop using facial recognition technology.

    I am okay with it to a degree. I don't think you should be issuing any sort of an arrest warrant based on facial recognition. I think you might get a clue from that and. From that clue, you can look at the phases and decide for yourself and interview the suspect, do some good old fashioned police work, but this facial recognition arresting people, putting them in jail and then costing them thousands of dollars plus their time and their reputation and what it does to your nerves and everything else is just absolutely insane.

    And bad arrests. So this article in the New York times goes through what happened. Apparently, the officers had been presented with a fraudulent driver's license, one of the officer's reports or did that. They saw a big bag of suspected marijuana in the man's prof pocket. They tried to handcuff him and that's when he ran, he had a rental car just goes on and on, but.

    It was a problem. And even though Mr. Parks had been arrested twice and incarcerated for selling drugs release back in 2016, doesn't mean that he's the guy that did all of this. So let's be careful. I'm not fond of what Clearview has done, obviously, just based on how I described it and who I quoted. And I don't like the idea of using this facial recognition technology to arrest people.

    Bottom line. So speaking about arresting people, when we get back, we're going to talk about what is called swatting attacks. I don't know if you've heard of these before. They're pretty common, unfortunately, and some of the technology that we've been bringing into our homes to keep us safer is now being used to put our lives in danger if you can believe that. 

    Yeah, absolutely true. We'll be talking about that. 

    You can also follow me online. Just go to Craig peterson.com. You can subscribe to my newsletter. I'm not an active poster in Facebook or anywhere else, so the newsletter is the best place to get my weekly show summaries.

    We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up in killing people. Yeah. Yeah. Death by police officer. Here we go.

     If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information. That I have available my podcasts and a few articles that we've written, and you'll also have the opportunity to subscribe to my newsletter. So I'll keep you up to date with the latest, most important articles of the week. I don't send all of my show notes anymore.

    I found that a lot of people. Just don't open them cause it's overwhelming. So I've been lately trying to focus on one tip in particular. So we'll see how this all goes in the future and you can always let me know what you think. Just email me [email protected]. I'd love to know, do prefer to get all of my show notes every week, or do you prefer what I've been doing lately, which is a deeper dive into one topic. That seems to be pretty popular, but I'm getting about a 40% interaction rate, which is really good on such a large list. 

    I just want to get the message out is my bottom line.

    We have these home cameras that we have welcomed into our homes. And one of the ones that has been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

    And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings to the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

    There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them a live, real-time access to all of the Ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

    And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring, doorbell cameras.

    Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because of why. Does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate, the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

    And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened on a number of occasions and far more than we like to talk about is that there are.

    The bad guys or people who don't like their neighbors and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting a prank led police to shoot dead 28-year-old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

    After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth.

    You can have teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. Apparently, they believe the report was an act of swatting where somebody makes a false report to a police department that causes the police to respond with a SWAT team.

    Now the audio of this emergency call had been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

    The color also said he had a handgun and had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

    When Mr. Finch came to the door, they said one round was released by the officers after the 28-year-old failed to comply with verbal orders to keep his hands up. Why would he, what did he do wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

    They said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them were dead, injured or taken hostage. His family told local media, he was not involved online gaming.

    Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that the hackers are out there who do this swatting maneuver on somebody. Then they have the hacked Ring camera at that house and they watch the SWAT team respond. Can you believe that?

    The FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices.

    How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that His revenue, his pay from the work he was doing, delivering food to people's homes was stolen by a hacker because he was using the same email address.

    Yes, to log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells that have allowed hackers to steal pet network passwords, et cetera.

    In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, it causes death, many examples of that, and we're still reusing passwords. Give me a break.

    We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me. 

    But anyway our businesses and government got broken that's what we're going to talk about right now.

    Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly, since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

    Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

    And in fact, That's a big problem still, but we'll talk about this right now. SolarWinds is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWinds. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

    We dropped SolarWinds as a vendor, and the reason we dropped them and we made it very clear to them as we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWinds a couple of years ago, and they wouldn't do anything about it.

    So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWinds. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

    Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presume now to be the hand of a Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

    He said SolarWinds, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it an easy target with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWinds websites stopped offering the client the compromised programs.

    Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached too, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

    This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because I, I didn't tell you guys this, but I do love the fact that I was right again.

    How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce.

    Schneider. You've probably seen him before. He is also, I think he writes for the Washington post. But remember when this came out the word about the SolarWindss hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

    Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just the North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

    In other words, going out after other countries in the cyber security realm. And we benefit from the lack of norms that are in cybersecurity, but here's what I really liked. The Bruce said. And I agree with entirely. I'm glad he must listen to the show. The fundamental problem is one of the economic incentives.

    The market rewards, quick development of products. It rewards new features. It rewards spying on customers, end-users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram, or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

    It doesn't reward reliability past a bare minimum, and it does not reward resilience at all. And this is what happened with SolarWinds. SolarWinds ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

    It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure it.

    It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

    I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely in excusable, right. Inexcusable. So this is happening with SolarWindss right now, but it's going to be happening with other places out there.

    We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWinds is a Puerto Rican born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

    The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from Tech Beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the US treasury department was hacked the US Department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cybersecurity, and infrastructure.

    Agency. SISA the department of Homeland security, the U S department of state, the department of justice, the national nuclear security administration, the US Department of energy, three US state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others. I use two of those.

    We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem. How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody - use a password manager and I will have a course on that this year.

    Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

    The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an IT security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

    Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have 1.4 email coming in and going out SMTP Imam.

    They should be controlled and controlled pretty tightly. According to the department of justice, apparently their email accounts were compromised about 4,000 dish. People's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

    It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what  they need access to?  Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense. 

    Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email [email protected] and let me know, be glad to send you stuff. 

    ME@Craig peterson.com. 

    Take care guys.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553.

    1 hr 23 min
  • AS HEARD ON: WGAN Mornings News with Matt Gagnon: Cloud Jacking, Passwords, Data Aggregators and the Government

    Good morning everybody!

    I was on WGAN this morning with Matt Gagnon and started this morning talking about Cloud Jacking what it is and how it is done. Then we discussed how to prevent it and that is by having good strong passwords that are different for each site you visit. We discussed password managers. Then we got into how the Government is getting around laws on tracking you -- they are buying data from Data aggregators. Here we go with Matt.

    And more tech tips, news, and updates visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: Hey, good morning, everybody. Craig Peterson here. I've got my early morning voice on this morning. It's a little cloggy. I was on this morning with Mr. Matt Gagnon. We talked about a few different things, including the new Chrome and Edge browser. Features and why Microsoft edge picked it up.

    [00:00:20] Also, the military intelligence is buying data on you. Where are they getting it? Why are they getting it? What's with cloud jacking and the rise of cloud jacking. Here we go with Mr. Matt Gagnon.

    [00:00:35] Matt Gagnon: It's all things. Technology tech talk with Craig Peterson right now on news radio 98, five FM and am five 60 WGAN seven 36 Wednesday morning.

    [00:00:49]Craig Peterson joining us as always on this time at this day, Craig, how are you this morning? Hey,

    [00:00:55] Craig Peterson: I'm here now. I'm ready to go.

    [00:00:59]Matt Gagnon: Well, let's get going on the topics of the day, if you don't mind. So you need to explain to probably the audience and myself, what cloud jacking is.

    [00:01:07] Why don't we start there?

    [00:01:08] Craig Peterson: Sure. This is a whole new problem. The cloud is just another word for somebody else's computer that you have no control over. It just amazed me how many companies thought, we'll just rush to the cloud. We'll use these cloud services and there's a lot of them out there now, and we don't have to worry about anything anymore. In reality, you do.

    [00:01:33] Microsoft does not guarantee that if you're using their windows, their Microsoft three 65 and their licenses and their email. They don't guarantee that data is not going to be lost or deleted accidentally. In fact, there was a huge problem with Microsoft dropping all of the conversations in Microsoft teams for one of these fortune 100 companies and just shrugging their shoulders.

    [00:01:58]The other problem has to do with security. You cannot assume that these cloud services are secure. Most of the businesses nowadays, and this is just no end of frustration to me, on trying to be first to market, they're not worrying about the longevity, the backups, the security, or anything that, really, they shouldn't be caring about. They're just worrying about having a product that mostly works and it's almost always in the cloud.

    [00:02:30]That brings up this cloud jacking problem, even though we've got all of this great cloud computing and it's going to save the world. The bottom line is the hackers are going after it.

    [00:02:43]They're going after it in a very big way. They're taking over business accounts that are up in the cloud. Remember, what about passwords, Matt? We've talked about it before, people are not using good passwords are not using password managers. I have a friend who he's in his seventies now. He drives for grub hub. That's how he makes a little bit extra money. So he has his online cloud account with grub hub. This is true for so many things. I'm just using this as an example. He noticed that he was due 700 and change payment. This was his wonderful paycheck coming in from delivering groceries in his seventies.

    [00:03:25] He's climbing stairs, he's bringing stuff around, he's working hard for it. What had happened is someone went ahead used the email address that they found in one of these dumps from one of these hacks. Used his password that they found in one of these dumps from one of these apps and hijacked his account.

    [00:03:46]There goes $700 of hard labor. It went right into the account or the bad guys, and he's kinda clamoring and I helped him out. I go ahead and go in with one password. You got to use a password manager.

    [00:04:01]The bad guys have now access to over 1 billion accounts with email addresses and passwords. They are all online people. Check them out. You can go to a website called, have I been poned pwn ed check there. Put in your email address. It'll tell you if the bad guys know your password.

    [00:04:26] They're just stuffing them in, Matt, and their cloud jackin. They're taking over your cloud account because if it had been on his computers, his business computers, or had been on Grubhubs computers, it would have been harder for people to break into. But because it's just on the web, I was just like, "I'm going to use, why I have three passwords that I use across the internet." It drives me crazy.

    [00:04:50]Matt Gagnon: We're speaking with Craig Peterson, our tech guru, who joins us on Wednesdays at this time.

    [00:04:54]Speaking of passwords, if you're having trouble with those passwords generating a good one, remembering them, et cetera. There is perhaps a solution with Google Chrome and Edge.

    [00:05:04] Craig Peterson: Yeah, there are a lot, a lot of companies that are trying to help us here with this problem, because this is a very big problem. Microsoft and Google both have a goal of completely eliminating passwords and not a bad idea, but we're nowhere near that right now.

    [00:05:21] So remember Microsoft Edge browser, isn't really Microsoft Edge. It is actually now Chrome under the hood. And both of them now, because Chrome has added it so guess what Microsoft gets it for free. They've added a nice little feature that tracks your passwords, what you're using, and also now helps you generate new passwords, safe ones, secure ones, and Google has gone an extra step, and I've got to praise them a bit for this. If you are saving your passwords using Google Chrome, it keeps an eye on the websites that are hacked and it keeps your an eye on your password and will let you know if your account has been effectively exposed with a username and password.

    [00:06:13]Using this new password generator, I think is a good step. If you're not going to get a real password manager again, get one password or last pass. Chrome and Edge are going to come to the rescue, give you this password generator with passwords that are hard to guess.

    [00:06:31]By the way, the current thinking on good passwords has nothing to do with an uppercase character, a lowercase, a special symbol, and number. Now a days the best passwords are little phrases that are joined together. You might have three words, problem challenge, solution, all separated by like the number two or a dash. That's one of the best passwords you can get.

    [00:06:56] This is great built in strong password generator. It could save you your paycheck and it would have saved the paycheck of my buddy.

    [00:07:06] Matt Gagnon: We're speaking with Craig Peterson, our tech guru, who joins us this time every Wednesday to go over what's happening in the world of technology.

    [00:07:12] You can also hear him on Saturdays at one o'clock for many of these very same topics in more depth. Finally Craig, the military intelligence buying location data, instead of getting warrants, according to a recent memo here. Tell me more about this story.

    [00:07:26] Craig Peterson: Ooh, this is something I've been warning about for a long time, right? If it's free, your probably the product. That's very, very true because so many of these free little apps are doing things in the background you may not be aware of including keeping track of where you are.

    [00:07:44] So Homeland security and now military intelligence agency, the defense intelligence agency have both been caught, if you will ,going to the data aggregators that are taking all of the data from all of these little apps that you have. That are they fun, they're free.

    [00:08:04] You know, the I have a hundred apps on my phone and I only use six of them, which is pretty common, by the way, those other apps are leaking information about you. Even some of the ones that you are using are leaking it. So this is a very, very big problem.

    [00:08:19] In the United States, they cannot monitor you , or your location without a warrant with some exceptions, but this is allowing them now to get full access to you where you are, where you're going. Thats sort of what Homeland security has been using it for.

    [00:08:37]Now it turns out that's what the defense intelligence agency has been using it for as well. This is a big fat loophole. That they are driving massive trucks through. It's just incredible. Oh, and by the way, there are all the license plate scanners out there. You might not be aware of it, but in some areas, if you get tickets, they will issue a warrant for your car after a period of time.

    [00:09:04]There's tow truck operators driving around that have license plates scanners on your cars and they'll drive to a parking structure or through a mall. They'll find cars that they can go ahead and tow and make some money on all of that license plate data. It Is also being set into this and many of the cities and towns that have license plate capture cameras or also selling it.

    [00:09:29]Your data is out there and we've got to take this back, Matt, we've got to stop allowing them to collect all this data on us. Apple's taken a very good step towards that. Now in the app store, they're the first to show you everything that any app is collecting on you right there in the app store.

    [00:09:49] Matt Gagnon: All right. That's Craig Peterson, our tech guru. Joining us at this time every Wednesday to go over the world of technology. Thank you as always, Craig, appreciate you joining us here and we will talk to you again next week, sir.

    [00:09:59] Craig Peterson: Thanks again, Matt.

    [00:10:00] Matt Gagnon: You bet. All right, so coming up next, we're gonna take a quick break here.

    [00:10:03] Craig Peterson: I got some good news too on this course. Oh my gosh. It's been a labor of love. But this improving windows security course, it's almost done. Been busy recording. 21 different modules are covering every aspect of windows and security. We're probably going to do some other stuff too, as part of this on VPNs and firewalls and stuff too.

    [00:10:29] Cause I think that's all needed. We may be a little longer than I had hoped, but I want a really, really great course when we're done with this. It's not going to take us much longer.

    [00:10:40] All right. Everybody, have a great rest of the week and we'll be back on the weekend.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…