Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • AS HEARD ON: WGAN Mornings News with Matt Gagnon: Tax implications of Remote Work, Facial Recognition and Denial of Service Attacks

    Good morning everybody! 

    I was on WGAN this morning with Matt Gagnon and started this morning talking about Tax Time and the surprising effects that may come in April for many of us.  Then we got into changes in the way Hackers are attacking businesses and then we got into Facial Recognition Technology and how it is being used. Here we go with Matt.

    And more tech tips, news, and updates visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Good morning,  Craig Peterson here.

    Today, we talked a little bit about distributed denial of service attacks. I explain what they are, how they're hurting businesses, particularly small businesses as the bad guys are doing more and more of them. We talked also about this problem with facial recognition software that has just completely gotten out of hand.

    So here we go with Mr. Matt Gagnon

    Matt Gagnon: [00:00:30] Tech talk with Craig Peterson right now on news radio 98.5  FM and AM 560 W G A N seven 36 Wednesday morning. Great time to talk to Craig Peterson, our tech guru, who joins us at this time every single week. And you can also hear him on Saturdays at this very station at one o'clock.

    So thanks for joining us as always. Craig, how are you this morning?

    Craig Peterson: [00:00:54] Hey doing well, coming out fighting to my Rocky theme.

    Matt Gagnon: [00:00:58] Indeed. It is 2021, sir. Nice to talk to you in the new year. Hopefully a better one than last year, certainly. 2021 means that it's probably about time too, start doing my taxes and you had some information here that I found very interesting about how the pandemic boosted remote workforce might in fact be in for a bit of a shock when it comes to tax time.

    What do you think about this?

    Craig Peterson: [00:01:21] We've seen so many people leaving the big cities, moving out into the suburbs, into the burbs. In many cases, just moving a long way away. People from New York City and other major metropolitan areas, Boston of course.  Many have ended up right here in Maine. Just all kinds of people all over the place, even like North Dakota in places.

    But the thing that is really starting to scare people, especially accountants, is the lawsuits that have had to been brought to bear. Some of these States have decided that even if you have never, ever set foot in their state if your employer is in one of these high tax States. Every one of them, by the way, Democrat-controlled States, then you have to pay.

    Taxes in your state now, Maine, and not your state, but their state main and math have an agreement in place that allows a little flexibility there. But if you started working for a company, even part-time as an employee, for instance, out of New York City, or even New York state, or some of these other different areas that you have to pay in New York City.

    There's city tax, income tax, county tax, and state tax for your income that you earned from that state over the course of the year. As I mentioned, there are a number of suits in play right now saying, Hey, this isn't fair. We don't work in that state. We've never worked in that state.

    But those regulators they're going to come after like crazy. I, one time exhibited as a vendor at a trade showdown in Connecticut. I started right then about a week later and for the next three years having to continually fight with the State of Connecticut department of taxes or whatever, they call it down there because they said you were down here, you had a presence here. You now have to pay corporate taxes on anything you sell.

    Even if it isn't in the state of Connecticut. So double-check with your Accountant. This is going to get a little nasty this year.

    We're speaking with Craig Peterson, our tech guru. He joins us at this time every Wednesday to go over what's happening in the world of technology.

    Matt Gagnon: [00:03:46] Another interesting thing here is about this facial recognition story that you sent to me as well. Another arrest here. Based on bad facial recognition matching, which is fascinating. Cause it's an interesting technology and it's becoming more increasingly used in law enforcement and for other purposes as well.

    Maybe not perfect though.

    Craig Peterson: [00:04:07] No. We think about fingerprint technology that's been around for well over a hundred years and it's based on all the little swirls and imperfections that are on our fingerprints. And initially when it came out. There were a lot of questions. The science wasn't totally proven.

    Now it's pretty well proven. And we can say with 95%, 8%, whatever, it might be the certainty that those fingerprints belong to this individual. However, what we've been finding with facial recognition is something quite a bit different. It's still early on that technology. Many people have the same basic features and that's where the problem comes in.

    We found people who have been arrested spent time in jail, had to defend themselves, hire an attorney because their faces matched a person who committed the crimes face according to facial recognition technology.

    Now we spoke a little bit, Matt, last year about this company called Clearview.  This company has been going through every picture that we have posted on social media now. It's, we're on the internet and grabbing them.  Then it tries to find landmarks on those pictures. Those faces is what's interesting. Yeah. Now when the police run your face through this Clearview database, which by the way, anybody almost can do with just an app on their phone.

    So they take a picture of you, at a traffic stop or on the street and run the through the database. They look for those same types of landmarks, try and line them up. They may or may not match if they match. Boom. All of a sudden you're a suspect in a case.

    There's a case that I just shared this week of a gentleman who was accused of shoplifting candy. This guy had to spend five grand to defend himself and they ended up dismissing the case for lack of evidence. Are you kidding me? Did anybody bother to look at the pictures? The one that Clearview or one of these other organizations companies said -  yeah, it matches him or her. Did anybody bother to look at them?  In some of these cases? No.

    The police are sent in with an arrest warrant to arrest someone. Those police officers are not double-checking all of this data all of the time. That gets very concerning and it isn't just minorities. We've heard of, for instance, black people's faces, particularly black men. This software has a hard time recognizing. The same thing's true for Asians and many other minorities, but it's also true for us white guys.

    This is not technology that's really ready yet. It might give people the police, et cetera, an idea of who it might be, but we're putting far too much trust in it. Places like Portland, Oregon, and others have said, we are banning facial recognition technology in our city.  In some cases, States are taking this up because of how inaccurate it is.

    Matt Gagnon: [00:07:24] Finally, Craig, before I let you go, the denial of service attacks have become a little more sophisticated, a little more complex in 2020. So that's a great harbinger for 2021. Tell me more about this.

    Craig Peterson: [00:07:36] In case you're not familiar with it, these are attacks that are used for a different type of ransom. And many times they're used by these quotes, social warriors, unquote. So here's what happens. A business has a website online that website is used for disseminating news or maybe for selling products online. What'll happen is one of these bad guys will say, Hey, if you do not pay this. Ransom. If you will, we're going to hold your website hostage. They will use. Home computers, tens of thousands of them to send web requests to the website. So what's happened is these home computers have been compromised and they have a remote control on them.

    So that's your own computer because you did not keep it up to date. So they'll have thousands of these computers now say give me your homepage or give me the checkout page on the website. Of course, the website now becomes completely overloaded and no one can legitimately get to the website or checkout, et cetera. It's become very prominent this last year because of the number of bot networks out there.

    But also due to companies like Amazon, and others are now renting computers by the hour. Some of these bad guys come in the rent a bunch of computers. Again, they could rent a thousand of them spend maybe a thousand dollars on them and ultimately end up with tens or even hundreds of thousands of dollars in ransom payments.

    So it did go up, as you mentioned this year, Matt, in a big way.  It's particularly harmful to small businesses that have no way to cope with these denial of service attacks and they are increasingly expensive to protect against and more and more of them.

    Hard to believe. It's 2021. It's one of these, Thank God it's 2021 because hopefully, things will be a little better, no matter what happened with the election, maybe we can get these things cleaned up.

    We are idiots for using technology like this in our elections.

    But anyway, that's it for now? I'll be back again this weekend.

    Take care, everybody.

    Bye-bye.

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

     

    11 min
  • Tech Talk with Craig Peterson Podcast: More Complex DDoS Attacks, Mobile Endpoint Security, Microsoft Loses Its Crown Jewel, Tax Time Surprise and More

    Welcome!

    This has been quite the week for Tech news with Big Tech lowering their Iron Fist on any opinions with which they don't agree. Social Media censorship is here and it has taught us that if you want to communicate freely you cannot and must not use their platforms or services. I will introduce you to a new service that is out of their control and completely decentralized -- like the original internet. Plus we will talk about Elon Musk, What'sApp and More so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    DDoS Attacks Spiked, Became More Complex in 2020

    Mobile Endpoint Security: Still the Crack in the Enterprise's Cyber Armor Amazon still hasn't fixed its problem with bait-and-switch reviews

    Pandemic-boosted remote workforce may be in for a shock at tax time

    Another Arrest, and Jail Time, Due to a Bad Facial Recognition Match

    How to Build Cyber Resilience in a Dangerous Atmosphere

    Hacked home cams used to livestream police raids in swatting attacks

    Microsoft Says SolarWinds Hackers Also Broke Into Its Source Code

    Google, Apple, and Amazon bans Parler

    Mastodon is the Only Open Social Network Remaining

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hi, everybody. We're going to talk about the latest type of attack that's coming in. What you need to know about it. What's going on with this endpoint security with so many of us working from home and Amazon still has not fixed its bait and switch review problem.

    Craig Peterson here. Thanks for joining me. Hey, this is all about technology. Of course. If you're new, I do a lot of work with security. In fact, I've been doing it for a very long time. I have had training that I've conducted here for most of the fortune 500 companies. Federal agencies, almost all of them. In fact, and more than 5,000 small businesses have turned to me to help get their stuff done. So we tend to talk about security, but we'd talked about a lot of other technology subjects here on the show, and I really bring a different look to it, frankly.

    It's all about results. It's about what it means to you. I hope you understand a little bit better. I don't know about you, but I'm not real fond of just here's a list of what to do with no reason behind it. I want to know why I'm doing it. I remember going to a Tony Robbins event some years back, and one of the things he pointed out was, Hey, it's one thing to put it into your calendar. It's another thing, of course, to make a goal. But if you really want something to happen, you have to have your big, why.

    So what is your big why do I need to do this? That's what we're doing with our course. That's coming up here just in probably about two weeks. We're finishing it up. Now we spend a lot of time on this. It's an introduction to Windows security and helping you to lock down your Windows machines. I think it's a course, everybody should take, everybody should know about, and this is geared towards consumers. The things we need to do as just a regular person who might be working from home in order to tighten up Windows.

    Now we have much more advanced courses too, but this is all of your basics. So keep an eye out. I'll publicly do a couple of webinars as part of this. If you want to know more about it and get in on some of these free webinars and get this information, just send an email to [email protected] and in the subject line. Put in Windows hardening or Windows course. Whatever you want so that I can figure out what's going on.

    Also, by the way, if you're listening to me, you might be the right person because I'm looking for someone to help me with handling all of these emails that I get. I have all kinds of filters in place. That's not what I'm worried about, what I'm worried about is getting answers to the people that need help. I tell people all the time, just email [email protected]. I get tons of people every week, just hitting reply from the newsletter. I would like to be able to make sure that we have people who, or at least a person who's really responsible for this and who is going to, in fact, let everybody know that we are paying attention and rattle my cage.

    What, I haven't gotten an answer back to you because, right now it takes me a week, sometimes longer. To get back to you, so I got to apologize for that. If you're interested in that, if you're somebody who is really big into helping people and likes to understand the computer stuff a bit, maybe knows a bit about security. Maybe you're already on my email list, just signed [email protected]. Send me an email [email protected]. Let me know you're interested and why you're interested in it. I'll send you a little bit more information because I do try and give back to everybody, but I have a business to run with some very big clients and small clients, but a lot of work to do all of the time. It might take me a little while to get back to you until I find this perfect person who hopefully is sitting out there and wants to do a little bit of work from home, no matter where they are, as long as they can get and send emails. That's probably about all the bandwidth they'll need, so you don't need a whole bunch of it. [email protected] for any questions or comments or anything else.

    Getting into our first article of the week. This one's from reading. And they're talking about the denial of service attacks. In fact, more specifically distributed denial of service attacks, spiking, right? This year, well in 2020, and it became more complex as well.

    So I wanted everyone to understand what a denial of service attack is because it is probably the number one reason that the. Quote internet, isn't working unquote denial of service attacks or where a bad guy decides that they want to hold a company hostage. How do you do that? In this day and age, people are all over the place.

    You're not about to walk in the front door armed and tell everybody, Hey, pay up or I'm not leaving. That's just not going to happen. Is it? When will you get right down to it? You don't have to do that anymore. You don't have to have a real hostage. All you have to do is say, Hey, we're going to hold your servers hostage.

    Now you probably know already about ransomware and ransomware is a real big problem. It is growing. It has been out there for a long time and we're, ransomware where they gain access to your systems. And they do one of two things, or even both one is. They will grab all of the data that looks interesting to them.

    So they'll look through your spreadsheets. I'll look through the documents that you have out there. They'll try and find information that they think that they could extort you with. And then the second thing they'll do is encrypt your files and say, pay up if you want to get your files back. And unfortunately many companies, many organizations, including healthcare organizations, government agencies, state, as well as federal.

    And locals have all been hit by this. And they find that their backups are not good enough. They either weren't working properly and they thought they were working or many times what happens is a, just weren't doing it at all. And so all of a sudden, all of their files are. Encrypted do you know the important ones and they just can't conduct business anymore.

    Of course, the first step is they've got to clean up all of these machines that have been infected before they even can do the backup. So in many cases, people are paying the ransom, even though it's been made clear by the state department and others that pane the ransom is supporting terrorism. And what they're doing now is.

    Bringing charges against some of these companies who should have been secure, because if you are a public company or even if you just have basic shareholders, not even a publicly-traded company and you are effectively out of business and by the way, getting one of these ransomware attacks can put you out of business.

    Most of the time it does put you out of business. And so they get. Sued and civilly and potentially criminally as well for sending a hundred thousand dollars, $10 million to terrorists around the world, which of course encourages them to go ahead and ran some more companies. Also lets them know that, Hey, you'll pay a ransom.

    So why not ransom you? It seems like a good idea. Doesn't it? And Oh, guess what they do ransom you and they'll ransom you again. You get the double whammy where you now have to try and get back into business so you say, okay it's going to be way cheaper to pay the ransom, which is what they want.

    That's part of the reason they looked at all your files to see if they can get the County records. How big a company are you? How much could you pay? Cause they're not going to charge a ransom of $10 million to some poor person who's retired. Just trying to go online and. The next step is they say, okay guys, you haven't paid the ransom.

    If you do not pay this extortion fee, we're going to release all of your files online. So now you're going to get. They extorted. And in other words, they'll say, Hey, we grabbed all of these files and they'll give you the names of some of the files Neil just gasp. Oh my gosh. That's our business plan for next year.

    That's our competitive analysis. Oh, that's our intellectual property. Those are all of the designs we've been working on for the last few years or decades in some cases. And I probably should do something about this. What can I do? Pay up this extortion money and we won't release them online.

    Now of course, sometimes they release them anyway. And the other big problem that people have with this sort of thing is if it does get out, you might actually be breaking a law. You might have what's called CUI or other information that really could nail. You legally with the federal or state government.

    So there's a whole lot of problems there. So that's one of the ways the bad guys are ransoming and extorting money from people, but there is another very big deal. And that's what we are talking about right now, which is a denial of service attack. And one of the beautiful things. Form from the standpoint of the bad guy with a denial of service attack is it's almost impossible to trace the source of the attack and it puts the company that's under attack out of business.

    So how would you like that when you get attacked by someone you don't know who's attacking you, you may not even know? Why because many times these types of attacks, which are increasingly cheaper for the bad guys to do many times, these types of attacks are conducted by social activists. Yeah, our green warriors out there and others who will start attacking in these inexpensive ways.

    Of course, you can find all kinds of information online, subscribe to my podcast as well. You'll find it on your favorite podcast platform and [email protected].

    We were just talking about ransomware, how it's being used to hold hostage, various companies, as well as being used for extortion. Pretty bad things. Now we're going to talk about a cheaper and easier way. The bad guys are. He didn't us.

    Hi guys, this is really a fun world, a scary world, all rolled into one because the bad guy's methods are becoming more effective and cheaper for them to conduct. That's the scary side of this whole thing. Because these bad guys are out there making many millions of dollars.

    It used to be difficult to do. They used to have a bad guy that really understood programming and understood the bugs that were existing in our networks and in our computers. Pulling all of that stuff together, trying to make the whole world really a worse place. It was just a very few people and then the dark web really grew where the bad guys that we're writing the software. Now we're selling it on online forums.

    You can go online and for 10 or 20 bucks, you can buy software that does all of the ransom stuff for you. If you don't mind giving away five or 10% of your illegal proceeds, all you have to do is. Sign up for an online service that will do everything for you on the backend of the ransomware. They'll do the tech support for the people who have been ransomed. They'll go ahead and yeah, they'll even take phone calls when the people are saying, okay, so how do I pay this? How do I buy Bitcoin in order to pay you? How do I make any of this stuff work? How do I put in this key that you sent me? It doesn't seem to be decrypting. What do I do? Absolutely amazing. It is really quite an industry.

    Then there's obviously pretty complicated and there are simpler ways for the bad guys to nail us. This is what's happened over the last year. 2020 set records over what are called distributed denial of service attacks. How they're used to harass organizations, extort them as well.

    The basic idea is you as an organization, have a website and it might be a federal government website. It might be your local soccer team or state or federal. It doesn't really matter. The extorter will say unless you do what we tell you to do. Which might be to pay a ransom or stop oil drilling in Alaska? It might be anything right.

    Some of these anarchists are out there and if you don't do it, what we're going to do is we're going to shut down your website. For a lot of businesses shutting down the website is a terrible thing because so much of their profit comes from the website.

    So many people mis-think profit. I was just thinking about this last week. Profit is not bad. It is not evil. Profit is what pays for the light bill. Profit is what pays for the medical plan. Pays for the employees. Pays for the physical facilities. Pays the employees electric bills for the home, for the cars, for everything. Okay. Profit is not evil. Profit is absolutely necessary in order for us to live.

    If you're getting money. You are getting the proceeds from a profit that was made by somebody. Now, obviously, if you work for a government agency that is taking money from people, I wouldn't consider that profit. If you are a regular person and entrepreneur or an employee, that profit is absolutely necessary.

    When one of these green warriors says, you got to stop drilling, or you've got to stop manufacturing this, or you need to free this person, et cetera, et cetera. You are worried because what are they going to do to you? Then you find out they're going to put you out of business. Then what do you do?

    So many companies have been complying. You see it all of the time, the people are extorting, various media outlets saying unless you stop taking or stop advertising on this program. It might be Glenn Beck. It might be Rush Limbaugh might be met any of these conservative radio programs. You'd like to listen to. Unless you stop advertising on those we're going to shut your website down. Most of these businesses concede. They give in to these terrorist demands that are made by these organizations. What they're afraid of is if these organizations do a denial of service attack, that their website's going to be unavailable and they are no longer going to be able to conduct business.

    That's just one of the things. There's other things that these bad guys do to extort businesses. When you go to a website and you go to the checkout page on that website, what's really happening? Obviously, you're sending a request to the webserver and it's a request for a page and it has to go through an encryption-decryption. Then it has to go into the back end that keeps track of everything in your cart. Then it has to go when they accept the payment, which might be a credit card, et cetera, et cetera. These web servers can only handle a certain amount of traffic. You've heard it before. Oh, my server crashed because I had just this heavy load on it. Too many people are trying to buy my product, which is actually not a bad thing.

    There are also problems with the amount of bandwidth. So you have a server. Great. It can handle a thousand requests per second. Let's say, which is pretty darn big servers is probably actual little server farm and the network connection to that server or server farm can only handle a hundred requests a second.

    So you've wasted money on the backend. So you tend to try and size that all appropriately. So you're not just pouring money down the drain. What happens with a distributed denial-of service attack is they get dozens, hundreds, or even thousands of computers to try and go in into the cart, try and do a checkout, trying and pull up pages that maybe have a lot of heavy graphics on them so that the server now has a huge load as does the network connection.

    So they're saying, okay, so what do I do about it now? There are some ways to deal with these types of attacks. Are some companies out there I can point you to, if you want to just drop me an email. If you have a web server you're concerned about maybe this happening to you, I can point you in the right direction to CloudFlare or some of these other ones that are out there.

    Just email [email protected]. Be glad to let you know a little bit more about it. But it is hard to shut down, particularly if you are a very small business and your internet provider has never really heard of you before. And the people who are maintaining this server you're in the same boat.

    You're paying me. How much am I? $8. Yeah, no, sorry. We're not gonna, we can't really help you. And in fact, they don't help you. And that can be, even if you're paying couple-hundred bucks, depends on the quality of the people that you're working with. So what they'll do then is have all of these computers hit it's called hitting the web server, trying to gain access to things and shut it down.

    Now, there are some services, as I mentioned that you can use to help stop these things once are underway. But the barrier to entry for performing a denial of service attack is extremely low. There are all kinds of, hire services that allow attackers to launch bigger and more consequential attacks.

    And it's pretty simple to orchestrate. So we've gotta be very careful. Global pandemic drove a sharp increase in these types of attacks. And they're going to continue. They're going to continue because they make money. Man. I'm looking at the FBI advisory on this too. It's frankly, pretty scary.

    We're going to talk about the crack in businesses' cyber armor and it might be you.

    Verizon's 2020 mobile security report has found that foreign 10 companies were breached through a mobile device. With so many of us working from home, frankly, this is really bad news.

    Mobile endpoint security is a real problem, frankly. It's the crack in our organization's cyber armor. We have mobile devices. Many of us are using Android, which you guys already know. Then I say you probably should not be used because of a few problems. The biggest problem, frankly, with it Android is that the security updates just don't make it onto most Android phones when you get right down to it.

    Big problem is that the manufacturers do not take the updates from Google, for Android, for security problems and put them on all of their devices. In fact, in most cases, you're looking at a six-month window before most of these devices have the security updates installed on them. If they ever get installed and looking at some of the statistics about which version of Android these devices are running, it's frankly very scary.

    So it's a huge problem. It's why I always recommend iOS Apple devices. The I-phones the eye pads for most businesses. If you need the utmost insecurity while there's some other things you probably need to look at, however iOS and the iPhone was certified by the military a couple of years ago. It's reasonably safe.

    Of course, nothing's perfect. But. Bottom line, a combination of these best in class technologies, like the I-phones and following some instructions I'm about to give here are really the front line in helping our organizations, our businesses, and you from falling victim to these ever-growing threats.

    These bad guys are extremely well-funded. We just saw Vietnam enter into the league of nations that are known as hackers attacking us. No, we've known about North Korea, China, Russia, Iran. Now we've got Vietnam. And many of those nations have a whole lot of money and their goal is not necessarily to extort all of that money from us.

    In many cases, the goal is just to cause havoc and confusion, and man, have they been good at doing that? So if they develop a tool. And then they share that tool with hackers all over the world. They've accomplished their goals, haven't they? Because they're causing havoc now. And in the case of North Korea, they do want hard currency.

    No question about it. But these tools that are for sale for cheap out on the dark web are being developed. By Russian and Chinese hackers for the most part official ones, they're working for their governments. Mobile devices have really been at the core of many of the 2020s. Highest profile attack.

    So for instance, we talked about this attack against Amazon CEO. Bezos's I phoned compromise incident. And what happened when a mobile device was penetrated by. Just using some bugs in an application and a video that was sent and opened. Okay. So you got to be careful about these things. That's another reason why in my windows hardening course, my introduction course, I really stress removing apps.

    You don't absolutely need it. And another thing that I talk about in this introduction to a windows security course is. The problem we have of the apps we use to communicate. And that's what nail Jeff Bezos. The guy got a divorce and it was just amazing the amount of money that was part of that divorce settlement.

    But he was using an app that he didn't need to be using, and that's how they got onto his phone and were able to grab other things. So just removing those apps, but. I'm really concerned right now about WhatsApp because so many people are using it. I've gotten questions. I've received questions from some of our listeners who have family members who are in the military overseas, and they're asking, Hey, can we use WhatsApp in order to have a secure chat with my daughter or husband, wife, whomever, it might be overseas in the military.

    And although WhatsApp is the most popular communications app it's got over. I think it's 2 billion users worldwide and it has had end ending encryption remember Facebook bought it a couple of years ago. And that makes it dangerous. And the new terms that have to be accepted for using WhatsApp in the future, indicate that Facebook really is starting to play some games here with how secure WhatsApp really is.

    So I go into a lot of detail in one of the modules on how to communicate securely, but there you go, Jeff Bezos, which was very expensive to him. Came in from a mobile device, simple fishing, most common way, mobile devices get compromised. And this is where you typically get an email that looks like it's from the bank or Amazon.

    And you click on a link and unfortunately, Because of the lockdown. So many of us are working from home using our own devices. And what that means is many of these devices have not been vetted by any form of security, professional. Okay. It's really bit of a problem and there's been a 37% increase worldwide.

    And according to this Verizon report in mobile fishing, Just between the last quarter of 2019 and the first of 2020 now add to that, the whole lockdown. And it's gotten a lot worse and that's according to the lookout who tries to keep tracking some of these things. We've also got the problem of a malicious wifi hotspot.

    So don't connect to those. What I advise you to do if you're out. On the road you're maybe at the airport or coffee shop? The good old days, right? Don't use the local wifi. Use your cell phone, use your data plan and have your cell phone. Tether your computer to go online. That's much safer than using wifi hotspots.

    And we go into quite a bit of training on that as well, in my introduction to windows security courses. So what happens if their security fails. That's where again, you've got to be using something that's moderately or fairly secure, like the iPhone, by the way. Oh gee, Phil Zimmerman. They started another company.

    I don't remember what it was called now. If you're interested, drop me an email. I'll look it up. But they have. Phones that are designed to be highly secure and they're actually Android-based, which they would have to be because Apple doesn't really so source code, unlike Android, you can get most of that source code.

    Anyways, worst outcomes here. Number one, some of these are very hard to detect some of these intrusions. They're hard to get rid of in many cases, and these are real problems. Rule number one, never jailbreak your phone because that's going to open you up to all kinds of problems. There could be spy where payloads that are put onto your phone, but the bottom line don't jailbreak them.

    Keep them up to date. Don't use Android. If you must use Android. The simple rule is to stick with the major manufacturers like Samsung and use their state-of-the-art phone, whatever the best one is that they have, and upgrade your phone at least every two years. If you're using Android. If you're using iOS, you got five years, which is why I phones tend a lot cheaper, frankly, and require encryption.

    All right. Lots more to talk about.

    I use Amazon all of the time, but there are some things to be very cautious about when it comes to Amazon. It's really not the trusted platform that I started using more than a decade ago. So we're going to get into that right now, bait and switch.

    If you miss any part of today's show, you can also find it [email protected]. Amazon has a lot of problems. In the last segment, we're just talking about how it's CEO got hacked via a message that came in through a messaging app. It was actually a video and it is a problem, right? So you've got that sort of a problem.

    You have the problem of being a small business and trying to compete with Amazon. I will admit that I use Amazon a lot for buying things. It's just simpler. The first thing you have to remember when you're using Amazon is they don't necessarily have the best price.

    In fact, many cases, they are not even close to the best price, both Amazon and Walmart have some amazing, huge stores online target, of course, does as well as some others, but. When you compare the prices between them. I think you might be a little surprised. One of the things Amazon's done to lock us in is this Amazon prime membership, which is really handy.

    You get some of the best deals because they have their prime day. Plus they have some special deals that are just for prime members at different times of the year. That's going to cost you more than a hundred bucks a year for that prime membership. But frankly, it makes up for it in shipping if you use a lot.

    And I'm sure that's part of what they're thinking here, right? And they also now because of courts and really being forced into it, they have a little notice saying that this price might not be the best price and it's available from other sellers. So you can click through and it'll show you other sellers that are there.

    On Amazon's website who have products that are, Amazon's also selling, but yeah, they might be cheaper. Usually when you add that less expensive price, plus what that other vendor on amazon.com wants to charge you for shipping. It's usually about the same price as what Amazon's going to offer it to you for.

    So keep that in mind when you're shopping, the price might not be the best. What looks like a great deal with the price. Mark might not be such a great deal after all. So buyer beware, right? But there's another problem. I, this last year for present got one of those massagers. Now I've really been into massagers for many decades.

    Now I used to get them a Brookstone. They always had the best selection. And so I just buy it from them. Since I got to try it in the store. And it was it was really great. And Brookstone in fact, was headquartered right in my hometown in Merrimack, New Hampshire. I thought that was cool too.

    Cause it's a supporting a local business. Of course, they were purchased. I think it was SIM bought them. And then I have no idea what they're doing nowadays. It closes most if not all of their stores, but anyway, so I've always liked the massagers. They help with those aches and pains that you get at any age.

    And particularly as you get a little bit older and. There was a massager that my massage therapist was using. And they just, one of these little percussive handheld things, it almost looks like a gun and it has a bunch of different attachments you can put on the end and it goes back and forth and just percussively massages.

    It does an amazing job. It gets the muscles that are tight to let go to loosen up. And so I went online and I found what I thought was probably the massagers she was using. She told me, and then of course I forgot what it was and there were dozens of them available on Amazon. So what do you look for social proof, right?

    Isn't that the normal way? So I look in for social proof, which is, Oh, here's the one with the thousand reviews and with the. Oh, five stars or four and a half star raining. Great. Let me just stop. I'll do that. Let me buy that. And you can always return it if it doesn't work. So I did buy it and it did work.

    And let me tell you, I'm just so happy with it, but what I noticed inside the package, it was a little card and I've been seeing this more and more on products that I buy from Amazon. Where the person who's actually fulfilling this order, send you a little notice and maybe ask for some feedback or says, Hey, don't complain to Amazon.

    If you have problems, go directly to us and we'll make sure it gets resolved because they want those five-star reviews from you legitimately. You can't blame the moment. If something happens, which it can happen, nothing's perfect. And they'd tear, take care of it. Lickety-split. I'm still going to give them that five-star review that they frankly deserve because it's a good little product.

    It wasn't necessarily their fault that there was some form of infant mortality, which does happen. And it happens with anybody any time you buy any sort of technology. So I. What did the card a little more closely at to see what it was and guess what they were doing? They said, Hey, listen, if you go on to Amazon and review our product, now they didn't say you had to give us a five-star review, but that was almost implied.

    If you go on to Amazon and review our product and you send us a picture of the review that you made by email. You can choose one of these gifts. And one of the gifts was a battery. For that massager. There were a couple of others that I don't remember cause the battery is the most appealing to me and I thought what the heck?

    I'm going to review it anyway. So I did and I sent them a picture of my email and it's been over a month and I haven't gotten my free battery. They got me to wondering what's really going on here. And I found an article here by Tim Lee over at ARS Technica. Saying that he bought for his kids, this little $24 drone very cool drone.

    And he gave it to his daughter to play with. And I'm not sure who the other kids were, but one of the propellers got stuck in her hair after the kids were playing with it for a few hours. It's really a cool one. It's got four propellers, but the whole thing is enclosed inside a little cage so that the kids can't really get their fingers into it and potentially get hurt.

    Although most of these little tiny drones, you can get whacked with those propellers, and it's not going to hurt at all. Really. They had fun. They were able to play around with it. But after that first few hours, it just basically stopped working because it got caught in the hair and that's going to happen.

    So he went online on Amazon and decided to do a search and he found a great review here. He searched for children's drone and sorted them by average customer review. Which makes sense to me. And he found a $23 drone with 6,400 reviews and an impressive five-star average rating. So let's promise you, that's what I would do, right?

    How about you? I, I think that's what most of the, most of us are doing. There's your social proof. But then he started to look at the five-star reviews. And this is something I talked about on the show about a year ago. How do you tell if the reviews are legitimate or not? While you can do a few things, one is looking for major grammatical errors, which a lot of these reviews have, but here's what he found now.

    Remember. This is supposedly a review for a drone. It says wonderful texture and great taste. Five stars. Absolutely love this, honey. It's quite different from any supermarket purchase, honey out tried. It's rich, thick, fragrant, and tastes wonderful. It's on the expensive side. Yes, but also worth it. The packaging is paper metal and glass in the jars.

    Definitely, be reused or recycled. There we go. There's a grammatical error, but not a lot of them. It goes on and on raving about this honey. This is a drone. So what's going on here? This is a real problem. Here's another review that he found. If you're looking to have a taste of Greece without making the journey, this honey does the trick.

    That was another customer, supposedly that same month, the third one wrote that it was dark luxurious pine honey, not too sweet, absolutely fantastic. With strained, creaky, yogurt and extra cream. Now he said, when you read the reviews on Amazon by date, he saw that the most recent reviewers actually had.

    Bought a drone and they were overwhelmingly not giving it five stars. Bought this from my grandson, a customer wrote on December 26. He played with the, for two hours before broke and it's no longer working. He gave the drone one star. But all these older reviews were for honey. So apparently the manufacturer had tricked Amazon and just thousands of reviews for an unrelated product below its a drone, helping the drone to unfairly rise to the top of Amazon.

    Search results. So there's, I think a very big word of caution. There's a lot of examples on Amazon about this sort of thing. This iPhone 10 battery case listing used to be for a leather wallet, phone case. Another battery case was formally listed for lightning charging cables, a Wi-Fi router that was listed as nanocomputers previously.

    Been by the way that one collecting reviews since 2003, here's a neck brace. It was formerly a shower caddy listing. Guitar string action gauge is now a page for magnetic glue, free eyelashes. So Amazon does say that they have clear guidelines about one product that should be grouped together, and they have guardrails.

    They call them in place to prevent abuse, but this is one type of abuse. And it's pretty obvious because a drone is not honey. So if you were actually to read those reviews, which obviously this guy that wrote this over to our set, Anika, Timothy Lee had not done before you started having problems.

    But if you actually read the reviews and they're all for the right product, then what. What about this back massager that I got this little massager. Is that gonna show up this way? No, it's not because people are going to give it the five-star reviews because they want the gifts are going to be headed their way.

    So be very cautious. Amazon has not solved this problem yet.

    We still got a lot to talk about, including taxes here. For those of us working from home, a big shocker coming.

    You might be in for a bit of a shock if you have been working remotely due to this whole lockdown thing. In fact, millions of us are going to have a bit of a shock coming up soon.

    We have been busy here for the first hour. Talking a little bit about the Amazon bait and switch reviews. What I do when I'm online shopping and how you can help keep yourself not just safer, but make sure you don't get ripped off.

    We went through an article from ARS Technica about how he did get ripped off for gifts this season. We also talked a little bit about mobile endpoint security, some of the problems that frankly we've had with our mobile devices. How Jeff Bezos in fact got a massive problem. I got involved with his divorce and everything else because of his mobile device and denial of service attacks. What that is all about?

    We're going to talk this hour a bit about our remote. Workforce the tax implications. We've got another arrest and jail time. So we're going to talk about bad facial recognition and what's going on there. Cyber resilience. And what can we do this year? I really want to get into these hacked home cameras used to live stream police, weight raids in what are called swatting attacks.

    And then. Solar winds mine. I was just because me, cause there are so many ways this massive hack could have been avoided. Our federal agencies have been compromised. Microsoft now says that due to this SolarWinds, hack somebody God into Microsoft source code. Those are the key to the kingdom.

    And one of the ways Microsoft realizes to stay secure is by keeping it source code secret. And of course we, no, that's work. Microsoft has never had any vulnerabilities. So we'll get into that a lot to talk about this hour. First off, let's talk about this problem with taxes. Many of us have problems, if you work in Maine and you work in Massachusetts, you could have a little bit of a tax problem, but there is a reciprocal agreement that's in place.

    So if you had been working in mass and you live in Maine, Okay. I can see that you're driving down to mass every day and you're living in Maine. So the reciprocity agreement covers that. But how about if you have never stepped foot in Massachusetts? How about if you started working for a company out of New York or a company out of California?

    Did you realize that many of these, all of them, by the way, Democrat administrations are now going to require you to pay state taxes, Connecticut, you name it. All of these, it is very concerning to me. And when we get right down to workforces and the fact that this whole lockdown has really accelerated this trend of working from home.

    And because of that, we've got employers who are letting their workers perform their jobs remotely from home most, if not all of the time. So where does illegal nexus tie in? So they're saying, Hey, listen, your employer. And you both knew exactly where you live and work, but the state departments of taxation can have some very different ideas about where here is.

    So as a result, Texas, Utah, Arkansas workers who are working for New York or Massachusetts based companies will have income taxes with health in the paychecks, even if they've never set foot in the home office. Or never set foot in this state. How about that one? The thing for New Hampshire if you live in Maine, of course.

    Yeah. A lot of these states that have state income taxes, will go ahead and say, okay you don't have to worry about paying our state income tax as well. Or in some cases, they look at it and say, Oh, you pay less state income tax. Then we charge our residents. I don't want to call them citizens because we are not being treated like true citizens anymore, but you pay less in your home state than our residents pay.

    So you don't have to make up the difference as well. So we've gotten dozens of major companies out there all the way through little guys who have been increasing their support from working from home permanently. And I think that's great. We have businesses closing offices. Thank goodness. I don't own business space.

    We've lent our leases laps counting on physical distance, flexible workforce was going to reduce real estate needs. I know one of my daughters is in that boat right now. And in many ways it can be a win-win employer can save overhead costs on those expensive square footage and high demand cities look at what's happened right now in San Francisco.

    For instance, they are a great example of San Francisco. The city has lost 43% of its tax revenue. So you look at it until K while they've lost a lot of tax revenue because of the lockdown and people aren't going out shopping. They're not buying stuff. No. According to the San Francisco economist and yes, indeed the city of San Francisco has its own economists.

    Know that a 43% drop in revenue is due to people moving out of the city. New York, San Francisco, Los Angeles, all expensive, and people are moving to Maine, to Montana, dial in from the woods or get a nice little place down in Florida for instance. But as far as the state's concerned, your beachside can banner might.

    Just as well be right in the middle of downtown Manhattan and you're going to be taxed as such. So we've had these problems for a long time, but living in one state, working in another, but typically it's been adjacent States, just like again, Maine and Massachusetts, right? DC, Maryland, Virginia, maybe Pennsylvania, West Virginia, Delaware.

    Kansas City itself goes across two States. You've got Kansas City, Kansas, and Kansas City, Missouri. So traveling across city limits can mean crossing state lines as well. So any major city near a border has lots of workers that go over the lines back and forth every day. And that's always been tricky from a tax perspective.

    Because both the state where you work and the state where you live is going to want to try and tax your income, but still typically only one state at a time has been able to tax you for your income. And most jurisdictions with a lot of overlaps have agreements, as I said, main and mass and New Hampshire doesn't really have that agreement because they don't have any state income tax or of course sales tax on almost anything.

    But. This is really going to be a problem, frankly. So keep in mind that if you are working for a company that is headquartered or even just has a presence in Arkansas, Connecticut, Delaware, Massachusetts, Nebraska, New York, and Pennsylvania. All of those States have convenient rules on the books that require any work performed for an employer-based in their state.

    That it be taxed as if the worker performing the job is actually. In the state, no matter where the employee is actually located now, New Hampshire is one of the nine states that does not have an income tax. And it's right now in the process of suing Massachusetts over its convenience rules and for other States, by the way, New Jersey, Connecticut, Hawaii, and Iowa are supporting the suit.

    So we'll see what happens there in federal courts. As you probably already know going to court doesn't mean the right thing is going to happen. It's gotten really bad, but at any rate, something to be careful about, if you are working remotely for a company, many of these States are going to become an after you for tax dollars.

    We got a couple of things to get in. I want to talk right now about facial recognition. We what a year, maybe more ago talked about this company called clear view AI Clearview. And what they've been doing has been questionable. They've gone online and done searches. They've combed through social media.

    And they've found and downloaded every picture. They can get the grubby little paws on, and then what they've done is they've put together some facial recognition software. So they've violated laws. They've violated platform rules. It's almost like Facebook when it got started, where apparently Zuckerberg went ahead and stole.

    All of the records of all of the kids that were there, going to school at Harvard and including their photographs and put together this little Facebook thing, the Facebook, and had people rating other people by their looks, et cetera, and just basically stole. To get his business started Facebook. That's the allegation that's been out there.

    There'd been a whole movie by this, about what he did. So that's what Clearview did too. They went ahead and decided we'll just steal all of the photos we can of people. They tied facial recognition software into it, and they perform scans of these images that were scraped from the internet and created a biometric database of the images.

    We're going to talk about that and how we now have people being wrong, not just accused, but arrested, spent jail time. It's a crazy world out there.

    The allegations are that Clearview stole your picture without your consent and without the consent of the websites you put them on. Now they are being used in this biometric database by the police and others with wrongful arrests.

    Hey, if you want to hear the whole show or an older show, you can find them, just go online to Craig peterson.com. You'll see the podcasts there. I podcast the whole radio show, as well as my appearances on radio and television right there. So you can listen to them as podcasts there or on your favorite podcast app. There you go.

    So we were talking about Clearview using these images that were scraped from the internet illegally. In some cases against obvious usage agreement, as well.

    Now is that they've got this biometric database of the images and they can use that database to match an image of one person to one of these preexisting images that has been analyzed and scanned and maybe stolen, right? Depending on how you want to look at it, the allegations are all the way across the board.

    Now neither you nor anybody else whose image was scraped from the internet, even know that it happened. Let alone give Clearview permission to use your image, right? They didn't get permission to take it, and they're not going to get permission to use it.

    So the details of these practices are not well-received by anybody out there. Even the New York Times came out about it last January, which is when I really started talking about it as well. Within three days of the New York times talking about what this Clearview company did, there was a federal class-action suit that was filed.

    And the complaint opened with a quote from justice Brandice that the greatest, dangerous to Liberty lurk in insidious encroachment by men of zeal well-meaning, but without understanding. So it's very interesting. There's a whole bunch of cases. I'm looking at the list of them right now. These will take a while before everything is finalized on them, but here's something we absolutely.

    Do know for a fact. And that is that there have been arrests that have been made due to this database. Anyone who identifies as a policeman can go ahead and download the app onto their iPhone or another device. And can then just take a picture of someone casually on the street. There are people who are making police cameras that are constantly streaming video.

    And on the backend are trying to do facial recognition. I've had a couple of them on my radio show a few years back, and it's cool because it gives the policemen an idea of, is this a bad guy or not? There is this somebody who we should trust somebody we could trust. I'm not really that worried about it.

    Just. Think about the most dangerous thing most pleased officers do, which is a traffic stop. They have no idea who's in the car. If that person's going to try and attack them, et cetera. So having a live stream, thinking about Robocop, which didn't end that well, and what was happening there with the ed two Oh nines as well as Robocop himself, being able to see a person and be able to tell right away what this person's background is if there's any wants or warrants, et cetera, out there.

    That's all well and good to a certain degree, but we just had another man. This is a New Jersey man who was accused of shoplifting and trying to hit a police officer with a car. He was wrongfully arrested based on facial recognition. Now, in this case, it's a black man and these facial recognition software programs that are available.

    Tend to do poorly with any minority, frankly. And or do terribly with some and do poorly with any of them and also do rather poorly with the good old, regular Caucasian in phases like mine. Okay. So this is a third person who's arrested for a crime. He did not commit. He spent 10 days in jail and paid around $5,000 to defend himself.

    So this is a guy that had nothing to do with it. The police got lazy, they said, Oh, we got a facial recognition match. It's this guy because they ran it through some software that had scraped some photos from the internet. Do you see where I'm going with this? And those photos from the internet say it's probably this guy, Nigeria parks.

    And we know his social media is saying it's Nigeria parks. This is where he lives. This is where he posts most of his pictures because you remember our pictures. When we take them, our smartphones have embedded GPS information. Oh, my gosh. And in this particular case, he was apparently 30 miles away from the scene of the crime.

    Okay. Pretty sad. Pretty sad. They dismissed the case because of a lack of evidence. Isn't that wonderful? But the department is now getting sued along with the prosecutor in the city of Woodbridge for false arrest, false imprisonment, and violation of his civil rights. I think he should absolutely win on that.

    2019. And this is an article that came from the New York Times. They're saying a national study of over a hundred facial recognition algorithms found that they didn't work as well on black and Asian. Faces, as I said a little bit earlier see an ACL or attorney named Wessler believes that police should stop using facial recognition technology.

    I am okay with it to a degree. I don't think you should be issuing any sort of an arrest warrant based on facial recognition. I think you might get a clue from that and. From that clue, you can look at the phases and decide for yourself and interview the suspect, do some good old fashioned police work, but this facial recognition arresting people, putting them in jail and then costing them thousands of dollars plus their time and their reputation and what it does to your nerves and everything else is just absolutely insane.

    And bad arrests. So this article in the New York times goes through what happened. Apparently, the officers had been presented with a fraudulent driver's license, one of the officer's report,s or did that. They saw a big bag of suspected marijuana in the man's prof pocket. They tried to handcuff him and that's when he ran, he had a rental car just goes on and on, but.

    It was a problem. And even though Mr. Parks had been arrested twice and incarcerated for selling drugs release back in 2016, doesn't mean that he's the guy that did all of this. So let's be careful. I'm not fond of what Clearview has done, obviously, just based on how I described it and who I quoted. And I don't like the idea of using this facial recognition technology to arrest people.

    Bottom line. So speaking about arresting people, when we get back, we're going to talk about what is called swatting attacks. I don't know if you've heard of these before. They're pretty common, unfortunately, and some of the technology that we've been bringing into our homes to keep us safer is now being used to put our lives in danger if you can believe that.

    Yeah, absolutely true. We'll be talking about that.

    You can also follow me online. Just go to Craig peterson.com. You can subscribe to my newsletter. I'm not an active poster in Facebook or anywhere else, so the newsletter is the best place to get my weekly show summaries.

    We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up in killing people. Yeah. Yeah. Death by a police officer. Here we go.

    If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information. That I have available my podcasts and a little articles that we've written, and you'll also have the opportunity to subscribe to my newsletter. So I'll keep you up to date with the latest, most important articles of the week. I don't send all of my show notes anymore.

    I found that a lot of people. Just don't open them cause it's overwhelming. So I've been lately trying to focus on one tip in particular. So we'll see how this all goes in the future and you can always let me know what you think. Just email me [email protected]. I'd love to know, do prefer to get all of my show notes every week or do you prefer what I've been doing lately, which is a deeper dive into one topic. That seems to be pretty popular, but I'm getting about a 40% interaction rate, which is really good on such a large list.

    I just want to get the message out is my bottom line.

    We have these home cameras that we have welcomed into our homes. And one of the ones that has been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

    And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings to the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

    There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them a live real-time access to all of the ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

    And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring, doorbell cameras.

    Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because of why. Does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

    And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened in a number of occasions and far more than we like to talk about is that there are.

    The bad guys or people who don't like their neighbor and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting prank led police to shoot dead 28 year old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

    After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth. You can have.

    Teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. And apparently they believe the report was an act of swatting where.

    Somebody makes a false report to a police department that causes the police to respond with a SWAT team. Now the audio of this emergency calls been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

    The color also said he had a handgun at had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

    When Mr. Finch came to the door, they said one round was released by the officers after the 28 year old failed to comply with verbal orders to keep his hands up. Why would he, what did he done wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

    And they said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them dead. Injured North taken hostage. His family told local media, he was not involved in online.

    Gaming. Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that the, that hackers are out there who do this swatting maneuver on somebody. And then they have the hacked ring camera at that house and they watch the SWAT team respond. Can you believe that?

    And the FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices. How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that his.

    His revenue, his pay from the work he was doing, delivering food to people's homes was stolen by a hacker because he was using the same email address. Yes. To log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells have allowed hackers to steal pet network passwords, et cetera.

    In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, it causes death, many examples of that, and we're still reusing passwords. Give me a break.

    We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

    But anyway our businesses and government got broken thats what we're going to talk about right now.

    Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

    Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

    And in fact, That's a big problem still, but we'll talk about this right now. SolarWindss is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWindss. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

    We dropped SolarWindss as a vendor, and the reason we dropped them and we made it very clear to them was we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWindss a couple of years ago, and they wouldn't do anything about it.

    So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWindss. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

    Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presumed now to being the hand of Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

    He said SolarWindss, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it an easy target interviews with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWindss websites stopped offering client the compromised programs.

    Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached to, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

    This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because I, I didn't tell you guys this, but I do love the fact that I was right again.

    How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce.

    Schneider. You've probably seen him before. He is also, I think he writes for the Washington post. But remember when this came out the word about the SolarWindss hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

    Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just the North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

    In other words, going out after other countries in the cyber security realm. And we benefit from the lack of norms that are in cybersecurity, but here's what I really liked. The Bruce said. And I agree with entirely. I'm glad he must listen to the show. The fundamental problem is one of economic incentives.

    The market rewards, quick development of products. It rewards new features. It rewards spine on customers, end users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

    It doesn't reward reliability past a bare minimum, and it does not reward resilient at all. And this is what happened with SolarWinds. SolarWindss ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

    It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure. It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

    I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely in excusable, right. Inexcusable. So this is happening with SolarWindss right now, but it's going to be happening with other places out there.

    We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWindss is a Puerto Rican born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

    The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from tech beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the U S treasury department was hacked the U S department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cyber security, and infrastructure.

    Agency. SISA the department of Homeland security, the U S department of state, the department of justice, the national nuclear security administration, the U S department of energy, three U S state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others. I use two of those.

    We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem. How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody use a password manager and I will have a course on that this year.

    Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

    The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an it security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

    Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have 1.4 email coming in and going out SMTP Imam.

    They should be controlled and controlled pretty tightly. According to the department of justice, apparently their email accounts were compromised about 4,000 dish. People's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

    It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

    Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email [email protected] and let me know, be glad to send you stuff.

    ME@Craig peterson.com.

    Take care guys.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 24 min
  • Tech Talk with Craig Peterson Podcast: More Complex DDoS Attacks, Mobile Endpoint Security, Microsoft Loses Its Crown Jewel, Tax Time Surprise and More

    Welcome!  

    This has been quite the week for Tech news with Big Tech lowering their Iron Fist on any opinions with which they don't agree.  Social Media censorship is here and it has taught us that if you want to communicate freely you cannot and must not use their platforms or services.  I will introduce you to a new service that is out of their control and completely decentralized -- like the original internet. Plus we will talk about Elon Musk, What'sApp and More so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    DDoS Attacks Spiked, Became More Complex in 2020

    Mobile Endpoint Security: Still the Crack in the Enterprise's Cyber Armor

    Amazon still hasn’t fixed its problem with bait-and-switch reviews

    Pandemic-boosted remote workforce may be in for a shock at tax time

    Another Arrest, and Jail Time, Due to a Bad Facial Recognition Match

    How to Build Cyber Resilience in a Dangerous Atmosphere

    Hacked home cams used to livestream police raids in swatting attacks

    Microsoft Says SolarWinds Hackers Also Broke Into Its Source Code

    Google, Apple, and Amazon bans Parler

    Mastodon is the Only Open Social Network Remaining

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hi, everybody. We're going to talk about the latest type of attack that's coming in. What you need to know about it. What's going on with this endpoint security with so many of us working from home and Amazon still has not fixed its bait and switch review problem.

    Craig Peterson here. Thanks for joining me.  Hey, this is all about technology. Of course. If you're new, I do a lot of work with security. In fact, I've been doing it for a very long time. I have had training that I've conducted here for most of the fortune 500 companies. Federal agencies, almost all of them. In fact, and more than 5,000 small businesses have turned to me to help get their stuff done. So we tend to talk about security, but we'd talked about a lot of other technology subjects here on the show, and I really bring a different look to it, frankly.

    It's all about results. It's about what it means to you.  I hope you understand a little bit better. I don't know about you, but I'm not real fond of just here's a list of what to do with no reason behind it. I want to know why I'm doing it. I remember going to a Tony Robbins event some years back, and one of the things he pointed out was, Hey, it's one thing to put it into your calendar. It's another thing, of course, to make a goal. But if you really want something to happen, you have to have your big, why.

    So what is your big why do I need to do this? That's what we're doing with our course. That's coming up here just in probably about two weeks. We're finishing it up. Now we spend a lot of time on this.  It's an introduction to Windows security and helping you to lock down your Windows machines. I think it's a course, everybody should take, everybody should know about, and this is geared towards consumers. The things we need to do as just a regular person who might be working from home in order to tighten up Windows.

    Now we have much more advanced courses too, but this is all of your basics. So keep an eye out. I'll publicly do a couple of webinars as part of this. If you want to know more about it and get in on some of these free webinars and get this information, just send an email to [email protected] and in the subject line. Put in Windows hardening or Windows course. Whatever you want so that I can figure out what's going on.

    Also, by the way, if you're listening to me, you might be the right person because I'm looking for someone to help me with handling all of these emails that I get. I have all kinds of filters in place. That's not what I'm worried about, what I'm worried about is getting answers to the people that need help. I tell people all the time, just email [email protected]. I get tons of people every week, just hitting reply from the newsletter.  I would like to be able to make sure that we have people who, or at least a person who's really responsible for this and who is going to, in fact, let everybody know that we are paying attention and rattle my cage.

    What, I haven't gotten an answer back to you because, right now it takes me a week, sometimes longer. To get back to you, so I got to apologize for that. If you're interested in that, if you're somebody who is really big into helping people and likes to understand the computer stuff a bit, maybe knows a bit about security. Maybe you're already on my email list, just signed [email protected]. Send me an email [email protected]. Let me know you're interested and why you're interested in it.  I'll send you a little bit more information because I do try and give back to everybody, but I have a business to run with some very big clients and small clients, but a lot of work to do all of the time. It might take me a little while to get back to you until I find this perfect person who hopefully is sitting out there and wants to do a little bit of work from home, no matter where they are, as long as they can get and send emails. That's probably about all the bandwidth they'll need, so you don't need a whole bunch of it. [email protected] for any questions or comments or anything else.

    Getting into our first article of the week. This one's from reading. And they're talking about the denial of service attacks. In fact, more specifically distributed denial of service attacks, spiking, right? This year, well in 2020, and it became more complex as well.

    So I wanted everyone to understand what a denial of service attack is because it is probably the number one reason that the. Quote internet, isn't working unquote denial of service attacks or where a bad guy decides that they want to hold a company hostage. How do you do that? In this day and age, people are all over the place.

    You're not about to walk in the front door armed and tell everybody, Hey, pay up or I'm not leaving. That's just not going to happen. Is it? When will you get right down to it? You don't have to do that anymore. You don't have to have a real hostage. All you have to do is say, Hey, we're going to hold your servers hostage.

    Now you probably know already about ransomware and ransomware is a real big problem. It is growing. It has been out there for a long time and we're, ransomware where they gain access to your systems. And they do one of two things, or even both one is. They will grab all of the data that looks interesting to them.

    So they'll look through your spreadsheets. I'll look through the documents that you have out there. They'll try and find information that they think that they could extort you with. And then the second thing they'll do is encrypt your files and say, pay up if you want to get your files back. And unfortunately many companies, many organizations, including healthcare organizations, government agencies, state, as well as federal.

    And locals have all been hit by this. And they find that their backups are not good enough. They either weren't working properly and they thought they were working or many times what happens is a, just weren't doing it at all. And so all of a sudden, all of their files are. Encrypted do you know the important ones and they just can't conduct business anymore.

    Of course, the first step is they've got to clean up all of these machines that have been infected before they even can do the backup. So in many cases, people are paying the ransom, even though it's been made clear by the state department and others that pane the ransom is supporting terrorism. And what they're doing now is.

    Bringing charges against some of these companies who should have been secure, because if you are a public company or even if you just have basic shareholders, not even a publicly-traded company and you are effectively out of business and by the way, getting one of these ransomware attacks can put you out of business.

    Most of the time it does put you out of business. And so they get. Sued and civilly and potentially criminally as well for sending a hundred thousand dollars, $10 million to terrorists around the world, which of course encourages them to go ahead and ran some more companies. Also lets them know that, Hey, you'll pay a ransom.

    So why not ransom you? It seems like a good idea. Doesn't it? And Oh, guess what they do ransom you and they'll ransom you again. You get the double whammy where you now have to try and get back into business so you say, okay it's going to be way cheaper to pay the ransom, which is what they want.

    That's part of the reason they looked at all your files to see if they can get the County records. How big a company are you? How much could you pay? Cause they're not going to charge a ransom of $10 million to some poor person who's retired. Just trying to go online and. The next step is they say, okay guys, you haven't paid the ransom.

    If you do not pay this extortion fee, we're going to release all of your files online. So now you're going to get. They extorted. And in other words, they'll say, Hey, we grabbed all of these files and they'll give you the names of some of the files Neil just gasp. Oh my gosh. That's our business plan for next year.

    That's our competitive analysis. Oh, that's our intellectual property. Those are all of the designs we've been working on for the last few years or decades in some cases. And I probably should do something about this. What can I do? Pay up this extortion money and we won't release them online.

    Now of course, sometimes they release them anyway. And the other big problem that people have with this sort of thing is if it does get out, you might actually be breaking a law. You might have what's called CUI or other information that really could nail. You legally with the federal or state government.

    So there's a whole lot of problems there. So that's one of the ways the bad guys are ransoming and extorting money from people, but there is another very big deal. And that's what we are talking about right now, which is a denial of service attack. And one of the beautiful things. Form from the standpoint of the bad guy with a denial of service attack is it's almost impossible to trace the source of the attack and it puts the company that's under attack out of business.

    So how would you like that when you get attacked by someone you don't know who's attacking you, you may not even know? Why because many times these types of attacks, which are increasingly cheaper for the bad guys to do many times, these types of attacks are conducted by social activists. Yeah, our green warriors out there and others who will start attacking in these inexpensive ways.

    Of course, you can find all kinds of information online, subscribe to my podcast as well. You'll find it on your favorite podcast platform and [email protected].

    We were just talking about ransomware, how it's being used to hold hostage, various companies, as well as being used for extortion. Pretty bad things. Now we're going to talk about a cheaper and easier way. The bad guys are. He didn't us.

    Hi guys, this is really a fun world, a scary world, all rolled into one because the bad guy's methods are becoming more effective and cheaper for them to conduct. That's the scary side of this whole thing. Because these bad guys are out there making many millions of dollars.

    It used to be difficult to do. They used to have a bad guy that really understood programming and understood the bugs that were existing in our networks and in our computers. Pulling all of that stuff together, trying to make the whole world really a worse place.  It was just a very few people and then the dark web really grew where the bad guys that we're writing the software. Now we're selling it on online forums.

    You can go online and for 10 or 20 bucks, you can buy software that does all of the ransom stuff for you.  If you don't mind giving away five or 10% of your illegal proceeds, all you have to do is. Sign up for an online service that will do everything for you on the backend of the ransomware. They'll do the tech support for the people who have been ransomed. They'll go ahead and yeah, they'll even take phone calls when the people are saying, okay, so how do I pay this? How do I buy Bitcoin in order to pay you? How do I make any of this stuff work? How do I put in this key that you sent me? It doesn't seem to be decrypting. What do I do? Absolutely amazing. It is really quite an industry.

    Then there's obviously pretty complicated and there are simpler ways for the bad guys to nail us. This is what's happened over the last year. 2020 set records over what are called distributed denial of service attacks. How they're used to harass organizations, extort them as well.

    The basic idea is you as an organization, have a website and it might be a federal government website. It might be your local soccer team or state or federal. It doesn't really matter. The extorter will say unless you do what we tell you to do. Which might be to pay a ransom or stop oil drilling in Alaska? It might be anything right.

    Some of these anarchists are out there and if you don't do it, what we're going to do is we're going to shut down your website. For a lot of businesses shutting down the website is a terrible thing because so much of their profit comes from the website.

    So many people mis-think profit.   I was just thinking about this last week. Profit is not bad. It is not evil. Profit is what pays for the light bill. Profit is what pays for the medical plan. Pays for the employees. Pays for the physical facilities. Pays the employees electric bills for the home, for the cars, for everything. Okay. Profit is not evil. Profit is absolutely necessary in order for us to live.

    If you're getting money. You are getting the proceeds from a profit that was made by somebody. Now, obviously, if you work for a government agency that is taking money from people, I wouldn't consider that profit. If you are a regular person and entrepreneur or an employee, that profit is absolutely necessary.

    When one of these green warriors says, you got to stop drilling, or you've got to stop manufacturing this, or you need to free this person, et cetera, et cetera.  You are worried because what are they going to do to you?  Then you find out they're going to put you out of business. Then what do you do?

    So many companies have been complying. You see it all of the time, the people are extorting, various media outlets saying unless you stop taking or stop advertising on this program. It might be Glenn Beck. It might be Rush Limbaugh might be met any of these conservative radio programs. You'd like to listen to.  Unless you stop advertising on those we're going to shut your website down.  Most of these businesses concede. They give in to these terrorist demands that are made by these organizations. What they're afraid of is if these organizations do a denial of service attack, that their website's going to be unavailable and they are no longer going to be able to conduct business.

    That's just one of the things. There's other things that these bad guys do to extort businesses. When you go to a website and you go to the checkout page on that website, what's really happening? Obviously, you're sending a request to the webserver and it's a request for a page and it has to go through an encryption-decryption. Then it has to go into the back end that keeps track of everything in your cart. Then it has to go when they accept the payment, which might be a credit card, et cetera, et cetera. These web servers can only handle a certain amount of traffic. You've heard it before. Oh, my server crashed because I had just this heavy load on it. Too many people are trying to buy my product, which is actually not a bad thing.

    There are also problems with the amount of bandwidth. So you have a server. Great.  It can handle a thousand requests per second. Let's say, which is pretty darn big servers is probably actual little server farm and the network connection to that server or server farm can only handle a hundred requests a second.

    So you've wasted money on the backend. So you tend to try and size that all appropriately. So you're not just pouring money down the drain. What happens with a distributed denial-of service attack is they get dozens, hundreds, or even thousands of computers to try and go in into the cart, try and do a checkout, trying and pull up pages that maybe have a lot of heavy graphics on them so that the server now has a huge load as does the network connection.

    So they're saying, okay, so what do I do about it now? There are some ways to deal with these types of attacks. Are some companies out there I can point you to, if you want to just drop me an email. If you have a web server you're concerned about maybe this happening to you, I can point you in the right direction to CloudFlare or some of these other ones that are out there.

    Just email [email protected]. Be glad to let you know a little bit more about it. But it is hard to shut down, particularly if you are a very small business and your internet provider has never really heard of you before. And the people who are maintaining this server you're in the same boat.

    You're paying me. How much am I? $8. Yeah, no, sorry. We're not gonna, we can't really help you. And in fact, they don't help you. And that can be, even if you're paying couple-hundred bucks, depends on the quality of the people that you're working with. So what they'll do then is have all of these computers hit it's called hitting the web server, trying to gain access to things and shut it down.

    Now, there are some services, as I mentioned that you can use to help stop these things once are underway. But the barrier to entry for performing a denial of service attack is extremely low. There are all kinds of, hire services that allow attackers to launch bigger and more consequential attacks.

    And it's pretty simple to orchestrate. So we've gotta be very careful. Global pandemic drove a sharp increase in these types of attacks. And they're going to continue. They're going to continue because they make money. Man. I'm looking at the FBI advisory on this too. It's frankly, pretty scary.

    We're going to talk about the crack in businesses' cyber armor and it might be you.

    Verizon's 2020 mobile security report has found that foreign 10 companies were breached through a mobile device. With so many of us working from home, frankly, this is really bad news.

    Mobile endpoint security is a real problem, frankly. It's the crack in our organization's cyber armor. We have mobile devices. Many of us are using Android, which you guys already know. Then I say you probably should not be used because of a few problems. The biggest problem, frankly, with it Android is that the security updates just don't make it onto most Android phones when you get right down to it.

    Big problem is that the manufacturers do not take the updates from Google, for Android, for security problems and put them on all of their devices. In fact, in most cases, you're looking at a six-month window before most of these devices have the security updates installed on them. If they ever get installed and looking at some of the statistics about which version of Android these devices are running, it's frankly very scary.

    So it's a huge problem. It's why I always recommend iOS Apple devices. The I-phones the eye pads for most businesses. If you need the utmost insecurity while there's some other things you probably need to look at, however iOS and the iPhone was certified by the military a couple of years ago. It's reasonably safe.

    Of course, nothing's perfect. But. Bottom line, a combination of these best in class technologies, like the I-phones and following some instructions I'm about to give here are really the front line in helping our organizations, our businesses, and you from falling victim to these ever-growing threats.

    These bad guys are extremely well-funded. We just saw Vietnam enter into the league of nations that are known as hackers attacking us. No, we've known about North Korea, China, Russia, Iran. Now we've got Vietnam. And many of those nations have a whole lot of money and their goal is not necessarily to extort all of that money from us.

    In many cases, the goal is just to cause havoc and confusion, and man, have they been good at doing that? So if they develop a tool. And then they share that tool with hackers all over the world. They've accomplished their goals, haven't they? Because they're causing havoc now. And in the case of North Korea, they do want hard currency.

    No question about it. But these tools that are for sale for cheap out on the dark web are being developed. By Russian and Chinese hackers for the most part official ones, they're working for their governments. Mobile devices have really been at the core of many of the 2020s. Highest profile attack.

    So for instance, we talked about this attack against Amazon CEO. Bezos's I phoned compromise incident. And what happened when a mobile device was penetrated by. Just using some bugs in an application and a video that was sent and opened. Okay. So you got to be careful about these things. That's another reason why in my windows hardening course, my introduction course, I really stress removing apps.

    You don't absolutely need it. And another thing that I talk about in this introduction to a windows security course is. The problem we have of the apps we use to communicate. And that's what nail Jeff Bezos. The guy got a divorce and it was just amazing the amount of money that was part of that divorce settlement.

    But he was using an app that he didn't need to be using, and that's how they got onto his phone and were able to grab other things. So just removing those apps, but. I'm really concerned right now about WhatsApp because so many people are using it. I've gotten questions. I've received questions from some of our listeners who have family members who are in the military overseas, and they're asking, Hey, can we use WhatsApp in order to have a secure chat with my daughter or husband, wife, whomever, it might be overseas in the military.

    And although WhatsApp is the most popular communications app it's got over. I think it's 2 billion users worldwide and it has had end ending encryption remember Facebook bought it a couple of years ago. And that makes it dangerous. And the new terms that have to be accepted for using WhatsApp in the future, indicate that Facebook really is starting to play some games here with how secure WhatsApp really is.

    So I go into a lot of detail in one of the modules on how to communicate securely, but there you go, Jeff Bezos, which was very expensive to him. Came in from a mobile device, simple fishing, most common way, mobile devices get compromised. And this is where you typically get an email that looks like it's from the bank or Amazon.

    And you click on a link and unfortunately, Because of the lockdown. So many of us are working from home using our own devices. And what that means is many of these devices have not been vetted by any form of security, professional. Okay. It's really bit of a problem and there's been a 37% increase worldwide.

    And according to this Verizon report in mobile fishing, Just between the last quarter of 2019 and the first of 2020 now add to that, the whole lockdown. And it's gotten a lot worse and that's according to the lookout who tries to keep tracking some of these things. We've also got the problem of a malicious wifi hotspot.

    So don't connect to those. What I advise you to do if you're out. On the road you're maybe at the airport or coffee shop? The good old days, right? Don't use the local wifi. Use your cell phone, use your data plan and have your cell phone.  Tether your computer to go online. That's much safer than using wifi hotspots.

    And we go into quite a bit of training on that as well, in my introduction to windows security courses. So what happens if their security fails. That's where again, you've got to be using something that's moderately or fairly secure, like the iPhone, by the way. Oh gee, Phil Zimmerman. They started another company.

    I don't remember what it was called now. If you're interested, drop me an email. I'll look it up. But they have. Phones that are designed to be highly secure and they're actually Android-based, which they would have to be because Apple doesn't really so source code, unlike Android, you can get most of that source code.

    Anyways, worst outcomes here. Number one, some of these are very hard to detect some of these intrusions. They're hard to get rid of in many cases, and these are real problems. Rule number one, never jailbreak your phone because that's going to open you up to all kinds of problems. There could be spy where payloads that are put onto your phone, but the bottom line don't jailbreak them.

    Keep them up to date. Don't use Android. If you must use Android. The simple rule is to stick with the major manufacturers like Samsung and use their state-of-the-art phone, whatever the best one is that they have, and upgrade your phone at least every two years. If you're using Android. If you're using iOS, you got five years, which is why I phones tend a lot cheaper, frankly, and require encryption.

    All right.  Lots more to talk about.

    I use Amazon all of the time, but there are some things to be very cautious about when it comes to Amazon. It's really not the trusted platform that I started using more than a decade ago. So we're going to get into that right now, bait and switch.

    If you miss any part of today's show, you can also find it [email protected]. Amazon has a lot of problems. In the last segment, we're just talking about how it's CEO got hacked via a message that came in through a messaging app. It was actually a video and it is a problem, right? So you've got that sort of a problem.

    You have the problem of being a small business and trying to compete with Amazon. I will admit that I use Amazon a lot for buying things. It's just simpler. The first thing you have to remember when you're using Amazon is they don't necessarily have the best price.

    In fact, many cases, they are not even close to the best price, both Amazon and Walmart have some amazing, huge stores online target, of course, does as well as some others, but. When you compare the prices between them. I think you might be a little surprised. One of the things Amazon's done to lock us in is this Amazon prime membership, which is really handy.

    You get some of the best deals because they have their prime day. Plus they have some special deals that are just for prime members at different times of the year. That's going to cost you more than a hundred bucks a year for that prime membership. But frankly, it makes up for it in shipping if you use a lot.

    And I'm sure that's part of what they're thinking here, right? And they also now because of courts and really being forced into it, they have a little notice saying that this price might not be the best price and it's available from other sellers. So you can click through and it'll show you other sellers that are there.

    On Amazon's website who have products that are, Amazon's also selling, but yeah, they might be cheaper. Usually when you add that less expensive price, plus what that other vendor on amazon.com wants to charge you for shipping. It's usually about the same price as what Amazon's going to offer it to you for.

    So keep that in mind when you're shopping, the price might not be the best. What looks like a great deal with the price. Mark might not be such a great deal after all. So buyer beware, right? But there's another problem. I, this last year for present got one of those massagers. Now I've really been into massagers for many decades.

    Now I used to get them a Brookstone. They always had the best selection. And so I just buy it from them. Since I got to try it in the store. And it was it was really great. And Brookstone in fact, was headquartered right in my hometown in Merrimack, New Hampshire. I thought that was cool too.

    Cause it's a supporting a local business. Of course, they were purchased. I think it was SIM bought them. And then I have no idea what they're doing nowadays. It closes most if not all of their stores, but anyway, so I've always liked the massagers. They help with those aches and pains that you get at any age.

    And particularly as you get a little bit older and. There was a massager that my massage therapist was using. And they just, one of these little percussive handheld things, it almost looks like a gun and it has a bunch of different attachments you can put on the end and it goes back and forth and just percussively massages.

    It does an amazing job. It gets the muscles that are tight to let go to loosen up. And so I went online and I found what I thought was probably the massagers she was using. She told me, and then of course I forgot what it was and there were dozens of them available on Amazon. So what do you look for social proof, right?

    Isn't that the normal way? So I look in for social proof, which is, Oh, here's the one with the thousand reviews and with the. Oh, five stars or four and a half star raining. Great. Let me just stop. I'll do that. Let me buy that. And you can always return it if it doesn't work. So I did buy it and it did work.

    And let me tell you, I'm just so happy with it, but what I noticed inside the package, it was a little card and I've been seeing this more and more on products that I buy from Amazon. Where the person who's actually fulfilling this order, send you a little notice and maybe ask for some feedback or says, Hey, don't complain to Amazon.

    If you have problems, go directly to us and we'll make sure it gets resolved because they want those five-star reviews from you legitimately. You can't blame the moment. If something happens, which it can happen, nothing's perfect. And they'd tear, take care of it. Lickety-split. I'm still going to give them that five-star review that they frankly deserve because it's a good little product.

    It wasn't necessarily their fault that there was some form of infant mortality, which does happen. And it happens with anybody any time you buy any sort of technology. So I. What did the card a little more closely at to see what it was and guess what they were doing? They said, Hey, listen, if you go on to Amazon and review our product, now they didn't say you had to give us a five-star review, but that was almost implied.

    If you go on to Amazon and review our product and you send us a picture of the review that you made by email. You can choose one of these gifts. And one of the gifts was a battery. For that massager. There were a couple of others that I don't remember cause the battery is the most appealing to me and I thought what the heck?

    I'm going to review it anyway. So I did and I sent them a picture of my email and it's been over a month and I haven't gotten my free battery. They got me to wondering what's really going on here. And I found an article here by Tim Lee over at ARS Technica. Saying that he bought for his kids, this little $24 drone very cool drone.

    And he gave it to his daughter to play with. And I'm not sure who the other kids were, but one of the propellers got stuck in her hair after the kids were playing with it for a few hours. It's really a cool one. It's got four propellers, but the whole thing is enclosed inside a little cage so that the kids can't really get their fingers into it and potentially get hurt.

    Although most of these little tiny drones, you can get whacked with those propellers, and it's not going to hurt at all. Really. They had fun. They were able to play around with it. But after that first few hours, it just basically stopped working because it got caught in the hair and that's going to happen.

    So he went online on Amazon and decided to do a search and he found a great review here. He searched for children's drone and sorted them by average customer review. Which makes sense to me. And he found a $23 drone with 6,400 reviews and an impressive five-star average rating. So let's promise you, that's what I would do, right?

    How about you? I, I think that's what most of the, most of us are doing. There's your social proof. But then he started to look at the five-star reviews. And this is something I talked about on the show about a year ago. How do you tell if the reviews are legitimate or not? While you can do a few things, one is looking for major grammatical errors, which a lot of these reviews have, but here's what he found now.

    Remember. This is supposedly a review for a drone. It says wonderful texture and great taste. Five stars. Absolutely love this, honey. It's quite different from any supermarket purchase, honey out tried. It's rich, thick, fragrant, and tastes wonderful. It's on the expensive side. Yes, but also worth it. The packaging is paper metal and glass in the jars.

    Definitely, be reused or recycled. There we go. There's a grammatical error, but not a lot of them. It goes on and on raving about this honey. This is a drone. So what's going on here? This is a real problem. Here's another review that he found. If you're looking to have a taste of Greece without making the journey, this honey does the trick.

    That was another customer, supposedly that same month, the third one wrote that it was dark luxurious pine honey, not too sweet, absolutely fantastic. With strained, creaky, yogurt and extra cream. Now he said, when you read the reviews on Amazon by date, he saw that the most recent reviewers actually had.

    Bought a drone and they were overwhelmingly not giving it five stars. Bought this from my grandson, a customer wrote on December 26. He played with the, for two hours before broke and it's no longer working. He gave the drone one star. But all these older reviews were for honey. So apparently the manufacturer had tricked Amazon and just thousands of reviews for an unrelated product below its a drone, helping the drone to unfairly rise to the top of Amazon.

    Search results. So there's, I think a very big word of caution. There's a lot of examples on Amazon about this sort of thing. This iPhone 10 battery case listing used to be for a leather wallet, phone case. Another battery case was formally listed for lightning charging cables, a Wi-Fi router that was listed as nanocomputers previously.

    Been by the way that one collecting reviews since 2003, here's a neck brace. It was formerly a shower caddy listing. Guitar string action gauge is now a page for magnetic glue, free eyelashes. So Amazon does say that they have clear guidelines about one product that should be grouped together, and they have guardrails.

    They call them in place to prevent abuse, but this is one type of abuse. And it's pretty obvious because a drone is not honey. So if you were actually to read those reviews, which obviously this guy that wrote this over to our set, Anika, Timothy Lee had not done before you started having problems.

    But if you actually read the reviews and they're all for the right product, then what. What about this back massager that I got this little massager. Is that gonna show up this way? No, it's not because people are going to give it the five-star reviews because they want the gifts are going to be headed their way.

    So be very cautious. Amazon has not solved this problem yet.

    We still got a lot to talk about, including taxes here. For those of us working from home, a big shocker coming.

    You might be in for a bit of a shock if you have been working remotely due to this whole lockdown thing. In fact, millions of us are going to have a bit of a shock coming up soon.

    We have been busy here for the first hour. Talking a little bit about the Amazon bait and switch reviews. What I do when I'm online shopping and how you can help keep yourself not just safer, but make sure you don't get ripped off.

    We went through an article from ARS Technica about how he did get ripped off for gifts this season. We also talked a little bit about mobile endpoint security, some of the problems that frankly we've had with our mobile devices. How Jeff Bezos in fact got a massive problem. I got involved with his divorce and everything else because of his mobile device and denial of service attacks. What that is all about?

    We're going to talk this hour a bit about our remote. Workforce the tax implications. We've got another arrest and jail time. So we're going to talk about bad facial recognition and what's going on there. Cyber resilience. And what can we do this year? I really want to get into these hacked home cameras used to live stream police, weight raids in what are called swatting attacks.

    And then. Solar winds mine. I was just because me, cause there are so many ways this massive hack could have been avoided. Our federal agencies have been compromised. Microsoft now says that due to this SolarWinds, hack somebody God into Microsoft source code. Those are the key to the kingdom.

    And one of the ways Microsoft realizes to stay secure is by keeping it source code secret. And of course we, no, that's work. Microsoft has never had any vulnerabilities. So we'll get into that a lot to talk about this hour. First off, let's talk about this problem with taxes. Many of us have problems, if you work in Maine and you work in Massachusetts, you could have a little bit of a tax problem, but there is a reciprocal agreement that's in place.

    So if you had been working in mass and you live in Maine, Okay. I can see that you're driving down to mass every day and you're living in Maine. So the reciprocity agreement covers that. But how about if you have never stepped foot in Massachusetts? How about if you started working for a company out of New York or a company out of California?

    Did you realize that many of these, all of them, by the way, Democrat administrations are now going to require you to pay state taxes, Connecticut, you name it. All of these, it is very concerning to me. And when we get right down to workforces and the fact that this whole lockdown has really accelerated this trend of working from home.

    And because of that, we've got employers who are letting their workers perform their jobs remotely from home most, if not all of the time. So where does illegal nexus tie in? So they're saying, Hey, listen, your employer. And you both knew exactly where you live and work, but the state departments of taxation can have some very different ideas about where here is.

    So as a result, Texas, Utah, Arkansas workers who are working for New York or Massachusetts based companies will have income taxes with health in the paychecks, even if they've never set foot in the home office. Or never set foot in this state. How about that one? The thing for New Hampshire if you live in Maine, of course.

    Yeah. A lot of these states that have state income taxes, will go ahead and say, okay you don't have to worry about paying our state income tax as well. Or in some cases, they look at it and say, Oh, you pay less state income tax. Then we charge our residents. I don't want to call them citizens because we are not being treated like true citizens anymore, but you pay less in your home state than our residents pay.

    So you don't have to make up the difference as well. So we've gotten dozens of major companies out there all the way through little guys who have been increasing their support from working from home permanently. And I think that's great. We have businesses closing offices. Thank goodness. I don't own business space.

    We've lent our leases laps counting on physical distance, flexible workforce was going to reduce real estate needs. I know one of my daughters is in that boat right now. And in many ways it can be a win-win employer can save overhead costs on those expensive square footage and high demand cities look at what's happened right now in San Francisco.

    For instance, they are a great example of San Francisco. The city has lost 43% of its tax revenue. So you look at it until K while they've lost a lot of tax revenue because of the lockdown and people aren't going out shopping. They're not buying stuff. No. According to the San Francisco economist and yes, indeed the city of San Francisco has its own economists.

    Know that a 43% drop in revenue is due to people moving out of the city. New York, San Francisco, Los Angeles, all expensive, and people are moving to Maine, to Montana, dial in from the woods or get a nice little place down in Florida for instance. But as far as the state's concerned, your beachside can banner might.

    Just as well be right in the middle of downtown Manhattan and you're going to be taxed as such. So we've had these problems for a long time, but living in one state, working in another, but typically it's been adjacent States, just like again, Maine and Massachusetts, right? DC, Maryland, Virginia, maybe Pennsylvania, West Virginia, Delaware.

    Kansas City itself goes across two States. You've got Kansas City, Kansas, and Kansas City, Missouri. So traveling across city limits can mean crossing state lines as well. So any major city near a border has lots of workers that go over the lines back and forth every day. And that's always been tricky from a tax perspective.

    Because both the state where you work and the state where you live is going to want to try and tax your income, but still typically only one state at a time has been able to tax you for your income. And most jurisdictions with a lot of overlaps have agreements, as I said, main and mass and New Hampshire doesn't really have that agreement because they don't have any state income tax or of course sales tax on almost anything.

    But. This is really going to be a problem, frankly. So keep in mind that if you are working for a company that is headquartered or even just has a presence in Arkansas, Connecticut, Delaware, Massachusetts, Nebraska, New York, and Pennsylvania. All of those States have convenient rules on the books that require any work performed for an employer-based in their state.

    That it be taxed as if the worker performing the job is actually. In the state, no matter where the employee is actually located now, New Hampshire is one of the nine states that does not have an income tax. And it's right now in the process of suing Massachusetts over its convenience rules and for other States, by the way, New Jersey, Connecticut, Hawaii, and Iowa are supporting the suit.

    So we'll see what happens there in federal courts. As you probably already know going to court doesn't mean the right thing is going to happen. It's gotten really bad, but at any rate, something to be careful about, if you are working remotely for a company, many of these States are going to become an after you for tax dollars.

    We got a couple of things to get in. I want to talk right now about facial recognition. We what a year, maybe more ago talked about this company called clear view AI Clearview. And what they've been doing has been questionable. They've gone online and done searches. They've combed through social media.

    And they've found and downloaded every picture. They can get the grubby little paws on, and then what they've done is they've put together some facial recognition software. So they've violated laws. They've violated platform rules. It's almost like Facebook when it got started, where apparently Zuckerberg went ahead and stole.

    All of the records of all of the kids that were there, going to school at Harvard and including their photographs and put together this little Facebook thing, the Facebook, and had people rating other people by their looks, et cetera, and just basically stole. To get his business started Facebook. That's the allegation that's been out there.

    There'd been a whole movie by this, about what he did. So that's what Clearview did too. They went ahead and decided we'll just steal all of the photos we can of people. They tied facial recognition software into it, and they perform scans of these images that were scraped from the internet and created a biometric database of the images.

    We're going to talk about that and how we now have people being wrong, not just accused, but arrested, spent jail time. It's a crazy world out there.

    The allegations are that Clearview stole your picture without your consent and without the consent of the websites you put them on. Now they are being used in this biometric database by the police and others with wrongful arrests.

    Hey, if you want to hear the whole show or an older show, you can find them, just go online to Craig peterson.com. You'll see the podcasts there. I podcast the whole radio show, as well as my appearances on radio and television right there. So you can listen to them as podcasts there or on your favorite podcast app. There you go.

    So we were talking about Clearview using these images that were scraped from the internet illegally. In some cases against obvious usage agreement, as well.

    Now is that they've got this biometric database of the images and they can use that database to match an image of one person to one of these preexisting images that has been analyzed and scanned and maybe stolen, right? Depending on how you want to look at it, the allegations are all the way across the board.

    Now neither you nor anybody else whose image was scraped from the internet, even know that it happened. Let alone give Clearview permission to use your image, right? They didn't get permission to take it, and they're not going to get permission to use it.

    So the details of these practices are not well-received by anybody out there. Even the New York Times came out about it last January, which is when I really started talking about it as well. Within three days of the New York times talking about what this Clearview company did, there was a federal class-action suit that was filed.

    And the complaint opened with a quote from justice Brandice that the greatest, dangerous to Liberty lurk in insidious encroachment by men of zeal well-meaning, but without understanding. So it's very interesting. There's a whole bunch of cases. I'm looking at the list of them right now. These will take a while before everything is finalized on them, but here's something we absolutely.

    Do know for a fact. And that is that there have been arrests that have been made due to this database. Anyone who identifies as a policeman can go ahead and download the app onto their iPhone or another device. And can then just take a picture of someone casually on the street. There are people who are making police cameras that are constantly streaming video.

    And on the backend are trying to do facial recognition. I've had a couple of them on my radio show a few years back, and it's cool because it gives the policemen an idea of, is this a bad guy or not? There is this somebody who we should trust somebody we could trust. I'm not really that worried about it.

    Just. Think about the most dangerous thing most pleased officers do, which is a traffic stop. They have no idea who's in the car. If that person's going to try and attack them, et cetera. So having a live stream, thinking about Robocop, which didn't end that well, and what was happening there with the ed two Oh nines as well as Robocop himself, being able to see a person and be able to tell right away what this person's background is if there's any wants or warrants, et cetera, out there.

    That's all well and good to a certain degree, but we just had another man. This is a New Jersey man who was accused of shoplifting and trying to hit a police officer with a car. He was wrongfully arrested based on facial recognition. Now, in this case, it's a black man and these facial recognition software programs that are available.

    Tend to do poorly with any minority, frankly. And or do terribly with some and do poorly with any of them and also do rather poorly with the good old, regular Caucasian in phases like mine. Okay. So this is a third person who's arrested for a crime. He did not commit. He spent 10 days in jail and paid around $5,000 to defend himself.

    So this is a guy that had nothing to do with it. The police got lazy, they said, Oh, we got a facial recognition match. It's this guy because they ran it through some software that had scraped some photos from the internet. Do you see where I'm going with this? And those photos from the internet say it's probably this guy, Nigeria parks.

    And we know his social media is saying it's Nigeria parks. This is where he lives. This is where he posts most of his pictures because you remember our pictures. When we take them, our smartphones have embedded GPS information. Oh, my gosh. And in this particular case, he was apparently 30 miles away from the scene of the crime.

    Okay. Pretty sad. Pretty sad. They dismissed the case because of a lack of evidence. Isn't that wonderful? But the department is now getting sued along with the prosecutor in the city of Woodbridge for false arrest, false imprisonment, and violation of his civil rights. I think he should absolutely win on that.

    2019. And this is an article that came from the New York Times. They're saying a national study of over a hundred facial recognition algorithms found that they didn't work as well on black and Asian. Faces, as I said a little bit earlier see an ACL or attorney named Wessler believes that police should stop using facial recognition technology.

    I am okay with it to a degree. I don't think you should be issuing any sort of an arrest warrant based on facial recognition. I think you might get a clue from that and. From that clue, you can look at the phases and decide for yourself and interview the suspect, do some good old fashioned police work, but this facial recognition arresting people, putting them in jail and then costing them thousands of dollars plus their time and their reputation and what it does to your nerves and everything else is just absolutely insane.

    And bad arrests. So this article in the New York times goes through what happened. Apparently, the officers had been presented with a fraudulent driver's license, one of the officer's report,s or did that. They saw a big bag of suspected marijuana in the man's prof pocket. They tried to handcuff him and that's when he ran, he had a rental car just goes on and on, but.

    It was a problem. And even though Mr. Parks had been arrested twice and incarcerated for selling drugs release back in 2016, doesn't mean that he's the guy that did all of this. So let's be careful. I'm not fond of what Clearview has done, obviously, just based on how I described it and who I quoted. And I don't like the idea of using this facial recognition technology to arrest people.

    Bottom line. So speaking about arresting people, when we get back, we're going to talk about what is called swatting attacks. I don't know if you've heard of these before. They're pretty common, unfortunately, and some of the technology that we've been bringing into our homes to keep us safer is now being used to put our lives in danger if you can believe that.

    Yeah, absolutely true. We'll be talking about that.

    You can also follow me online. Just go to Craig peterson.com. You can subscribe to my newsletter. I'm not an active poster in Facebook or anywhere else, so the newsletter is the best place to get my weekly show summaries.

    We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up in killing people. Yeah. Yeah. Death by a police officer. Here we go.

    If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information. That I have available my podcasts and a little articles that we've written, and you'll also have the opportunity to subscribe to my newsletter. So I'll keep you up to date with the latest, most important articles of the week. I don't send all of my show notes anymore.

    I found that a lot of people. Just don't open them cause it's overwhelming. So I've been lately trying to focus on one tip in particular. So we'll see how this all goes in the future and you can always let me know what you think. Just email me [email protected]. I'd love to know, do prefer to get all of my show notes every week or do you prefer what I've been doing lately, which is a deeper dive into one topic. That seems to be pretty popular, but I'm getting about a 40% interaction rate, which is really good on such a large list.

    I just want to get the message out is my bottom line.

    We have these home cameras that we have welcomed into our homes. And one of the ones that has been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

    And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings to the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

    There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them a live real-time access to all of the ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

    And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring, doorbell cameras.

    Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because of why. Does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

    And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened in a number of occasions and far more than we like to talk about is that there are.

    The bad guys or people who don't like their neighbor and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting prank led police to shoot dead 28 year old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

    After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth. You can have.

    Teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. And apparently they believe the report was an act of swatting where.

    Somebody makes a false report to a police department that causes the police to respond with a SWAT team. Now the audio of this emergency calls been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

    The color also said he had a handgun at had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

    When Mr. Finch came to the door, they said one round was released by the officers after the 28 year old failed to comply with verbal orders to keep his hands up. Why would he, what did he done wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

    And they said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them dead. Injured North taken hostage. His family told local media, he was not involved in online.

    Gaming. Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that the, that hackers are out there who do this swatting maneuver on somebody. And then they have the hacked ring camera at that house and they watch the SWAT team respond. Can you believe that?

    And the FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices. How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that his.

    His revenue, his pay from the work he was doing, delivering food to people's homes was stolen by a hacker because he was using the same email address. Yes. To log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells have allowed hackers to steal pet network passwords, et cetera.

    In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, it causes death, many examples of that, and we're still reusing passwords. Give me a break.

    We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

    But anyway our businesses and government got broken thats what we're going to talk about right now.

    Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

    Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

    And in fact, That's a big problem still, but we'll talk about this right now. SolarWindss is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWindss. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

    We dropped SolarWindss as a vendor, and the reason we dropped them and we made it very clear to them was we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWindss a couple of years ago, and they wouldn't do anything about it.

    So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWindss. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

    Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presumed now to being the hand of Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

    He said SolarWindss, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it an easy target interviews with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWindss websites stopped offering client the compromised programs.

    Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached to, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

    This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because I, I didn't tell you guys this, but I do love the fact that I was right again.

    How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce.

    Schneider. You've probably seen him before. He is also, I think he writes for the Washington post. But remember when this came out the word about the SolarWindss hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

    Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just the North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

    In other words, going out after other countries in the cyber security realm. And we benefit from the lack of norms that are in cybersecurity, but here's what I really liked. The Bruce said. And I agree with entirely. I'm glad he must listen to the show. The fundamental problem is one of economic incentives.

    The market rewards, quick development of products. It rewards new features. It rewards spine on customers, end users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

    It doesn't reward reliability past a bare minimum, and it does not reward resilient at all. And this is what happened with SolarWinds. SolarWindss ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

    It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure. It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

    I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely in excusable, right. Inexcusable. So this is happening with SolarWindss right now, but it's going to be happening with other places out there.

    We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWindss is a Puerto Rican born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

    The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from tech beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the U S treasury department was hacked the U S department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cyber security, and infrastructure.

    Agency. SISA the department of Homeland security, the U S department of state, the department of justice, the national nuclear security administration, the U S department of energy, three U S state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others. I use two of those.

    We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem. How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody use a password manager and I will have a course on that this year.

    Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

    The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an it security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

    Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have 1.4 email coming in and going out SMTP Imam.

    They should be controlled and controlled pretty tightly. According to the department of justice, apparently their email accounts were compromised about 4,000 dish. People's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

    It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what  they need access to?  Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

    Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email [email protected] and let me know, be glad to send you stuff.

    ME@Craig peterson.com.

    Take care guys.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 24 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Facial Recognition and AI Technology

    Welcome!

    Good morning, everybody. I was on WTAG this morning with Jim Polito who is back from his convalescence. We got into a discussion about AI and how it is not as trustworthy as people might think.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here. I was on with the now recovered. Mr. Polito. Yes, indeed. He was in the hospital, this whole COVID thing. Oh, nasty. We got into some depth here on facial recognition. It is gotten pretty bad here when governments using it and misusing it. There are people in jail that just shouldn't be there. It's just not so nice.

    We talked about that and a little bit about the weather in Canada. So here we go with Mr. Polito.

    Jim Polito: [00:00:35] You know what? Let's put it all aside. Let's not even play his intro cause he requires no introduction.

    I'm talking about our tech talk guru and great friend Craig Peterson. Good morning. Sir

    Craig Peterson: [00:00:50] Hey, good morning, Jim.

    Jim Polito: [00:00:52] You got to get to facial recognition, but I got to tell you something that Tommy B mentioned. Of course, you being a Canadian, you understand the jet stream and how the jet stream dips from Canada in the winter. That brings us the cool weather. He said first of all, that the jet stream is flat across the country, with no troughs.

    He said Canada is warmer than usual right now. Could you define what warmer than usual and what it means for Canada to be warmer than usual in January?

    Craig Peterson: [00:01:26] I imported an article on Montreal and which is not that far North and the different sounds snow makes in the winter. It was saying, when it hits 30 below, you get a crunch. Eskimos, I don't know if you know it, but they have what is it like 10 or 12 words for snow, depending on what kind of snow. It is

    Definitions it's different. There's an injun word called a Chinook. And if you are out in Alberta, which is in Western Canada, a chinook is where you get a bubble of warm air. I can remember going to school as a kid being all bundled up because it was, whatever degrees below zero.

    And that. Back in the Fahrenheit days. And then as she would come in and you could see the temperature go up 50 degrees in the matter of less than an hour, but cold weather, warm weather in Canada depending on where you are. Yeah, it's not warm.

    Jim Polito: [00:02:33] It's all relative. Tommy B has talked about the phenomenon of the Chinook and just how weird that is.

    It's almost like. A bubble of oil floating through the water or vinegar. It's the weirdest thing. Yeah, he has, he has described it, right? Yeah. Tommy said that you actually see it coming and wow. Pretty cool. All right. Let's get to look. We know that. Facial recognition. Technology has been an issue with race in that individuals say it miss identifies people of color.

    Now we've been told, let's start with the Las Vegas casinos, which were really the early adopters of this, other than the government that Hey, no facial recognition technology works. It makes certain measurements. That's why knows who you are. You can put a beard on and glasses. It's still going to know who you are, but you're saying that in criminal cases and this just isn't just race or minorities. This is everybody that facial recognition technologies had issues.

    Craig Peterson: [00:03:49]I think we're falling into a trap here, unfortunately, and it's a very common one. People seem to think that computers somehow are better and less error-prone than people.

    The bottom line is that computers are at least no better than the programmer. That becomes a real problem here because it's people, you watch even a shy guy movie, and the computers say that and such, and therefore it must be the way to go. It's almost like watching Fauci, right?

    He might be correct when it comes specifically to one extremely narrow area, which is a problem with almost every Ph.D. I've ever known in my life, is just too narrow. But when you start to consider other factors you're wrong. What's happened now is the police department is believing the results that are coming back from these facial recognition systems.

    We know that they were used for instance, out West in the peaceful demonstrations that happened out in Portland, in Seattle, when they were burning when they were demonstrating against this terrific president

    Jim Polito: [00:05:06] the peaceful demonstration. I love the guy Baghdad, Bob the CNN reporter in front of the fire.

    Craig Peterson: [00:05:12] This is mostly peaceful. So they were using it to try and track people. But we've got a real problem here. It really was exposed the last year with this company called Clearview. Do you remember these guys?

    Jim Polito: [00:05:26] Yeah.

    Craig Peterson: [00:05:27] What happened there is. They were scraping the internet. They were going onto the internet. They were finding people, posting pictures of themselves, their friends or families on Facebook, et cetera. They were pulling all of this into a database and then they have the computer do some analysis on it. Folks, AI-artificial intelligence is not intelligence.

    Machine learning is not learning like the way we learn and the results that come out of these systems just can not be trusted. The really bad thing about this is they're using the results. And so they'll take a picture that they got off of the ATM or some other monitor and they'll take that picture, they'll plug it into the Clearview or some of these other systems. It says it's Joe blow and they believe it. And they go and arrest Joe blow.

    There are cases now where they've thrown Joe blow in prison or jail, I should say. Then they try and prosecute him and he's trying to defend himself. It turns out that in some of these cases, nobody even looked at the pictures, they just trusted the computer.

    Jim Polito: [00:06:37] We're talking with our good friend, Craig Peterson, tech talk guru. Craig, you know what this kind of worries me about, but I do think it's because there has been too much trust in the system. But there are systems now that try to duplicate the work of a, so we all know, you get an x-ray like, believe me, I was just sick. I had plenty of chest x-rays okay. A radiologist reads that x-ray goes through it and yeah, this is okay. Here's what I see. There are just like facial recognition. There are these systems to try to duplicate the work of a radiologist and they haven't been successful. They can be used as a backup. They can be used as a check, but you still need a human being, a man or a woman in front of that image, looking at it.

    There are certain things that the computers, when you do 3d technology and there certain things with a mammogram that sometimes a computer is very effective at finding a certain pattern of blood vessels and whatever.

    But I don't know the eyes of a real person to me make the difference.

    I'll put like money into a bill counter. Trust that, but that's about it.

    Craig Peterson: [00:07:58] Yeah, that's it. Yeah. And AI has been used a lot in medicine lately. Some of this computer stuff doesn't make sense. You mentioned one example, counting money, right?

    Another example that seems to be pretty good is finding cancerous skin cells. So it's basically just taking a picture of your arm. You can get an app for that by the way, and it'll check it out. Some are other types of diagnosis, certain types of cancer in different parts of the body can be detected fairly well by computer.

    And again Fauci narrow areas they are actually better than the human is. But right now, I don't know. It's in the far 90% of the time, a person's going to do a better job.

    Will that flip, he says. The type of AI's that we're looking at for the next 10, 20 years, they are going to get better in certain, very narrow ways. We're not going to be able to see a true tricorder that gives a full diagnosis for many, I think decades.

    Jim Polito: [00:09:09] Well, hold on a second. You dropped a star Trek reference thinking that I would not pick up that Dr. McCoy and his tricorder that I would not pick that up. I know you did that. Just to test me. You drop that in there.

    Yes. He had the little thing he opened up and then he had the little thing he would hold over you. And it basically diagnosed everything.

    Craig Peterson: [00:09:35] Yeah. That's the one I remember too. Dr. McCoy said that he wasn't a bricklayer. He, all he understood was this one narrow part of medicine. And yet we are at pastor Fauci.

    Jim Polito: [00:09:52] Yeah. Wait a minute.

    Didn't he once operate on a Vulcan, remember that one, and the ship was under attack. And I, it was either Spock's father or something. He operated on a Vulcan. Jim his blood is green. Jim, I don't know what to do. On that note, this has been too hard. This is fascinating.

    Obviously, folks, we have a great show from our tech talker, Craig Peterson on the weekends.

    But Craig, how do folks find out more about all of your great work?

    Craig Peterson: [00:10:23] Oh, and this year, things are much better. I am now publishing at least weekly, a little training you can take. It's absolutely free. In addition to getting my newsletter and finding out about the live little training I do and the bigger ones, just go to Craig Peterson, song.com.

    All of the stuff you need to know. I post there right in the homepage, sign up to that email list. I am not going to harass you. Just Craig peterson.com.

    Jim Polito: [00:10:52] I can assure you that he will not. And he does this segment with us out of the goodness of his heart. Craig, always a pleasure, and we will catch up with you next week.

    Craig Peterson: [00:11:04] Bye-bye

    thank you, Craig guy, Craig Peterson. Everybody. Yeah. Yeah. Go to Craig peterson.com. No, he doesn't try to sell you anything. Anyway, a final word when we return. You're listening to the Jim Pollito show. Your safe space.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Facial Recognition and AI Technology

    Welcome!

    Good morning, everybody. I was on WTAG this morning with Jim Polito who is back from his convalescence.  We got into a discussion about AI and how it is not as trustworthy as people might think.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here. I was on with the now recovered. Mr. Polito. Yes, indeed. He was in the hospital, this whole COVID thing. Oh, nasty.  We got into some depth here on facial recognition. It is gotten pretty bad here when governments using it and misusing it. There are people in jail that just shouldn't be there. It's just not so nice.

    We talked about that and a little bit about the weather in Canada. So here we go with Mr. Polito.

    Jim Polito: [00:00:35] You know what? Let's put it all aside. Let's not even play his intro cause he requires no introduction.

    I'm talking about our tech talk guru and great friend Craig Peterson. Good morning. Sir

    Craig Peterson: [00:00:50] Hey, good morning, Jim.

    Jim Polito: [00:00:52] You got to get to facial recognition, but I got to tell you something that Tommy B mentioned. Of course, you being a Canadian, you understand the jet stream and how the jet stream dips from Canada in the winter.  That brings us the cool weather. He said first of all, that the jet stream is flat across the country, with no troughs.

    He said Canada is warmer than usual right now. Could you define what warmer than usual and what it means for Canada to be warmer than usual in January?

    Craig Peterson: [00:01:26] I imported an article on Montreal and which is not that far North and the different sounds snow makes in the winter.  It was saying, when it hits 30 below, you get a crunch. Eskimos, I don't know if you know it, but they have what is it like 10 or 12 words for snow, depending on what kind of snow. It is

    Definitions it's different. There's an injun word called a Chinook. And if you are out in Alberta, which is in Western Canada, a chinook is where you get a bubble of warm air.  I can remember going to school as a kid being all bundled up because it was, whatever degrees below zero.

    And that. Back in the Fahrenheit days. And then as she would come in and you could see the temperature go up 50 degrees in the matter of less than an hour, but cold weather, warm weather in Canada depending on where you are. Yeah, it's not warm.

    Jim Polito: [00:02:33] It's all relative. Tommy B has talked about the phenomenon of the Chinook and just how weird that is.

    It's almost like. A bubble of oil floating through the water or vinegar. It's the weirdest thing. Yeah, he has, he has described it, right? Yeah. Tommy said that you actually see it coming and wow. Pretty cool. All right. Let's get to look. We know that. Facial recognition. Technology has been an issue with race in that individuals say it miss identifies people of color.

    Now we've been told, let's start with the Las Vegas casinos, which were really the early adopters of this, other than the government that Hey, no facial recognition technology works. It makes certain measurements. That's why knows who you are. You can put a beard on and glasses. It's still going to know who you are, but you're saying that in criminal cases and this just isn't just race or minorities. This is everybody that facial recognition technologies had issues.

    Craig Peterson: [00:03:49]I think we're falling into a trap here, unfortunately, and it's a very common one. People seem to think that computers somehow are better and less error-prone than people.

    The bottom line is that computers are at least no better than the programmer. That becomes a real problem here because it's people, you watch even a shy guy movie, and the computers say that and such, and therefore it must be the way to go. It's almost like watching Fauci, right?

    He might be correct when it comes specifically to one extremely narrow area, which is a problem with almost every Ph.D. I've ever known in my life, is just too narrow. But when you start to consider other factors you're wrong. What's happened now is the police department is believing the results that are coming back from these facial recognition systems.

    We know that they were used for instance, out West in the peaceful demonstrations that happened out in Portland, in Seattle, when they were burning when they were demonstrating against this terrific president

    Jim Polito: [00:05:06] the peaceful demonstration. I love the guy Baghdad, Bob the CNN reporter in front of the fire.

    Craig Peterson: [00:05:12] This is mostly peaceful. So they were using it to try and track people. But we've got a real problem here. It really was exposed the last year with this company called Clearview. Do you remember these guys?

    Jim Polito: [00:05:26] Yeah.

    Craig Peterson: [00:05:27] What happened there is. They were scraping the internet. They were going onto the internet. They were finding people, posting pictures of themselves, their friends or families on Facebook, et cetera. They were pulling all of this into a database and then they have the computer do some analysis on it. Folks, AI-artificial intelligence is not intelligence.

    Machine learning is not learning like the way we learn and the results that come out of these systems just can not be trusted. The really bad thing about this is they're using the results. And so they'll take a picture that they got off of the ATM or some other monitor and they'll take that picture, they'll plug it into the Clearview or some of these other systems. It says it's Joe blow and they believe it. And they go and arrest Joe blow.

    There are cases now where they've thrown Joe blow in prison or jail, I should say. Then they try and prosecute him and he's trying to defend himself.  It turns out that in some of these cases, nobody even looked at the pictures, they just trusted the computer.

    Jim Polito: [00:06:37] We're talking with our good friend, Craig Peterson, tech talk guru. Craig, you know what this kind of worries me about, but I do think it's because there has been too much trust in the system. But there are systems now that try to duplicate the work of a, so we all know,  you get an x-ray like, believe me, I was just sick.  I had plenty of chest x-rays okay. A radiologist reads that x-ray goes through it and yeah, this is okay.  Here's what I see.  There are just like facial recognition. There are these systems to try to duplicate the work of a radiologist and they haven't been successful. They can be used as a backup. They can be used as a check, but you still need a human being, a man or a woman in front of that image, looking at it.

    There are certain things that the computers, when you do 3d technology and there certain things with a mammogram that sometimes a computer is very effective at finding a certain pattern of blood vessels and whatever.

    But I don't know the eyes of a real person to me make the difference.

    I'll put like money into a bill counter. Trust that, but that's about it.

    Craig Peterson: [00:07:58] Yeah, that's it. Yeah. And AI has been used a lot in medicine lately. Some of this computer stuff doesn't make sense. You mentioned one example, counting money, right?

    Another example that seems to be pretty good is finding cancerous skin cells. So it's basically just taking a picture of your arm. You can get an app for that by the way, and it'll check it out. Some are other types of diagnosis, certain types of cancer in different parts of the body can be detected fairly well by computer.

    And again Fauci narrow areas they are actually better than the human is. But right now, I don't know. It's in the far 90% of the time, a person's going to do a better job.

    Will that flip,  he says. The type of AI's that we're looking at for the next 10, 20 years, they are going to get better in certain, very narrow ways.  We're not going to be able to see a true tricorder that gives a full diagnosis for many, I think decades.

    Jim Polito: [00:09:09] Well,  hold on a second. You dropped a star Trek reference thinking that I would not pick up that Dr. McCoy and his tricorder that I would not pick that up. I know you did that. Just to test me. You drop that in there.

    Yes. He had the little thing he opened up and then he had the little thing he would hold over you. And it basically diagnosed everything.

    Craig Peterson: [00:09:35] Yeah. That's the one I remember too. Dr. McCoy said that he wasn't a bricklayer. He, all he understood was this one narrow part of medicine. And yet we are at pastor Fauci.

    Jim Polito: [00:09:52] Yeah. Wait a minute.

    Didn't he once operate on a Vulcan, remember that one, and the ship was under attack. And I, it was either Spock's father or something. He operated on a Vulcan. Jim his blood is green. Jim, I don't know what to do. On that note, this has been too hard. This is fascinating.

    Obviously, folks, we have a great show from our tech talker, Craig Peterson on the weekends.

    But Craig, how do folks find out more about all of your great work?

    Craig Peterson: [00:10:23] Oh, and this year, things are much better. I am now publishing at least weekly, a little training you can take. It's absolutely free. In addition to getting my newsletter and finding out about the live little training I do and the bigger ones, just go to Craig Peterson, song.com.

    All of the stuff you need to know. I post there right in the homepage, sign up to that email list. I am not going to harass you. Just Craig peterson.com.

    Jim Polito: [00:10:52] I can assure you that he will not. And he does this segment with us out of the goodness of his heart. Craig, always a pleasure, and we will catch up with you next week.

    Craig Peterson: [00:11:04] Bye-bye

    thank you, Craig guy, Craig Peterson. Everybody. Yeah. Yeah. Go to Craig peterson.com. No, he doesn't try to sell you anything. Anyway, a final word when we return. You're listening to the Jim Pollito show. Your safe space.

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • AS HEARD ON NH Today WGIR-AM 610: The fallout of the SolarWinds Hack, GoDaddy Phishing Debacle and More

    Welcome,

    Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about the Lockdown and the effects it is having on our kids and the amount of time they are spending online. I shared some tips about staying safe online, for kids, yourself, and our senior parents. Here we go with Chris.

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Were into SolarWinds and our federal government network since 2019.

    Good morning, everybody. Craig Peterson here. I was on with Mr. Chris Ryan. He's the new host of New Hampshire today, which is heard throughout the entire state and large parts actually of Maine and Vermont. We had a chance this morning to talk a little more about the SolarWinds hack.

    We went at it a different angle. It's interesting with the different hosts, right? It's just like when I hold a live webinar, the different hosts have different questions, different opinions, and it drives me in a different direction. That's exactly what happened this morning.

    We talked about why is it happening? Not why is Russia or China or any of these other countries attacking us? That's not the question, but why can they? Why aren't we doing enough? That's what we talked about. I think that of course, I think I was right there. It was really, it was a lot of fun. So stick around, you're going to find out a little bit more about why I say this hack happened and how it actually ties in with COVID. So here we go with Mr. Chris Ryan.

    Chris Ryan: [00:01:19] Craig, how are you?

    Craig Peterson: [00:01:21] Tis I. Doing well this morning.

    Chris Ryan: [00:01:24] Good. Appreciate you joining us for the show. So I have a couple of topics I want to get to with you today. As we address the issue of cybersecurity, there was this huge story about Russia and what they're able to do in terms of infiltrating our government's websites and entities and so forth.

    Then that story went away. To me, it is an incredibly significant story and one that's, I think that we need to be cognizant of. What were your big takeaways from that and the message that it sends in regards to our overall cybersecurity as entities and individuals?

    Craig Peterson: [00:01:59] Yeah. Boy, this is really a big deal.

    I think the reason a lot of people stopped covering it is that, frankly, it's a very scary thing and a little hard for most people to understand, so I'm glad you brought it up. But I'm looking at this as an absolute wake up call. How many of these we had, Chris? Three years ago, we had Equifax was, do you remember that? It was huge. Basically, everybody in North America's information was stolen.

    We decided, okay, we got to lock things down a little bit. In this case, SolarWinds, these guys had made multiple huge mistakes. Now SolarWinds software, this Orion software that we're talking about is used by businesses and government agencies to basically command and control their own network computers internally. They are used for security. SolarWinds says it's probably 18,000 of our clients that ended up getting hacked.

    Delving into this a little bit more because in the biz we have been paying attention, right? It looks like the Russians, whoever was, were into SolarWinds and our federal government networks since 2019.

    Now, for far more than one year. Those 18,000 organizations that were affected by this hack, weren't just government agencies. They were what are called managed services providers. Chris, these are businesses that provide IT, outsourced information technology support for businesses all over the country, basically small businesses. So take that 18,000 and multiply it by a minimum of 100 and you start to get an idea of what the impact of this thing is.

    The fact they were in our federal agencies just is absolutely incredible. I'm putting out a little video this week for anyone who's interested in seeing it, I'll send out a link to my email list and we've got a few thousand people on that. I'm going to explain the basics here.

    How you as a tiny business could have protected yourself from this kind of a hack. For our federal agencies to not do the very, very basics here is absolutely astounding. It proves a point I've been saying for decades, which is bottom-line people in every industry just aren't paying attention to security at all. Incompetence runs rampant in every industry, including IT.

    We have to pull up our socks. We have to tighten our firewalls, just the basic stuff.

    To pull these tricks like GoDaddy pulled on their employees here about a week and a half ago is absolutely wrong.

    What GoDaddy did. Once they said, okay we're going to make sure our employees don't open emails that might be phishing attacks that are really emails that are trying to attack us. GoDaddy sent out an internal email saying a $650 employee bonus. So if you want the $650 employee bonus click here and fill out this form.

    They sent it to 500 employees. They did click. They did fill out that form. I can't imagine anything crueler than what they did.

    Now the GoDaddy employees aren't going to be opening an email. Their businesses aren't going to be able to be conducted the way it always has been because they're afraid of opening the email.

    There are much better ways to do this. Chris, my brain is exploding. I got to find the duct tape before my headaches.

    Great. Craig Peterson, joining us here on, New Hampshire today.

    Chris Ryan: [00:06:03] The final thing. You mentioned the deficiencies and we have heard about them. We have known about them in regards to our federal infrastructure. It has been discussed for years, but seemingly little has been done about it.

    Senator Shaheen talked about Kaspersky. I believe is the name of it. Which is a Russian firm, which does some cybersecurity. She had concerns about that being used by government entities and private citizens and it has. What is the concern that you have in regards to this deficiency? If it's continually discussed, why is it not substantively addressed?

    Craig Peterson: [00:06:38] She is absolutely right about Kaspersky. There've been a lot of concerns. They have been a leader in certain parts of cybersecurity,

    But, there was an order that the Trump administration put out that it had to be removed from all of our federal networks. So she's absolutely right about that. We've got to pull our socks.

    These orders again by the Trump administration to pull out some of this Chinese equipment that is embedded into some of our networks is absolutely right. Businesses are just playing fast and loose with this.

    I've been trying to figure out the mentality behind that. What is it? Why are they not really paying attention?

    I think the bottom line is even with federal contractors, because I'm not sure if you know it or not, but I've been running training for two years for the Federal Bureau of investigation, for FBI, I'm the guy that ran all of this InfraGard training. I worked with government agencies. I worked with NGOs, private organizations, and I think it's pretty simple from a business standpoint.

    If I'm going to remove Kaspersky, some of this Chinese equipment. If I'm going to comply with the federal regulations that are already in place that come with a 10-year prison sentence. If I don't comply and I get hacked and come with tens of millions of dollars in fines. If I'm going to spend half a million dollars on that and my competitors are not going to spend a dime on it. How could I stay in business?

    So until we've got, just like the inoculations, right? Where until everybody is basically immune or we have herd immunity, we're not going to get past this COVID infection. Much the same in cybersecurity until most businesses are doing it or building it into their business costs and can compete with other businesses because they're all on equal footing. This is just going to continue going on.

    Chris Ryan: [00:08:40] I appreciate your time.

    Craig Peterson: [00:08:42] Thanks

    Craig Peterson with tech talk joining us here on - New Hampshire today. I am Chris Ryan, along with Justin McIsaac. Chuck Zada joins us up next from the financial exchange still to come, governor Sununu as well as Senator Hassan, Jacoby Meyers from the Patriots.

    This is New Hampshire today on news radio six, 10, and 96 seven.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • AS HEARD ON NH Today WGIR-AM 610: The fallout of the SolarWinds Hack, GoDaddy Phishing Debacle and More

    Welcome,

    Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about the Lockdown and the effects it is having on our kids and the amount of time they are spending online.  I shared some tips about staying safe online, for kids, yourself, and our senior parents. Here we go with Chris. 

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Were into SolarWinds and our federal government network since 2019.

    Good morning, everybody. Craig Peterson here. I was on with Mr. Chris Ryan. He's the new host of New Hampshire today, which is heard throughout the entire state and large parts actually of Maine and Vermont. We had a chance this morning to talk a little more about the SolarWinds hack.

    We went at it a different angle. It's interesting with the different hosts, right? It's just like when I hold a live webinar, the different hosts have different questions, different opinions, and it drives me in a different direction.  That's exactly what happened this morning.

    We talked about why is it happening? Not why is Russia or China or any of these other countries attacking us? That's not the question, but why can they? Why aren't we doing enough? That's what we talked about.  I think that of course, I think I was right there.  It was really, it was a lot of fun. So stick around, you're going to find out a little bit more about why I say this hack happened and how it actually ties in with COVID. So here we go with Mr. Chris Ryan.

    Chris Ryan: [00:01:19] Craig, how are you?

    Craig Peterson: [00:01:21] Tis I. Doing well this morning.

    Chris Ryan: [00:01:24] Good. Appreciate you joining us for the show. So I have a couple of topics I want to get to with you today. As we address the issue of cybersecurity, there was this huge story about Russia and what they're able to do in terms of infiltrating our government's websites and entities and so forth.

    Then that story went away. To me, it is an incredibly significant story and one that's, I think that we need to be cognizant of. What were your big takeaways from that and the message that it sends in regards to our overall cybersecurity as entities and individuals?

    Craig Peterson: [00:01:59] Yeah. Boy, this is really a big deal.

    I think the reason a lot of people stopped covering it is that, frankly, it's a very scary thing and a little hard for most people to understand, so I'm glad you brought it up. But I'm looking at this as an absolute wake up call. How many of these we had, Chris? Three years ago, we had Equifax was, do you remember that? It was huge. Basically, everybody in North America's information was stolen.

    We decided, okay, we got to lock things down a little bit. In this case, SolarWinds, these guys had made multiple huge mistakes. Now SolarWinds software, this Orion software that we're talking about is used by businesses and government agencies to basically command and control their own network computers internally. They are used for security. SolarWinds says it's probably 18,000 of our clients that ended up getting hacked.

    Delving into this a little bit more because in the biz we have been paying attention, right? It looks like the Russians, whoever was, were into SolarWinds and our federal government networks since 2019.

    Now, for far more than one year. Those 18,000 organizations that were affected by this hack, weren't just government agencies. They were what are called managed services providers. Chris, these are businesses that provide IT, outsourced information technology support for businesses all over the country, basically small businesses. So take that 18,000 and multiply it by a minimum of 100 and you start to get an idea of what the impact of this thing is.

    The fact they were in our federal agencies just is absolutely incredible.  I'm putting out a little video this week for anyone who's interested in seeing it, I'll send out a link to my email list and we've got a few thousand people on that. I'm going to explain the basics here.

    How you as a tiny business could have protected yourself from this kind of a hack. For our federal agencies to not do the very, very basics here is absolutely astounding. It proves a point I've been saying for decades, which is bottom-line people in every industry just aren't paying attention to security at all.  Incompetence runs rampant in every industry, including IT.

    We have to pull up our socks. We have to tighten our firewalls, just the basic stuff.

    To pull these tricks like GoDaddy pulled on their employees here about a week and a half ago is absolutely wrong.

    What GoDaddy did. Once they said, okay we're going to make sure our employees don't open emails that might be phishing attacks that are really emails that are trying to attack us. GoDaddy sent out an internal email saying a $650 employee bonus. So if you want the $650 employee bonus click here and fill out this form.

    They sent it to 500 employees. They did click. They did fill out that form. I can't imagine anything crueler than what they did.

    Now the GoDaddy employees aren't going to be opening an email. Their businesses aren't going to be able to be conducted the way it always has been because they're afraid of opening the email.

    There are much better ways to do this. Chris, my brain is exploding. I got to find the duct tape before my headaches.

    Great. Craig Peterson, joining us here on, New Hampshire today.

    Chris Ryan: [00:06:03] The final thing. You mentioned the deficiencies and we have heard about them. We have known about them in regards to our federal infrastructure. It has been discussed for years, but seemingly little has been done about it.

    Senator Shaheen talked about Kaspersky. I believe is the name of it. Which is a Russian firm, which does some cybersecurity. She had concerns about that being used by government entities and private citizens and it has. What is the concern that you have in regards to this deficiency?  If it's continually discussed, why is it not substantively addressed?

    Craig Peterson: [00:06:38] She is absolutely right about Kaspersky. There've been a lot of concerns. They have been a leader in certain parts of cybersecurity,

    But, there was an order that the Trump administration put out that it had to be removed from all of our federal networks. So she's absolutely right about that. We've got to pull our socks.

    These orders again by the Trump administration to pull out some of this Chinese equipment that is embedded into some of our networks is absolutely right. Businesses are just playing fast and loose with this.

    I've been trying to figure out the mentality behind that. What is it? Why are they not really paying attention? 

    I think the bottom line is even with federal contractors, because I'm not sure if you know it or not, but I've been running training for two years for the Federal Bureau of investigation, for FBI, I'm the guy that ran all of this InfraGard training. I worked with government agencies. I worked with NGOs, private organizations, and I think it's pretty simple from a business standpoint.

    If I'm going to remove Kaspersky, some of this Chinese equipment. If I'm going to comply with the federal regulations that are already in place that come with a 10-year prison sentence. If I don't comply and I get hacked and come with tens of millions of dollars in fines. If I'm going to spend half a million dollars on that and my competitors are not going to spend a dime on it. How could I stay in business?

    So until we've got, just like the inoculations, right? Where until everybody is basically immune or we have herd immunity, we're not going to get past this COVID infection. Much the same in cybersecurity until most businesses are doing it or building it into their business costs and can compete with other businesses because they're all on equal footing. This is just going to continue going on.

    Chris Ryan: [00:08:40] I appreciate your time.

    Craig Peterson: [00:08:42] Thanks

    Craig Peterson with tech talk joining us here on - New Hampshire today. I am Chris Ryan, along with Justin McIsaac. Chuck Zada joins us up next from the financial exchange still to come, governor Sununu as well as Senator Hassan, Jacoby Meyers from the Patriots.

    This is New Hampshire today on news radio six, 10, and 96  seven.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Tech Talk with Craig Peterson Podcast: VPNs, Ransomware, Facebook and More

    Welcome!

    This week I am spending a bit of time discussing why you should not use VPNs and why Google removed an Android VPN from the PlayStore. Then some tech predictions for the coming year and Ransomware and More so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Google Removed Shady Android VPN App That Allowed MiTM Attacks

    Don't use VPN services.

    Kazakhstan spies on citizens' HTTPS traffic; browser-makers fight back

    Twitter repeals retweet roadblocks, Facebook follows suit

    2021 Cybersecurity Predictions: The Intergalactic Battle Begins

    Russia's hacking frenzy is a reckoning

    FBI says DoppelPaymer ransomware gang is harassing victims who refuse to pay

    Intel falls on report Microsoft plans to design own chips for PCs and servers

    Facebook Repays News Industry It Destroyed With Print Ads Begging You to Hate Apple

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] I mentioned on the air earlier this week, a friend of mine who got hacked, he's trying to make some money. He's retired doing a little grub hub type delivery service, and all of his money was going to a bad guy. So we're going to get into that.

    Hi everybody. This of course is Craig Peterson. Oh, I hope you guys are having a great week weekend. Hopefully a few have the week off next week. And we'll get back to it after the first of the year.

    The hacking frenzy is just not, I talked about it last weekend, where we've got now the bad guys, assuming it's the Russians.

    There seems to be a lot of speculation that it really is. However, I want to explain why you never really know who does a hack. There are. Tools out there that are used by hackers. And most of these tools are just shared within their little community out on the dark web. And you can go right now if you know how to get onto the dark web and which site to go to you can go right now and grab almost any of those tools that the hackers are using to break into your computer, Mike and beater.

    Everybody's computer out there. That is a problem. And it's a problem with trying to identify who's doing the hack because if you are using the tool that is usually used by China, for instance, there's a whole bunch of tools that are named after pandas because that's China. And it's just, the name is the name.

    It's doesn't necessarily have a whole lot of significance. Okay. But the tools China uses the techniques they use are used potentially by other countries as well. So Russia could be using tools that are usually used by the North Koreans. And, so how do you know by the tool you don't and then on top of it, you have the problem.

    Of people hopping around. You've seen that before. Remember war games, Matthew Broderick, man, when was at 80 sometimes sometime, and it was showing how it was hopping through different machines. And different modem banks in order to get where it wanted to go. And you've certainly seen that in bond movies and everything else where they're hopping from server to server.

    And so they're trying to trace who is this? Where are they coming from? Because we're going to go catch them. And they'll show a little graphic up on the screen and it shows, okay. Boom. Okay. Argentina, and then it's Brazil. And then it went over to Moscow and then over to Beijing and then over to Montreal.

    And then you can't do that, that, that technology does not exist. There's no way for you to know. Because if you don't have control or access to all of these servers that are all over the world, how can you know, you just can't and then to make matters, even worse, the bad guys have compromised, small business computers and home computers as well.

    That really creates some problems because now what we're talking about is the bad guys getting on to your home computer and using that as a base of operations. We've had many times where someone's home computer was used to attack the Pentagon and it had nothing to do with that poor person whose computer was being used.

    We've talked before on the show about how some of these terrorists have been taking over. Business servers, just regular web servers. Hey, it's my server. And I use it for whatever might be e-commerce nowadays. And didn't realize that Al-Qaeda was using my server to share a video of Americans being beheaded.

    That has happened. So if China wanted to attack the US would they necessarily want the US to know it was China, might they want the US to think it's Russia? All of these bigger countries have that ability and now even smaller company countries. We're seeing Vietnam now. One of these nation-state hackers.

    And we're seeing, of course, as you already know, North Korea and China and Russia have been hacking for a long time and it seriously looks like they interfered potentially even directly in our elections because this big hack, these solar winds hack that happened solar winds software that was used to penetrate.

    All kinds of federal agencies, businesses, infrastructure, et cetera. Also penetrated the election systems in some States. It also penetrated the company that makes the election software for most of our elections here in the United States, it is really that bad. So we can't say for sure that this was Russia.

    It might be, it might not be the full assessment of what even happened from that hack is still probably months or frankly years away. We know the department of Homeland security. Commerce treasury state, all founded their systems had been breached and they're saying it was Russian hackers and it may well be Russian hackers.

    I don't have access to any of the hard data to be able to tell you for sure that's who it was, but. These hackers, Russia or whomever, it might be we're in our government systems for months, including some of our election systems. Now, is that a big deal or what now? We're thinking that this is Russia's cozy bear. And they are basically turning business software into a Trojan. And that's what the solar winds thing hack was all about. They had software that is used in networks to monitor and control networks, and it had been turned into a Trojan. Now a Trojan is like a Trojan horse. It's a piece of software that looks like it's something other than what it is.

    That technique has been used for many years, but what did they do while they were in these networks? It's absolutely crazy to look at FireEye, which is the company that discovered this was using solar wind software. They discovered the hack on their own networks and the networks as some of them.

    Clients as well, FireEye is a three and a half billion dollar security company. They are huge. And they said that they had been hacked by a nation-state, and it goes through what the software was. It's a Ryan, which is one of the SolarWinds products. We have used their products before we stopped using them because of some security problems that we had found in their software.

    So we stopped using solar winds 18 months or so ago, and now it has come out that one of the people inside solar wind warned the company about the way they built the software and distributed it and that their software could be used for hacks, which is. In fact, it absolutely was, but this is really bad news because since March they've been in some of these systems, government, and otherwise they've been in our election systems.

    I saw this study. I don't know if you've seen it. That was reported out of, I think it was Michigan, where they had been looking at what's happened with the voting systems. One of the systems was given to a security team who looked into it and found, yeah. There are some serious problems here. It was misattributing votes and it was rejecting.

    What was it like 35% or more of the ballots that should not have been rejected and just open to everything up to total hacking? It's very bad. So are we at war with Russia? Because they have gotten into things like our water systems as part of this hack, our critical infrastructure, our government agencies.

    What's going on? There is a system in place that the federal government's been using is called Einstein patrols. Yeah. Just that Einstein. And what it does is it looks on the networks to see if they're being hacked, but just our software that so many of us use that we should not be using anymore.

    That is the antivirus. That's looking for signatures. Einstein only is effective at identifying known threats. So it's like a bouncer. If you go to a nightclub that has a list of people not to let in, and yet he, he lets him all of these people with knives and guns who are swearing. They're going to kill everyone inside because they're not on the list.

    All right. So this is very inadequate. This Einstein system that the federal government's using in the face of these types of sophisticated hack attacks, and they use these hackers that solar winds or Orion backdoor to gain access to these networks, they wanted access to one of the things that we are trying to get really moving here for smaller businesses is.

    Logging, because if you're not logging, what's going on, you don't know what the bad guys got access to. And you got to keep those logs. Those logs have to be searchable. And if your security company is doing their job, they should be keeping all of the logs from all of these machines for at least two weeks, if not months.

    And you might want to ask them that. Because what happens, frankly, with these things is there's a lot of retrospective work that goes on. Just like with my buddy who got hacked, just trying to make a few bucks over at grub hub. We'll talk more about his specific case in a few minutes, but. I had to spend hours going through forensic information. I can get my hands on him to figure out exactly what happened and what do we need to do to mitigate this problem for him.

    We're going to talk about that exactly. On one guy, trying to make some bucks gets hacked. What can you do to stop it?

    So how did my buddy get fooled or what happened here? That his accounts got hacked. He was locked out and the money that he was trying to make from driving for GrubHub just disappeared. We're going to get right into that.

    So let's get into this problem and it is a problem. It's a very big problem with hackers.

    We've been talking a lot about the nation-state stuff that's been going on, and frankly, the way this latest hack. Hit us all frankly, is very hard to address. This is like the attacker beams themselves into the business's network. But what about my friend?

    What happened to him? How did this all work? He has, and I understand this man. He has not been following all of my advice and I'm sure this is true for most people out there because much of this is confusing. And I'm thinking I should probably do a little bit of training on this one as well for you guys.

    And if you're interested, I need to know. And the only way I'll know is if you email me [email protected] and let me know, you're interested in protecting your online account. I'd be glad to put something together, believe me, and we can have a little bit of free training available for you guys. So again, [email protected], but this was a wake-up moment for so many people.

    In the case of my friend, here's what happened. He was expecting a payment from GrubHub and it could be anybody, it doesn't have to be GrubHub and it was going to go straight into his bank account. How does the configure where he's paid his password, his username, his email address? All of those are configured either in the app or on the website for GrubHub.

    All well and good. Isn't it. It should be pretty easy to do. And in fact, it was, and that's exactly what he did now. Let's talk about the mistake he made. He got an email with a link in it to GrubHub, and he clicked on that. You are you getting what's going on here now? So he clicked on the link for supposedly GrubHub and it wasn't GrubHub. But that's all he had to do. Cause now what he did is he confirmed that people are in fact, or that he in fact had a grubHub interest or GrubHub account. Now sometimes what'll happen is you click on it. It'll take you to a website of a bank or GrubHub in this case, and it's not the real website.

    It'll ask you to verify your username and your password, and you'll type it in. Between you and me, I think he probably did that, but he wouldn't admit to it. So what'll happen is that point is they now have your username and password. Cause you just typed it in and they'll will oftentimes say invalid password, please try again.

    They'll just. Automatically redirect you to the real website, assuming that you gave them your proper username and password, but they can still get you in many cases, even if you don't give your username and password. Rule number one. Remember when you are on your email account and you're looking at the emails and somebody says Hey, you've got to click here in order to verify something, or someone's trying to break into your account.

    So click here so that we can get, get things straightened out and taken care of and blah, blah, blah, rule number one, don't click on that. Rule number two is in. And if you do click on it, don't give any information about yourself, like your username and password, but by clicking on it, you gave a little bit of information.

    So here's what happens. The bad guys send out these. These are like Nigerian scam emails. They have a list of over right now. I think it's about three or 4 billion email addresses. So they'll send out emails to this list of addresses and people will randomly respond, even though they know they should not be responding.

    So they randomly respond to the email by clicking on it. Now they know that my buddy's email address is a valid email address and he was clicking through to do something like it. Might've said, Hey GrubHub, you got to verify your account information or your delivery route or something. Something that's compelling to people who deliver for GrubHub to click on.

    And frankly, even if you don't deliver, if you have a GrubHub account and you have a credit card, a credit card tied into it it might be worthwhile for them to steal that credit card information. Okay. So you collect and that's all you did was you clicked on that email. What happens next is then our friends will have the bad guys we'll say, Oh, okay.

    So that was email account [email protected] and that's where his account email account was [email protected]. Okay, great. Let's have a look online. So I took my body to a website that I recommended you guys use many times and it's called, have I been poned.com? So I want you right now, whether you're on your phone or in front of a computer, go to have I been poned.com and that's spelled like you'd expect it to be it's.

    Have I been B E N P w N E d.com. Have I been polling.com and then type in your email address, I'm going to type in his right now. So this is the email address he was using. I'm not going to tell you exactly what it is. His email address don't embarrass him, but yeah. It says that he was postponed in eight data breaches and found no pastes.

    So here's what that means. Data breaches are where his data was Nolan from a third party. In his case, I'm [email protected] and it says for him, Adobe and October 23rd, Teen 153 million Adobe accounts were breached. Okay. Funny. And so the compromised data from Adobe in 2013 was email addresses, password, hands, passwords, and usernames.

    Now they were, the passwords are encrypted, but it was done very poorly and easy to resolve back to plain text. Okay. So Adobe had his username and his password. And again, between you and me. He has not changed his password in at least 10 years. Okay. So that means they had his email address and his password from the theft from Adobe.

    Oh. But there's more, they also got his email address and password along the way with the email addresses and passwords of 164 million other people from LinkedIn in May, 2016. Oh, and by the way, LinkedIn was hacked also in 2012. So data's out there. It's you can just buy it. Let's see. Aluminum PDF. I don't use that, but apparently he does.

    It was hacked last year, 15 and a half million records of user data appeared for download. Included authentication tokens, which means they don't even have to log in. They can just hack it using a special web browser code, email addresses, genders names, passwords spoken languages and usernames river city media spam list 1.4 billion.

    Records that was in January, 2017 and share this 2018 41 million sTraffic it's a Israeli Mark marketing company at a database, 140 gigabytes of personal data, all kinds of stuff. And it goes on and on. So we'll tell you why clicking on that email is bad when we get back and how they use that. Along with this data that's available out there on the dark web.

    We were talking about our hack, a friend of mine whose account got hacked. His paycheck got stolen and he could not get anything back. So we're going through what happened, why and what I did about it.

    Don't forget, you can also go online. Craig peterson.com. Subscribe to my newsletter, get all of my show notes and warnings and information about trainings, all of that stuff. Craig peterson.com.

    We established that my friend had his information stolen multiple times within in fact, the last year online.

    Now that's a bad thing, frankly, especially when they've got your email address and your passwords. So they sent an email to him and he admits that they did, and that email had a link in it to click on and he admits that he clicked on it. And as I mentioned before, just clicking on that email becomes a problem.

    Because now all they have to do is they track who it is that collect. So they know it was [email protected] because it's tracked. If you look at most links and emails, including the emails I send out, it actually doesn't take you to the ultimate destination. It takes you to another site that is tracking.

    What you're doing is tracking the. Number of clicks and what people are interested in. And that makes sense for people like me, where I'm trying to find out what are you guys interested in so that I can help you out and give you more of that type of information? In the case of the bad guys, they now know that X, Y, [email protected] clicked on this email about the drivers for grub hub.

    All they have to do is look into one of these online databases of stolen identities and find the email address the email for in this case, right? X, Y, [email protected] is that email in there. And the answer is going to be, yes, the email is in there and then they say, okay, X, Y, [email protected]. What's the password and they've got the password right in there.

    So now all they had to do is use his email address and his password over at grub hub. So now they're in there in his account or grub hub, and these people were smart enough to know. All they have to do now is go to the account information pages and change the deposit to account. And that's exactly what they did.

    So they changed the deposit to account. So his payment for delivering all of these different things that GrubHub delivers from local restaurants, et cetera, that payment is now. In their bank account and they have what are known as money mules. I don't know if you saw that mule movie with Clinton sword.

    It was absolutely fantastic. But these money mules are people in the us that fall for the scam of hay. We have a few accounts and we can't have a us bank account. So what we're going to do is we're going to wire you the money in, let's say PayPal, and then I want you to split it up and wired into these other accounts.

    So now you are mule. You are money laundering for them. And a lot of people have fallen for that scam and the FBI and the secret service have arrested a lot of these ringleaders over this type of nastiness that they've been really perpetrating against all of us. So it's a bad thing. So what happens now is he goes to log in to his account.

    It still works. They didn't change his password. Life was still good for him. And he's able to do his work still. However, he notices that his money didn't show up and GrubHub says, yeah, we deposited the money in your account. No problem. So he goes in, he looks at a double-check see, count, just being thorough.

    And he finds, Whoa, wait a minute. This is not my account number. So now we start to get a little bit worried and that's when he calls me up and he comes over and we spend about four hours tracking this down and fixing it. What the bad guys ended up doing is he had changed his password. So now what can they do?

    They're out of luck, right? No, they're not because remember they still have access to who is X, Y, [email protected]. Email. All they do is go to grub hub and say, forgot password and grub hub dutifully sends a password reset to his Hotmail account who has access to his Hotmail account. They do. And so he then says, Oh my gosh, I can't get into my GrubHub account anymore.

    So we go back and forth on this. Ultimately the bad guys. Turned on two factor authentication on his Hotmail account, which is Pinedale by Microsoft outlook.com nowadays. And with two factor authentication, you have to have an authentication app in order to. Change passwords, or even in sometimes now in his case, he was lucky because he was still logged in to outlook to his Hotmail account.

    And we were able to use that to get around some problems. I'm not going to get into all of the gory little details of it, but we managed to reset everything. Thank goodness. So he's now getting his money from grub hub, but ultimately what I ended up having to do is set him up with a one password account.

    Now I have done this for him before, and he has never used it because it is confusing. You gotta really pay attention when you're doing this stuff, because I had to do two or three times with some of these online services that he uses and his banks. But one password is what I recommend. He bought the family version, which is $5 a month.

    There's a one week free trial. I don't get any money from this. One password doesn't pay me anything. Give me anything, nothing. They don't even acknowledge. I exist. All right. We do use it for some of our clients as well, and we do use it for some of our internal stuff too, but what happened is, I got one password set up. We set it up to use two factor authentication.

    One password will act as an authenticator now. I like one password. It just spelled literally one, the digit one password.com. You'll find them online. With the two factor authentication, what happens is when you go to log in, you're going to give you a password.

    And then it's going to ask you for six digit number and that six digit number changes every 30 seconds, which is really a good thing, frankly. We obviously changed his passwords. Now he was very concerned because he doesn't want to have to remember a different password for every website. That's what one password is there for.

    And we use one password to generate fairly memorable passwords, at least easy enough to type in for all of his websites who went through them. One by one, we changed the passwords. On those website, we using one password, had one password. Remember them, those websites that could use nothing indicator for verification, we set up the two factor authentication and now he's cruising along.

    Everything is reset. He has good passwords, different ones on each one of his accounts. And he only has to remember one password, which is that. The password, which is really a passphrase that he uses to get into one password. It makes life much, much easier. And an automatic automatically synchronizes between his iPhone and his desktop computer.

    It also runs on Android and windows and stuff too. So it's very good software. Check it out. If he had done this a few months ago. He would be in pretty good shape as it turns out he didn't, but thank goodness we were able to recover. And by the way, if he didn't have the two factor authentication, because remember the bad guys set it up, he'd have to wait 30 days.

    Another warning and a deletion from the Google play store this week for a VPN service. We're going to tell you about that as well as explain why you should not be using VPN services in most, but not all cases.

    Craig, Peterson here. You can visit me [email protected]. Hey, thanks for joining me today.

    VPNs, I think are one of the least understood technologies that many of us use almost every day. VPNs are used for us to connect to the office. Many people use VPNs to try and keep their information private. It's not as though there's anything to hide in most of these cases, it's just that it's nobody else's business.

    It's not something that people want to share. So they do use VPN. So how do they work? How do they not work? What are the issues involved? That's a little bit about what we're going to cover right now, but let's start with Google. There's a VPN called super VPN free. Now this is a VPN client and the way VPNs work is you have a server, which you can think of as the end point, and you have your client.

    So the client resides on your computer or your mobile device, and it connects to the server. If you're a business and you are trying to use a VPN in order to allow your no, usually not customers, but suppliers or employees to connect into the office. I hope that you're using a model called a zero trust model because what it is really is an Excel.

    to your network. So you're extending that employee's home network or that provider's network office network, you're extending it into yours and you're joining them together, which is obviously a very scary thing to do and can be a very bad thing to do and allow. Some of the malicious software to spread onto the networks.

    Okay. So we've talked about that a lot over time. In this case, the super VPN free VPN client. Has something that is called man in the middle. Now, the way this works is just think of broken telephone. If you've ever tried to play that before we used to do it with a cans, tin cans and strings. Between the cans.

    And so you'd have three people and one person would talk into the can and the person in the middle would hear the message and then would relay it through another can to another buddy who's down that piece of string. And that allowed us to go greater distances. It wasn't, it was a lot of fun. And then of course the old broken telephone game.

    That we used to play the, you might have 10 or 20 people and you try and pass a message from one person to the next and not mess it up. Now, some people of course would mess it up on purpose, but you really can have some fun with those games. In this case, the man in the middle was the VPN server.

    Cause you remember the data's going from your device over an encrypted, hopefully secure connection over the internet. And then it arrives at the VPN server and what this server was doing. And unfortunately, what far too many VPN servers was we're still doing is known as a man in the middle attack. Yeah, the data is going from your device to their server.

    It is encrypted and hopefully using good encryption. And then the next stage is it's decrypted at their server. So you're trying to go to the bank, you're entering account information. And, but that VPN server in the middle of this whole conversation is monitoring everything you're doing. So it gets onto their server.

    They can see your usernames, they can see your passwords, they can see your account numbers, and then it opens a connection from their server to your bank. Yeah. Dangerous. So if you had. This shady VPN app from the Google play store called super VPN free. You might want to remove it, but this is a more generic problem than just one single VPN app.

    This problem is in fact very common. So I want to run through some other reasons why you probably don't want to use VPN services. Remember number one. There might be a man in the middle attack going on and we've even got countries doing that. Now China does that, so they can monitor everything. Even when it's encrypted, we've got cows Exton right now, spying on citizens, HTTPS encrypted traffic.

    And it's a, it's a bad thing. Bottom line VPNs that we're normally using. Now, this does not mean a VPN. That's a private network. That's used internally inside of businesses, but the types of VPNs that consumers are buying, and unfortunately, far too many businesses are buying unknowingly.

    Number one logging, many of these VPN say that the services, Hey, we don't log, which somehow is supposed to make you feel better about it. Some of them say we only logged for 30 minutes. Remember that it's rare for the VPN servers themselves to be in a data center. That's owned by that VPN provider.

    So we have other servers on that same network and that provider that's giving or leasing or renting of that VPN server. Space in that data center is going to be logging all that. So remember, it's in the VPN providers best interest to log their users. It lets them deflect blame to the country. If the customer's doing something that's illegal, if they get a DMCA, take down notice, et cetera, et cetera.

    So if the VPN provider is logging, now, they. If they got into legal trouble would have a little bit of a leg stand on. Even if you're paying $10 a month for the vPN service, it doesn't even pay for their expenses. Most of these VPNs are making money off of you. Okay. Bottom line. And there's a number of ways they're doing it.

    I have a whole webinar on VPNs. And if you want, I'll send you a link. To the copy of my last VPN webinar. Be glad to let you know a little bit more about that. Now there are some VPNs that servers and services that have gone out of business. Recently, one of them is called hide my ass. They went out of business and they gave up all of the information about their users years ago.

    And this was w. We talked about, in fact, on my radio show, this was a G almost 10 years ago. And they handed over evidence that resulted in the arrest of some some of their clients, frankly, who were doing some things that were pretty nasty. Guess what? That provides us with another reason not to use VPN services because we are being lumped in with.

    Every type of evil person you can think of, right? There are the majority of these VPN users. They might be like you and me, and just trying to keep prying eyes from our ISP, from Comcast, from whomever, keep those prying eyes away from our. Our systems, our data is none of their business, and I don't want to share it with them.

    However, the criminals that are out there, the arch criminals that are out there, they are using these VPN services. So the IP addresses of most of these VPN services are actually blacklisted. By some of these providers that are out there and blacklisting is bad because have been using the VPN services or services like tore, for instance, in the onion network are you're going to be blocked at, in quite a number of different banks and other websites.

    We block them routinely for our. Clients as well, because we can't really tell, are you a bad guy? Are you a nation state like China or Russia trying to hack in or are you just using a VPN to try and stay safe? Okay. So there's another reason not to use VPNs. And you might say, Hey, listen, I'm paying anonymously.

    I'm using Bitcoin, whatever might be in order to pay for it. You remember, you're still connecting to the VPN service using your own internet address, and they can log that and it can be traced. VPNs. Don't provide security. Frankly, they are what we call in the business of proxy. And that means that you connect to a server that connects to another server and there might be cashing proxies, et cetera, in order to cut down on their bandwidth.

    But that's what they are. They just are not providing more security. If you think you want more privacy, remember VPNs, don't provide privacy with a few exceptions. They are, again, just a proxy. They're effectively a middleman. Sometimes you're even using this man in the middle attack. We talked about early, earlier.

    If somebody wants to tap your connection, they can still do it. They just have to do it at a different point. Now, remember that the VPN service you're using does not take you to that bank website that you want to go to. That VPN service takes you to some point in the U S or Italy or Sweden, wherever it might be.

    And at that point, now it's out on the open internet. If they want to tap your connection, they can still do it. They just do it a different point. And these major nation States that are trying to spy on people, they also rent. Server time and data from the exact same places that these VPN services are renting from.

    So they then launch attacks against the VPN servers so they can get it, all that information. They can decode. They can do the man in the middle attacks, whatever they want to do. So you're not getting more privacy because all they have to do is monitor at a different point. And although your internet service provider might be tracking where you're going online and selling some of that information, most of these VPN services are doing that exact same as well.

    Now, if you think that you want more encryption and that's why you're going to do it well, you know what? Just using HTTPS on your web browser, that is enough security for almost anything you might be doing. So make sure you using HTTPS colon slash. The websites you want to go to because that website is now connected to you via a VPN provided by that server, like your bank or wherever it is, you may be going online.

    I'm going to do more about VPNs after the first of the year, drop me an email [email protected], if you'd like to find out more.

    You are probably fairly familiar with all of the normal tips about shopping online. We're going to get into little more detail here and what you should do while you're shopping and after your view have been shopping.

    You can find almost all of this stuff up on my [email protected]. And if you are not subscribed to my newsletter or my podcast, please take a minute to do that on your favorite podcasting application.

    There are a lot of tricks they're going on right now when it comes to online shopping things that we have to be very aware of. And you've probably heard about many of them before. There are, of course, all kinds of nasty people out there that are trying to trick us into maybe given a credit card where we shouldn't and I want to.

    Play it a little bit of audio as well from my daughter. And this is really sad, but she got this phone call and it came through on regarding some fallbacks activities in the state of Washington. Do we need to talk to you as soon as possible? This call is from social security administration.

    I'm literally trying to apartment (509) 524-9631. I think it's (509) 524-9631. Thank you. Now I usually don't play the phone number when someone leaves a message. But in this case, I don't know. I, if I was you, I probably would not call it. Cause now they know that you are a person who is potentially going to be open for fraud.

    So don't call those numbers. I think that's an important thing for us all to remember. But in case you couldn't quite make it, how it was the social security administration calling and they were calling because they saw some fraudulent activity in Washington. And so they wanted to follow up with you and you, they wanted you to call back.

    So obviously. Don't do that. My daughter got this phone call just this Thursday and it was in her voicemail. Don't call these people back. I have a friend who he will see a phone number coming in, right call come in. Oh, I don't recognize that call. And so he'll just let it go to voicemail and he doesn't listen to the voicemail.

    He just calls the number back. Hi, you called. Don't do that. And there's a couple of reasons. One is in the, in most of these cases, they are trying to get information about you so they know you'll call them. So they might be able to trick you. But in most cases, that caller ID is fake. So they're sending you a caller ID and it says some phone numbers.

    Sometimes they even use phone numbers of police departments, which is really funny. There's a video online of a police captain getting one of these fraud calls and she keeps this fraudster on the phone and who's telling her that he's going to report her to the local police. They're going to come by and arrest her unless she pays him right now.

    And she's just doing everything she can to not laugh because she's the chief of police. Are you kidding me? And she knew it was a fraudster. So we have to be very careful with these people. And so many of us, particularly the older generations are trusting, and that can be a bad thing, but it's not just them.

    It's the young people too. I am shocked at what they will do, what they'll get away with and how they just don't. Care about cybersecurity. Really don't care. I had a discussion with one of my, one of my sons and he didn't care. He was just, he was pushing back as hard as he possibly could. So maybe it's a dad thing.

    Cause I'm his dad and I'm into cybersecurity. It's what I've done for a living for decades. And he is just rebelling. And he's how old is he now? He's probably 24 or something like that, but I know a lot of us rebel and push back against this stuff. Just like I talked about earlier with the printers, we know we should be keeping our firmware up to date, but we just don't.

    So watch out for those scammers. One time I was. On the floor of a trade show. And I was actually exhibiting there at the trade show and talking with people and everything back and forth. And I thought it was going pretty well. And then I got a phone call and I answered it and it was a lady from the IRS or at least that's what she said she was.

    And I knew it was just totally fake because the IRS doesn't just call you out of the blue, the social security administration. Doesn't just call you out of the blue. They will send you a letter. It's really that simple. So I hung up on her and she called back like six times and I told her, listen, this is a scam.

    I know it's a scam she was asking for. I think it was Apple gift cards were really Apple gift cards. I can see Amazon gift cards, but Apple's a little more limited, I don't know. I don't know. Maybe they'd just buy. Apple phones with those gift cards and then sell them on the gray market or the black market once they got the hands on.

    I just don't know. So it is happening and it is going to happen even more this year. And many people ask why would someone do that? Right there? In many cases, they don't really know what they're doing. They're just calling from a call center and they've got a script to read and they are told that it's legitimate, right?

    In another cases. And of course the people who are running this scam know it's not legitimate. And then other cases, they're an active participant, but they're making money. And it's the only way they know how to make money is rip people off, which is just a shame. And. Between you and I see this all the time in the it world, where there are a lot of businesses out there that are scam artists, they put up a shingle saying I'm a managed services provider, or I'm an it professional because there's money in it.

    And they're not, we have a client. This was absolutely fantastic on Thursday this week. One of our texts. One of our senior texts, one, one of my sons in fact, was out there. And he said that we were the best, it support people he has ever seen. And he's been in business for about 40 years and he was just ever so grateful.

    I was at to everything that we're doing for him and his. Team his company, helping him to grow and solving all of these it problems. He doesn't even have to think about them. He doesn't even hear about them because many times we solve them before they even know about it. But we're right on top of it.

    And we're helping them, we get the right equipment. So he doesn't have to. Buy it again, when it breaks and he doesn't have to do with the downtime that you always have to deal with when something breaks or something fails. So he is very grateful. And so am I frankly, for what he's done for us, which is pay his bill it's right.

    So yeah. They're very good people and made me feel very good about that. But anyhow okay. So I am going on and on here, but let's talk about the online shopping and the safety for online shopping. There is a great article that I picked up from Cece. Which is a federal government agencies called the cybersecurity and infrastructure security agency.

    C I S a.gov is where you'll find a lot of this online, but let's go through some of the tips. The first one is the best defense there is, frankly, which is be aware. Before you do anything, stop and look. And I do that all of the time. I get an email from someone. It might be a legitimate email. It might be legit from Amazon or from Walmart or whatever online store.

    So I always stop and look at it. And number one thing to look for is the grammar. Good English grammar, at least good enough. English grammar that you think that they're probably a native English speaker. Okay. Now you say, great. And there's all kinds are wonderful people who aren't here, English speakers in.

    That's true. Okay. There are multiple things to look at. We're just talking about one of them here right now, which is, are they native English speaker or is this very poor or grammar? Because most businesses are not going to send out an email. They're just full of grammatical mistakes or spelling mistakes.

    Does that make sense to you? They're not going to do that because frankly it just reflects very badly on them. And that's not something that you want to have happen. So that's the first thing to do next. Double check all of the URLs. So that email from address should be absolutely correct. Is it absolutely amazon.com or is it AMA dash Z O n.com or is it a M Z O n.com?

    Any of these. Misspellings common misspellings, things that you might just overlook normally, does that email contain any of those types of things? That's all a part of awareness. And what we're trying to prevent here are what are called phishing attacks, or even spear phishing attacks, where they are sending us something that looks legitimate on its surface, but obviously.

    Is not when you get right into it. So in most cases, when I get an email from somebody, what whomever they might be, I look at it and say, is this a legitimate communication? Am I expecting it? And if it's from a bank of mine or some other vendor, I rarely ever click on the link in there. I usually go to their website directly.

    There's usually most banks have the. Messages thing and you can right there in that messages say, yeah, okay, no problem. Here it is this the same message that they sent me via email. And if you do that, then, it's legit. It's just You don't call back a phone number. If they say they're calling from the local police department, you look them up in the book and yet, and you look them up online, right?

    Who has books anymore? You call that number, not the number that they gave him. All right.

    Now that we know the basics, let's get into the details of what are some of the things you can do. In addition, we're going to get into multi-factor authentication and much more. So here we go.

    Let's talk about these devices that we're going to be buying this year and in next year. 2020 is going to come to an end. I'm really hoping some of this stuff's going to spill over into next year. There's a few things you really should be doing, especially with your bank or Amazon, anywhere where you have financial data. And one of those things is called multifactor authentication.

    A lot of these businesses have this called also two factor authentication. You might see it abbreviated as. To FFA or MFA, but what that allows you to do is have something, and combine that with something you have. That's always been the best practice when it comes to security. Now, obviously there's even more stringent stuff that you could potentially do, but that's your basics of the best stuff.

    So what is this two factor authentication? In many cases, businesses are using a text to message that they'll send you when you log in. So you go into your account. Normally it's where you would set your password and you'll see something there about multi-factor authentication or two factor authentication.

    You'll go to that. And in most cases, they'll ask for your. Phone number and they'll send you a text message to verify it. And. You're off and running. So now the next time you go to log into that site, it's going to want your username or email address, and it's going to want also your password. And hopefully you're using a different password on every website out there.

    And then it's going to send you a text message and that text message will have a number that you can then type in on the website. And then this is okay. This is really you. Now you gotta be careful with this because there are a number of people who have been bamboozled by this. One of the ways they got bamboozled was where yes, indeed.

    People stole their phone number. So an attacker knows that you have something valuable, they want to get into your bank account, or maybe it's get into your Bitcoin account, whatever it might be. And they find out what your cell phone number is. And then they call up your cell phone provider and they say, Hey, I've got a new phone.

    And then they give the, all of the information for the new phone and they can bamboozle them. To get them to switch. And before you know it, cause you're not getting to notice, Hey, I just didn't get any phone calls. Not a big deal. In fact, it's wonderful that people haven't been bothering me on the phone, but what has actually ended up happening is they now have your email address.

    They have assumed. I assume that they have your password because most people use the same password on multiple sites, or it's an easy to guess password, easy enough to find the breached passwords on the dark web. I do it all of the time when I'm looking for dark web stuff for my clients, but now they have your phone number.

    So when they go to log into that bank account, They've got the email address. They got your password. Cause you, you have used that same password elsewhere. And when the bank sends a text message to your phone, it doesn't go to your phone and you don't even know it went to your phone. So here's an important tip.

    Contact your cell provider and have them use a pin or a password with you so that when you call up, they're going to ask you what's the password for the account. Now this is going to be a different password than you'd use on the website. But it's going to be a password. In some cases, it's a pin. So come up with something that you don't use anywhere else and set it up with your cell phone provider.

    All right. So that way, if they are going to hijack your SMS or text messages, it doesn't matter because even then they can't get through, but there's a better way. Okay. There's a better way to do all of this. There are some paid and some free two factor authentication apps. What I use personally, and what we use with our customers is called duo D U O.

    We've been using them for years. Cisco of course bought them because they were the best in the business. That's what Cisco does. So duo allows you to have a different type of two factor authentication. You can also use Google authenticator, which is free. You can use last pass. In fact, I got an email this week from one of the subscribers to my email list, thanking me for the recommendation for last pass.

    And by the way, if you want a copy. I have my special report. I'd be glad to send it to you. That talks about passwords talks about one PA password and last pass and what you should do a little bit about two factor authentication. So I use duo. I also have Google authenticator, although I don't really use that at all.

    I tend to use Google or do I should say. What happens with that is they'll display a QR code when you're setting up the two factor authentication. That's one of those square things that has all of the little squares inside of it that you can use to go to a website is typically what you'd use it for in this case, it then syncs up a special Countdown a few old 30 seconds, and it'll give you a six digit code that you can use.

    And that code is only good for 30 seconds. So now when you go to login, you're going to give you username or email. You're going to give your password. And then it's going to ask you for that. Code so you can use again with duo, I have adjust automatically. It comes up, it's integrated with my one password as well.

    So I can now log in and I know it's extra safe because even if someone steals my phone number, It's not going to do them any good because I do not use my phone for verification for two factor authentication. Now there's one more trick that you could play if you wanted to. And I have done this more than once.

    Some websites do not allow you to use an authenticator app. Yeah, I know behind the times, aren't they? So you have to use SMS. If you want to use two factor authentication, other words, you have to have a text message sent to you. So what I do with those sites is I have a phone number that isn't a real phone.

    So I have a phone number that I got years ago from a company that Google bought nowadays, Google calls it Google voice. So I have a Google voice number and I will give them that number. Now, why would I give him that number? First of all, I can filter calls that are coming in and text messages and everything out.

    And then Google will forward the text message to my phone. And remember it's Google. So it's not terribly private, but that's okay because those numbers are usually only good for a number of minutes. Okay. So it's not a very big deal, but the reason I use. Something like Google voice is it's not a real phone number, so they can't call up T-Mobile or Verizon or whoever you have your phone through pretending to be you and get them to transfer that phone number.

    Because they can't and they won't. Okay. It's very important. The, the SIM card that you have in your phone nowadays, some of these devices have virtual SIM cards. That SIM card that's in your phone can not be stolen or duplicated or anything else either if you're using one of these Google voice numbers.

    So some really important tips there. I hope you took some notes.

    If you didn't, you can find this online. I post these as podcasts that you'll find right on my website @craigpeterson.com. You can listen to them, take notes. My wife even provides a transcription of these things most of the time. Bless her heart she spends a lot of time doing that and she'd appreciate it. Check it out online craig peterson.com.

    We're talking about how to keep your devices safe that you're buying this year things you're getting for family, for friends, maybe for yourself as well. And we're going to get into it more. Now we've got some real surprising things for you guys.

    One of the things that we have to do, and this is again, over and over again, but better than 60% computers have windows, computers are not up to date. Remember we're buying nine devices that are basically computers. Do you remember that whole Barbie thing from not too long ago?

    I, in fact, was on TV with this thing and it was sending audio up to the internet and we were able to intercept it. We did a whole thing on television about this. Obviously it's a very big problem because it's your kid's information. Voices being sent up in the Barbie was interacting. Dope now Mattel cleaned some of that stuff up and that's always a good thing.

    But the point behind this whole computer in a toy or other device thing is that their computers we're talking about mobile phones. And Android phones, just not getting security updates. If you're going to insist on using an Android phone, make sure you get the latest model every two years, because even Samsung only supports their phones.

    They're top of the line phones for two years. Okay. Versus your iPhone, which is good for five or more years. So keep those phones up to date. In fact, when you first get the phone, probably the first thing you should do is check for a software update. Computers are the same thing. Whether you're getting one of these Chromebooks, which are very good in generally speaking, I'll remember it's Google.

    Okay. But the Chromebooks tend to be kept up-to-date because it's pretty much automatic. And I know a lot of security researchers. Use Chromebooks and use them exclusively because they don't have the same security problems as windows. What's one of the reasons apples don't get attacked as much as windows computers.

    Don't because the Macs frankly, are not as common. They're only about 8% of the market out there, depending on whose numbers you're listening to. So why would they go after it? Plus it's a little more hardened than windows is. In fact, it's a lot more hardened than windows is. And Microsoft is starting to FY fall in behind Apple's lead, which I think is a good thing.

    So those computers update them immediately. If you're still running windows seven, make sure you get 10 cause seven. Isn't getting the updates anymore. If you're running windows eight, 8.1, make sure again, you upgrade to windows 10, but brand new computers. Shouldn't come with those. Another quick word of warning about computers that you're buying the home edition of windows does not have the same features as the business additions or enterprise additions of windows.

    So you might want to, when you're buying something, look for windows professional, it has more options. And one of the options that could save your bacon is the ability to put off update. Now, you're I hear you saying Craig, you're always telling us to update. Early and update often. Yeah, that's very true because many times when you get that patch, it's because there is something going on in the wild, bad guys are actively using it to exploit you to exploit your fault.

    Okay. So there's some very good reasons to stay up to date, but. Hey, here's a problem. I had a law office call me up because right in the middle of them, putting together some documents for the court that were due in less than two hours windows and they were running home edition, decided it was going to force them to do an update.

    You can imagine the trouble that ensued because they weren't going to be able to get the paperwork filed with the court in time. Very big problem. But even if you're not an attorney, you're not dealing with the court. When the windows professional does give you the option to schedule the. Dates, you can push them off for a week and then you can get into the more advanced stuff too, with the device management, MDM type stuff where you can now manage that device and make that device secure most, if not all of the time.

    Okay. So let's move on to the next tablets again. You look at something like the Amazon Kindle, the firearms and the here's my watch talking hit the Siri button accidentally. So the Amazon Kindle fire that is an Android tablet. Now, one of the advantages is it is updated by Amazon automatically. It gets all of these security updates and other things.

    Yeah. That's a very good thing, and it gets them for a fair length of time and they are cheap. You can get them for 50 bucks, 70 bucks brand new from Amazon. And I got one a year or two ago, probably a couple of years ago. And it wasn't well packaged and it's shipping and the. The front screen was just cracked all the way down.

    So I returned it, they shipped me another one and that one wasn't cracked. So that's good, but I've kept an eye on it and it has been very good. And I also got with the Amazon fire tablet, one of these stands that you can put it in, it's a charging stand, but when you place it in the charging, stand it then becomes an Amazon Alexa.

    So a little kids come over grandkids, and they want me to play baby shark, which is an annoying song that the grandkids, every generation has this. I remember a slightly older grandchild. A granddaughter who used to love ah, jeepers. What was a gummy bear? That's what it was. Gummy bear.

    Remember that song was incredibly annoying too. And he, in fact, I ended up getting the guy who wrote the sock on radio show with me to talk a little bit about it. It was fun actually. Those of us who needed to be kept up to date all of those tablets, because they are real computers, but nowadays we're buying appliances.

    Like I remember five years ago, I think it was out of the consumer electronics show. I saw a, another one. Before, your home that you put into your home and it had an Android operating system in it, it connected to wifi and it allowed you remotely to say, Oh, you know that steak or Rosa told you to cook in the oven at 5:00 PM, I'm going to be late.

    Okay. So you just go online and I type it into my phone and ta-da, I am now all set. There we go. And it's not going to start cooking it until six 30. That's all well and good, but that appliance has a computer in it and it's sent into wifi. I have you updated it. And does it self update and for how long are they going to be providing updates for that oven?

    Or, I'm sure my now five years later, there's no more updates for it. So you now have a, an appliance, a device that is frankly dangerous on your network, because if somebody, again, they come over to your house, they've got a laptop, they connect to your wifi and it now infects your appliance.

    Okay. Whether it's your washer or your dryer. Those are the two most common, I think right now that are internet connected or your oven or your microwave or your garage doors or your security system or your lights, those can all get infected. And now they are used as launching points to infect everything else.

    You network. Check the update, make sure everything's up to date. And in some cases it's pretty hard to update, but it's worth it. You have to do it even your children's toys. One of the things I do is I put them on a network segment that has no access to anything else. I have an IOT wifi network, internet of things.

    All right. You're listening to Craig Peterson. Make sure you visit me online at craig peterson.com and sign up for my newsletter.

    We've talked about, multi-factor authentication, we've talked about, of course, protecting your devices by keeping your software up to date and that's everything nowadays, really, and how to do that. What's up for that. Now we're going to go into a couple more good points.

    So we did talk about multifactor or two factor software update. Now, once you've purchased an internet connected device, no matter what it is, if it's a router or firewall, if it's a Barbie doll, change the default password.

    Now, in most cases you can connect to the device, just using a web browser that makes it very simple. So you use the web browser, you connect to the device. Most of them have web servers on them. If you can imagine that, a little doll with a web server on it, but yeah, that's what happens. Your refrigerator probably has one of his internet connected and your washer dryer, a almost every even light bulbs have little web servers built into them and you want to connect to them and change the default password.

    So look up the manual. It's probably not going to tell you how to do it with. The information that's in the packing, but if you go online and search for that device, you can find out how to change it and use this is just normal recommendations, right? Use different passwords for every device and always use complex passwords.

    Now complex doesn't mean that it has to have special symbols in this upper case, that lowercase, et cetera, it can just be. Three or four words strung together. That's all it needs to be. You might want to throw a digit or two in there, maybe a special character too, but a phrase is the best. And in order to do that, you're probably best off.

    Using a password manager to help out. So that means using something like one password or last pass. And once you've got that in place, it'll generate these passwords for you automatically it'll remember them. It keeps them encrypted. So you only have to remember one password and that's the password you have set for.

    The password manager now, in my case, I've got it set up with duo again. So I'll go into one password and one password is going to ask me for my password and it's also going to authenticate me via duo on my smartphone. So there's a multifactor three factor authentication. Okay. So important for all of these devices that connect to the internet.

    Also check the devices, privacy, and security settings. And a lot of times the manufacturer will. Let you set up an account on their website. And from there, you can tell it what information you want to share and don't want to share. Now, remember what I was talking about in the last hour with Apple, they are being very good about this and they are now demanding that all of the app developers disclose to you.

    That you have in deed, given consent for this information or that information to be used by that app developer and sold. But you can go to the Mattel website, set up an account for your device or the Samsung or whatever it might be. And right there, you can examine. Your privacy settings and what do I want to allow the vendor to gain access to?

    Okay. Make sure you're not sharing more information. Yeah. Then you absolutely need to provide, they're not going to ask you for social security numbers or other things. There's no reason to write that stuff that the bank or the IRS is going to want. Not these guys, at least, hopefully. Make sure you're enabling automatic software updates, wherever you can.

    The latest version of the software. Usually tells you that it has the latest security fixes. Hopefully it does, but it also helps to ensure the manufacturer still support it. Because if you've got automatic updates and they're sending updates to you and a hundred thousand of your closest friends who also have the same device, they're going to continue to support it.

    And that way, the latest patches are going to be out there, but if you're not getting the updates and nobody else is the manufacturer is not going to have a lot of incentive to give you security updates, then there's the normal stuff about, don't use public wifi. Yeah. That's generally a good idea.

    But if you're using a secure server connection, That's that little lock up in the URL bar. Then you are effectively creating a VPN between your web browser and that remote server, and that's going to be quite safe. So purpose personally, I don't worry so much about that. I do worry about my machine being attacked, but I also have a very good firewall turned on and I have all of the services that I don't need to have shared.

    Turned off and I am going to do. Class on this, a little course on hardening windows. In fact, we've got it all written. We've got slides together. We'll probably be doing that after the first of the year. So keep an eye on your email for that. Cause anybody who gets my newsletter, I'll tell you about that.

    How to harden windows, so that even if you are on a public wifi somewhere, you're going to be relatively safe and the same. Thing's true. If you're. Using your phone for instance, and you're sharing your phone's network connection with your computer. It could still be used by bad guys to try and get into your phone.

    These ISP internet service providers are not completely on top of all the security. Okay. All of the basic stuff don't provide personal information, financial information. I tend to use. These one time, if you will use credit card numbers. So every time I, if I go to a site and I want to buy something let's say I'm on GoDaddy buying a domain or I'm on Walmart side or Amazon site.

    Each one of those, I use a different credit card number with, so check out your credit card provider, all of the major ones, visa and MasterCard. They have the ability to create virtual credit card numbers. And that way that credit card number can only be used on that website. So you give this, you create this credit card number.

    It's very easy to do. It's usually a plugin in your browser. You create a credit card number and it's for amazon.com. And now if somebody were to get that credit card number from Amazon and try and use it somewhere else, it will not work. It will only work on amazon.com. Isn't that cool. And then the other advantage is if someone starts to miss using it, then you can just turn off that virtual credit card number.

    It's really that simple. So have a look at that. Then one time use credit card numbers or these virtual credit card numbers, which is what I like. Where you can use it multiple times on that site, you don't have to create a new one every time, a available from most banks and all major credit card companies.

    Okay. Also be careful with the websites. You're going to make sure you type that URL correctly. As I said before, I always spend a few extra seconds. Whenever I'm on a website, I'm going to a website. I'm reading email, just making sure that it is correct. I spelled Amazon Houghton, or the email address that sent it to me.

    Is legitimate. I can't believe how many times I get an email. It's a phishing email and it's from [email protected]. And that's a word of warning too, to the small businesses that are trying to do online stuff. Make sure you have your own domain. That you're not using Gmail or Hotmail or Yahoo.

    I've seen so many people doing that got even proton mail. Proton mail is quite secure and it's really nice the way they're doing it. It's hosted in Switzerland. Check them out by the way. I put something about that in my newsletter bought a month ago. With what that's all about. And if you want it, just let me know, just email [email protected] and in the subject line mentioned proton mail or something, and I'll forward you that newsletter so that you have it, but you can always search.

    If you don't delete my newsletters, you can always search for that information, but you can have proton mail set you up with your own domain. So it's from Bob's country store.com instead of Bob's country store, gmail.com. Okay. It looks much more legitimate. Let's see offers obviously be careful with those don't click links or download attachments, unless you're.

    Really confident. Again, I tend to go to the website as opposed to click on the email that I got, there always this warning or that other thing, just go to their website, make sure that it's all being encrypted again. That's that little padlock, if it's closed or your information's encrypted, which is really good.

    If you can use a credit card. Don't use a debit card there's laws to limit your liability for fraudulent credit card charges, but you don't really have quite the same level of protection when you're using a debit card and the money will be taken out of your account with a debit card. If a bad guy. Is using your debit card and then you have to file a police report and then you have to file with the company that gave you the debit card.

    And then you have to wait for the money to be credited back to your account. And in the meantime, your checks are bouncing or. If you use the debit card for other things, it is being Denine. Okay. So be very careful with that. Insufficient funds are always going out there. So there's a lot of it's of other things.

    And I would urge you to just be very careful, very cautious, just like Santa Claus, checks his list and checks it twice to the same thing all the time when you're online. Hey, if you don't get my free newsletter right now, make sure you sign up. I have all kinds of tips. That's what it's about. You also get all of my podcasts segment that you can just click on right there in the emails makes your life easy and helps to keep you safe.

    Online. Just visit me online. Craig Peterson.com. You can go look at anything you want. If you scroll down on the homepage, there's a little form you can fill out. If you have an explicit question for me, always glad to answer them. And then at the bottom of the page, a little subscribe box will show up as well.

    Take care, have a great weekend. Join me again next week.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 25 min
  • Tech Talk with Craig Peterson Podcast: VPNs, Ransomware, Facebook and More

    Welcome!  

    This week I am spending a bit of time discussing why you should not use VPNs and why Google removed an Android VPN from the PlayStore. Then some tech predictions for the coming year and Ransomware and More so be sure to Listen in.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Tech Articles Craig Thinks You Should Read:

    Google Removed Shady Android VPN App That Allowed MiTM Attacks

    Don't use VPN services.

    Kazakhstan spies on citizens’ HTTPS traffic; browser-makers fight back

    Twitter repeals retweet roadblocks, Facebook follows suit

    2021 Cybersecurity Predictions: The Intergalactic Battle Begins

    Russia’s hacking frenzy is a reckoning

    FBI says DoppelPaymer ransomware gang is harassing victims who refuse to pay

    Intel falls on report Microsoft plans to design own chips for PCs and servers

    Facebook Repays News Industry It Destroyed With Print Ads Begging You to Hate Apple

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] I mentioned on the air earlier this week, a friend of mine who got hacked, he's trying to make some money. He's retired doing a little grub hub type delivery service, and all of his money was going to a bad guy. So we're going to get into that.

    Hi everybody. This of course is Craig Peterson. Oh, I hope you guys are having a great week weekend. Hopefully a few have the week off next week. And we'll get back to it after the first of the year.

    The hacking frenzy is just not, I talked about it last weekend, where we've got now the bad guys, assuming it's the Russians.

    There seems to be a lot of speculation that it really is. However, I want to explain why you never really know who does a hack. There are. Tools out there that are used by hackers. And most of these tools are just shared within their little community out on the dark web. And you can go right now if you know how to get onto the dark web and which site to go to you can go right now and grab almost any of those tools that the hackers are using to break into your computer, Mike and beater.

    Everybody's computer out there. That is a problem. And it's a problem with trying to identify who's doing the hack because if you are using the tool that is usually used by China, for instance, there's a whole bunch of tools that are named after pandas because that's China. And it's just, the name is the name.

    It's doesn't necessarily have a whole lot of significance. Okay. But the tools China uses the techniques they use are used potentially by other countries as well. So Russia could be using tools that are usually used by the North Koreans. And, so how do you know by the tool you don't and then on top of it, you have the problem.

    Of people hopping around. You've seen that before. Remember war games, Matthew Broderick, man, when was at 80 sometimes sometime, and it was showing how it was hopping through different machines. And different modem banks in order to get where it wanted to go. And you've certainly seen that in bond movies and everything else where they're hopping from server to server.

    And so they're trying to trace who is this? Where are they coming from? Because we're going to go catch them. And they'll show a little graphic up on the screen and it shows, okay. Boom. Okay. Argentina, and then it's Brazil. And then it went over to Moscow and then over to Beijing and then over to Montreal.

    And then you can't do that, that, that technology does not exist. There's no way for you to know. Because if you don't have control or access to all of these servers that are all over the world, how can you know, you just can't and then to make matters, even worse, the bad guys have compromised, small business computers and home computers as well.

    That really creates some problems because now what we're talking about is the bad guys getting on to your home computer and using that as a base of operations. We've had many times where someone's home computer was used to attack the Pentagon and it had nothing to do with that poor person whose computer was being used.

    We've talked before on the show about how some of these terrorists have been taking over. Business servers, just regular web servers. Hey, it's my server. And I use it for whatever might be e-commerce nowadays. And didn't realize that Al-Qaeda was using my server to share a video of Americans being beheaded.

    That has happened. So if China wanted to attack the US would they necessarily want the US to know it was China, might they want the US to think it's Russia? All of these bigger countries have that ability and now even smaller company countries. We're seeing Vietnam now. One of these nation-state hackers.

    And we're seeing, of course, as you already know, North Korea and China and Russia have been hacking for a long time and it seriously looks like they interfered potentially even directly in our elections because this big hack, these solar winds hack that happened solar winds software that was used to penetrate.

    All kinds of federal agencies, businesses, infrastructure, et cetera. Also penetrated the election systems in some States. It also penetrated the company that makes the election software for most of our elections here in the United States, it is really that bad. So we can't say for sure that this was Russia.

    It might be, it might not be the full assessment of what even happened from that hack is still probably months or frankly years away. We know the department of Homeland security. Commerce treasury state, all founded their systems had been breached and they're saying it was Russian hackers and it may well be Russian hackers.

    I don't have access to any of the hard data to be able to tell you for sure that's who it was, but. These hackers, Russia or whomever, it might be we're in our government systems for months, including some of our election systems. Now, is that a big deal or what now? We're thinking that this is Russia's cozy bear. And they are basically turning business software into a Trojan. And that's what the solar winds thing hack was all about. They had software that is used in networks to monitor and control networks, and it had been turned into a Trojan. Now a Trojan is like a Trojan horse. It's a piece of software that looks like it's something other than what it is.

    That technique has been used for many years, but what did they do while they were in these networks? It's absolutely crazy to look at FireEye, which is the company that discovered this was using solar wind software. They discovered the hack on their own networks and the networks as some of them.

    Clients as well, FireEye is a three and a half billion dollar security company. They are huge. And they said that they had been hacked by a nation-state, and it goes through what the software was. It's a Ryan, which is one of the SolarWinds products. We have used their products before we stopped using them because of some security problems that we had found in their software.

    So we stopped using solar winds 18 months or so ago, and now it has come out that one of the people inside solar wind warned the company about the way they built the software and distributed it and that their software could be used for hacks, which is. In fact, it absolutely was, but this is really bad news because since March they've been in some of these systems, government, and otherwise they've been in our election systems.

    I saw this study. I don't know if you've seen it. That was reported out of, I think it was Michigan, where they had been looking at what's happened with the voting systems. One of the systems was given to a security team who looked into it and found, yeah. There are some serious problems here. It was misattributing votes and it was rejecting.

    What was it like 35% or more of the ballots that should not have been rejected and just open to everything up to total hacking? It's very bad. So are we at war with Russia? Because they have gotten into things like our water systems as part of this hack, our critical infrastructure, our government agencies.

    What's going on? There is a system in place that the federal government's been using is called Einstein patrols. Yeah. Just that Einstein. And what it does is it looks on the networks to see if they're being hacked, but just our software that so many of us use that we should not be using anymore.

    That is the antivirus. That's looking for signatures. Einstein only is effective at identifying known threats. So it's like a bouncer. If you go to a nightclub that has a list of people not to let in, and yet he, he lets him all of these people with knives and guns who are swearing. They're going to kill everyone inside because they're not on the list.

    All right. So this is very inadequate. This Einstein system that the federal government's using in the face of these types of sophisticated hack attacks, and they use these hackers that solar winds or Orion backdoor to gain access to these networks, they wanted access to one of the things that we are trying to get really moving here for smaller businesses is.

    Logging, because if you're not logging, what's going on, you don't know what the bad guys got access to. And you got to keep those logs. Those logs have to be searchable. And if your security company is doing their job, they should be keeping all of the logs from all of these machines for at least two weeks, if not months.

    And you might want to ask them that. Because what happens, frankly, with these things is there's a lot of retrospective work that goes on. Just like with my buddy who got hacked, just trying to make a few bucks over at grub hub. We'll talk more about his specific case in a few minutes, but. I had to spend hours going through forensic information. I can get my hands on him to figure out exactly what happened and what do we need to do to mitigate this problem for him.

    We're going to talk about that exactly. On one guy, trying to make some bucks gets hacked. What can you do to stop it?

    So how did my buddy get fooled or what happened here? That his accounts got hacked. He was locked out and the money that he was trying to make from driving for GrubHub just disappeared. We're going to get right into that.

    So let's get into this problem and it is a problem. It's a very big problem with hackers.

    We've been talking a lot about the nation-state stuff that's been going on, and frankly, the way this latest hack. Hit us all frankly, is very hard to address. This is like the attacker beams themselves into the business's network. But what about my friend?

    What happened to him? How did this all work? He has, and I understand this man. He has not been following all of my advice and I'm sure this is true for most people out there because much of this is confusing. And I'm thinking I should probably do a little bit of training on this one as well for you guys.

    And if you're interested, I need to know. And the only way I'll know is if you email me [email protected] and let me know, you're interested in protecting your online account. I'd be glad to put something together, believe me, and we can have a little bit of free training available for you guys. So again, [email protected], but this was a wake-up moment for so many people.

    In the case of my friend, here's what happened. He was expecting a payment from GrubHub and it could be anybody, it doesn't have to be GrubHub and it was going to go straight into his bank account. How does the configure where he's paid his password, his username, his email address? All of those are configured either in the app or on the website for GrubHub.

    All well and good. Isn't it. It should be pretty easy to do. And in fact, it was, and that's exactly what he did now. Let's talk about the mistake he made. He got an email with a link in it to GrubHub, and he clicked on that. You are you getting what's going on here now? So he clicked on the link for supposedly GrubHub and it wasn't GrubHub. But that's all he had to do. Cause now what he did is he confirmed that people are in fact, or that he in fact had a grubHub interest or GrubHub account. Now sometimes what'll happen is you click on it. It'll take you to a website of a bank or GrubHub in this case, and it's not the real website.

    It'll ask you to verify your username and your password, and you'll type it in. Between you and me, I think he probably did that, but he wouldn't admit to it. So what'll happen is that point is they now have your username and password. Cause you just typed it in and they'll will oftentimes say invalid password, please try again.

    They'll just. Automatically redirect you to the real website, assuming that you gave them your proper username and password, but they can still get you in many cases, even if you don't give your username and password. Rule number one. Remember when you are on your email account and you're looking at the emails and somebody says Hey, you've got to click here in order to verify something, or someone's trying to break into your account.

    So click here so that we can get, get things straightened out and taken care of and blah, blah, blah, rule number one, don't click on that. Rule number two is in. And if you do click on it, don't give any information about yourself, like your username and password, but by clicking on it, you gave a little bit of information.

    So here's what happens. The bad guys send out these. These are like Nigerian scam emails. They have a list of over right now. I think it's about three or 4 billion email addresses. So they'll send out emails to this list of addresses and people will randomly respond, even though they know they should not be responding.

    So they randomly respond to the email by clicking on it. Now they know that my buddy's email address is a valid email address and he was clicking through to do something like it. Might've said, Hey GrubHub, you got to verify your account information or your delivery route or something. Something that's compelling to people who deliver for GrubHub to click on.

    And frankly, even if you don't deliver, if you have a GrubHub account and you have a credit card, a credit card tied into it it might be worthwhile for them to steal that credit card information. Okay. So you collect and that's all you did was you clicked on that email. What happens next is then our friends will have the bad guys we'll say, Oh, okay.

    So that was email account [email protected] and that's where his account email account was [email protected]. Okay, great.  Let's have a look online. So I took my body to a website that I recommended you guys use many times and it's called, have I been poned.com? So I want you right now, whether you're on your phone or in front of a computer, go to have I been poned.com and that's spelled like you'd expect it to be it's.

    Have I been B E N P w N E d.com. Have I been polling.com and then type in your email address, I'm going to type in his right now. So this is the email address he was using. I'm not going to tell you exactly what it is. His email address don't embarrass him, but yeah. It says that he was postponed in eight data breaches and found no pastes.

    So here's what that means. Data breaches are where his data was Nolan from a third party. In his case, I'm [email protected] and it says for him, Adobe and October 23rd, Teen 153 million Adobe accounts were breached. Okay. Funny. And so the compromised data from Adobe in 2013 was email addresses, password, hands, passwords, and usernames.

    Now they were, the passwords are encrypted, but it was done very poorly and easy to resolve back to plain text. Okay. So Adobe had his username and his password. And again, between you and me. He has not changed his password in at least 10 years. Okay. So that means they had his email address and his password from the theft from Adobe.

    Oh. But there's more, they also got his email address and password along the way with the email addresses and passwords of 164 million other people from LinkedIn in May, 2016. Oh, and by the way, LinkedIn was hacked also in 2012. So data's out there. It's you can just buy it. Let's see. Aluminum PDF. I don't use that, but apparently he does.

    It was hacked last year, 15 and a half million records of user data appeared for download. Included authentication tokens, which means they don't even have to log in. They can just hack it using a special web browser code, email addresses, genders names, passwords spoken languages and usernames river city media spam list 1.4 billion.

    Records that was in January, 2017 and share this 2018 41 million sTraffic it's a Israeli Mark marketing company at a database, 140 gigabytes of personal data, all kinds of stuff. And it goes on and on. So we'll tell you why clicking on that email is bad when we get back and how they use that. Along with this data that's available out there on the dark web.

    We were talking about our hack, a friend of mine whose account got hacked. His paycheck got stolen and he could not get anything back. So we're going through what happened, why and what I did about it.

    Don't forget, you can also go online. Craig peterson.com. Subscribe to my newsletter, get all of my show notes and warnings and information about trainings, all of that stuff. Craig peterson.com.

    We established that my friend had his information stolen multiple times within in fact, the last year online.

    Now that's a bad thing, frankly, especially when they've got your email address and your passwords. So they sent an email to him and he admits that they did, and that email had a link in it to click on and he admits that he clicked on it. And as I mentioned before, just clicking on that email becomes a problem.

    Because now all they have to do is they track who it is that collect. So they know it was [email protected] because it's tracked. If you look at most links and emails, including the emails I send out, it actually doesn't take you to the ultimate destination. It takes you to another site that is tracking.

    What you're doing is tracking the. Number of clicks and what people are interested in. And that makes sense for people like me, where I'm trying to find out what are you guys interested in so that I can help you out and give you more of that type of information? In the case of the bad guys, they now know that X, Y, [email protected] clicked on this email about the drivers for grub hub.

    All they have to do is look into one of these online databases of stolen identities and find the email address the email for in this case, right? X, Y, [email protected] is that email in there. And the answer is going to be, yes, the email is in there and then they say, okay, X, Y, [email protected]. What's the password and they've got the password right in there.

    So now all they had to do is use his email address and his password over at grub hub. So now they're in there in his account or grub hub, and these people were smart enough to know. All they have to do now is go to the account information pages and change the deposit to account. And that's exactly what they did.

    So they changed the deposit to account. So his payment for delivering all of these different things that GrubHub delivers from local restaurants, et cetera, that payment is now. In their bank account and they have what are known as money mules. I don't know if you saw that mule movie with Clinton sword.

    It was absolutely fantastic. But these money mules are people in the us that fall for the scam of hay. We have a few accounts and we can't have a us bank account. So what we're going to do is we're going to wire you the money in, let's say PayPal, and then I want you to split it up and wired into these other accounts.

    So now you are mule. You are money laundering for them. And a lot of people have fallen for that scam and the FBI and the secret service have arrested a lot of these ringleaders over this type of nastiness that they've been really perpetrating against all of us. So it's a bad thing. So what happens now is he goes to log in to his account.

    It still works. They didn't change his password. Life was still good for him. And he's able to do his work still. However, he notices that his money didn't show up and GrubHub says, yeah, we deposited the money in your account. No problem. So he goes in, he looks at a double-check see, count, just being thorough.

    And he finds, Whoa, wait a minute. This is not my account number. So now we start to get a little bit worried and that's when he calls me up and he comes over and we spend about four hours tracking this down and fixing it. What the bad guys ended up doing is he had changed his password. So now what can they do?

    They're out of luck, right? No, they're not because remember they still have access to who is X, Y, [email protected]. Email. All they do is go to grub hub and say, forgot password and grub hub dutifully sends a password reset to his Hotmail account who has access to his Hotmail account. They do. And so he then says, Oh my gosh, I can't get into my GrubHub account anymore.

    So we go back and forth on this. Ultimately the bad guys. Turned on two factor authentication on his Hotmail account, which is Pinedale by Microsoft outlook.com nowadays. And with two factor authentication, you have to have an authentication app in order to. Change passwords, or even in sometimes now in his case, he was lucky because he was still logged in to outlook to his Hotmail account.

    And we were able to use that to get around some problems. I'm not going to get into all of the gory little details of it, but we managed to reset everything. Thank goodness. So he's now getting his money from grub hub, but ultimately what I ended up having to do is set him up with a one password account.

    Now I have done this for him before, and he has never used it because it is confusing. You gotta really pay attention when you're doing this stuff, because I had to do two or three times with some of these online services that he uses and his banks. But one password is what I recommend. He bought the family version, which is $5 a month.

    There's a one week free trial.  I don't get any money from this. One password doesn't pay me anything. Give me anything, nothing. They don't even acknowledge. I exist. All right.  We do use it for some of our clients as well, and we do use it for some of our internal stuff too, but what happened is, I got one password set up. We set it up to use two factor authentication.

    One password will act as an authenticator now. I like one password. It just spelled literally one, the digit one password.com. You'll find them online. With the two factor authentication, what happens is when you go to log in, you're going to give you a password.

    And then it's going to ask you for six digit number and that six digit number changes every 30 seconds, which is really a good thing, frankly.  We obviously changed his passwords. Now he was very concerned because he doesn't want to have to remember a different password for every website. That's what one password is there for.

    And we use one password to generate fairly memorable passwords, at least easy enough to type in for all of his websites who went through them. One by one, we changed the passwords. On those website, we using one password, had one password. Remember them, those websites that could use nothing indicator for verification, we set up the two factor authentication and now he's cruising along.

    Everything is reset. He has good passwords, different ones on each one of his accounts. And he only has to remember one password, which is that. The password, which is really a passphrase that he uses to get into one password. It makes life much, much easier. And an automatic automatically synchronizes between his iPhone and his desktop computer.

    It also runs on Android and windows and stuff too. So it's very good software. Check it out. If he had done this a few months ago. He would be in pretty good shape as it turns out he didn't, but thank goodness we were able to recover. And by the way, if he didn't have the two factor authentication, because remember the bad guys set it up, he'd have to wait 30 days.

    Another warning and a deletion from the Google play store this week for a VPN service. We're going to tell you about that as well as explain why you should not be using VPN services in most, but not all cases.

    Craig, Peterson here. You can visit me [email protected].  Hey, thanks for joining me today.

    VPNs, I think are one of the least understood technologies that many of us use almost every day. VPNs are used for us to connect to the office. Many people use VPNs to try and keep their information private. It's not as though there's anything to hide in most of these cases, it's just that it's nobody else's business.

    It's not something that people want to share. So they do use VPN. So how do they work? How do they not work? What are the issues involved? That's a little bit about what we're going to cover right now, but let's start with Google. There's a VPN called super VPN free. Now this is a VPN client and the way VPNs work is you have a server, which you can think of as the end point, and you have your client.

    So the client resides on your computer or your mobile device, and it connects to the server. If you're a business and you are trying to use a VPN in order to allow your no, usually not customers, but suppliers or employees to connect into the office. I hope that you're using a model called a zero trust model because what it is really is an Excel.

    to your network. So you're extending that employee's home network or that provider's network office network, you're extending it into yours and you're joining them together, which is obviously a very scary thing to do and can be a very bad thing to do and allow. Some of the malicious software to spread onto the networks.

    Okay. So we've talked about that a lot over time. In this case, the super VPN free VPN client. Has something that is called man in the middle. Now, the way this works is just think of broken telephone. If you've ever tried to play that before we used to do it with a cans, tin cans and strings. Between the cans.

    And so you'd have three people and one person would talk into the can and the person in the middle would hear the message and then would relay it through another can to another buddy who's down that piece of string. And that allowed us to go greater distances. It wasn't, it was a lot of fun. And then of course the old broken telephone game.

    That we used to play the, you might have 10 or 20 people and you try and pass a message from one person to the next and not mess it up. Now, some people of course would mess it up on purpose, but you really can have some fun with those games. In this case, the man in the middle was the VPN server.

    Cause you remember the data's going from your device over an encrypted, hopefully secure connection over the internet. And then it arrives at the VPN server and what this server was doing. And unfortunately, what far too many VPN servers was we're still doing is known as a man in the middle attack. Yeah, the data is going from your device to their server.

    It is encrypted and hopefully using good encryption. And then the next stage is it's decrypted at their server. So you're trying to go to the bank, you're entering account information. And, but that VPN server in the middle of this whole conversation is monitoring everything you're doing. So it gets onto their server.

    They can see your usernames, they can see your passwords, they can see your account numbers, and then it opens a connection from their server to your bank. Yeah. Dangerous. So if you had. This shady VPN app from the Google play store called super VPN free. You might want to remove it, but this is a more generic problem than just one single VPN app.

    This problem is in fact very common. So I want to run through some other reasons why you probably don't want to use VPN services. Remember number one. There might be a man in the middle attack going on and we've even got countries doing that. Now China does that, so they can monitor everything. Even when it's encrypted, we've got cows Exton right now, spying on citizens, HTTPS encrypted traffic.

    And it's a, it's a bad thing. Bottom line VPNs that we're normally using. Now, this does not mean a VPN. That's a private network. That's used internally inside of businesses, but the types of VPNs that consumers are buying, and unfortunately, far too many businesses are buying unknowingly.

    Number one logging, many of these VPN say that the services, Hey, we don't log, which somehow is supposed to make you feel better about it. Some of them say we only logged for 30 minutes. Remember that it's rare for the VPN servers themselves to be in a data center. That's owned by that VPN provider.

    So we have other servers on that same network and that provider that's giving or leasing or renting of that VPN server. Space in that data center is going to be logging all that. So remember, it's in the VPN providers best interest to log their users. It lets them deflect blame to the country. If the customer's doing something that's illegal, if they get a DMCA, take down notice, et cetera, et cetera.

    So if the VPN provider is logging, now, they. If they got into legal trouble would have a little bit of a leg stand on. Even if you're paying $10 a month for the vPN service, it doesn't even pay for their expenses. Most of these VPNs are making money off of you. Okay. Bottom line. And there's a number of ways they're doing it.

    I have a whole webinar on VPNs. And if you want, I'll send you a link. To the copy of my last VPN webinar. Be glad to let you know a little bit more about that. Now there are some VPNs that servers and services that have gone out of business. Recently, one of them is called hide my ass. They went out of business and they gave up all of the information about their users years ago.

    And this was w. We talked about, in fact, on my radio show, this was a G almost 10 years ago. And they handed over evidence that resulted in the arrest of some some of their clients, frankly, who were doing some things that were pretty nasty. Guess what? That provides us with another reason not to use VPN services because we are being lumped in with.

    Every type of evil person you can think of, right? There are the majority of these VPN users. They might be like you and me, and just trying to keep prying eyes from our ISP, from Comcast, from whomever, keep those prying eyes away from our. Our systems, our data is none of their business, and I don't want to share it with them.

    However, the criminals that are out there, the arch criminals that are out there, they are using these VPN services. So the IP addresses of most of these VPN services are actually blacklisted. By some of these providers that are out there and blacklisting is bad because have been using the VPN services or services like tore, for instance, in the onion network are you're going to be blocked at, in quite a number of different banks and other websites.

    We block them routinely for our. Clients as well, because we can't really tell, are you a bad guy? Are you a nation state like China or Russia trying to hack in or are you just using a VPN to try and stay safe? Okay. So there's another reason not to use VPNs. And you might say, Hey, listen, I'm paying anonymously.

    I'm using Bitcoin, whatever might be in order to pay for it. You remember, you're still connecting to the VPN service using your own internet address, and they can log that and it can be traced. VPNs. Don't provide security. Frankly, they are what we call in the business of proxy. And that means that you connect to a server that connects to another server and there might be cashing proxies, et cetera, in order to cut down on their bandwidth.

    But that's what they are. They just are not providing more security. If you think you want more privacy, remember VPNs, don't provide privacy with a few exceptions. They are, again, just a proxy. They're effectively a middleman. Sometimes you're even using this man in the middle attack. We talked about early, earlier.

    If somebody wants to tap your connection, they can still do it. They just have to do it at a different point. Now, remember that the VPN service you're using does not take you to that bank website that you want to go to. That VPN service takes you to some point in the U S or Italy or Sweden, wherever it might be.

    And at that point, now it's out on the open internet. If they want to tap your connection, they can still do it. They just do it a different point. And these major nation States that are trying to spy on people, they also rent. Server time and data from the exact same places that these VPN services are renting from.

    So they then launch attacks against the VPN servers so they can get it, all that information. They can decode. They can do the man in the middle attacks, whatever they want to do. So you're not getting more privacy because all they have to do is monitor at a different point. And although your internet service provider might be tracking where you're going online and selling some of that information, most of these VPN services are doing that exact same as well.

    Now, if you think that you want more encryption and that's why you're going to do it well, you know what? Just using HTTPS on your web browser, that is enough security for almost anything you might be doing. So make sure you using HTTPS colon slash. The websites you want to go to because that website is now connected to you via a VPN provided by that server, like your bank or wherever it is, you may be going online.

    I'm going to do more about VPNs after the first of the year, drop me an email [email protected], if you'd like to find out more.

    You are probably fairly familiar with all of the normal tips about shopping online. We're going to get into little more detail here and what you should do while you're shopping and after your view have been shopping.

    You can find almost all of this stuff up on my [email protected]. And if you are not subscribed to my newsletter or my podcast, please take a minute to do that on your favorite podcasting application.

    There are a lot of tricks they're going on right now when it comes to online shopping things that we have to be very aware of. And you've probably heard about many of them before. There are, of course, all kinds of nasty people out there that are trying to trick us into maybe given a credit card where we shouldn't and I want to.

    Play it a little bit of audio as well from my daughter. And this is really sad, but she got this phone call and it came through on regarding some fallbacks activities in the state of Washington. Do we need to talk to you as soon as possible? This call is from social security administration.

    I'm literally trying to apartment (509) 524-9631. I think it's (509) 524-9631. Thank you. Now I usually don't play the phone number when someone leaves a message. But in this case, I don't know. I, if I was you, I probably would not call it. Cause now they know that you are a person who is potentially going to be open for fraud.

    So don't call those numbers. I think that's an important thing for us all to remember. But in case you couldn't quite make it, how it was the social security administration calling and they were calling because they saw some fraudulent activity in Washington. And so they wanted to follow up with you and you, they wanted you to call back.

    So obviously. Don't do that. My daughter got this phone call just this Thursday and it was in her voicemail. Don't call these people back. I have a friend who he will see a phone number coming in, right call come in. Oh, I don't recognize that call. And so he'll just let it go to voicemail and he doesn't listen to the voicemail.

    He just calls the number back. Hi, you called. Don't do that. And there's a couple of reasons. One is in the, in most of these cases, they are trying to get information about you so they know you'll call them. So they might be able to trick you. But in most cases, that caller ID is fake. So they're sending you a caller ID and it says some phone numbers.

    Sometimes they even use phone numbers of police departments, which is really funny. There's a video online of a police captain getting one of these fraud calls and she keeps this fraudster on the phone and who's telling her that he's going to report her to the local police. They're going to come by and arrest her unless she pays him right now.

    And she's just doing everything she can to not laugh because she's the chief of police. Are you kidding me? And she knew it was a fraudster. So we have to be very careful with these people. And so many of us, particularly the older generations are trusting, and that can be a bad thing, but it's not just them.

    It's the young people too. I am shocked at what they will do, what they'll get away with and how they just don't. Care about cybersecurity. Really don't care. I had a discussion with one of my, one of my sons and he didn't care. He was just, he was pushing back as hard as he possibly could. So maybe it's a dad thing.

    Cause I'm his dad and I'm into cybersecurity. It's what I've done for a living for decades. And he is just rebelling. And he's how old is he now? He's probably 24 or something like that, but I know a lot of us rebel and push back against this stuff. Just like I talked about earlier with the printers, we know we should be keeping our firmware up to date, but we just don't.

    So watch out for those scammers. One time I was. On the floor of a trade show. And I was actually exhibiting there at the trade show and talking with people and everything back and forth. And I thought it was going pretty well. And then I got a phone call and I answered it and it was a lady from the IRS or at least that's what she said she was.

    And I knew it was just totally fake because the IRS doesn't just call you out of the blue, the social security administration. Doesn't just call you out of the blue. They will send you a letter. It's really that simple. So I hung up on her and she called back like six times and I told her, listen, this is a scam.

    I know it's a scam she was asking for. I think it was Apple gift cards were really Apple gift cards. I can see Amazon gift cards, but Apple's a little more limited, I don't know. I don't know. Maybe they'd just buy. Apple phones with those gift cards and then sell them on the gray market or the black market once they got the hands on.

    I just don't know. So it is happening and it is going to happen even more this year. And many people ask why would someone do that? Right there? In many cases, they don't really know what they're doing. They're just calling from a call center and they've got a script to read and they are told that it's legitimate, right?

    In another cases. And of course the people who are running this scam know it's not legitimate. And then other cases, they're an active participant, but they're making money. And it's the only way they know how to make money is rip people off, which is just a shame. And. Between you and I see this all the time in the it world, where there are a lot of businesses out there that are scam artists, they put up a shingle saying I'm a managed services provider, or I'm an it professional because there's money in it.

    And they're not, we have a client. This was absolutely fantastic on Thursday this week. One of our texts. One of our senior texts, one, one of my sons in fact, was out there. And he said that we were the best, it support people he has ever seen. And he's been in business for about 40 years and he was just ever so grateful.

    I was at to everything that we're doing for him and his. Team his company, helping him to grow and solving all of these it problems. He doesn't even have to think about them. He doesn't even hear about them because many times we solve them before they even know about it. But we're right on top of it.

    And we're helping them, we get the right equipment. So he doesn't have to. Buy it again, when it breaks and he doesn't have to do with the downtime that you always have to deal with when something breaks or something fails. So he is very grateful. And so am I frankly, for what he's done for us, which is pay his bill it's right.

    So yeah. They're very good people and made me feel very good about that. But anyhow okay. So I am going on and on here, but let's talk about the online shopping and the safety for online shopping. There is a great article that I picked up from Cece. Which is a federal government agencies called the cybersecurity and infrastructure security agency.

    C I S a.gov is where you'll find a lot of this online, but let's go through some of the tips. The first one is the best defense there is, frankly, which is be aware. Before you do anything, stop and look. And I do that all of the time. I get an email from someone. It might be a legitimate email. It might be legit from Amazon or from Walmart or whatever online store.

    So I always stop and look at it. And number one thing to look for is the grammar. Good English grammar, at least good enough. English grammar that you think that they're probably a native English speaker. Okay. Now you say, great. And there's all kinds are wonderful people who aren't here, English speakers in.

    That's true. Okay. There are multiple things to look at. We're just talking about one of them here right now, which is, are they native English speaker or is this very poor or grammar? Because most businesses are not going to send out an email. They're just full of grammatical mistakes or spelling mistakes.

    Does that make sense to you? They're not going to do that because frankly it just reflects very badly on them. And that's not something that you want to have happen. So that's the first thing to do next. Double check all of the URLs. So that email from address should be absolutely correct. Is it absolutely amazon.com or is it AMA dash Z O n.com or is it a M Z O n.com?

    Any of these. Misspellings common misspellings, things that you might just overlook normally, does that email contain any of those types of things? That's all a part of awareness. And what we're trying to prevent here are what are called phishing attacks, or even spear phishing attacks, where they are sending us something that looks legitimate on its surface, but obviously.

    Is not when you get right into it. So in most cases, when I get an email from somebody, what whomever they might be, I look at it and say, is this a legitimate communication? Am I expecting it? And if it's from a bank of mine or some other vendor, I rarely ever click on the link in there. I usually go to their website directly.

    There's usually most banks have the. Messages thing and you can right there in that messages say, yeah, okay, no problem. Here it is this the same message that they sent me via email. And if you do that, then, it's legit. It's just You don't call back a phone number. If they say they're calling from the local police department, you look them up in the book and yet, and you look them up online, right?

    Who has books anymore? You call that number, not the number that they gave him. All right.

    Now that we know the basics, let's get into the details of what are some of the things you can do. In addition, we're going to get into multi-factor authentication and much more. So here we go.

    Let's talk about these devices that we're going to be buying this year and in next year. 2020 is going to come to an end. I'm really hoping some of this stuff's going to spill over into next year. There's a few things you really should be doing, especially with your bank or Amazon, anywhere where you have financial data. And one of those things is called multifactor authentication.

    A lot of these businesses have this called also two factor authentication. You might see it abbreviated as. To FFA or MFA, but what that allows you to do is have something, and combine that with something you have. That's always been the best practice when it comes to security. Now, obviously there's even more stringent stuff that you could potentially do, but that's your basics of the best stuff.

    So what is this two factor authentication? In many cases, businesses are using a text to message that they'll send you when you log in. So you go into your account. Normally it's where you would set your password and you'll see something there about multi-factor authentication or two factor authentication.

    You'll go to that. And in most cases, they'll ask for your. Phone number and they'll send you a text message to verify it. And. You're off and running. So now the next time you go to log into that site, it's going to want your username or email address, and it's going to want also your password. And hopefully you're using a different password on every website out there.

    And then it's going to send you a text message and that text message will have a number that you can then type in on the website. And then this is okay. This is really you. Now you gotta be careful with this because there are a number of people who have been bamboozled by this. One of the ways they got bamboozled was where yes, indeed.

    People stole their phone number. So an attacker knows that you have something valuable, they want to get into your bank account, or maybe it's get into your Bitcoin account, whatever it might be. And they find out what your cell phone number is. And then they call up your cell phone provider and they say, Hey, I've got a new phone.

    And then they give the, all of the information for the new phone and they can bamboozle them. To get them to switch. And before you know it, cause you're not getting to notice, Hey, I just didn't get any phone calls. Not a big deal. In fact, it's wonderful that people haven't been bothering me on the phone, but what has actually ended up happening is they now have your email address.

    They have assumed. I assume that they have your password because most people use the same password on multiple sites, or it's an easy to guess password, easy enough to find the breached passwords on the dark web. I do it all of the time when I'm looking for dark web stuff for my clients, but now they have your phone number.

    So when they go to log into that bank account, They've got the email address. They got your password. Cause you, you have used that same password elsewhere. And when the bank sends a text message to your phone, it doesn't go to your phone and you don't even know it went to your phone. So here's an important tip.

    Contact your cell provider and have them use a pin or a password with you so that when you call up, they're going to ask you what's the password for the account. Now this is going to be a different password than you'd use on the website. But it's going to be a password. In some cases, it's a pin. So come up with something that you don't use anywhere else and set it up with your cell phone provider.

    All right. So that way, if they are going to hijack your SMS or text messages, it doesn't matter because even then they can't get through, but there's a better way. Okay. There's a better way to do all of this. There are some paid and some free two factor authentication apps. What I use personally, and what we use with our customers is called duo D U O.

    We've been using them for years. Cisco of course bought them because they were the best in the business. That's what Cisco does. So duo allows you to have a different type of two factor authentication. You can also use Google authenticator, which is free. You can use last pass. In fact, I got an email this week from one of the subscribers to my email list, thanking me for the recommendation for last pass.

    And by the way, if you want a copy. I have my special report. I'd be glad to send it to you. That talks about passwords talks about one PA password and last pass and what you should do a little bit about two factor authentication. So I use duo. I also have Google authenticator, although I don't really use that at all.

    I tend to use Google or do I should say. What happens with that is they'll display a QR code when you're setting up the two factor authentication. That's one of those square things that has all of the little squares inside of it that you can use to go to a website is typically what you'd use it for in this case, it then syncs up a special Countdown a few old 30 seconds, and it'll give you a six digit code that you can use.

    And that code is only good for 30 seconds. So now when you go to login, you're going to give you username or email. You're going to give your password. And then it's going to ask you for that. Code so you can use again with duo, I have adjust automatically. It comes up, it's integrated with my one password as well.

    So I can now log in and I know it's extra safe because even if someone steals my phone number, It's not going to do them any good because I do not use my phone for verification for two factor authentication. Now there's one more trick that you could play if you wanted to. And I have done this more than once.

    Some websites do not allow you to use an authenticator app. Yeah, I know behind the times, aren't they? So you have to use SMS. If you want to use two factor authentication, other words, you have to have a text message sent to you. So what I do with those sites is I have a phone number that isn't a real phone.

    So I have a phone number that I got years ago from a company that Google bought nowadays, Google calls it Google voice. So I have a Google voice number and I will give them that number. Now, why would I give him that number? First of all, I can filter calls that are coming in and text messages and everything out.

    And then Google will forward the text message to my phone. And remember it's Google. So it's not terribly private, but that's okay because those numbers are usually only good for a number of minutes. Okay. So it's not a very big deal, but the reason I use. Something like Google voice is it's not a real phone number, so they can't call up T-Mobile or Verizon or whoever you have your phone through pretending to be you and get them to transfer that phone number.

    Because they can't and they won't. Okay. It's very important. The, the SIM card that you have in your phone nowadays, some of these devices have virtual SIM cards. That SIM card that's in your phone can not be stolen or duplicated or anything else either if you're using one of these Google voice numbers.

    So some really important tips there. I hope you took some notes.

    If you didn't, you can find this online. I post these as podcasts that you'll find right on my website @craigpeterson.com. You can listen to them, take notes. My wife even provides a transcription of these things most of the time. Bless her heart she spends a lot of time doing that and she'd appreciate it. Check it out online craig peterson.com.

    We're talking about how to keep your devices safe that you're buying this year things you're getting for family, for friends, maybe for yourself as well. And we're going to get into it more. Now we've got some real surprising things for you guys.

    One of the things that we have to do, and this is again, over and over again, but better than 60% computers have windows, computers are not up to date. Remember we're buying nine devices that are basically computers. Do you remember that whole Barbie thing from not too long ago?

    I, in fact, was on TV with this thing and it was sending audio up to the internet and we were able to intercept it. We did a whole thing on television about this. Obviously it's a very big problem because it's your kid's information. Voices being sent up in the Barbie was interacting. Dope now Mattel cleaned some of that stuff up and that's always a good thing.

    But the point behind this whole computer in a toy or other device thing is that their computers we're talking about mobile phones. And Android phones, just not getting security updates. If you're going to insist on using an Android phone, make sure you get the latest model every two years, because even Samsung only supports their phones.

    They're top of the line phones for two years. Okay. Versus your iPhone, which is good for five or more years. So keep those phones up to date. In fact, when you first get the phone, probably the first thing you should do is check for a software update. Computers are the same thing. Whether you're getting one of these Chromebooks, which are very good in generally speaking, I'll remember it's Google.

    Okay. But the Chromebooks tend to be kept up-to-date because it's pretty much automatic. And I know a lot of security researchers. Use Chromebooks and use them exclusively because they don't have the same security problems as windows. What's one of the reasons apples don't get attacked as much as windows computers.

    Don't because the Macs frankly, are not as common. They're only about 8% of the market out there, depending on whose numbers you're listening to. So why would they go after it? Plus it's a little more hardened than windows is. In fact, it's a lot more hardened than windows is. And Microsoft is starting to FY fall in behind Apple's lead, which I think is a good thing.

    So those computers update them immediately. If you're still running windows seven, make sure you get 10 cause seven. Isn't getting the updates anymore. If you're running windows eight, 8.1, make sure again, you upgrade to windows 10, but brand new computers. Shouldn't come with those. Another quick word of warning about computers that you're buying the home edition of windows does not have the same features as the business additions or enterprise additions of windows.

    So you might want to, when you're buying something, look for windows professional, it has more options. And one of the options that could save your bacon is the ability to put off update. Now, you're I hear you saying Craig, you're always telling us to update. Early and update often. Yeah, that's very true because many times when you get that patch, it's because there is something going on in the wild, bad guys are actively using it to exploit you to exploit your fault.

    Okay. So there's some very good reasons to stay up to date, but. Hey, here's a problem. I had a law office call me up because right in the middle of them, putting together some documents for the court that were due in less than two hours windows and they were running home edition, decided it was going to force them to do an update.

    You can imagine the trouble that ensued because they weren't going to be able to get the paperwork filed with the court in time. Very big problem. But even if you're not an attorney, you're not dealing with the court. When the windows professional does give you the option to schedule the. Dates, you can push them off for a week and then you can get into the more advanced stuff too, with the device management, MDM type stuff where you can now manage that device and make that device secure most, if not all of the time.

    Okay. So let's move on to the next tablets again. You look at something like the Amazon Kindle, the firearms and the here's my watch talking hit the Siri button accidentally. So the Amazon Kindle fire that is an Android tablet. Now, one of the advantages is it is updated by Amazon automatically. It gets all of these security updates and other things.

    Yeah. That's a very good thing, and it gets them for a fair length of time and they are cheap. You can get them for 50 bucks, 70 bucks brand new from Amazon. And I got one a year or two ago, probably a couple of years ago. And it wasn't well packaged and it's shipping and the. The front screen was just cracked all the way down.

    So I returned it, they shipped me another one and that one wasn't cracked. So that's good, but I've kept an eye on it and it has been very good. And I also got with the Amazon fire tablet, one of these stands that you can put it in, it's a charging stand, but when you place it in the charging, stand it then becomes an Amazon Alexa.

    So a little kids come over grandkids, and they want me to play baby shark, which is an annoying song that the grandkids, every generation has this. I remember a slightly older grandchild. A granddaughter who used to love ah, jeepers. What was a gummy bear? That's what it was. Gummy bear.

    Remember that song was incredibly annoying too. And he, in fact, I ended up getting the guy who wrote the sock on radio show with me to talk a little bit about it. It was fun actually. Those of us who needed to be kept up to date all of those tablets, because they are real computers, but nowadays we're buying appliances.

    Like I remember five years ago, I think it was out of the consumer electronics show. I saw a, another one. Before, your home that you put into your home and it had an Android operating system in it, it connected to wifi and it allowed you remotely to say, Oh, you know that steak or Rosa told you to cook in the oven at 5:00 PM, I'm going to be late.

    Okay. So you just go online and I type it into my phone and ta-da, I am now all set. There we go. And it's not going to start cooking it until six 30. That's all well and good, but that appliance has a computer in it and it's sent into wifi. I have you updated it. And does it self update and for how long are they going to be providing updates for that oven?

    Or, I'm sure my now five years later, there's no more updates for it. So you now have a, an appliance, a device that is frankly dangerous on your network, because if somebody, again, they come over to your house, they've got a laptop, they connect to your wifi and it now infects your appliance.

    Okay. Whether it's your washer or your dryer. Those are the two most common, I think right now that are internet connected or your oven or your microwave or your garage doors or your security system or your lights, those can all get infected. And now they are used as launching points to infect everything else.

    You network. Check the update, make sure everything's up to date. And in some cases it's pretty hard to update, but it's worth it. You have to do it even your children's toys. One of the things I do is I put them on a network segment that has no access to anything else. I have an IOT wifi network, internet of things.

    All right. You're listening to Craig Peterson. Make sure you visit me online at craig peterson.com and sign up for my newsletter.

    We've talked about, multi-factor authentication, we've talked about, of course, protecting your devices by keeping your software up to date and that's everything nowadays, really, and how to do that. What's up for that. Now we're going to go into a couple more good points.

    So we did talk about multifactor or two factor software update. Now, once you've purchased an internet connected device, no matter what it is, if it's a router or firewall, if it's a Barbie doll, change the default password.

    Now, in most cases you can connect to the device, just using a web browser that makes it very simple. So you use the web browser, you connect to the device. Most of them have web servers on them. If you can imagine that, a little doll with a web server on it, but yeah, that's what happens. Your refrigerator probably has one of his internet connected and your washer dryer, a almost every even light bulbs have little web servers built into them and you want to connect to them and change the default password.

    So look up the manual. It's probably not going to tell you how to do it with. The information that's in the packing, but if you go online and search for that device, you can find out how to change it and use this is just normal recommendations, right? Use different passwords for every device and always use complex passwords.

    Now complex doesn't mean that it has to have special symbols in this upper case, that lowercase, et cetera, it can just be. Three or four words strung together. That's all it needs to be. You might want to throw a digit or two in there, maybe a special character too, but a phrase is the best. And in order to do that, you're probably best off.

    Using a password manager to help out. So that means using something like one password or last pass. And once you've got that in place, it'll generate these passwords for you automatically it'll remember them. It keeps them encrypted. So you only have to remember one password and that's the password you have set for.

    The password manager now, in my case, I've got it set up with duo again. So I'll go into one password and one password is going to ask me for my password and it's also going to authenticate me via duo on my smartphone. So there's a multifactor three factor authentication. Okay. So important for all of these devices that connect to the internet.

    Also check the devices, privacy, and security settings. And a lot of times the manufacturer will. Let you set up an account on their website. And from there, you can tell it what information you want to share and don't want to share. Now, remember what I was talking about in the last hour with Apple, they are being very good about this and they are now demanding that all of the app developers disclose to you.

    That you have in deed, given consent for this information or that information to be used by that app developer and sold. But you can go to the Mattel website, set up an account for your device or the Samsung or whatever it might be. And right there, you can examine. Your privacy settings and what do I want to allow the vendor to gain access to?

    Okay. Make sure you're not sharing more information. Yeah. Then you absolutely need to provide, they're not going to ask you for social security numbers or other things. There's no reason to write that stuff that the bank or the IRS is going to want. Not these guys, at least, hopefully. Make sure you're enabling automatic software updates, wherever you can.

    The latest version of the software. Usually tells you that it has the latest security fixes. Hopefully it does, but it also helps to ensure the manufacturer still support it. Because if you've got automatic updates and they're sending updates to you and a hundred thousand of your closest friends who also have the same device, they're going to continue to support it.

    And that way, the latest patches are going to be out there, but if you're not getting the updates and nobody else is the manufacturer is not going to have a lot of incentive to give you security updates, then there's the normal stuff about, don't use public wifi. Yeah. That's generally a good idea.

    But if you're using a secure server connection, That's that little lock up in the URL bar. Then you are effectively creating a VPN between your web browser and that remote server, and that's going to be quite safe. So purpose personally, I don't worry so much about that. I do worry about my machine being attacked, but I also have a very good firewall turned on and I have all of the services that I don't need to have shared.

    Turned off and I am going to do. Class on this, a little course on hardening windows. In fact, we've got it all written. We've got slides together. We'll probably be doing that after the first of the year. So keep an eye on your email for that. Cause anybody who gets my newsletter, I'll tell you about that.

    How to harden windows, so that even if you are on a public wifi somewhere, you're going to be relatively safe and the same. Thing's true. If you're. Using your phone for instance, and you're sharing your phone's network connection with your computer. It could still be used by bad guys to try and get into your phone.

    These ISP internet service providers are not completely on top of all the security. Okay. All of the basic stuff don't provide personal information, financial information. I tend to use. These one time, if you will use credit card numbers. So every time I, if I go to a site and I want to buy something let's say I'm on GoDaddy buying a domain or I'm on Walmart side or Amazon site.

    Each one of those, I use a different credit card number with, so check out your credit card provider, all of the major ones, visa and MasterCard. They have the ability to create virtual credit card numbers. And that way that credit card number can only be used on that website. So you give this, you create this credit card number.

    It's very easy to do. It's usually a plugin in your browser. You create a credit card number and it's for amazon.com. And now if somebody were to get that credit card number from Amazon and try and use it somewhere else, it will not work. It will only work on amazon.com. Isn't that cool. And then the other advantage is if someone starts to miss using it, then you can just turn off that virtual credit card number.

    It's really that simple. So have a look at that. Then one time use credit card numbers or these virtual credit card numbers, which is what I like. Where you can use it multiple times on that site, you don't have to create a new one every time, a available from most banks and all major credit card companies.

    Okay. Also be careful with the websites. You're going to make sure you type that URL correctly. As I said before, I always spend a few extra seconds. Whenever I'm on a website, I'm going to a website. I'm reading email, just making sure that it is correct. I spelled Amazon Houghton, or the email address that sent it to me.

    Is legitimate. I can't believe how many times I get an email. It's a phishing email and it's from [email protected]. And that's a word of warning too, to the small businesses that are trying to do online stuff. Make sure you have your own domain. That you're not using Gmail or Hotmail or Yahoo.

    I've seen so many people doing that got even proton mail. Proton mail is quite secure and it's really nice the way they're doing it. It's hosted in Switzerland. Check them out by the way. I put something about that in my newsletter bought a month ago. With what that's all about. And if you want it, just let me know, just email [email protected] and in the subject line mentioned proton mail or something, and I'll forward you that newsletter so that you have it, but you can always search.

    If you don't delete my newsletters, you can always search for that information, but you can have proton mail set you up with your own domain. So it's from Bob's country store.com instead of Bob's country store, gmail.com. Okay. It looks much more legitimate. Let's see offers obviously be careful with those don't click links or download attachments, unless you're.

    Really confident. Again, I tend to go to the website as opposed to click on the email that I got, there always this warning or that other thing, just go to their website, make sure that it's all being encrypted again. That's that little padlock, if it's closed or your information's encrypted, which is really good.

    If you can use a credit card. Don't use a debit card there's laws to limit your liability for fraudulent credit card charges, but you don't really have quite the same level of protection when you're using a debit card and the money will be taken out of your account with a debit card. If a bad guy. Is using your debit card and then you have to file a police report and then you have to file with the company that gave you the debit card.

    And then you have to wait for the money to be credited back to your account. And in the meantime, your checks are bouncing or. If you use the debit card for other things, it is being Denine. Okay. So be very careful with that. Insufficient funds are always going out there. So there's a lot of it's of other things.

    And I would urge you to just be very careful, very cautious, just like Santa Claus, checks his list and checks it twice to the same thing all the time when you're online. Hey, if you don't get my free newsletter right now, make sure you sign up. I have all kinds of tips. That's what it's about. You also get all of my podcasts segment that you can just click on right there in the emails makes your life easy and helps to keep you safe.

    Online. Just visit me online. Craig Peterson.com. You can go look at anything you want. If you scroll down on the homepage, there's a little form you can fill out. If you have an explicit question for me, always glad to answer them. And then at the bottom of the page, a little subscribe box will show up as well.

    Take care, have a great weekend. Join me again next week.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 25 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: VPNs, Browsers, Apple and Security

    Welcome!

    Good morning, everybody. I was on WTAG on Jim's show this morning with Steve Fourni and we had, I think, a really good discussion about security, privacy, what Mozilla's doing, why Firefox people are praising Apple, new anti-tracking technology. Here we go with Steve

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Hi everybody. Craig Peterson here. I was on Jim's show this morning and we had, I think, a really good discussion about security, privacy, what Mozilla's doing, why Firefox people are praising Apple, new anti-tracking technology. How you can take advantage of this no matter what kind of. The system you are using and about law enforcement here shutting down VPN services, people going to jail over this.

    So again, yeah, I told you how many years ago, how long have I been talking about VPNs and how dangerous they really are? So we got into that and I explained what types you shouldn't use, et cetera. That's what this is all about. Hope everybody has a great week. I am going to air the best of we'll call it and showing this weekend and cover a few different topics.

    So I, I really hope you guys had a great holiday season and have a fantastic new year take care.

    Steve Fourni: [00:01:04] All right. Here's Craig Peterson, Craig. It's Steve Forni here in Springfield. Good morning.

    By the seat of our pants today, Craig, so welcome and welcome into the mess.

    Craig Peterson: [00:01:14] Yeah. Hey, Danny's a true professional here.

    You, I understand. Dan,

    Steve Fourni: [00:01:19] He gets paid more than I do. Oh, man.

    Craig Peterson: [00:01:22] Yeah. It is the week between, so we get a break today. There are no sweeps this week so we can, we can take it a little easy.

    Steve Fourni: [00:01:29] Yeah, absolutely. And speaking of taking it easy, it looks like Apple has stepped up its anti-trafficking privacy features.

    And Mozilla. Is it Mozilla? I always never know how to pronounce that, but I do use Firefox Mozilla regularly and they are

    Craig Peterson: [00:01:44] yeah. And yeah, this is really cool. You're right. Your Mozilla is how you pronounce it. Congratulations and gee, man, I just can't let them, I'm sorry. I D I can't help myself this morning.

    It's Firefox. And if you're using just a standard browser and you want to stay safe, it's a good idea to use Firefox and Firefox has really been getting a lot of advertisers upset. They have a special little fenced-in thing that they put in place automatically. If you go onto Facebook, Where it restricts Facebook from accessing any of the data from any of the other websites you went to.

    Of course, Facebook really hates that. And Mozilla's Firefox is also with the next big release. Having a new feature where it blocks every website from knowing what any other website has done is see because these guys out there that are trying to track you. We're talking about mostly advertisers here, not the criminals, but they've gotten really smart.

    So they'll say, Oh, I know if you go to iheart.com. That I, heart.com is going to have their logo on the page. And the URL for that logo is iheart.com/logo,dot JPEG, for instance, so that they know that's the case. So now you go to X, Y, z.com and at X, Y, z.com. And you have your cookies blocked.

    So they'll say, Oh, okay no cookies. Okay, fine. Fine fine. Done. Let me try and download iheart.com/logo.jpeg and so it'll put the request out in a time how long it takes it to get that graph. Is it, this stuff is just so advanced Steve, and the graphical shows up in a couple of milliseconds because it's cast because you been to the iHeart radio site.

    And so even without cookies, That website, like it could be, Facebook could be anything knows where you've gone online because they can check to see if you've got the iHeart logo cached. They can check to see if you've been to X, Y, or Z site. So Firefox from Mozilla. Is going to really tighten down, not just on fire, not just on Facebook, like they have been, but on Firefox doing it for every website that's out there.

    But now these guys that Mozilla, very privacy-conscious, very security conscious. They're now praising this new release of Apple's operating system iOS for the I-phones and iPads. And Apple's really got Facebook in a tizzy right now. The Zuck is really upset because what Apple is doing is changing the way it allows advertisers to track you. When you're online there are these little tags that Apple has put in place that you could change in their advertising tags, and you can go into your settings and you can change it. And that kind of blows who's out of the water. Anybody that's been tracking you?

    Apple has changed it again, now. They're saying, Hey, listen to Facebook or whatever sites. Wants to track you. And they're in putting it in place too, for the apps. There've been all kinds of complaints about apps, for instance, and the tracking. Our friends over the department of Homeland security have been accused of and admitted to buying information from app developers about people who might be illegally in the country and track where they are located.

    This isn't just on iOS. This is way worse over on the Android side. So there are all of these companies that are data aggregators that are getting data from everywhere they can that have been paying the app developers to use their libraries.

    Apple is going to be tracking that, stopping it, letting you know somebody is trying to track you. And it's a free app, Steve, that you downloaded. It ain't free. Okay. They are, many of these are tracking you.

    So Apple is really raising the bar here on stopping the tracking. Improving security, which Apple's always been far better at than Android, which is why one of the reasons why I say never ever used Android.

    Hopefully, I had enough ever since there for it.

    Steve Fourni: [00:06:17] How about. Google. Are they going to do anything in terms of, cause one of the biggest issues? I have a big issue with Google. I'm still convinced they put one of my local flower shops out of business because when you Google it, all you get are ads for pro flowers.

    But I, I feel Google itself is the one that again when I say into my phone, boy, I could really use a new toolset. All of a sudden I get ads on Google for toolsets, and obviously they have Google Chrome, which competes with Mozilla. I know we're talking about something different, but are they approaching Google sort of the same way, or is there any sort of connection between Mozilla and Apple against Google?

    Craig Peterson: [00:06:51] Yeah. Google Chrome, as you mentioned, the Chrome browser very popular. It's probably the number one browser out there. Just generally speaking is a big contractor. They love to track you what you're doing, where you're going. Remember Google is business is selling information about you. So if you're using Mozilla, if you are using a browser from a company, and Firefox from a company that doesn't want to share your data, Google not only wants to share it, they want to sell it. They want to put it together. They want to make them the center of your life.

    You might remember Steve, back in the day, Google has a motto. I shouldn't say was, don't be evil. Do you remember that? You can't find that on their website anymore?

    It's the definition of evil. Now, when it comes to this sort of thing about your information. So the safest browsers, if you're using Firefox, Steve like I said, that's probably the safest ish, depending on what we're talking about. But from your privacy standpoint, it's definitely the safest, it's one of the safest from a security standpoint, another one that's very good is one Apple puts out.

    And if you're using an Apple device, you're already using it probably by default, you are it's called Safari S A F A R. I. Your little blue round logo and it's available on their desktops, the Apple desktops, but it's also available for Windows and Apple is very good about not again, tracking Apple does not make money by selling your information.

    Apple makes money by selling you hardware and services versus again, Google, which is the, as I said, the definition of evil. There are studies that have been done about how Google this last election cycle made major changes to the way people voted some interesting studies came out, looking at orange County in California which has been a very conservative County for years, and studies showing that in that one County, Google changed 30 to 50,000 votes just by doing what you talked about, Steve, which is my local florist run out of business. And I'd bet it was Google showing ads for these national flower shops. That's what they've done. And that's what they did during this election cycle as well to promote candidates they liked.

    Steve Fourni: [00:09:29] That's scary. And I know I've heard you talk in the past about this, but I guess while we're on it if people want to search something, but they don't want Google, I know you've said duckduckgo. Which again, to me, I have a hard time with just, cause it sounds childish. Like Google works cause you could just say, yeah, just Google it. Like it works. It flows off the tongue.

    I think marketing is a big part of that saying yeah, just DuckDuckgo. It doesn't really fit the lexicon, very well.

    Craig Peterson: [00:09:55] You could use Quant as well, Q W A N T that's another one you can just quantify. It sounds cooler than a duck.

    I say doc and Qwant is another one that's pretty safe. It's out of Europe. It's out of France more specifically. But I really liked Duck Duck Go. In fact nowadays. It's rare that I use Google. If I'm looking for something really technical, I actually use something called Devon think, which is a.

    A database system and search engine that searches search engine just called a metasearch and it runs on my own hardware here. So I have a watch, certain sites for things, and puts it all together. But that's my first. And then you use Google if it's very technical, and if it has anything to do with anything else, I use duck go because they don't even use your search queries in order to feed you results which of course Google does.

    Duck go just takes general advertising and they do all of this on purpose because they want you to have a safe, fair online search experience.

    Steve Fourni: [00:11:04] Very interesting. We're talking with Craig Peterson, our tech guru, and maybe we can just sneak this in a quick here because. VPN services enabling cybercrime and law enforcement agencies trying to crack down on it. How's that going?

    Craig Peterson: [00:11:20] People who listen to my show, know I am no fan of these VPN services. And in fact, most of them, they are almost always let me just put it this way. Almost always.

    They make your data last year. And there are quite a few reasons I talk about it. And I got a really nice note this week from one of our listeners saying that she stopped using these services because they do make it much less safe. But this case here, global law enforcement agencies now, including the FBI have shut down some more of these.

    VPN services that were being used by criminals to launch ransomware campaigns, phishing attacks men in the middle attacks, where they have now access to all of your data. So you're using this VPM service, Steve, in order to be safer to keep your data encrypted, all of the lies and promises that they tell you in these ads that they run.

    And in fact, what's happening here is these VPN services, because they were shut down here by operation Nova. I led out of Germany. In fact, they're pleased agencies over there, operation Nova, they were decrypting, everything you were sent over the network. So you're going to your bank. They've got your bank account information.

    They've got your login. They've got your password. They've got it all. The only way to be really safe. And you know what, one more thing on that this is the way the campaigns stayed safe. You wonder why we haven't seen campaign emails leaked to, because of this one trick that I'm about to tell you, and that is, they used.

    Two-factor authentication. Now not the type that sends a text to you, your phone, but one of these fobs, one of these keys that are available now, Google actually sells one. Surprisingly enough. Now they use it internally. I like duo, D U O, which we use professionally. And there are also YubiKeys, which we really like. Y U B I K E Y S

    So when you log into a website using one of these things, What happens is it's something, which is a username and password, along with something you have, which is a six-digit code that changes every 30 seconds. And that's why we haven't seen the Democrats' email leak. The Republican's email leak this time around, and that's what can defeat.

    These VPNs are actually grabbing your information and selling it on the dark web and people's bank accounts are being emptied because of it. But Interpol Europol the FBI has been shutting some of these down stoned use. Oh,

    Steve Fourni: [00:14:10] scary stuff. Craig, this is all good information for the people. If they want more information now, obviously you got the show.

    What else? How else can they get all the resources that you offer?

    Craig Peterson: [00:14:21] I have, of course, a weekly newsletter that you can catch and you can just get that by going to Craig peterson.com and sign up as you've probably guessed. I'm not one of these heavy marketers, but if you're ingesting VPNs, et cetera, I've done some webinars.

    I can send you a link to watch them. Just email me. M E @Craig peterson.com and in the subject line. Put in VPN so that I know what you're looking for. And [email protected]. I can send you info on that or anything, but if you go to the website, you can send it, you'll get my newsletter and you'll find out about future training, too.

    Great stuff as always, Craig, really appreciate the time. Have a great new year and we will catch up in 2021.

    Looking forward to it. Hey take care of Steve and Danny, both and Jim listening at home.

    Steve Fourni: [00:15:11] Yeah, no doubt. We appreciate the time and we'll catch up. There goes our buddy Craig Peterson, great stuff is always taking things and breaking it down for us all to understand which is right.

    Craig Peterson: [00:15:22] And a happy new year to everybody out there take care. We will be back after the first of the year more stuff. Of course, we'll be talking about now. Hopefully, it'll be a bit of a better year. I think I'm going to come out with something too for businesses, small businesses on okay. Post-COVID.

    How do you get your remote workers secure? We've got to pull up our socks on now and really let's make this a business and no longer just to hack. Anyway, let me know if you're interested in that. You can always email again, me at Craig peterson.com. Let me know. That's how I come up with these ideas. You guys ask you have questions about things.

    And I always put together a response. Sometimes it's on the radio. Sometimes it's a little, a special report and sometimes, of course, it's a full-court, so would take care of everybody. I so appreciate you being with me.

    Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    17 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…