
Sign up to save your podcasts
Or


Welcome!
Good morning, everybody. I was on WTAG on Jim's show this morning with Steve Fourni and we had, I think, a really good discussion about security, privacy, what Mozilla's doing, why Firefox people are praising Apple, new anti-tracking technology. Here we go with Steve
For more tech tips, news, and updates, visit - CraigPeterson.com.
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hi everybody. Craig Peterson here. I was on Jim's show this morning and we had, I think, a really good discussion about security, privacy, what Mozilla's doing, why Firefox people are praising Apple, new anti-tracking technology. How you can take advantage of this no matter what kind of. The system you are using and about law enforcement here shutting down VPN services, people going to jail over this.
So again, yeah, I told you how many years ago, how long have I been talking about VPNs and how dangerous they really are? So we got into that and I explained what types you shouldn't use, et cetera. That's what this is all about. Hope everybody has a great week. I am going to air the best of we'll call it and showing this weekend and cover a few different topics.
So I, I really hope you guys had a great holiday season and have a fantastic new year take care.
Steve Fourni: [00:01:04] All right. Here's Craig Peterson, Craig. It's Steve Forni here in Springfield. Good morning.
By the seat of our pants today, Craig, so welcome and welcome into the mess.
Craig Peterson: [00:01:14] Yeah. Hey, Danny's a true professional here.
You, I understand. Dan,
Steve Fourni: [00:01:19] He gets paid more than I do. Oh, man.
Craig Peterson: [00:01:22] Yeah. It is the week between, so we get a break today. There are no sweeps this week so we can, we can take it a little easy.
Steve Fourni: [00:01:29] Yeah, absolutely. And speaking of taking it easy, it looks like Apple has stepped up its anti-trafficking privacy features.
And Mozilla. Is it Mozilla? I always never know how to pronounce that, but I do use Firefox Mozilla regularly and they are
Craig Peterson: [00:01:44] yeah. And yeah, this is really cool. You're right. Your Mozilla is how you pronounce it. Congratulations and gee, man, I just can't let them, I'm sorry. I D I can't help myself this morning.
It's Firefox. And if you're using just a standard browser and you want to stay safe, it's a good idea to use Firefox and Firefox has really been getting a lot of advertisers upset. They have a special little fenced-in thing that they put in place automatically. If you go onto Facebook, Where it restricts Facebook from accessing any of the data from any of the other websites you went to.
Of course, Facebook really hates that. And Mozilla's Firefox is also with the next big release. Having a new feature where it blocks every website from knowing what any other website has done is see because these guys out there that are trying to track you. We're talking about mostly advertisers here, not the criminals, but they've gotten really smart.
So they'll say, Oh, I know if you go to iheart.com. That I, heart.com is going to have their logo on the page. And the URL for that logo is iheart.com/logo,dot JPEG, for instance, so that they know that's the case. So now you go to X, Y, z.com and at X, Y, z.com. And you have your cookies blocked.
So they'll say, Oh, okay no cookies. Okay, fine. Fine fine. Done. Let me try and download iheart.com/logo.jpeg and so it'll put the request out in a time how long it takes it to get that graph. Is it, this stuff is just so advanced Steve, and the graphical shows up in a couple of milliseconds because it's cast because you been to the iHeart radio site.
And so even without cookies, That website, like it could be, Facebook could be anything knows where you've gone online because they can check to see if you've got the iHeart logo cached. They can check to see if you've been to X, Y, or Z site. So Firefox from Mozilla. Is going to really tighten down, not just on fire, not just on Facebook, like they have been, but on Firefox doing it for every website that's out there.
But now these guys that Mozilla, very privacy-conscious, very security conscious. They're now praising this new release of Apple's operating system iOS for the I-phones and iPads. And Apple's really got Facebook in a tizzy right now. The Zuck is really upset because what Apple is doing is changing the way it allows advertisers to track you. When you're online there are these little tags that Apple has put in place that you could change in their advertising tags, and you can go into your settings and you can change it. And that kind of blows who's out of the water. Anybody that's been tracking you?
Apple has changed it again, now. They're saying, Hey, listen to Facebook or whatever sites. Wants to track you. And they're in putting it in place too, for the apps. There've been all kinds of complaints about apps, for instance, and the tracking. Our friends over the department of Homeland security have been accused of and admitted to buying information from app developers about people who might be illegally in the country and track where they are located.
This isn't just on iOS. This is way worse over on the Android side. So there are all of these companies that are data aggregators that are getting data from everywhere they can that have been paying the app developers to use their libraries.
Apple is going to be tracking that, stopping it, letting you know somebody is trying to track you. And it's a free app, Steve, that you downloaded. It ain't free. Okay. They are, many of these are tracking you.
So Apple is really raising the bar here on stopping the tracking. Improving security, which Apple's always been far better at than Android, which is why one of the reasons why I say never ever used Android.
Hopefully, I had enough ever since there for it.
Steve Fourni: [00:06:17] How about. Google. Are they going to do anything in terms of, cause one of the biggest issues? I have a big issue with Google. I'm still convinced they put one of my local flower shops out of business because when you Google it, all you get are ads for pro flowers.
But I, I feel Google itself is the one that again when I say into my phone, boy, I could really use a new toolset. All of a sudden I get ads on Google for toolsets, and obviously they have Google Chrome, which competes with Mozilla. I know we're talking about something different, but are they approaching Google sort of the same way, or is there any sort of connection between Mozilla and Apple against Google?
Craig Peterson: [00:06:51] Yeah. Google Chrome, as you mentioned, the Chrome browser very popular. It's probably the number one browser out there. Just generally speaking is a big contractor. They love to track you what you're doing, where you're going. Remember Google is business is selling information about you. So if you're using Mozilla, if you are using a browser from a company, and Firefox from a company that doesn't want to share your data, Google not only wants to share it, they want to sell it. They want to put it together. They want to make them the center of your life.
You might remember Steve, back in the day, Google has a motto. I shouldn't say was, don't be evil. Do you remember that? You can't find that on their website anymore?
It's the definition of evil. Now, when it comes to this sort of thing about your information. So the safest browsers, if you're using Firefox, Steve like I said, that's probably the safest ish, depending on what we're talking about. But from your privacy standpoint, it's definitely the safest, it's one of the safest from a security standpoint, another one that's very good is one Apple puts out.
And if you're using an Apple device, you're already using it probably by default, you are it's called Safari S A F A R. I. Your little blue round logo and it's available on their desktops, the Apple desktops, but it's also available for Windows and Apple is very good about not again, tracking Apple does not make money by selling your information.
Apple makes money by selling you hardware and services versus again, Google, which is the, as I said, the definition of evil. There are studies that have been done about how Google this last election cycle made major changes to the way people voted some interesting studies came out, looking at orange County in California which has been a very conservative County for years, and studies showing that in that one County, Google changed 30 to 50,000 votes just by doing what you talked about, Steve, which is my local florist run out of business. And I'd bet it was Google showing ads for these national flower shops. That's what they've done. And that's what they did during this election cycle as well to promote candidates they liked.
Steve Fourni: [00:09:29] That's scary. And I know I've heard you talk in the past about this, but I guess while we're on it if people want to search something, but they don't want Google, I know you've said duckduckgo. Which again, to me, I have a hard time with just, cause it sounds childish. Like Google works cause you could just say, yeah, just Google it. Like it works. It flows off the tongue.
I think marketing is a big part of that saying yeah, just DuckDuckgo. It doesn't really fit the lexicon, very well.
Craig Peterson: [00:09:55] You could use Quant as well, Q W A N T that's another one you can just quantify. It sounds cooler than a duck.
I say doc and Qwant is another one that's pretty safe. It's out of Europe. It's out of France more specifically. But I really liked Duck Duck Go. In fact nowadays. It's rare that I use Google. If I'm looking for something really technical, I actually use something called Devon think, which is a.
A database system and search engine that searches search engine just called a metasearch and it runs on my own hardware here. So I have a watch, certain sites for things, and puts it all together. But that's my first. And then you use Google if it's very technical, and if it has anything to do with anything else, I use duck go because they don't even use your search queries in order to feed you results which of course Google does.
Duck go just takes general advertising and they do all of this on purpose because they want you to have a safe, fair online search experience.
Steve Fourni: [00:11:04] Very interesting. We're talking with Craig Peterson, our tech guru, and maybe we can just sneak this in a quick here because. VPN services enabling cybercrime and law enforcement agencies trying to crack down on it. How's that going?
Craig Peterson: [00:11:20] People who listen to my show, know I am no fan of these VPN services. And in fact, most of them, they are almost always let me just put it this way. Almost always.
They make your data last year. And there are quite a few reasons I talk about it. And I got a really nice note this week from one of our listeners saying that she stopped using these services because they do make it much less safe. But this case here, global law enforcement agencies now, including the FBI have shut down some more of these.
VPN services that were being used by criminals to launch ransomware campaigns, phishing attacks men in the middle attacks, where they have now access to all of your data. So you're using this VPM service, Steve, in order to be safer to keep your data encrypted, all of the lies and promises that they tell you in these ads that they run.
And in fact, what's happening here is these VPN services, because they were shut down here by operation Nova. I led out of Germany. In fact, they're pleased agencies over there, operation Nova, they were decrypting, everything you were sent over the network. So you're going to your bank. They've got your bank account information.
They've got your login. They've got your password. They've got it all. The only way to be really safe. And you know what, one more thing on that this is the way the campaigns stayed safe. You wonder why we haven't seen campaign emails leaked to, because of this one trick that I'm about to tell you, and that is, they used.
Two-factor authentication. Now not the type that sends a text to you, your phone, but one of these fobs, one of these keys that are available now, Google actually sells one. Surprisingly enough. Now they use it internally. I like duo, D U O, which we use professionally. And there are also YubiKeys, which we really like. Y U B I K E Y S
So when you log into a website using one of these things, What happens is it's something, which is a username and password, along with something you have, which is a six-digit code that changes every 30 seconds. And that's why we haven't seen the Democrats' email leak. The Republican's email leak this time around, and that's what can defeat.
These VPNs are actually grabbing your information and selling it on the dark web and people's bank accounts are being emptied because of it. But Interpol Europol the FBI has been shutting some of these down stoned use. Oh,
Steve Fourni: [00:14:10] scary stuff. Craig, this is all good information for the people. If they want more information now, obviously you got the show.
What else? How else can they get all the resources that you offer?
Craig Peterson: [00:14:21] I have, of course, a weekly newsletter that you can catch and you can just get that by going to Craig peterson.com and sign up as you've probably guessed. I'm not one of these heavy marketers, but if you're ingesting VPNs, et cetera, I've done some webinars.
I can send you a link to watch them. Just email me. M E @Craig peterson.com and in the subject line. Put in VPN so that I know what you're looking for. And [email protected]. I can send you info on that or anything, but if you go to the website, you can send it, you'll get my newsletter and you'll find out about future training, too.
Great stuff as always, Craig, really appreciate the time. Have a great new year and we will catch up in 2021.
Looking forward to it. Hey take care of Steve and Danny, both and Jim listening at home.
Steve Fourni: [00:15:11] Yeah, no doubt. We appreciate the time and we'll catch up. There goes our buddy Craig Peterson, great stuff is always taking things and breaking it down for us all to understand which is right.
Craig Peterson: [00:15:22] And a happy new year to everybody out there take care. We will be back after the first of the year more stuff. Of course, we'll be talking about now. Hopefully, it'll be a bit of a better year. I think I'm going to come out with something too for businesses, small businesses on okay. Post-COVID.
How do you get your remote workers secure? We've got to pull up our socks on now and really let's make this a business and no longer just to hack. Anyway, let me know if you're interested in that. You can always email again, me at Craig peterson.com. Let me know. That's how I come up with these ideas. You guys ask you have questions about things.
And I always put together a response. Sometimes it's on the radio. Sometimes it's a little, a special report and sometimes, of course, it's a full-court, so would take care of everybody. I so appreciate you being with me.
Bye-bye.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed the current Cybersecurity Pandemic and Phishing and what happened to Jim Polito, the host, this past week and then hit on travesty to the American worker through the H1B Visa program and how Facebook and other Big Tech is front and center with it. Here we go with Jim.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hi guys, Craig Peterson here.
I meant to post this and we managed not to. So this is from last week, actually. It's a week old now. It's my explanation of what happened with this nasty, big hack with Mr. Jim Pollito. Here we go with Jim from about a week ago. Oh, there's Velma barking. What does this all mean?
Jim Polito: [00:00:26] Oh, yeah, this is the guy, everybody, especially after what happened yesterday. Massive security problems affecting thousands of businesses and government agencies and who was on top of the whole thing. Our good friend and tech talk guru. Craig Peterson. Good morning, sir.
Craig Peterson: [00:00:46] This is pretty bad news.
Jim Polito: [00:00:48] Yeah, very bad news.
Danny yesterday at one point said to me, Hey, Google's not working, then it came back. YouTube was down, then it came back. Then we found out, Oh, it's almost like the matrix when there's a little bit of Deja Vu in the matrix, you notice it, that means they changed something.
Craig, so what's going on? What happened?
Craig Peterson: [00:01:08] This is really, really big for the fifth time. Only the fifth time in five years we've got an emergency security order coming out from this new national office for cybersecurity. This order is for all government agencies, as well as ordering federal civilian agencies to power down any of these SolarWinds devices, that are out there in their networks. Power them down.
Now SolarWinds is something that over 300,000 businesses use. It includes all 499 of the Fortune 500 companies, includes 22,000 managed service providers. What happened here was really tricky.
It was discovered by this company called FireEye, who found out that they had been breached. Now, FireEye is one of these big cybersecurity companies and they were using SolarWinds software.
Now this real quick, if you are really trying to be secure and you can't really do this yourself. If you're a smaller company, like under about 200 employees.
You have what's called Red team-Blue team trials. This, if you're in the military, you know what that is. So you have a red team attacking your computer systems and a blue team defending your computer systems. It's a drill. It's a really good drill. Fire Eye's red team tools, the tools for attacking businesses and government agencies, which is what they do all day long, were stolen from this hack.
They looked a little bit further and they found out is that what came through was this SolarWinds technology, which is used by almost every fortune 500 company.
It's been out there for, I think it was since May, this year. They managed to get their malicious code into SolarWinds product that they were shipping out to people. They even got them signed properly with the proper checks.
So now the US cybersecurity and infrastructure security agency, called CISA issued this directive on Sunday. Specifically, we're talking about SolarWinds Orion products.
Now my company, I am a master managed security services provider. That's what we do. We are the top of the heap, right? We went through all of these warnings. We got them from the FBI and every other three-letter agency that exists. We went through everything that we had. It looks like the problem was they had misconfigured the software. Not follow the manufacturer's instructions. Thank God we had done it. None of our clients got compromised.
This couldn't be bigger.
Jim Polito: [00:04:14] We're talking with Craig Peterson, our tech talk guru, about a massive hack, yesterday. Who did it?
Craig Peterson: [00:04:20] That's the question, right now? Fingers pointing at Russia. But.
Jim Polito: [00:04:25] What a surprise.
Craig Peterson: [00:04:27] Yeah. Russia. It could be almost anyone it's so hard to tell. I don't think we'll ever know, definitively. We've seen the Chinese hack into systems through Russian servers and we've seen the opposite happen. Now even, Vietnam has gotten into this game. Let me tell you, this was some serious hacking that happened here. People that really knew what they were doing.
So we don't think it's a cybercriminal gang. We think it's a nation-state.
Jim Polito: [00:05:01] That's the thing. They're not looking for credit card information. Isn't it interesting that they went after? Infrastructure, which would be the power grid. We all know what could happen should the power grid be hacked and shut down.
Was this simply either the Chinese or the Russians, whoever, basically an act of war, but testing out and trying to figure out a way to shut down our utilities.
Craig Peterson: [00:05:32] Absolutely. Absolutely. Our utilities use this software too, but you know what? They're going to get even more out of this than just control of the utilities. Federal agencies have now been compromised Gar-on-teed.
That means that they've got whatever information on FBI criminal cases. I'm not saying for sure, we know the FBI was hacked, as part of this. But I'd be shocked if they weren't, right. All the way through everything in the Department of Justice, everything in our military, you name it. Okay. Our power grid, our water control systems, these things are controlled by the software.
It drives me crazy because there are so many companies out there that hang up a shingle, saying we are a managed security services provider. They've got this flashy website and they've got some really cool looking seals on the site. People fall for it. We get called in. Every one of our clients that we have today had previously had a managed security services provider that failed them.
Now we're seeing the federal agencies, these people that we're paying top dollar to. They are supposed to protect our information and our government appears to be incompetent. Yes, I said that, incompetent. If you got hacked by this, you didn't even read the freaking directions.
Jim Polito: [00:07:03] We're talking with our good friend, Craig Peterson, tech talk guru.
This is not to get everyone concerned the sky is falling. But something has to be done here.
Let me go in the opposite direction. Please tell me, Craig, that we're doing exactly the same thing in China. In Russia. In Vietnam. In North Korea. Please tell me that we have, look, we made the vaccine, we're smarter than them. Please tell me that we're smarter than them and when they turn around, they'll realize, wow, there's been a gun pointed at our head the whole time. We didn't even realize it. Is that mutually assured destruction. What kept the peace in the cold war?
Tell me that's happening.
Craig Peterson: [00:07:47] It is happening. Every branch of the military and our Justice department, have hackers that are breaking in. In fact, I'm glad you brought it up because there was an unprecedented major leak quote, unquote of official records of 2 million members of the Chinese communist party, many of whom are now living and working all over the world, including Australia, the UK, the United States.
We now have and its public information, now, because I'm guessing we leaked it. The data has the names, the party positions, date of birth, National identification number, ethnicity telephone numbers of communist party members that have been set up inside Western companies, as well as our Congress and our military infrastructure and our federal government.
So the answer's yes. We now have details of 79,000 communist party branches as well.
So yes, we are fighting back.
Jim Polito: [00:08:54] Now, I want to bring you to another portion of this. I know you're not big into the James Bond stuff, but we have a James Bond type situation. We had Christine Fung, a spy, a student who was a spy from China with a member of Congress. We find out this is not an isolated incident. That they are cozying up to young and up and coming politicians. And she did with Swalwell, probably slept with him. Although he won't say, he says it's classified. That's a very good excuse. The bill Clinton should have used that one. I'm sorry, it's classified. That she slept with other, mayors or whatever, that this is going on quite a bit.
Yeah. Diane Feinstein had a driver who was a spy for years.
Now, isn't it time to say, Hey, no more students from China? At least to pause it. To send a message, because obviously we're letting them come in and to our faces, they're slitting our throats.
Craig Peterson: [00:09:53] They absolutely are. Detailed analysis of these records revealed that Pfizer and AstraZeneca. You've probably heard of those companies lately. Those companies employed 123 Chinese communist party loyalists. More than 600 party members across branches working at British banks, HSBC, Standard Chartered, Rolls Royce.,Airbus, Boeing. Yes. They come to our schools. They learn from us, which is all well and good, typically speaking. Then they take it and they try and replicate it in China and compete with us.
We are funding these schools. In so many States, a hundred percent and we're training them. We are teaching them. They are then moving up through the ranks.
So look, Swawell. Look at him. This little honeypot when he was mayor. You get about up and coming. And so they're taking our technology. We are losing our place in the world, right now. One of the biggest up and coming technologies is artificial intelligence. Guess where Google moved their AI research? To China.
Jim Polito: [00:11:05] Don't say it. That's a great place to be.
Craig Peterson: [00:11:08] In China. It's a great place to be. It's up and coming. Isn't it? Wouldn't it be wonderful if the Chinese get a leg up on the rest of the world with artificial intelligence technology? To do the types of things we are seeing them do now, and I keep pounding on the table, I'm gonna hurt my hand, but it absolutely ridiculous.
Jim Polito: [00:11:26] I just don't know, without getting into politics. I just don't know-how. First of all, I feel like knowing all this, I wish Trump had done more. I don't know what he was doing behind the scenes.
The second part of this is, I don't see how Joe Biden has any kind of a policy to deal with this, and secondly, he's compromised. His son is compromised. He's a friend of China. He's compromised.
Craig Peterson: [00:11:51] Yeah, I have to agree with you there. I want to add a nice little word to this. We're talking about Congressmen Swalwell and what happened with him. Senator Feinstein. This information about this unprecedented leak of the 2 million Chinese communist party upper echelon people who have been planted in foreign governments, came out two days ago.
What do you want to bet? Our hacking got this stuff. We started going through it and that how he was exposed with his girlfriend.
Jim Polito: [00:12:22] Yeah.
Craig Peterson: [00:12:23] Intelligence committee. Are you kidding me!
Jim Polito: [00:12:28] Craig, it's just crazy. The fact that Nancy Pelosi covered it up. I'm sorry if you've had any kind of a relationship with someone who was a spy and you're now on an intelligence committee and you weren't taken off of that intelligence committee. You weren't investigated. You got a defensive briefing. General Flynn didn't get a defensive briefing. He got a " we're going to try to catch you in a lie to the FBI" briefing. Swalwell got a "we're going to give you a defensive briefing."
We found out the girl that you're Fang bang your girl. We found out she's a spy. You might want to stop seeing her. =That's it. That's it? No, really? That's it. Oh. Stopped dating her.
Craig Peterson: [00:13:10] We've got to pull up socks. President Trump kept saying that he was trying to clean up the swamp. The swamp is now, definitely including, these members of the Chinese communist party.
We already know, I've talked before. About clients that I've gained. These clients had active Chinese back doors that were stealing their information. Now we find, over the weekend, that we had 18,000 organizations, government agencies, and businesses that were almost certainly compromised in this massive cyber attack.
Jim Polito: [00:13:42] Sickening.
Craig, I appreciate it. Craig Peterson, folks. Craig, what is the website? So folks can always be in touch with you.
Craig Peterson: [00:13:51] Go to Craig peterson.com. I'll send out an email a little later today, going through this. What happened if you were using SolarWinds, or if you're using an IT vendor, the questions need to ask them I'll get that out today.
And probably, maybe not till tomorrow with some of these lists. But I'll keep you informed Craig peterson.com and make sure you subscribe.
Jim Polito: [00:14:14] Yeah, it's good, it's a great thing to do.
Craig, always always a pleasure to have an expert like you, and when something like this happens and we'll catch up with you.
Craig Peterson: [00:14:22] All right. Take care, Jim.
Jim Polito: [00:14:23] You too.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed the current Cybersecurity Pandemic and Phishing and what happened to Jim Polito, the host, this past week and then hit on travesty to the American worker through the H1B Visa program and how Facebook and other Big Tech is front and center with it. Here we go with Jim.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hi guys, Craig Peterson here.
I meant to post this and we managed not to. So this is from last week, actually. It's a week old now. It's my explanation of what happened with this nasty, big hack with Mr. Jim Pollito. Here we go with Jim from about a week ago. Oh, there's Velma barking. What does this all mean?
Jim Polito: [00:00:26] Oh, yeah, this is the guy, everybody, especially after what happened yesterday. Massive security problems affecting thousands of businesses and government agencies and who was on top of the whole thing. Our good friend and tech talk guru. Craig Peterson. Good morning, sir.
Craig Peterson: [00:00:46] This is pretty bad news.
Jim Polito: [00:00:48] Yeah, very bad news.
Danny yesterday at one point said to me, Hey, Google's not working, then it came back. YouTube was down, then it came back. Then we found out, Oh, it's almost like the matrix when there's a little bit of Deja Vu in the matrix, you notice it, that means they changed something.
Craig, so what's going on? What happened?
Craig Peterson: [00:01:08] This is really, really big for the fifth time. Only the fifth time in five years we've got an emergency security order coming out from this new national office for cybersecurity. This order is for all government agencies, as well as ordering federal civilian agencies to power down any of these SolarWinds devices, that are out there in their networks. Power them down.
Now SolarWinds is something that over 300,000 businesses use. It includes all 499 of the Fortune 500 companies, includes 22,000 managed service providers. What happened here was really tricky.
It was discovered by this company called FireEye, who found out that they had been breached. Now, FireEye is one of these big cybersecurity companies and they were using SolarWinds software.
Now this real quick, if you are really trying to be secure and you can't really do this yourself. If you're a smaller company, like under about 200 employees.
You have what's called Red team-Blue team trials. This, if you're in the military, you know what that is. So you have a red team attacking your computer systems and a blue team defending your computer systems. It's a drill. It's a really good drill. Fire Eye's red team tools, the tools for attacking businesses and government agencies, which is what they do all day long, were stolen from this hack.
They looked a little bit further and they found out is that what came through was this SolarWinds technology, which is used by almost every fortune 500 company.
It's been out there for, I think it was since May, this year. They managed to get their malicious code into SolarWinds product that they were shipping out to people. They even got them signed properly with the proper checks.
So now the US cybersecurity and infrastructure security agency, called CISA issued this directive on Sunday. Specifically, we're talking about SolarWinds Orion products.
Now my company, I am a master managed security services provider. That's what we do. We are the top of the heap, right? We went through all of these warnings. We got them from the FBI and every other three-letter agency that exists. We went through everything that we had. It looks like the problem was they had misconfigured the software. Not follow the manufacturer's instructions. Thank God we had done it. None of our clients got compromised.
This couldn't be bigger.
Jim Polito: [00:04:14] We're talking with Craig Peterson, our tech talk guru, about a massive hack, yesterday. Who did it?
Craig Peterson: [00:04:20] That's the question, right now? Fingers pointing at Russia. But.
Jim Polito: [00:04:25] What a surprise.
Craig Peterson: [00:04:27] Yeah. Russia. It could be almost anyone it's so hard to tell. I don't think we'll ever know, definitively. We've seen the Chinese hack into systems through Russian servers and we've seen the opposite happen. Now even, Vietnam has gotten into this game. Let me tell you, this was some serious hacking that happened here. People that really knew what they were doing.
So we don't think it's a cybercriminal gang. We think it's a nation-state.
Jim Polito: [00:05:01] That's the thing. They're not looking for credit card information. Isn't it interesting that they went after? Infrastructure, which would be the power grid. We all know what could happen should the power grid be hacked and shut down.
Was this simply either the Chinese or the Russians, whoever, basically an act of war, but testing out and trying to figure out a way to shut down our utilities.
Craig Peterson: [00:05:32] Absolutely. Absolutely. Our utilities use this software too, but you know what? They're going to get even more out of this than just control of the utilities. Federal agencies have now been compromised Gar-on-teed.
That means that they've got whatever information on FBI criminal cases. I'm not saying for sure, we know the FBI was hacked, as part of this. But I'd be shocked if they weren't, right. All the way through everything in the Department of Justice, everything in our military, you name it. Okay. Our power grid, our water control systems, these things are controlled by the software.
It drives me crazy because there are so many companies out there that hang up a shingle, saying we are a managed security services provider. They've got this flashy website and they've got some really cool looking seals on the site. People fall for it. We get called in. Every one of our clients that we have today had previously had a managed security services provider that failed them.
Now we're seeing the federal agencies, these people that we're paying top dollar to. They are supposed to protect our information and our government appears to be incompetent. Yes, I said that, incompetent. If you got hacked by this, you didn't even read the freaking directions.
Jim Polito: [00:07:03] We're talking with our good friend, Craig Peterson, tech talk guru.
This is not to get everyone concerned the sky is falling. But something has to be done here.
Let me go in the opposite direction. Please tell me, Craig, that we're doing exactly the same thing in China. In Russia. In Vietnam. In North Korea. Please tell me that we have, look, we made the vaccine, we're smarter than them. Please tell me that we're smarter than them and when they turn around, they'll realize, wow, there's been a gun pointed at our head the whole time. We didn't even realize it. Is that mutually assured destruction. What kept the peace in the cold war?
Tell me that's happening.
Craig Peterson: [00:07:47] It is happening. Every branch of the military and our Justice department, have hackers that are breaking in. In fact, I'm glad you brought it up because there was an unprecedented major leak quote, unquote of official records of 2 million members of the Chinese communist party, many of whom are now living and working all over the world, including Australia, the UK, the United States.
We now have and its public information, now, because I'm guessing we leaked it. The data has the names, the party positions, date of birth, National identification number, ethnicity telephone numbers of communist party members that have been set up inside Western companies, as well as our Congress and our military infrastructure and our federal government.
So the answer's yes. We now have details of 79,000 communist party branches as well.
So yes, we are fighting back.
Jim Polito: [00:08:54] Now, I want to bring you to another portion of this. I know you're not big into the James Bond stuff, but we have a James Bond type situation. We had Christine Fung, a spy, a student who was a spy from China with a member of Congress. We find out this is not an isolated incident. That they are cozying up to young and up and coming politicians. And she did with Swalwell, probably slept with him. Although he won't say, he says it's classified. That's a very good excuse. The bill Clinton should have used that one. I'm sorry, it's classified. That she slept with other, mayors or whatever, that this is going on quite a bit.
Yeah. Diane Feinstein had a driver who was a spy for years.
Now, isn't it time to say, Hey, no more students from China? At least to pause it. To send a message, because obviously we're letting them come in and to our faces, they're slitting our throats.
Craig Peterson: [00:09:53] They absolutely are. Detailed analysis of these records revealed that Pfizer and AstraZeneca. You've probably heard of those companies lately. Those companies employed 123 Chinese communist party loyalists. More than 600 party members across branches working at British banks, HSBC, Standard Chartered, Rolls Royce.,Airbus, Boeing. Yes. They come to our schools. They learn from us, which is all well and good, typically speaking. Then they take it and they try and replicate it in China and compete with us.
We are funding these schools. In so many States, a hundred percent and we're training them. We are teaching them. They are then moving up through the ranks.
So look, Swawell. Look at him. This little honeypot when he was mayor. You get about up and coming. And so they're taking our technology. We are losing our place in the world, right now. One of the biggest up and coming technologies is artificial intelligence. Guess where Google moved their AI research? To China.
Jim Polito: [00:11:05] Don't say it. That's a great place to be.
Craig Peterson: [00:11:08] In China. It's a great place to be. It's up and coming. Isn't it? Wouldn't it be wonderful if the Chinese get a leg up on the rest of the world with artificial intelligence technology? To do the types of things we are seeing them do now, and I keep pounding on the table, I'm gonna hurt my hand, but it absolutely ridiculous.
Jim Polito: [00:11:26] I just don't know, without getting into politics. I just don't know-how. First of all, I feel like knowing all this, I wish Trump had done more. I don't know what he was doing behind the scenes.
The second part of this is, I don't see how Joe Biden has any kind of a policy to deal with this, and secondly, he's compromised. His son is compromised. He's a friend of China. He's compromised.
Craig Peterson: [00:11:51] Yeah, I have to agree with you there. I want to add a nice little word to this. We're talking about Congressmen Swalwell and what happened with him. Senator Feinstein. This information about this unprecedented leak of the 2 million Chinese communist party upper echelon people who have been planted in foreign governments, came out two days ago.
What do you want to bet? Our hacking got this stuff. We started going through it and that how he was exposed with his girlfriend.
Jim Polito: [00:12:22] Yeah.
Craig Peterson: [00:12:23] Intelligence committee. Are you kidding me!
Jim Polito: [00:12:28] Craig, it's just crazy. The fact that Nancy Pelosi covered it up. I'm sorry if you've had any kind of a relationship with someone who was a spy and you're now on an intelligence committee and you weren't taken off of that intelligence committee. You weren't investigated. You got a defensive briefing. General Flynn didn't get a defensive briefing. He got a " we're going to try to catch you in a lie to the FBI" briefing. Swalwell got a "we're going to give you a defensive briefing."
We found out the girl that you're Fang bang your girl. We found out she's a spy. You might want to stop seeing her. =That's it. That's it? No, really? That's it. Oh. Stopped dating her.
Craig Peterson: [00:13:10] We've got to pull up socks. President Trump kept saying that he was trying to clean up the swamp. The swamp is now, definitely including, these members of the Chinese communist party.
We already know, I've talked before. About clients that I've gained. These clients had active Chinese back doors that were stealing their information. Now we find, over the weekend, that we had 18,000 organizations, government agencies, and businesses that were almost certainly compromised in this massive cyber attack.
Jim Polito: [00:13:42] Sickening.
Craig, I appreciate it. Craig Peterson, folks. Craig, what is the website? So folks can always be in touch with you.
Craig Peterson: [00:13:51] Go to Craig peterson.com. I'll send out an email a little later today, going through this. What happened if you were using SolarWinds, or if you're using an IT vendor, the questions need to ask them I'll get that out today.
And probably, maybe not till tomorrow with some of these lists. But I'll keep you informed Craig peterson.com and make sure you subscribe.
Jim Polito: [00:14:14] Yeah, it's good, it's a great thing to do.
Craig, always always a pleasure to have an expert like you, and when something like this happens and we'll catch up with you.
Craig Peterson: [00:14:22] All right. Take care, Jim.
Jim Polito: [00:14:23] You too.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Steve Fourni We discussed VPNs and Man in the Middle Attacks (MITM,) Here we go with Steve.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hey, good morning everybody. I was on with Mr. Steve Forni this morning, Jim Polito is out. He is sick. Oh my gosh. This COVID thing apparently got them, but anyway, I don't think that's secret information, but It might be insider stuff. But anyway, I spoke with Steve Forni, who is one of the producers he's in central mass this morning.
And we really got into this whole VPN thing. And how Google now has removed another. VPN that uses a man in the middle attacks. So explain what that all is and everything else. And if you are interested in finding out more about VPNs, just email [email protected]. I can send you a link to a webinar I did about VPNs.
All right, take care. Here we go.
Steve Fourni: [00:00:50] Steve Forni here in Springfield. Danny is in Worcester and that music, that means it's time to hang out with our tech talk guru, Craig Peterson, to give us high-tech information at a like a fourth-grade reading level which is easy for us all to digest, which is great. Craig, thank you so much for taking the time today, buddy. Appreciate it.
Craig Peterson: [00:01:09] Hey, glad to be here. No, I try and aim high or at least seventh grade.
Okay.
It had a problem. I don't know if you've used some of these online sites. I love Grammarly by the way. If you've never heard of it and you ever have to write anything and you want to make sure it's correct.
Use Grammarly. It is just amazing. I've subscribed to that for a while now. There are other sites too, that tell you what grade level you're writing is at? I was consistently writing at like grade 13 or something, the first year of college. I use those tools to get it down to about seventh grade. Just the seventh grade so that most people can understand it, because who here is really going to go for a college degree in computer security and technology. Okay. You nailed it. I'm just impressed. Steve. You understand what I'm trying to do?
Steve Fourni: [00:02:01] Well, I appreciate that. I admit I am a word nerd and I even refuse to end my tweets with a preposition.
Craig Peterson: [00:02:07] But
Steve Fourni: [00:02:07] I know I'm a little different maybe, but I also, I can't do math, so there's that.
Craig Peterson: [00:02:13] So here's that to boldly go where no man has gone
Steve Fourni: [00:02:15] before.
That's right. So obviously a lot of people working from home trying to figure out the whole deal of getting it done here. Preferably on the fly for a lot of people and VPN has become an issue here. Can you tell us at least about the one that Google had to shut down?
Craig Peterson: [00:02:31] Oh, this is a real problem, frankly, for everybody I've done a whole course on it. And I promise I am going to do another course after the first of a year because of the VPNs or something, people really don't understand very well.
With this whole lockdown thing that we've been doing, it's been a problem because we all of a sudden started using VPNs, remote desktop, and all of these things. They have been a very real problem. And we've seen it now. In a few different places out there. And one of them is what you just mentioned with our friends over at Google.
And Google has removed that shady Android VPN app. They've removed, not just one, but multiples of these that were in the place store. It's called the super VPN. Free VPN clients. Now the problem to just make this really short and simple. Now. After the first of the year, probably early February, maybe late January, maybe we'll try and do it earlier, but we'll have more details on VPN and how to use them, how to set them up, and everything else.
But here's the bottom line. This VPN allowed what's called a man-in-the-middle attack. We've seen governments doing this now around the world. And what that means is think of the days of the string telephones that we'd make the little kids with the cans. Have you ever played this where you have a friend who's talking into the queue one, can it transmit over the string to the other cans? They have that up to one ear and then you have another friend with another string and another set of cans. So you hear it from a friend a and you speak into the can to friend B to relay it along so that you can go long distances 30 feet and that's a man in the middle.
So you're relying on that man in the middle to relay your message properly like a broken telephone, a game we've all played. And what happens with this? A man in the middle attack is the VPN that you're using is actually being used. There's somebody in the middle using your VPN that you thought made your life safer.
But in fact, They are intercepting everything. They're decrypting, everything. They're looking at everything. And now they have your usernames, your passwords, the whole nine yards. So Google just removed it yet. Another one of these VPN apps. It routed the place store. These things exist. There are so many reasons not to use a public VPN bottom line just don't use VPN services.
And if you want more on this, I did a webinar earlier this year on VPN, and I can send you a link to be able to watch this. Cause I did record it on VPNs. And what are the risks? In most cases with most of these VPN services, you're actually making your data and do you less safe, not safer. So how is that Steve?
Steve Fourni: [00:05:42] Craig, it brings me to what I guess we opened up with was bringing things down to a level. People can understand I'm wondering if. If any of this own onus falls on it department for whatever company you work, for which again, can't really tell at your average employee, everything that they need to know about the VPN instead, they're just like, okay, here's the icon put in your username and password and hit connect.
That's all you need to know. Don't worry about anything else. As opposed to telling them things, to look out for updates, like using this, you don't use that. Taking that from an elementary level and bringing the knowledge to the employees up a little bit. So they know what to look out for.
Maybe that's a conversation that's not being had.
Craig Peterson: [00:06:25] I think you're right about them, but it still gets so complicated. So quickly. I one, I'm using an example here, a friend of mine yesterday, a really good friend. He and I ride motorcycles together all the time. And I got a call from him, Steve yesterday morning and Hey, can I come over?
I said, okay, why do you want to come over? You? Nothing personal love to see you. And he says I gotta talk about he's retired. And he's delivering for grub hub and people have ordered from that's this food service where you can have a, buy something from a local restaurant habit delivered right to your home.
So he drives around in his little Volvo and picks up from the restaurant and then delivers it to the home and makes a few bucks from it. He even does it to me. And so I spent four hours with him yesterday, cause his account was hacked. All of his pay was going to somebody that hacked into his Microsoft email account.
And had gone in and changed his grub hub, paid to account to another bank account that was owned by the hacker. And then the hacker also took over his email account. So that any time now, because he's using the same Microsoft email account for everything, same password for everything, or at least almost everything.
Do you see the warning flags going up, Steve? They took it over. It took us four hours for me to figure out what had been going on, what happened. And I got him using a password manager yesterday. One password is what I have them using. It's five bucks a month for a family of five. You can share passwords, you can have your own individual passwords and it creates new passwords, but I got him all cleaned up.
And when you're talking about this problem, Steve, with VPN and businesses, and do we understand all of this? Here's the guy that hangs out with me. Okay. I'm talking to pump his stuff all the time. I don't just play this on the radio. This is what I do. And he still hadn't done it cause it was April, it was very confusing for him to try and figure this all out.
So the businesses that have their own VPN. That are properly protecting those VPNs with what's called nowadays zero trust, but those ones, Steve are quite safe. The ones that are not safe are these public ones where you sign up, you, you hear them advertise Norton VPN or this VPN, or that VPN uses our VPN super VPN free.
As we just found out, got removed from Google. Those are the ones that get really dangerous, but even the VPN services, the businesses are using internally have problems because a VPN is just a network. And anything attached to it can potentially get through. So businesses are really now finding the problems they have with the VPN because they're using just a low level one.
They don't have a really good next-generation firewall. Steve and the bad guys have taken control of home computers like my buddy's computer and have gone from the home computers through the VPN, and now attacked the business itself. And we're finding that more and more. We've got FBI warnings and everything else anyway, blah, blah, blah ramble.
Steve Fourni: [00:09:59] Oh, cause one more quick question on that before we get to another topic because I'm wondering if there's a way that, that people might be able to tell if one is legit or not. Like for instance, our company wifi is honestly, it's a pain in the rear to get on the thing. I have to put in this password, then they have to send a notification to my
Craig Peterson: [00:10:15] phone.
Then I have to hit it
Steve Fourni: [00:10:16] on that thing. And then I got to go back to the computer and I got, it's like a four-step process just to log on. Whereas maybe some of these places are just like, Oh, what's your name, Steve. Okay. You're in. Yay. Like maybe that's a, is that a flagger or are they all making it intense?
Craig Peterson: [00:10:31] There's just something I think is a norm across every industry. And that is incompetence around runs rampant in every profession. So at a company like iHeart, of course, you've got some really good people who are doing it right. Most of the time. And that's all I'm asking for is most of the time, but yeah, you're, I think your point is a great one.
If it's just, I log in with this password, if you're using Microsoft remote desktop to connect. Wow. That is being used like crazy by the bad guys out there. And then of course we have the huge act from last week where now it looks like Russia got into the federal government agencies. Tens of thousands of businesses affected here.
It's crazy
Steve Fourni: [00:11:17] talking with Craig Peterson, our tech guru, and one other topic before I wanted to let you go. Cause we are, we're talking about Russia and China. And now it looks like Kazic Stan wants in, on the action. What is happening over there?
Craig Peterson: [00:11:29] This is true in China as well, but yeah, Tasic Stan.
What they've done here now is they have it set up so that you have to install it. Some software from the government in order to go online. And what that software does, is it installs a key in the very least, you have to install this key on your computer. And that I was like, sound government, see everything anybody is doing now.
On ongoing, online, any of their citizens, anybody that installed stops on Google Mozilla. Those are the guys that make Firefox Apple and Microsoft have all joined forces now. And all of those browsers received updates recently that blocked this trick that the Kazakhstan government is playing on it. I'm going to use the term citizens here residents at the very least because it was sending all of their data in the clear for the government to read.
And just real quick, Steve. Met in the UN embassy last Mueller earlier this year, I got down in Washington, DC with an African government and they have a data center that is, was built by the Chinese. And we can talk about this one for hours. But they wanted to secure it in the bottom line is there is no way because governments like this Kazakhstan government, Chinese government that is now by the way, providing computer equipment all around the world have completely infiltrated all of those systems.
And now as part of this recovery, economic package out there, they are going to be helping smaller internet service providers. And that means some of our listeners here, Steve, and this area in the Northeast, they are going to help them buy plane pain, to rip and remove this Chinese equipment that has been found to be spying on all of us.
So that, I guess a little bit of good news, a trillion here, a trillion there, maybe some of it will go to good use.
Steve Fourni: [00:13:35] And if they put these efforts towards things like infrastructure, maybe the country of Kazakhstan would be in a little bit better shape. They just need to focus all this energy elsewhere, but that's another topic for another day,
Craig, you provide a wealth of knowledge and helpful information for folks, where can they go to get more of that information?
Craig Peterson: [00:13:55] The best place is probably to go to is Craig peterson.com. You'll see lots of stuff there. My podcasts are pretty much everywhere and of course, you can listen right here on TAG and W H Y N I think just those two stations right now, but you can listen right here. On Saturday or Sundays at 11:00 AM.
I knew I could get it straight. I haven't had my coffee yet.
Steve Fourni: [00:14:18] You know what that 11:00 AM on H Y N and leads right into sports Sunday with Steve Forni at noon. How about that, Craig? You and me back to back? How about that?
We'll talk we're, we're going to talk this week about Canada, not wanting to come to the US to play hockey.
So maybe you want to tune in for that one.
Craig Peterson: [00:14:31] Cause they don't want to. Your folks up there,
Steve Fourni: [00:14:35] Craig Peterson. Thanks so much for the time. We'll catch up.
Craig Peterson: [00:14:38] All right, bye-bye.
Steve Fourni: [00:14:39] And Merry Christmas too, by the way, Craig. Yeah, Merry Christmas. My friend there goes our buddy, Craig Peterson. Good stuff there. As always,
Craig Peterson: [00:14:45] I am planning on recording a new show for this weekend, so I'll keep an eye out for that and be back tomorrow.
Take care, everybody.
Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Steve Fourni We discussed VPNs and Man in the Middle Attacks (MITM,) Here we go with Steve.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hey, good morning everybody. I was on with Mr. Steve Forni this morning, Jim Polito is out. He is sick. Oh my gosh. This COVID thing apparently got them, but anyway, I don't think that's secret information, but It might be insider stuff. But anyway, I spoke with Steve Forni, who is one of the producers he's in central mass this morning.
And we really got into this whole VPN thing. And how Google now has removed another. VPN that uses a man in the middle attacks. So explain what that all is and everything else. And if you are interested in finding out more about VPNs, just email [email protected]. I can send you a link to a webinar I did about VPNs.
All right, take care. Here we go.
Steve Fourni: [00:00:50] Steve Forni here in Springfield. Danny is in Worcester and that music, that means it's time to hang out with our tech talk guru, Craig Peterson, to give us high-tech information at a like a fourth-grade reading level which is easy for us all to digest, which is great. Craig, thank you so much for taking the time today, buddy. Appreciate it.
Craig Peterson: [00:01:09] Hey, glad to be here. No, I try and aim high or at least seventh grade.
Okay.
It had a problem. I don't know if you've used some of these online sites. I love Grammarly by the way. If you've never heard of it and you ever have to write anything and you want to make sure it's correct.
Use Grammarly. It is just amazing. I've subscribed to that for a while now. There are other sites too, that tell you what grade level you're writing is at? I was consistently writing at like grade 13 or something, the first year of college. I use those tools to get it down to about seventh grade. Just the seventh grade so that most people can understand it, because who here is really going to go for a college degree in computer security and technology. Okay. You nailed it. I'm just impressed. Steve. You understand what I'm trying to do?
Steve Fourni: [00:02:01] Well, I appreciate that. I admit I am a word nerd and I even refuse to end my tweets with a preposition.
Craig Peterson: [00:02:07] But
Steve Fourni: [00:02:07] I know I'm a little different maybe, but I also, I can't do math, so there's that.
Craig Peterson: [00:02:13] So here's that to boldly go where no man has gone
Steve Fourni: [00:02:15] before.
That's right. So obviously a lot of people working from home trying to figure out the whole deal of getting it done here. Preferably on the fly for a lot of people and VPN has become an issue here. Can you tell us at least about the one that Google had to shut down?
Craig Peterson: [00:02:31] Oh, this is a real problem, frankly, for everybody I've done a whole course on it. And I promise I am going to do another course after the first of a year because of the VPNs or something, people really don't understand very well.
With this whole lockdown thing that we've been doing, it's been a problem because we all of a sudden started using VPNs, remote desktop, and all of these things. They have been a very real problem. And we've seen it now. In a few different places out there. And one of them is what you just mentioned with our friends over at Google.
And Google has removed that shady Android VPN app. They've removed, not just one, but multiples of these that were in the place store. It's called the super VPN. Free VPN clients. Now the problem to just make this really short and simple. Now. After the first of the year, probably early February, maybe late January, maybe we'll try and do it earlier, but we'll have more details on VPN and how to use them, how to set them up, and everything else.
But here's the bottom line. This VPN allowed what's called a man-in-the-middle attack. We've seen governments doing this now around the world. And what that means is think of the days of the string telephones that we'd make the little kids with the cans. Have you ever played this where you have a friend who's talking into the queue one, can it transmit over the string to the other cans? They have that up to one ear and then you have another friend with another string and another set of cans. So you hear it from a friend a and you speak into the can to friend B to relay it along so that you can go long distances 30 feet and that's a man in the middle.
So you're relying on that man in the middle to relay your message properly like a broken telephone, a game we've all played. And what happens with this? A man in the middle attack is the VPN that you're using is actually being used. There's somebody in the middle using your VPN that you thought made your life safer.
But in fact, They are intercepting everything. They're decrypting, everything. They're looking at everything. And now they have your usernames, your passwords, the whole nine yards. So Google just removed it yet. Another one of these VPN apps. It routed the place store. These things exist. There are so many reasons not to use a public VPN bottom line just don't use VPN services.
And if you want more on this, I did a webinar earlier this year on VPN, and I can send you a link to be able to watch this. Cause I did record it on VPNs. And what are the risks? In most cases with most of these VPN services, you're actually making your data and do you less safe, not safer. So how is that Steve?
Steve Fourni: [00:05:42] Craig, it brings me to what I guess we opened up with was bringing things down to a level. People can understand I'm wondering if. If any of this own onus falls on it department for whatever company you work, for which again, can't really tell at your average employee, everything that they need to know about the VPN instead, they're just like, okay, here's the icon put in your username and password and hit connect.
That's all you need to know. Don't worry about anything else. As opposed to telling them things, to look out for updates, like using this, you don't use that. Taking that from an elementary level and bringing the knowledge to the employees up a little bit. So they know what to look out for.
Maybe that's a conversation that's not being had.
Craig Peterson: [00:06:25] I think you're right about them, but it still gets so complicated. So quickly. I one, I'm using an example here, a friend of mine yesterday, a really good friend. He and I ride motorcycles together all the time. And I got a call from him, Steve yesterday morning and Hey, can I come over?
I said, okay, why do you want to come over? You? Nothing personal love to see you. And he says I gotta talk about he's retired. And he's delivering for grub hub and people have ordered from that's this food service where you can have a, buy something from a local restaurant habit delivered right to your home.
So he drives around in his little Volvo and picks up from the restaurant and then delivers it to the home and makes a few bucks from it. He even does it to me. And so I spent four hours with him yesterday, cause his account was hacked. All of his pay was going to somebody that hacked into his Microsoft email account.
And had gone in and changed his grub hub, paid to account to another bank account that was owned by the hacker. And then the hacker also took over his email account. So that any time now, because he's using the same Microsoft email account for everything, same password for everything, or at least almost everything.
Do you see the warning flags going up, Steve? They took it over. It took us four hours for me to figure out what had been going on, what happened. And I got him using a password manager yesterday. One password is what I have them using. It's five bucks a month for a family of five. You can share passwords, you can have your own individual passwords and it creates new passwords, but I got him all cleaned up.
And when you're talking about this problem, Steve, with VPN and businesses, and do we understand all of this? Here's the guy that hangs out with me. Okay. I'm talking to pump his stuff all the time. I don't just play this on the radio. This is what I do. And he still hadn't done it cause it was April, it was very confusing for him to try and figure this all out.
So the businesses that have their own VPN. That are properly protecting those VPNs with what's called nowadays zero trust, but those ones, Steve are quite safe. The ones that are not safe are these public ones where you sign up, you, you hear them advertise Norton VPN or this VPN, or that VPN uses our VPN super VPN free.
As we just found out, got removed from Google. Those are the ones that get really dangerous, but even the VPN services, the businesses are using internally have problems because a VPN is just a network. And anything attached to it can potentially get through. So businesses are really now finding the problems they have with the VPN because they're using just a low level one.
They don't have a really good next-generation firewall. Steve and the bad guys have taken control of home computers like my buddy's computer and have gone from the home computers through the VPN, and now attacked the business itself. And we're finding that more and more. We've got FBI warnings and everything else anyway, blah, blah, blah ramble.
Steve Fourni: [00:09:59] Oh, cause one more quick question on that before we get to another topic because I'm wondering if there's a way that, that people might be able to tell if one is legit or not. Like for instance, our company wifi is honestly, it's a pain in the rear to get on the thing. I have to put in this password, then they have to send a notification to my
Craig Peterson: [00:10:15] phone.
Then I have to hit it
Steve Fourni: [00:10:16] on that thing. And then I got to go back to the computer and I got, it's like a four-step process just to log on. Whereas maybe some of these places are just like, Oh, what's your name, Steve. Okay. You're in. Yay. Like maybe that's a, is that a flagger or are they all making it intense?
Craig Peterson: [00:10:31] There's just something I think is a norm across every industry. And that is incompetence around runs rampant in every profession. So at a company like iHeart, of course, you've got some really good people who are doing it right. Most of the time. And that's all I'm asking for is most of the time, but yeah, you're, I think your point is a great one.
If it's just, I log in with this password, if you're using Microsoft remote desktop to connect. Wow. That is being used like crazy by the bad guys out there. And then of course we have the huge act from last week where now it looks like Russia got into the federal government agencies. Tens of thousands of businesses affected here.
It's crazy
Steve Fourni: [00:11:17] talking with Craig Peterson, our tech guru, and one other topic before I wanted to let you go. Cause we are, we're talking about Russia and China. And now it looks like Kazic Stan wants in, on the action. What is happening over there?
Craig Peterson: [00:11:29] This is true in China as well, but yeah, Tasic Stan.
What they've done here now is they have it set up so that you have to install it. Some software from the government in order to go online. And what that software does, is it installs a key in the very least, you have to install this key on your computer. And that I was like, sound government, see everything anybody is doing now.
On ongoing, online, any of their citizens, anybody that installed stops on Google Mozilla. Those are the guys that make Firefox Apple and Microsoft have all joined forces now. And all of those browsers received updates recently that blocked this trick that the Kazakhstan government is playing on it. I'm going to use the term citizens here residents at the very least because it was sending all of their data in the clear for the government to read.
And just real quick, Steve. Met in the UN embassy last Mueller earlier this year, I got down in Washington, DC with an African government and they have a data center that is, was built by the Chinese. And we can talk about this one for hours. But they wanted to secure it in the bottom line is there is no way because governments like this Kazakhstan government, Chinese government that is now by the way, providing computer equipment all around the world have completely infiltrated all of those systems.
And now as part of this recovery, economic package out there, they are going to be helping smaller internet service providers. And that means some of our listeners here, Steve, and this area in the Northeast, they are going to help them buy plane pain, to rip and remove this Chinese equipment that has been found to be spying on all of us.
So that, I guess a little bit of good news, a trillion here, a trillion there, maybe some of it will go to good use.
Steve Fourni: [00:13:35] And if they put these efforts towards things like infrastructure, maybe the country of Kazakhstan would be in a little bit better shape. They just need to focus all this energy elsewhere, but that's another topic for another day,
Craig, you provide a wealth of knowledge and helpful information for folks, where can they go to get more of that information?
Craig Peterson: [00:13:55] The best place is probably to go to is Craig peterson.com. You'll see lots of stuff there. My podcasts are pretty much everywhere and of course, you can listen right here on TAG and W H Y N I think just those two stations right now, but you can listen right here. On Saturday or Sundays at 11:00 AM.
I knew I could get it straight. I haven't had my coffee yet.
Steve Fourni: [00:14:18] You know what that 11:00 AM on H Y N and leads right into sports Sunday with Steve Forni at noon. How about that, Craig? You and me back to back? How about that?
We'll talk we're, we're going to talk this week about Canada, not wanting to come to the US to play hockey.
So maybe you want to tune in for that one.
Craig Peterson: [00:14:31] Cause they don't want to. Your folks up there,
Steve Fourni: [00:14:35] Craig Peterson. Thanks so much for the time. We'll catch up.
Craig Peterson: [00:14:38] All right, bye-bye.
Steve Fourni: [00:14:39] And Merry Christmas too, by the way, Craig. Yeah, Merry Christmas. My friend there goes our buddy, Craig Peterson. Good stuff there. As always,
Craig Peterson: [00:14:45] I am planning on recording a new show for this weekend, so I'll keep an eye out for that and be back tomorrow.
Take care, everybody.
Bye-bye.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
This week I am spending a bit of time discussing The huge hack on SolarWinds Orion Software and why we will be feeling the repercussions for years -- and yes it could have been prevented. Then we will talk a little bit more about Election fallout and how this hack might have something to do with it. Then Fire-Eye hack and New and Improved (well -- another variation) of Ransomware and More so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
Gaming Over the Holidays? 7 Important Security Tips
Looking at Using a Contact-Tracing App? Contact-Tracing Apps Still Expose Users to Security, Privacy Issues
Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data
Knowing What the Enemy Knows Is Key to Proper Defense
Major Cybersecurity Vendor FireEye Breach -- Fallout Yet to Be Felt
New AdWare Silently Modifies Search Results
Ransomware gangs are getting faster at encrypting networks. That will make it harder to stop
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] In case you didn't hear, we have had a massive hack. We're going to be talking about that and what it means to you. What it means to the federal government. What it means to organizations that are using SolarWinds. Oh my
Hi everybody. Craig Peterson here. Had a great discussion this week with Mr. Matt Gagnon Wednesday morning, as we usually do, and we're going to continue that now. Let's get into it in a little bit more depth.
You probably heard me pounding on that table and it was just unbelievable because the bottom line here is these particular hacks were effective because these supposedly "Professional Security People" did not follow the basics. They didn't have the software configured according to the manufacturer of the software's specifications.
So number one, read the directions.
Number two, they didn't use the most basic of security controls that are out there.
You've got to watch these domains, capabilities, practices, processes. That's what we are always talking about in the cybersecurity business. They were not monitoring outbound connections. They didn't stop the call home stuff.
What I keep telling you guys, the easiest way to stop the spread of some of this nasty software is to use Cisco Umbrella. It's just that simple. Cisco Umbrella for just regular people is free. How could you get better than that?
When you get into the business level, which you cannot buy on their website. You can buy some very good stuff from the Umbrella website, from Cisco then you get a lot more features and fine-tuning and granularity and stuff.
If they had just been using Cisco Umbrella, that probably would have stopped the call home. That's what it does. Okay.
These are professional organizations that got hit here. Professional organizations.
We do not allow Willy nilly, outbound connections.
Some of these pieces of software pretend that they are a web browser and they just want to go to this website. If you're allowing your employees on your network to go Willy nilly, wherever they want online, you got some problems.
If you're just filtering for instance, Oh I'm not going to let them go to porn sites or something. Violence sites or Netflix to watch TV movies all day long. Instead of working, that's not good enough. That might help to keep them paying attention a little bit more to their work. I've found frankly, much of the time, they spend trying to figure out how to get around those filters. We catch people doing that all of the time. You have to talk to them and explain why the most dangerous parts of the internet, from a security standpoint, are the parts of the internet where you are going to have some of that nasty content that they might be looking at for. Once they understand that, usually they wake up and smarten up, et cetera, et cetera. But if that's all you're filtering for.
How are you going to know that there is a piece of Chinese back door software on your network, that's trying to get out? How are you going to know that there's a Russian back door trying to get out? Or there is a hacker that's in your network who is exfiltrating all of your data and then they're going to hold your data. Not quite hostage to where it used to be, but they're going to extort you and say, Hey, if you don't pay up, we're going to release all of this intellectual property to the internet.
The right way to do it is you only allow outbound connections to places they have to go for work.
We have a company, our client, just as an example, who is in the Department of Defense space. They are a subcontractor and they deal with parts for airplane engines, certain parts. As such, they have all kinds of federal regulations and those regulations mean that they can't have data that gets stolen, that gets exfiltrated, right? That's the whole idea. They're supposed to be secure. So what do we do in a case like that?
The people that work there can only get two websites that are approved. There websites of their suppliers. Their websites of their clients and that is all. They cannot go anywhere else. Why? Because part of the problem here is what just happened this week.
What happened this week with this massive order? This has only happened five times before in all of history. We'll talk about that, as well. What is this order? What happened is they tried to go out to some other websites.
Let's say they got infected, and their computer had some nasty-ware on there that was trying to call home. Just do its ET thing, call home. It tries to get out of the network using what looks to be an innocent little web connection. It gets there normally. But if we block everything except the website that they absolutely have to go to, that software is not gonna be able to get out of their network, is it?
This is not rocket science. Yet we've got 18,000 organizations that look like they got hit in this massive cyber attack. Massive. There's a company out there called SolarWinds. Now, SolarWinds we have used in the past. We stopped using them because of some of their practices. We just couldn't, in good conscience use them. Knowing what they were doing and how they were doing it.
But SolarWinds has this network management software. They have sold it to government agencies, massive companies, 499 of the Fortune 500 companies use SolarWinds. They have this network management product called Orion. Apparently, they like any other good little software vendor-provided updates.
The updates between March and June 2020 apparently had a little extra payload.
Now, the way these actors, the bad guys got this payload into SolarWinds software really shows that it was a Nation-State.
Now of course the media is out there saying Russia, which is what they usually do. You'd think it was probably more likely to be China. But you know what we'll probably never know because these people were very sophisticated. They basically reversed engineered a one-way hash function called SHA-1 which you should not be using anymore. It was thought to be relatively safe. They combined that with another vulnerability in a web server and in some software that supports the web server and is supported by the web server and bam they're in.
SolarWinds sent out updates to their clients. Those updates included updates and went to government agencies, all, but one Fortune 500 company, and over 22,000 managed services providers.
Now, we're going to talk about MSPs some more, and we've talked about them in the past. This is a big deal. Most businesses don't do the information technology function themselves. They might have somebody that's in charge of it, but that person is the person who goes out and tries to find somebody to take care of the systems or do an audit or whatever it might be that they're trying to do. That makes sense, I think. So that's what they're trying to do. But do they really know what they should do? What they shouldn't do? What should be done? What shouldn't be done? That's a subject that we'll take up a little bit later.
This compromised software was distributed as a software update to SolarWinds customers by SolarWinds. It turned out that their software had this payload in it that now allowed an as yet unknown bad guy to get into the networks.
Now there's a statement that was filed with the securities and exchange commission. I'm looking at it right now by SolarWinds corporation and talking about the Orion products. They say that SolarWinds believes that the Orion products downloaded, implemented, or updated during the relevant period, starting in March this year, contained the vulnerability. Orion products download implemented before the relevant period and not updated, did not contain the vulnerability. It goes on and on. It says SolarWinds values of privacy and security of its over 300,000 customers.
I can't believe that this would happen. So not only was SolarWinds caught up in this but so were many of their customers and you will find it interesting to know who some of their customers are because they have also been in the news lately for different reasons.
This is just fascinating. The biggest hack in recent history, and one, that's going to have consequences for years, literally years.
Make sure you visit me online. Craig peterson.com.
We've established that there was a hack. We've established that the media thinks Russia did it and so do many security consultants. We're not absolutely sure. We probably never will be.
What is this hack doing? How is SolarWinds tied into Dominion?
This hack has been absolutely scary as heck. One of the congressmen who got a briefing on Tuesday about what had been going on. Called this absolutely terrifying. Now that is a terrifying statement to make and the accusations are that Russian government hackers are responsible for this.
Now we've seen since March this software by SolarWinds called Orion, which was in place in 18,000 organizations, was compromised. Once it was in the network, it gave bad guys access to that network. Coming out this week on Thursday, we found that the feds have, in fact, said that yes, we were affected by this. Now affected, what does that mean? Ultimately, the pros and cons to this.
The list of affected US government agencies and entities include the Commerce Department, the Department of Homeland Security, the Pentagon, the Treasury Department, the US postal service, and the National Institutes of Health. Isn't that amazing actually it is institutes, right?
This is a long list of suspected Russian hacks into the US as well as many of our allies and other nations out there. This is very scary to hear that because Russia has been using hackers, they have been using bots, and they have had other means to try and influence elections in the United States and elsewhere.
Before this latest election, we had the Democrats saying our election that elected President Trump there was influenced was hacked by the Russians. And of course, as you know of investigations for four years, they never really found that Trump was colluding with Russia.
I think the focus was absolutely wrong in those investigations. It should have been on what happened with our elections? How safe is our election software? How about the hardware? How about the mechanisms that are in place? The federal government does have guidelines for this election vote tabulating software and hardware. They have error rates that are allowed just like they have so many mouse parts that can be in peanut butter. They have error rates that are far lower than are being reported, right now. Oh, thousands of times more ballots were rejected than were allowed by law. But nothing is happening. Nothing happened.
They investigated one person, one, man, basically President Trump. A number of other people were caught up in this investigation as they laid traps for people.
We did not do a major investigation into these systems. To me, that is absolutely inexcusable. Now we're seeing some other evidence that is something that I think we should be paying some attention to and that ties right into this hack of SolarWinds.
As I mentioned, all but one, of the Fortune 500 companies use their software. 18,000 different organizations installed the version of SolarWinds Orion products that were in fact known to not just be vulnerable, but have built into them hacking tools, which is just astounding to me.
Are we going to look into this now? Because looking right on this is from the Gateway Pundit.com. They went to dominion voting software. You can go to the homepage. They probably removed it by now, but it was there when I had a quick look on their website.
This emergency directive 21 dot 01. Very rare. Only has been issued five times in the last five years is saying remove all of this. Yet Dominion Voting is apparently a customer of SolarWinds and Dominion Voting brags about how they use SolarWinds. That is scary, very scary to me. Let's talk about what it does mean.
It does mean that our friends Dominion Voting, who has been accused of having terrible software, all the way through having major backdoors in their software. Our friends over Dominion Voting could well, have been completely compromised by that is SolarWinds attack. Completely compromised.
We don't know if they were but we do know that they were using it and they are the ones with our voting machines. This goes back to what I talked about last week, where I think there is only one solution to being able to be confident about votes.
Obviously, it's too late now to deal with all of the potential voter fraud, software errors, hardware failures that have occurred in past elections. It really is too late based on the evidence I've seen, to quote Attorney General Barr. But how about the future? How about we do an investigation into these companies that are providing us with the hardware and software. Or better yet, my solution is we have ballots printed. Those ballots have serial numbers on them with a very good check sum. All we do with those ballots is we scan them on regular commercial, industrial scanners that keep pictures of those votes. So we have a hard copy that we can go to at any time of the votes. We can analyze them. We can compare it to the vote counts, et cetera. We take those pictures now and we run them through very inexpensive software.
Very inexpensive, under a thousand dollars to buy a license for some of the software. What that software does is it looks at the images that were taken by these scanners. And it goes ahead and tallies votes. If we use two or three different software packages, they should pretty much agree. Our error rate should be less than one in a hundred thousand or maybe even a million. Should be pretty darn low. Then we hand tabulate a few of these just to double-check, make sure everything is all right. We now have hard counts.
People add up the counts and as always, you have election observers from the two major parties and the minor parties they're watching this whole process.
I am for absolute transparency here. I think all of those images of the votes should also be made available to anyone who wants to download them. This is the age of the internet. Why are we not making the images of the votes available for anyone who wants to look at them? Private individuals can tally the votes and come up with what should have happened, what the count should be.
You expect a little bit of variance, but absolute transparency. People add up those votes. It's all audited. There are cameras running, webcams 24 seven watching the voting machines. Watching the election workers. Streaming to anyone who cares to look. Now we have absolute transparency. Now we can believe the vote.
That I think is the only way we can handle this.
We're going to run through some checklists here about what gamers should be doing. If you're giving a video game or one of these consoles to maybe some of your kids. I don't dunno. Maybe your husband, maybe they are kids. We're all kids. What should they be looking for this year?
We are talking about this massive hack we've been talking about, and we're going to get into some other stuff right now. I wanted to mention one more thing. When we were just talking about this major hack may have been Russia, maybe China. Sometimes it's really hard to tell who it is. If these are good hackers and these are by the way were very good hackers.
SolarWinds I just can't hold them a hundred percent responsible for this hack because part of the problem was people not reading directions, not doing just the very basic practices that are established in the industry for trying to keep things safe.
So keep that in mind as well. But it is a huge problem. It's something we all have to pay a little bit of attention to.
I had a great question this week when I was on the radio, I was asked, Hey, please tell me that there are people in our government who are trying to do the same type of thing to other governments.
And you might've heard about what is it? I would call a person hack, right? This is what is called in the industry a honeypot. You probably heard about US Representative Eric Swalwell. He is a California politician, which makes a lot of sense. He has been in office since 2013 and he is also on a very. Interesting committee.
When we are talking about Representative Swalwell, his committee assignment includes him being on the Select Committee on Intelligence. Okay. Ranking member of its central intelligence agency subcommittee. He also retained his seat on the United States House Committee on science space and technology according to Wikipedia.
This is very scary because he fell for the oldest trick in the book. It also tells us just the links China will go to in order to hack our people, our country. Don't worry, we're going to tie all of this into our hackers. Okay.
He, as well as another politician from California. Yes indeed sitting us Senator she had a driver, I think it was for about 20 years who was a Chinese spy.
Eric Swalwell had this girlfriend and apparently, this happened when he was just a mayor before he had moved up to the house. Then, of course, moved into the intelligence committee. A lady who became his girlfriend was doing everything you might expect of a honeypot, a Chinese lady who was trying to get information out of him. I don't know what information he got she got out of him. He had a lot of information.
Now. If this were to happen to a Republican, of course, just by default, the morals of a Republican would be well. I really messed up. I'm sorry. I resign. At least resign from the intelligence committee, but I resign from Congress. That has happened before. Much different response. It's just amazing to watch from a Democrat and Republican.
Nancy Pelosi should have removed him from his very sensitive government positions. This guy has demonstrated that he can't keep his well, you know what I mean, and not reliable when it comes to secrets. Why hasn't the FBI said, I don't care what you say, Ms. Pelosi, we want this Congressman removed?
The big question is how did we find out about this? What ended up happening that brought us to the point where we realized that Eric Swalwell was a major security risk and was on the select intelligence committee? On oversight committees. Okay. It's scary, isn't it?
This ties into this whole hacking agenda. It looks like we might have been hacking, as well. I'd be shocked if we weren't. We have teams, red teams, in every branch of government, basically, that hack. That's what they do. They're hacking in order to see what weaknesses we have. But this has been barely reported at all.
This also happened last week. A major leak of official records from the Chinese communist party. Many of these Chinese communist party higher-ups are living and working in other countries, including the United States, Australia, United Kingdom of course, and this list that's been uncovered has about 2 million members of the Chinese communist party.
Now, remember these people have sworn an oath to do everything they can to protect and build up the communist party. Okay. This database lists names, party positions, dates of birth, national identification numbers, ethnicity, telephone numbers of these members.
Now. Australia Sky News on Sunday reported that the database quote "lifts the lid" on how the party operates under president and chairman Xi Jinping. The leak shows that the party branches are embedded in some of the world's biggest companies and even inside government agencies. Communist party branches have been set up inside Western companies, allowing the infiltration of those companies by CCP members who if called on are answerable directly to the communist party. To the chairman, the president himself.
So apparently along with the personal identifying details of almost 2 million communist party members, there are also details of 79,000 communist party branches. Many of them inside companies. Now there was some analysis done of this member, we've only had it for what about a week now, but the analysis has been done so far has been interesting, cause that's revealed that both Pfizer and AstraZeneca, both companies who have vaccines for this COVID virus both of these companies together employed 123 party loyalists.
There were more than 600 party members across 19 branches working at British banks, HSBC and standard chartered.
In 2016, in addition, the Daily Mail's reporting that firms with the defense industry interests, like Airbus, Boeing, and Rolls Royce employed hundreds of party members.
Now, when I found interesting is the response by the US media and the response by some of these companies. It's been reported that some of these companies, when they were alerted to the Chinese party membership of some of their people said "we're not interested in the political parties that our employees belong to."
Which is just shocking. We're not talking about basic parties here. We're talking about what effectively is an enemy of the United States and frankly, we're also looking at this hack as a declaration of war by Russia, by China.
China's done this before, too. In fact, we think they were behind another major hack you've heard of just a few years ago.
The PS five and Xbox series X apparently are almost impossible to get. Best Buy just can't get restock. But assuming you got one, what are some of the tips that you need to know? If you are playing games or your kids or grandkids are.
Video games, I've never gotten into them, but it's probably my generation. Back when I was a teenager, we had these text-based games that we would play sometimes. You're sitting in there on a teletype and you're typing into this computer over 110 bod modem. Oh, my gosh.
It was fun, so you were in a twisty maze of tunnels? I can't remember the exact wording and then you'd go left or right. And I never spent a whole lot of time on those things. Because I basically considered it a waste of time. I've played like Mario cart a couple of times when we got it for the kids and that's probably the extent of it. I've played with some of these video games that Apple has released now as part of their arcade product. I am shocked at how good they are. How good the. Resolution is. And the movement of the phone itself can be read by the game. Your phone is your controller. So if you play games on these video devices or on a PC of some sort or even a Mac. You're not too worried about availability because the software is easy, right? It doesn't cost much to duplicate that software. Probably doesn't even cost a penny, nowadays for the guys to download the game to someone. Of course, there are other charges and stuff involved, but it's just so easy to do.
So we're going to have a lot of them this year. Many of the people who are playing these games are the younger millennial generation, the Z generation, and both of them really have issues when it comes to security.
I mentioned this before in talking with my youngest son, about two weeks ago, about security. He just didn't seem to care. Now, we had given him a really good firewall router and a wifi system built into it. All kinds of processing that was going on. It was a Cisco device. Cisco firewall. It was analyzing everything coming into his network, everything going out from his network. It does a very good job of it. It had a limit of, I think, it was 250 megabits worth of data flowing through it. He said megabytes, and I'd have to look at the specs on it. Actually, I do think it's two hundred and 50 megabits and that particular device was great.
You're cruising the web. You have software of a machine gets infected, trying to get out. It'll shut it down just as all of this. His roommate, who calls himself a gamer, didn't like that at all. So he ordered a gigabit network coming in. It's a gigabit over RF cable modem, which is crazy. Cause you're not going to get it and we had previously explained, Hey, listen. Your biggest problem is going to be latency turnaround. It's not going to be the bandwidth. We showed him these statistics that our router had gathered that he never used more than 10 megabits of the worth of bandwidth, which is, pretty normal.
I've read some studies on it and 10 megabits, 20 megabits. That's the max that is used by these video games. He knew better, cause he's in his twenties, and he's a professional gamer, almost. Not that he makes money from it, but he's a professional gamer and he has been talking in the gaming community.
So rule number one is they don't need as much bandwidth as they think they need. What they need is a, basically a jitter-free line so that they can talk to their friends without any problems while they're playing the games. They need a very quick turnaround, so the round trip time needs to be fast.
I brought up with my son, Hey, listen. You realize that he went out and upgraded the line and then ripped out, while you were gone, the firewall. He put in a better one than handles a gigabit and of course, yeah, no better. The wifi that he has in the house that his friend purchased as his roommate, does not provide gigabit over the Wi-FI. It just doesn't happen. It can't happen on any of this consumer stuff when you get right down to it and you look at it hard, right?
Many companies are lying to us. They publish these specs. They give all of this data and it is so misleading. I said, this is a problem now because you have security at the bottom of the pile, when it comes to your network now. Anything that gets onto his machine is going to get onto yours. The firewall was actually a zero-trust basis and would not allow his friend's gaming computer to access his computer or anything else on the network that it wasn't explicitly allowed to access. And you do you know what he told me? He said he doesn't care.
Now. I don't know. So if this is your dad and you've been doing internet cybersecurity for 30 years, and you're just getting carried away type thing that you get from an under 30 five-year-old son.
I've got kids that are actually that age too. There certainly is a difference, a major difference. I don't know what it is, but the stats that I've seen in the studies I've read are showing that these younger millennials and generation Z, which this of our kids is right on that cusp, don't care about cybersecurity. Part of the reason is that they just have given up. Now, I've been fighting it for over 30 years. I haven't given up yet, but they have, it's just a fact of life.
Just like you have to be on social media and you have to post these pictures of your wonderful life. It's just crazy.
Here are seven tips and I got these from dark reading, a great website, but obviously, I'm going to comment on them a much different way than Dark Reading's approach to it.
But I really liked these points.
Number one, we've got to make sure our kids and ourselves understand that personal information needs to be kept personal. Now, I know every one of us in this country has had our data stolen. It's guaranteed. It hasn't all been stolen and it's from a snapshot in time.
For instance, the Equifax hack. Yes, indeed. That's pretty much everybody in this country, Canada, much of Europe's personal information. Our salaries, our home addresses, our social security numbers. Everything was stolen, but that's years ago. By the way, that was probably done by the Chinese communist party. Remember that they're socialists. We talked about this last week. They steal stuff. That's what they do because they just can't compete. They don't like competition. They want to sit on their hands for the most part. Now, China's done some interesting things. With trying to combine the ability to have some free trade with the government-controlled economy, right?
They're not just like we are. Not capitalists, they are not communist there. There's never, ever even with the Soviet Union and what happened in Venezuela and Cuba, they have never actually achieved pure communism.
We don't have pure capitalism here either. Don't let them share personal information, make sure they realize that every little bit of information they share, they may be sharing with a hacker. Someone that's going to break in. We had break-ins in our neighborhood. This was probably about five years ago. A bunch of break-ins bunch of stuff stolen. Our house at that time was never broken into. It turned out that it was a kid from the neighborhood whose family had moved out and he knew things about people in the neighborhood and when they worked and when they were taking vacations. So he came back in and he started stealing from the houses, he'd break into them and steal stuff. In some cases, apparently, kids had given him codes to be able to enter houses. It's amazing.
It reminds us again of another, a best practice. That we should be exercised in business and you need to exercise in your home as well. That is when someone leaves a job. What do you do? You shut down their accounts, do it all automatically. That's the way it should work. You archived their data so they can't get back in. Now we've seen instances where network people who had been doing network work at a business left and stole just tons of things, shut down networks, change passwords because that hadn't happened.
And in this case, It's a good idea to change the code on your door lock pretty frequently. Keep track of who has what code, right? Doesn't that make sense to you? Then on top of that, with these fancier new ones where you can use the Bluetooth, the cell phone To program it.
So you just bring the phone close to the door and it automatically unlocks, it gets more complicated. It's easy to set up, but we've got to make sure we erase them.
So number one, don't share personal information. The next one, obvious as heck. We talk about it all the time but take care of your home network. Don't do what my son did and put in a cheap router. My son's roommate did make sure it's secured using multi-factor authentication. Now there are some ways around some of this, so that's why I recommend you do not use texting for multi-factor authentication. Use something like DUO or 1password or Last Pass or Google Authenticator. It's really going to help.
Stay away from chats. Now, this is difficult because much of the social stuff that goes on with gaming is over chats that are built into these games. So just be careful when they're in chats because it is used by these honeypots and others to get personal information. Kids don't realize, Hey, listen, dad is a high up in this company and I probably shouldn't be talking about that because honeypot to go after our kids, to get at us.
Avoid third party stores, apps, turn off Universal Plug And Play. (UPNP) If you still have it on your network and beware of scams when playing online. So some good tips for the kids.
This latest declaration of war as it's been called may be bad enough for government agencies and bigger companies, and 22,000 managed services providers. But man ransomware.
Then follow up to our last hour, DNI, the Director of National Intelligence Ratcliffe was supposed to have come out with a report as of yesterday about the elections and about foreign interference. Because of disagreement within the National Intelligence Community, it did not get released, at least not yet. It should be out fairly soon.
The big talk and the disagreement between various people who are in the organization, one of those jobs for life things, right? The deep state as President Trump has called it. Is that how much involvement did China really have? How much involvement did Russia have? I strongly suspect. Russia had a lot of involvement here in hacking. In fact, even our voting machines, as we talked about in the last hour because of the SolarWinds hack. How about China? They're saying it looks like it could be a major influence and have had a big impact on the election, in a number of ways, but we're not going to get into that right now.
Those big hacks have been very successful against larger companies all, but one, of the Fortune 500 apparently was affected and some 22,000 managed services providers countrywide use it according to SolarWinds, about 18,000 businesses. Were using the affected or infected, depending on how you want to look at this, but using the affected software. That's a real big deal, frankly. How about you and me? What does it mean to us as business people, as home users, et cetera? I want you guys to understand this a little better, so I'm going to explain it and I appreciate all the comments I've had about how much you guys appreciate me doing a little deeper dive into this far deeper than most anyone else can. You get these guys on the radio that just talk about absolute fluff in technology. Mainly because they don't know any better. I've just been doing this for too long.
One of these commentators, a lady who's had her own radio show for years. Just amuses me to know she was a marketer for years before she got on the radio. Maybe that's why she's a lot more successful on the radio than I am, but I'm much more successful in tech than she is.
You as a regular end-user, you're probably not badly affected by this hack, this SolarWinds hack, and all of the subsequent hacks that happened. It's probably not a huge deal for you because your home computers were not running this Orion software from SolarWinds, and you're probably not using any of the other software that's out there. I'm continually reminding everybody and I'm covering this as well in my Windows Hardening Course, which's coming up soon.
When I was recording this week, it made me think about this a little bit, that you and I, as home users know better than to buy things like Norton and try and use them or some of these other antivirus products, because in this day and age with Windows 10, just not considering anything else in the network, but just the computer itself, you are probably best off using Windows Defender and making sure your computer stays up to date.
You also know if you want to spend a couple of bucks. There is some other good stuff out there that's going to help and one of those is Malwarebytes. In fact, I'm going to try and include a link to some of them Malwarebytes stuff this week. Malwarebytes is another good little piece of software to have, and how much I like Umbrella.
You'll find that online, of course, umbrella.com and you can get the free version. You can get the paid version. If you are a business, you need to talk to a reseller, like me, and have them set you up with the business version. Those three things are going to go a very long way.
Obviously, you need to lock down Windows and harden it. That's why we're doing this whole little course coming up here soon. If you are a business now you might be in some trouble. I have been saying now for three, four years, as well as the FBI has been saying this and I covered it in some of the FBI InfraGard webinars that I hosted. If you're an MSP, if you're a managed services provider or break-fix shop, in other words, if you take care of other peoples and more particularly businesses computers, you are a major target. You have to pull up your socks.
Now, the Department of Defense with this cybersecurity maturity thing that they've come out with CMMC. They have made it very obvious because he specifically says it that if you are a managed services provider, you have to meet the requirements that the Department of Defense is putting on to their customers or their suppliers. I think that makes a lot of sense.
If you are a managed services provider, you probably have pretty much, if not completely full access to your customer's computers and networks. So if you have a customer, that deals with the Portsmouth Naval shipyard, for instance, that is a Federal Government DOD facility and if those DOD contractors that are out there on base have to meet certain requirements for cybersecurity, you would expect that you as a managed services provider have to meet those same requirements.
The answer is yes, absolutely you do. We're talking about some serious policies and procedures, some serious hardware to help make sure everything's working right. Some serious monitoring of the hardware and the software and the alerts. It's a lot of work.
We've talked about it before. Basically, if you have less than 200 people, you probably can't afford it. There is no easy button when it comes to the NIST 800-171 or the CMMC standards. So you turn to one organization, that's a managed service security services provider and you expect that they are going to be able to take care of you. I don't think that's unreasonable.
What should you be doing? How can you have these guys take care of you? The answer is almost none of them can. No, they'll say so. They'll put a nice little logo up on their site and, Oh my gosh, aren't we just, Mr. Wonderful, Mrs. Wonderful. In reality, many of these companies know the buzz words. They know the key phrases, but they are not up to snuff when it comes to doing security or including their own security.
So they'll go to other vendors. They go to distributors, try and get some help. This goes back to how I started out here, talking about these tech shows, where the host really knows very little about the actual technology. You want someone that understands. If you want a good meal, you're going to go to one of these celebrity chefs. They know the business and they know the business from the start to the end. You're not going to go to a fry cook for Wendy's, in order to get a great meal. Now, you might get a decent meal.
So the Department of Defense is now pushing all of these standards down to the MSSP's. This is why we are actually a Master Managed Security Services provider. We provide security services through and for these Managed Services Providers, I think that just makes a whole lot of sense, but these companies have access to other businesses.
Computer networks have been under attack forever and this now proves my point I've been trying to make for years. Which is the SolarWinds attack was directed at 22,000 companies that call themselves Managed Services Providers. Why? Because that's where the money is, that's where the access, the keys to the kingdom are for so many companies and so many government agencies are these managed services provider.
Now, this is difficult because I promise this week to get something out about selecting a managed services provider. I have something, if you want a copy of it, make sure you email me [email protected] because I got a little checklist that I put together. It's one of these generic ones.
I'm not trying to say, Hey, you got to hire me. You know how that goes? Where they put out an RFP, requests for proposal and there's only one company in the whole world that could possibly meet all of those specific requirements. Been in business for 30.6 years, is located within two miles of us, et cetera, et cetera. No, that's not what this is. This is a real nice generic list that you can use to help evaluate anyone out there that is going to be helping you out with your security.
So whoever it was, the Russians, most likely knew what they were doing. So they got not only the 22,000 managed services providers that got them in their site, but they also got all of these government agencies, and all, but one, of the Fortune 500 is right there in their sites.
They are not stupid. This was a very difficult hack and they pulled it off. They would have been continuing to pull it off, frankly, for a very long time.
So if you outsource your IT, which you have to do, because that's the only easy way to get some real talent part-time, which is what most small businesses need. They don't need necessarily full-time on their staff, but they need full-time attention. and you got to pay attention.
Drop me an email. [email protected]. I'll be sure to get it back to you.
Ransomware is no longer just the domain of basic hackers or even NationStates. Like what we saw with this massive SolarWinds hacks and targeting managed services provider. It is now changing ransomware in a big way.
What is behind the headlines and really helping people to try and understand it a little bit better? I've always been told I'm good at and something I do enjoy doing. I guess that's a good thing, right? For you guys, as well as for me.
Ransomware has been evolving over the years. We've talked about it here on the show before, but the idea behind ransomware that those people who aren't familiar with has changed from really one idea, now, to two core ideas.
So the first idea is the one you may be familiar with which is they get some malware on your computer. However, it might be, they might be sending an email phishing email, trying to trick you into clicking on something and then installing some software. It might be via a worm or a remote hack, right? It could be a little virus that gets in, but the idea behind ransomware is that it gets on your machine and then it phones home.
Some of this stuff is very fancy. You can go onto the dark web and you can find ransomware for cheap money. You can even buy ransomware as a service. So what you do is you send out the ransomware to email addresses, right? The ones you've bought or stolen or harvested from the internet. Another reason, by the way, you should never have your email addresses up on a website where it's easy for software to grab.
Ransomware as a service does everything. Some of these companies, my gosh, you pay them either a fixed fee or a fixed fee plus a percentage of your take and they'll run the whole gamut for you. They'll provide tech support for people who get ransomware.
Here's what will happen. That person clicked on that email. They installed that software that got the virus. There was a drive-by worm, whatever it might be and in the background now starts encrypting all of the major files. It looks for things like word docs and Excel spreadsheets, et cetera and it encrypts them all. It calls home first, nowadays, for instructions and tells the bad guys, "Hey, here's the key I'm using to do the encryption." It gets really fancy today. We'll get into that one in a minute.
Then it pops up on your screen. "Hey, all your files are encrypted. You got ransomware to contact us." It gives you an email address or something else to contact them with. It has a big takeaway. It says, "Hey, you've only got so many hours to contact us, or the ransom goes up and goes up" To try and get you to move, and then you will pay via Bitcoin. Almost always.
Which, by the way, has been driving up the value of Bitcoin. Because people have been buying it in order to pay ransoms. So that's what we're used to.
The newer ransomware does things a little bit differently. So it gets onto your machine in much the same way. But the next step that it takes once it's on your machine, is it starts looking at files and finding files and usually it'll wait because what it's doing at that point now is it's pumping, poking a hole out of your network, back to the main controller for the ransomware guys.
So it gets on your machine. It grabs the names of some of the files. It then connects back to home. It calls home. Once it's called home, it sends the names of your files and then it sits there. Now the ransomware guys are pretty busy actually. Cause so many people to fall for this stuff and haven't done what they needed to do to keep the ransomware out. The ransomware guys, usually within a few days, will then remote control your computer and they'll poke around and they'll find, Oh wow, here's client lists. Oh my gosh, personal information. I can sell that for as much as $20 a record. That's a lot of money, right? Especially for someone in Eastern Europe, which is where most of these things come from. Then what will happen is they will look around some more and they'll start trying to spread laterally, East, West, inside your network. So now they're inside your network and they say, Oh my gosh, there's 20, 30, 40, 50 machines in here. It'll try and infect these other machines using the same or different techniques where it tries to spread like a worm, or a little virus, going around inside your network. And then it says, Oh my gosh, this is a medical office. Oh my gosh, this is a Department of Defense manufacturer. It's. Oh, wow. Wow.
When they got all of these records, all of these data. They might find things like also bank account numbers and transfer numbers, ACH accounts. All of this stuff. That's what it's looking for. Now. It's doing all of this in the background. You don't realize what's happening. Your computers just work in a way at this point that is probably not even slow. Then the next step that they take is they decide, okay, what are we going to do? You know what? I think that we can extort money from this person if we pull these files. So they'll grab a bunch of files. They don't remove them from your computer. They just make a copy of them from the computer, from your file server or wherever they are in your network. It may be all of your files and may just be a few of them. Once they're done with that, they will either encrypt everything and hold for normal ransom or not.
If they hold you for normal ransom, the same normal stuff applies a little red screen comes up. Oh, you've got ransomware. We can help you fix it. Contact us, give us a copy of this number. Take a picture of the screen and then off you go buying Bitcoin and paying them off.
Remembering because you listened to this show that the Department of Justice may come after you if you pay the ransom for supporting terrorists and terrorist demands, but that's a separate issue.
Now you get your key to decrypt and according to the FBI, about half of the time, you'll get all your files back.
Okay. So far that all sounds pretty normal, but the next part is what they've been doing more recently, which is. Okay guys, thanks for paying that, by the way. We are a different company. We're a different group of bad guys, and we have copies of some of your files and unless you pay us. We're going to release those files out on the internet, the dark web, or maybe the regular web put them up in a paste bin or wherever they might want to put them.
Pastebin is a website that hosts these files, zip files, and other things with all kinds of information in it. That is obviously sensitive because why would you pay extortion otherwise? So that's what they do.
Secondarily, they try and get you to pay them to not release your data. Okay. So in many cases, you have paid twice, you paid once to decrypt the data you paid a second time in order to gain access to that data. Or excuse me, just stop other people from gaining access to your data.
Does that make sense to you guys? That's what they've been doing.
Now we've got a new scale that these ransomware guys have. They are really catching up quickly with the Nation States that we've been talking about earlier. These are called advanced persistent threat groups. Just the regular gangs now have stepped it up.
You can get this show and many others via podcast. Just go to my website, Craig peterson.com.
Ransomware has gone from being opportunistic over to the other side, where they may spend months or even years on a network and a business and a government. So we're going to talk about the East-West spread of ransomware.
We've had a major hack this week that has affected federal government agencies, all but one of the Fortune 500 agencies. It's affected 22,000 of these managed services providers potentially at least 18,000 organizations are confirmed with being affected by this.
We're thinking it's Russia, but who knows? You cannot really tell. In the last segment, we went through the major changes in ransomware over the years. As I mentioned, the intro, opportunism, that's been the name of the game. They just send out a lot of feelers. They do a lot of scanning and they find somebody that is just vulnerable. That's the bottom line. They want vulnerable businesses. Once they find a vulnerable business, they move to the next step. That next step in the past has been just encrypting everything so that you and I really have no way to respond to it.
It has gotten fancier. These advanced persistent threats are what the name implies. They're an advanced attack method. They're persistent. In other words, once they're on a network or on a machine, they stay there and there is a threat because of these ransomware groups, such as DAPL, painter, and revival. Have gotten on to the networks have been very targeted at what networks are trying to get onto.
They want networks of businesses and these cyber-criminal hackers find vulnerabilities on the networks as they move around inside the network. That's what East to West is moving around inside finding other vulnerabilities. They often spend months laying the groundwork to compromise the systems with ransomware before finally unleashing the attack and encrypting the network.
They've found that phase two, which was let's get on the network. Let's find the valuable files. Let's hold them for ransom. That just takes a long time. If they've stolen people's credentials, if they've stolen, social security, numbers, bank, account numbers, credit card numbers, et cetera. It takes a long time to sell them and get their money back. So they really aren't trying and to speed things up, frankly, spending months on a network isn't unheard of and it's become more and more common.
These threat groups will hide for even years before they are detected, if they're detected at all, their goal is surveillance of the network. Finding all of the weaknesses and then stealing sensitive data, rather than just making money right off the bat with ransomware. These groups are making millions of dollars per attack. It's become so effective that many businesses if you look at their filings with the security and exchange commissions, are buying Bitcoin in preparation for a ransom. Isn't that something, in other words, they expect a ransom to happen. So they're just buying Bitcoin. So they have it to pay if it happens. Okay.
So the there's been this transition from being opportunistic. Into the types of threats, we've seen from NationStates here for years. It is much more profitable for these bad guys to completely cover an organization with ransomware. Now, remember that's not necessarily the primary target, but it's also a really good cover for them because now you're trying to deal with the ransomware threat.
So what do you do if you have ransomware? The best thing is don't get it in the first place. We've gone over that quite a few times here on the show, but the basics: Make sure you're running windows defender, Make sure that you are using Umbrella, so they have a hard time calling home.
Make sure you go on to the next stage as well. Maybe add Malwarebytes.
You also have to protect that network. I am a Cisco reseller and we have techs that are fire jumper certified. We know what happens. We can come in afterward and do clean up. This, unfortunately, is how we pick up most of our customers. Or we can go in beforehand and help to protect you because you want to stop them from getting in.
The regular email filters just aren't enough. So we run it through just all kinds of tasks. We had an email from one of our clients here just about a week ago saying, Oh, I got this email. It seems to be fishing. How did that get through? Yeah, we stopped a thousand of those. It's types of emails and one snuck through. Nothing's perfect.
We've got to remember that as well. So if it does get in someone bringing in a thumb drive from home or using the VPN into the office, that hasn't been properly protected. Most of them aren't, by the way, everybody that gets in, what do you do then? Hopefully, you have a good backup. You're probably going to have to wipe all of your machines. Depending on the threat involved, that might be pretty difficult because they can get into different parts of the machine that you just can't get them out of.
The next evolution of ransomware is that these groups gain more experience with these successful attacks. That time where they're taking between that initial compromise could be months or even years, that amount of time will become much shorter. Meaning there's less time to potentially detect this suspicious activity before it's too late.
We know from what Talos has been reporting, as well as others, that the compromise timeframe where they poke around inside your network is nowadays somewhere between three and five days. So you have a few days to catch them in your network.
Now, if you don't notice them, well it's probably a little bit too late, but again, hopefully, have good backups.
Having good backups means, by the way, the three, two, one principle on backups. It means that you need to be testing them as well. Make sure you can restore your business from backup and you might even want to do what we've done for our bigger clients, a one a multi-national where we had backup hardware there at their facilities. So if something were to happen, let's say that there was a fire in the front part of their building, where their main data center was, we could transfer all operations to the back part of the building, where we had our own servers sitting there that could take over at an instant notice. Then we also have servers in the cloud that have all of their data. In an attempt to keep them up to date in almost real-time so they can stay in business. That's what you need to do. If you're going to survive ransomware.
Now there are also normal things. Make sure you're applying security patches to everything. Make sure you are using multiple network segments that can not communicate with each other. So for instance, your building control systems should be on a completely different network than your office workers' computers, and those computers should be on a completely different network than this server. They should be going through a firewall to get to the server and an internal one.
You should have multiple layers of firewalls. In this company, I'm thinking of, this multi-national, we have seven layers of firewalls that you have to pass through in some cases, depending on where you are. That helps keep them out. Okay.
The security patches you got to do, you've got to patch all of your internet of things devices.
You cannot let people bring personal devices in. It just goes on and on.
These are the types of controls, the best practices that we need to have. All right.
You've probably heard of contact-tracing apps. Who knows what's going to happen with that virus over the next year or two years or what viruses might be coming after that. We're going to talk about the safety of the apps themselves.
One of the big things that have been pushed in many parts of the world is contact tracing. Some states require us if we go to a restaurant to give our name, right? To give our phone number for contact. If there was someone at the restaurant who calls up the restaurant and says, "yeah, Hey, I came down with COVID-19 symptoms", then the restaurant's supposed to call up everybody who was there at the restaurant. Now, how effective is that? I really don't know.
It's people, I would not want to give my information to people. I think we should just assume that we're living in a world with viruses and we should take precautions. If I was in the groups, one of the groups that were very susceptible to the virus. I think I would take a lot more precautions and frankly, isn't that the way it should be. If you are susceptible, then maybe you should lockdown. Not shut down - locked down, everybody else.
We've never done anything quite this way before. You find typhoid Mary, and she gets quarantined, not everybody else. That's always the way we've done it. And it just makes a lot of sense.
One of the proposals that have come out that they're saying, Hey, this is going to help us in the today and into the future, are these contact tracing apps? I'm looking at an article right now that was over on dark reading saying that they tested nearly 100 contact tracing apps. Now, these are apps that are on your smartphone that might use Bluetooth for proximity detection to another phone. They might use some other technologies. I've seen some that actually start to squeal and make noise. If you get close to somebody else that's running one of these apps. So that, okay, I'm within the one-meter limit.
Of the nearly a hundred they tested, they found 40% had significant security issues. Either using GPS locations or Bluetooth proximity detection in order to determine your potential exposure to somebody else. Now, these are mostly apps that are not using this new Apple and Google exposure notifications protocol. I found that kind of interesting Apple has been very good at trying to preserve our privacy. In fact, there's a huge fight already going on between Facebook and Apple. If you have the latest version of iOS, you can go into the app store, look at an app, and I would challenge you to do that.
If you've got your phone right now, iOS phone, and you're up to date, open up the app store search for the Facebook app. Then once you're on the Facebook app page, scroll down a little bit and it'll have a section in there on security that goes on for pages and pages. Yeah. More button. Okay. Read more of what it is that Facebook is doing with your data. So Facebook's pretty upset about that saying this is going to hurt small businesses who need to micro-target, and they're not wrong about that. Apple is saying, Hey, we're trying to preserve the privacy and security of people who use Apple equipment, which I absolutely do agree with.
Well, a company known as Guardsquare, which is a mobile security firm analyzed 75 contact tracing apps, 52 Android apps, and 43 iOS apps and found that 40% did not use the Apple Google protocol that Apple and Google worked together on this to come out with.
The bottom line here, what is it is going to be safe? How can we protect user privacy? This protocol is designed to protect it. Most of those applications used GPS system data too. Figure out your location of other people and linked it to the phone numbers or in some cases, passport identifiers.
Now, GPS can be fairly accurate, but if you want it really accurate, you have to add to some other data that is transmitted by all major airports, because there's a variance. The density of the atmosphere, which can vary depending on whether it's raining, how much water is in the air, snow, and other things. They transmit variances that can be used in conjunction with GPS to get an actual, accurate location. Once you get into a building or have you ever been inside a big city and found all of a sudden your GPS data is just terrible. Your automatic map stuff just isn't working, right? Those big buildings are blocking the signals from some of the satellites that you are depending on. That's what they have found with these apps. Many of them are trying to use GPS. They are gathering that and keeping the information and selling the information, which is a bad thing. It's not terribly accurate. Okay.
So first off don't use these apps at all. If you're in one of the risk groups, You are also now relying on other people to have the same app or the same protocol being used in order for your app to do any good at all, because they are combining the data from everyone that's self-reporting in an area to figure out if there's potential exposure. If they're not self-reporting, if they don't have that same app, you're not going to get any information.
So in June, Guardsquare looked at 17 different Android apps and found only one that fully encrypted and obfuscated data.
They have done a survey here in the last month and it has gotten a little bit better, but of those 95 apps, they found 32 Android apps and 25 iOS apps actually use the official API of the exposure notification system created by Apple and Google.
So bottom line, don't use these contract contact tracing apps. They're not useful. They're not useful, if not enough, people are using them. Then to top it off, they are not encrypting the data and anonymizing the data.
FireEye, man, this is the company that found out about that SolarWinds breach that we spent the first hour talking about today. FireEye is a security research company. Part of what you should be doing and is required to do is to have red team blue team exercises. What that means is you have people who are attacking your network, and then you have people who are defending the network. So you have a team of people whose goal is to break in and another team whose goal is to defend. You might remember. I talked to him about a company that hadn't been hired to do this out. Where was it? Missouri or something. They tried to break into the courthouse that they had been hired to test. Then there was a dispute over turf and everything else, and these guys went to jail and they had to go to court. The whole thing was quite the mass. Okay.
That's a red team- blue team type strategy. We don't do physical incursions ourselves. It's just a little bit too risky for us. It takes more people more time, but we do the type of Computer incursions and FireEye has red team tools that are used to break in. That is a problem because FireEye was compromised as part of this SolarWinds hack. Their tools were stolen. These are the FireEye red team tools that are used by their security teams to break into businesses. This is the gift that's going to keep on giving.
You might remember the NSA was broken into and their red team tools were stolen. The tools they use to monitor foreign governments and officials hack into computers. Well, this is a real problem. Okay. Many of these red team tools that were stolen from FireEye have already been released to the community and there's even an open-source virtual machine called commandoVM. Just absolutely unreal.
Apparently, none of the red team tools that were stolen by the attacker contain zero-day exploits and they apply well-known methods to break in. In other words, if you had been patching your systems, taking care of it, unlike what happened with so many companies out there. Right?
Home Depot, what happened to them? The TJX community of businesses, Equifax on and on Who did not keep up with best practices or even patches you might be okay. But if you are more of a security guy, like I am they have released hundreds of countermeasures that you can use, including things like Open IOC, Yara, Snort, ClamAV, all tools that we use here as well. There's a whole FireEye git hub repository. Git Hub is where people can distribute software and things. It's usually used by the open-source community and they've got directions and what you can do and everything else. So I think FireEye has responded extremely well to this. It's going to hurt their business. No doubt. It's going to hurt a lot of other businesses. No doubt, but I really like what they have done and you can look it all up online.
If you want a little more information. Just email me [email protected] and it might be time for me to put together with other, a little course, Oh, maybe a big course on how to use these tools to test your own security as well as to defend your security.
That's it for today. Thanks for joining me. Make sure you join me online as well. craigpeterson.com.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome! Â
This week I am spending a bit of time discussing The huge hack on SolarWinds Orion Software and why we will be feeling the repercussions for years -- and yes it could have been prevented. Then we will talk a little bit more about Election fallout and how this hack might have something to do with it. Then Fire-Eye hack and New and Improved (well -- another variation) of Ransomware and More so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
Gaming Over the Holidays? 7 Important Security Tips
Looking at Using a Contact-Tracing App? Contact-Tracing Apps Still Expose Users to Security, Privacy Issues
Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data
Knowing What the Enemy Knows Is Key to Proper Defense
Major Cybersecurity Vendor FireEye Breach -- Fallout Yet to Be Felt
New AdWare Silently Modifies Search Results
Ransomware gangs are getting faster at encrypting networks. That will make it harder to stop
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] In case you didn't hear, we have had a massive hack. We're going to be talking about that and what it means to you. What it means to the federal government. What it means to organizations that are using SolarWinds. Oh my
Hi everybody. Craig Peterson here. Had a great discussion this week with Mr. Matt Gagnon Wednesday morning, as we usually do, and we're going to continue that now. Let's get into it in a little bit more depth.
You probably heard me pounding on that table and it was just unbelievable because the bottom line here is these particular hacks were effective because these supposedly "Professional Security People" did not follow the basics. They didn't have the software configured according to the manufacturer of the software's specifications.
So number one, read the directions.
Number two, they didn't use the most basic of security controls that are out there.
You've got to watch these domains, capabilities, practices, processes. That's what we are always talking about in the cybersecurity business. They were not monitoring outbound connections. They didn't stop the call home stuff.
What I keep telling you guys, the easiest way to stop the spread of some of this nasty software is to use Cisco Umbrella. It's just that simple. Cisco Umbrella for just regular people is free. How could you get better than that?
When you get into the business level, which you cannot buy on their website. You can buy some very good stuff from the Umbrella website, from Cisco then you get a lot more features and fine-tuning and granularity and stuff.
If they had just been using Cisco Umbrella, that probably would have stopped the call home. That's what it does. Okay.
These are professional organizations that got hit here. Professional organizations.
We do not allow Willy nilly, outbound connections.
Some of these pieces of software pretend that they are a web browser and they just want to go to this website. If you're allowing your employees on your network to go Willy nilly, wherever they want online, you got some problems.
If you're just filtering for instance, Oh I'm not going to let them go to porn sites or something. Violence sites or Netflix to watch TV movies all day long. Instead of working, that's not good enough. That might help to keep them paying attention a little bit more to their work. I've found frankly, much of the time, they spend trying to figure out how to get around those filters. We catch people doing that all of the time. You have to talk to them and explain why the most dangerous parts of the internet, from a security standpoint, are the parts of the internet where you are going to have some of that nasty content that they might be looking at for. Once they understand that, usually they wake up and smarten up, et cetera, et cetera. But if that's all you're filtering for.
How are you going to know that there is a piece of Chinese back door software on your network, that's trying to get out? How are you going to know that there's a Russian back door trying to get out? Or there is a hacker that's in your network who is exfiltrating all of your data and then they're going to hold your data. Not quite hostage to where it used to be, but they're going to extort you and say, Hey, if you don't pay up, we're going to release all of this intellectual property to the internet.
The right way to do it is you only allow outbound connections to places they have to go for work.
We have a company, our client, just as an example, who is in the Department of Defense space. They are a subcontractor and they deal with parts for airplane engines, certain parts. As such, they have all kinds of federal regulations and those regulations mean that they can't have data that gets stolen, that gets exfiltrated, right? That's the whole idea. They're supposed to be secure. So what do we do in a case like that?
The people that work there can only get two websites that are approved. There websites of their suppliers. Their websites of their clients and that is all. They cannot go anywhere else. Why? Because part of the problem here is what just happened this week.
What happened this week with this massive order? This has only happened five times before in all of history. We'll talk about that, as well. What is this order? What happened is they tried to go out to some other websites.
Let's say they got infected, and their computer had some nasty-ware on there that was trying to call home. Just do its ET thing, call home. It tries to get out of the network using what looks to be an innocent little web connection. It gets there normally. But if we block everything except the website that they absolutely have to go to, that software is not gonna be able to get out of their network, is it?
This is not rocket science. Yet we've got 18,000 organizations that look like they got hit in this massive cyber attack. Massive. There's a company out there called SolarWinds. Now, SolarWinds we have used in the past. We stopped using them because of some of their practices. We just couldn't, in good conscience use them. Knowing what they were doing and how they were doing it.
But SolarWinds has this network management software. They have sold it to government agencies, massive companies, 499 of the Fortune 500 companies use SolarWinds. They have this network management product called Orion. Apparently, they like any other good little software vendor-provided updates.
The updates between March and June 2020 apparently had a little extra payload.
Now, the way these actors, the bad guys got this payload into SolarWinds software really shows that it was a Nation-State.
Now of course the media is out there saying Russia, which is what they usually do. You'd think it was probably more likely to be China. But you know what we'll probably never know because these people were very sophisticated. They basically reversed engineered a one-way hash function called SHA-1 which you should not be using anymore. It was thought to be relatively safe. They combined that with another vulnerability in a web server and in some software that supports the web server and is supported by the web server and bam they're in.
SolarWinds sent out updates to their clients. Those updates included updates and went to government agencies, all, but one Fortune 500 company, and over 22,000 managed services providers.
Now, we're going to talk about MSPs some more, and we've talked about them in the past. This is a big deal. Most businesses don't do the information technology function themselves. They might have somebody that's in charge of it, but that person is the person who goes out and tries to find somebody to take care of the systems or do an audit or whatever it might be that they're trying to do. That makes sense, I think. So that's what they're trying to do. But do they really know what they should do? What they shouldn't do? What should be done? What shouldn't be done? That's a subject that we'll take up a little bit later.
This compromised software was distributed as a software update to SolarWinds customers by SolarWinds. It turned out that their software had this payload in it that now allowed an as yet unknown bad guy to get into the networks.
Now there's a statement that was filed with the securities and exchange commission. I'm looking at it right now by SolarWinds corporation and talking about the Orion products. They say that SolarWinds believes that the Orion products downloaded, implemented, or updated during the relevant period, starting in March this year, contained the vulnerability. Orion products download implemented before the relevant period and not updated, did not contain the vulnerability. It goes on and on. It says SolarWinds values of privacy and security of its over 300,000 customers.
I can't believe that this would happen. So not only was SolarWinds caught up in this but so were many of their customers and you will find it interesting to know who some of their customers are because they have also been in the news lately for different reasons.
This is just fascinating. The biggest hack in recent history, and one, that's going to have consequences for years, literally years.
Make sure you visit me online. Craig peterson.com.
We've established that there was a hack. We've established that the media thinks Russia did it and so do many security consultants. We're not absolutely sure. We probably never will be.
What is this hack doing? How is SolarWinds tied into Dominion?
This hack has been absolutely scary as heck. One of the congressmen who got a briefing on Tuesday about what had been going on. Called this absolutely terrifying. Now that is a terrifying statement to make and the accusations are that Russian government hackers are responsible for this.
Now we've seen since March this software by SolarWinds called Orion, which was in place in 18,000 organizations, was compromised. Once it was in the network, it gave bad guys access to that network. Coming out this week on Thursday, we found that the feds have, in fact, said that yes, we were affected by this. Now affected, what does that mean? Ultimately, the pros and cons to this.
The list of affected US government agencies and entities include the Commerce Department, the Department of Homeland Security, the Pentagon, the Treasury Department, the US postal service, and the National Institutes of Health. Isn't that amazing actually it is institutes, right?
This is a long list of suspected Russian hacks into the US as well as many of our allies and other nations out there. This is very scary to hear that because Russia has been using hackers, they have been using bots, and they have had other means to try and influence elections in the United States and elsewhere.
Before this latest election, we had the Democrats saying our election that elected President Trump there was influenced was hacked by the Russians. And of course, as you know of investigations for four years, they never really found that Trump was colluding with Russia.
I think the focus was absolutely wrong in those investigations. It should have been on what happened with our elections? How safe is our election software? How about the hardware? How about the mechanisms that are in place? The federal government does have guidelines for this election vote tabulating software and hardware. They have error rates that are allowed just like they have so many mouse parts that can be in peanut butter. They have error rates that are far lower than are being reported, right now. Oh, thousands of times more ballots were rejected than were allowed by law. But nothing is happening. Nothing happened.
They investigated one person, one, man, basically President Trump. A number of other people were caught up in this investigation as they laid traps for people.
We did not do a major investigation into these systems. To me, that is absolutely inexcusable. Now we're seeing some other evidence that is something that I think we should be paying some attention to and that ties right into this hack of SolarWinds.
As I mentioned, all but one, of the Fortune 500 companies use their software. 18,000 different organizations installed the version of SolarWinds Orion products that were in fact known to not just be vulnerable, but have built into them hacking tools, which is just astounding to me.
Are we going to look into this now? Because looking right on this is from the Gateway Pundit.com. They went to dominion voting software. You can go to the homepage. They probably removed it by now, but it was there when I had a quick look on their website.
This emergency directive 21 dot 01. Very rare. Only has been issued five times in the last five years is saying remove all of this. Yet Dominion Voting is apparently a customer of SolarWinds and Dominion Voting brags about how they use SolarWinds. That is scary, very scary to me. Let's talk about what it does mean.
It does mean that our friends Dominion Voting, who has been accused of having terrible software, all the way through having major backdoors in their software. Our friends over Dominion Voting could well, have been completely compromised by that is SolarWinds attack. Completely compromised.
We don't know if they were but we do know that they were using it and they are the ones with our voting machines. This goes back to what I talked about last week, where I think there is only one solution to being able to be confident about votes.
Obviously, it's too late now to deal with all of the potential voter fraud, software errors, hardware failures that have occurred in past elections. It really is too late based on the evidence I've seen, to quote Attorney General Barr. But how about the future? How about we do an investigation into these companies that are providing us with the hardware and software. Or better yet, my solution is we have ballots printed. Those ballots have serial numbers on them with a very good check sum. All we do with those ballots is we scan them on regular commercial, industrial scanners that keep pictures of those votes. So we have a hard copy that we can go to at any time of the votes. We can analyze them. We can compare it to the vote counts, et cetera. We take those pictures now and we run them through very inexpensive software.
Very inexpensive, under a thousand dollars to buy a license for some of the software. What that software does is it looks at the images that were taken by these scanners. And it goes ahead and tallies votes. If we use two or three different software packages, they should pretty much agree. Our error rate should be less than one in a hundred thousand or maybe even a million. Should be pretty darn low. Then we hand tabulate a few of these just to double-check, make sure everything is all right. We now have hard counts.
People add up the counts and as always, you have election observers from the two major parties and the minor parties they're watching this whole process.
I am for absolute transparency here. I think all of those images of the votes should also be made available to anyone who wants to download them. This is the age of the internet. Why are we not making the images of the votes available for anyone who wants to look at them? Private individuals can tally the votes and come up with what should have happened, what the count should be.
You expect a little bit of variance, but absolute transparency. People add up those votes. It's all audited. There are cameras running, webcams 24 seven watching the voting machines. Watching the election workers. Streaming to anyone who cares to look. Now we have absolute transparency. Now we can believe the vote.
That I think is the only way we can handle this.
We're going to run through some checklists here about what gamers should be doing. If you're giving a video game or one of these consoles to maybe some of your kids. I don't dunno. Maybe your husband, maybe they are kids. We're all kids. What should they be looking for this year?
We are talking about this massive hack we've been talking about, and we're going to get into some other stuff right now. I wanted to mention one more thing. When we were just talking about this major hack may have been Russia, maybe China. Sometimes it's really hard to tell who it is. If these are good hackers and these are by the way were very good hackers.
SolarWinds I just can't hold them a hundred percent responsible for this hack because part of the problem was people not reading directions, not doing just the very basic practices that are established in the industry for trying to keep things safe.
So keep that in mind as well. But it is a huge problem. It's something we all have to pay a little bit of attention to.
I had a great question this week when I was on the radio, I was asked, Hey, please tell me that there are people in our government who are trying to do the same type of thing to other governments.
And you might've heard about what is it? I would call a person hack, right? This is what is called in the industry a honeypot. You probably heard about US Representative Eric Swalwell. He is a California politician, which makes a lot of sense. He has been in office since 2013 and he is also on a very. Interesting committee.
When we are talking about Representative Swalwell, his committee assignment includes him being on the Select Committee on Intelligence. Okay. Ranking member of its central intelligence agency subcommittee. He also retained his seat on the United States House Committee on science space and technology according to Wikipedia.
This is very scary because he fell for the oldest trick in the book. It also tells us just the links China will go to in order to hack our people, our country. Don't worry, we're going to tie all of this into our hackers. Okay.
He, as well as another politician from California. Yes indeed sitting us Senator she had a driver, I think it was for about 20 years who was a Chinese spy.
Eric Swalwell had this girlfriend and apparently, this happened when he was just a mayor before he had moved up to the house. Then, of course, moved into the intelligence committee. A lady who became his girlfriend was doing everything you might expect of a honeypot, a Chinese lady who was trying to get information out of him. I don't know what information he got she got out of him. He had a lot of information.
Now. If this were to happen to a Republican, of course, just by default, the morals of a Republican would be well. I really messed up. I'm sorry. I resign. At least resign from the intelligence committee, but I resign from Congress. That has happened before. Much different response. It's just amazing to watch from a Democrat and Republican.
Nancy Pelosi should have removed him from his very sensitive government positions. This guy has demonstrated that he can't keep his well, you know what I mean, and not reliable when it comes to secrets. Why hasn't the FBI said, I don't care what you say, Ms. Pelosi, we want this Congressman removed?
The big question is how did we find out about this? What ended up happening that brought us to the point where we realized that Eric Swalwell was a major security risk and was on the select intelligence committee? On oversight committees. Okay. It's scary, isn't it?
This ties into this whole hacking agenda. It looks like we might have been hacking, as well. I'd be shocked if we weren't. We have teams, red teams, in every branch of government, basically, that hack. That's what they do. They're hacking in order to see what weaknesses we have. But this has been barely reported at all.
This also happened last week. A major leak of official records from the Chinese communist party. Many of these Chinese communist party higher-ups are living and working in other countries, including the United States, Australia, United Kingdom of course, and this list that's been uncovered has about 2 million members of the Chinese communist party.
Now, remember these people have sworn an oath to do everything they can to protect and build up the communist party. Okay. This database lists names, party positions, dates of birth, national identification numbers, ethnicity, telephone numbers of these members.
Now. Australia Sky News on Sunday reported that the database quote "lifts the lid" on how the party operates under president and chairman Xi Jinping. The leak shows that the party branches are embedded in some of the world's biggest companies and even inside government agencies. Communist party branches have been set up inside Western companies, allowing the infiltration of those companies by CCP members who if called on are answerable directly to the communist party. To the chairman, the president himself.
So apparently along with the personal identifying details of almost 2 million communist party members, there are also details of 79,000 communist party branches. Many of them inside companies. Now there was some analysis done of this member, we've only had it for what about a week now, but the analysis has been done so far has been interesting, cause that's revealed that both Pfizer and AstraZeneca, both companies who have vaccines for this COVID virus both of these companies together employed 123 party loyalists.
There were more than 600 party members across 19 branches working at British banks, HSBC and standard chartered.
In 2016, in addition, the Daily Mail's reporting that firms with the defense industry interests, like Airbus, Boeing, and Rolls Royce employed hundreds of party members.
Now, when I found interesting is the response by the US media and the response by some of these companies. It's been reported that some of these companies, when they were alerted to the Chinese party membership of some of their people said "we're not interested in the political parties that our employees belong to."
Which is just shocking. We're not talking about basic parties here. We're talking about what effectively is an enemy of the United States and frankly, we're also looking at this hack as a declaration of war by Russia, by China.
China's done this before, too. In fact, we think they were behind another major hack you've heard of just a few years ago.
The PS five and Xbox series X apparently are almost impossible to get. Best Buy just can't get restock. But assuming you got one, what are some of the tips that you need to know? If you are playing games or your kids or grandkids are.
Video games, I've never gotten into them, but it's probably my generation. Back when I was a teenager, we had these text-based games that we would play sometimes. You're sitting in there on a teletype and you're typing into this computer over 110 bod modem. Oh, my gosh.
It was fun, so you were in a twisty maze of tunnels? I can't remember the exact wording and then you'd go left or right. And I never spent a whole lot of time on those things. Because I basically considered it a waste of time. I've played like Mario cart a couple of times when we got it for the kids and that's probably the extent of it. I've played with some of these video games that Apple has released now as part of their arcade product. I am shocked at how good they are. How good the. Resolution is. And the movement of the phone itself can be read by the game. Your phone is your controller. So if you play games on these video devices or on a PC of some sort or even a Mac. You're not too worried about availability because the software is easy, right? It doesn't cost much to duplicate that software. Probably doesn't even cost a penny, nowadays for the guys to download the game to someone. Of course, there are other charges and stuff involved, but it's just so easy to do.
So we're going to have a lot of them this year. Many of the people who are playing these games are the younger millennial generation, the Z generation, and both of them really have issues when it comes to security.
I mentioned this before in talking with my youngest son, about two weeks ago, about security. He just didn't seem to care. Now, we had given him a really good firewall router and a wifi system built into it. All kinds of processing that was going on. It was a Cisco device. Cisco firewall. It was analyzing everything coming into his network, everything going out from his network. It does a very good job of it. It had a limit of, I think, it was 250 megabits worth of data flowing through it. He said megabytes, and I'd have to look at the specs on it. Actually, I do think it's two hundred and 50 megabits and that particular device was great.
You're cruising the web. You have software of a machine gets infected, trying to get out. It'll shut it down just as all of this. His roommate, who calls himself a gamer, didn't like that at all. So he ordered a gigabit network coming in. It's a gigabit over RF cable modem, which is crazy. Cause you're not going to get it and we had previously explained, Hey, listen. Your biggest problem is going to be latency turnaround. It's not going to be the bandwidth. We showed him these statistics that our router had gathered that he never used more than 10 megabits of the worth of bandwidth, which is, pretty normal.
I've read some studies on it and 10 megabits, 20 megabits. That's the max that is used by these video games. He knew better, cause he's in his twenties, and he's a professional gamer, almost. Not that he makes money from it, but he's a professional gamer and he has been talking in the gaming community.
So rule number one is they don't need as much bandwidth as they think they need. What they need is a, basically a jitter-free line so that they can talk to their friends without any problems while they're playing the games. They need a very quick turnaround, so the round trip time needs to be fast.
I brought up with my son, Hey, listen. You realize that he went out and upgraded the line and then ripped out, while you were gone, the firewall. He put in a better one than handles a gigabit and of course, yeah, no better. The wifi that he has in the house that his friend purchased as his roommate, does not provide gigabit over the Wi-FI. It just doesn't happen. It can't happen on any of this consumer stuff when you get right down to it and you look at it hard, right?
Many companies are lying to us. They publish these specs. They give all of this data and it is so misleading. I said, this is a problem now because you have security at the bottom of the pile, when it comes to your network now. Anything that gets onto his machine is going to get onto yours. The firewall was actually a zero-trust basis and would not allow his friend's gaming computer to access his computer or anything else on the network that it wasn't explicitly allowed to access. And you do you know what he told me? He said he doesn't care.
Now. I don't know. So if this is your dad and you've been doing internet cybersecurity for 30 years, and you're just getting carried away type thing that you get from an under 30 five-year-old son.
I've got kids that are actually that age too. There certainly is a difference, a major difference. I don't know what it is, but the stats that I've seen in the studies I've read are showing that these younger millennials and generation Z, which this of our kids is right on that cusp, don't care about cybersecurity. Part of the reason is that they just have given up. Now, I've been fighting it for over 30 years. I haven't given up yet, but they have, it's just a fact of life.
Just like you have to be on social media and you have to post these pictures of your wonderful life. It's just crazy.
Here are seven tips and I got these from dark reading, a great website, but obviously, I'm going to comment on them a much different way than Dark Reading's approach to it.
But I really liked these points.
Number one, we've got to make sure our kids and ourselves understand that personal information needs to be kept personal. Now, I know every one of us in this country has had our data stolen. It's guaranteed. It hasn't all been stolen and it's from a snapshot in time.
For instance, the Equifax hack. Yes, indeed. That's pretty much everybody in this country, Canada, much of Europe's personal information. Our salaries, our home addresses, our social security numbers. Everything was stolen, but that's years ago. By the way, that was probably done by the Chinese communist party. Remember that they're socialists. We talked about this last week. They steal stuff. That's what they do because they just can't compete. They don't like competition. They want to sit on their hands for the most part. Now, China's done some interesting things. With trying to combine the ability to have some free trade with the government-controlled economy, right?
They're not just like we are. Not capitalists, they are not communist there. There's never, ever even with the Soviet Union and what happened in Venezuela and Cuba, they have never actually achieved pure communism.
We don't have pure capitalism here either. Don't let them share personal information, make sure they realize that every little bit of information they share, they may be sharing with a hacker. Someone that's going to break in. We had break-ins in our neighborhood. This was probably about five years ago. A bunch of break-ins bunch of stuff stolen. Our house at that time was never broken into. It turned out that it was a kid from the neighborhood whose family had moved out and he knew things about people in the neighborhood and when they worked and when they were taking vacations. So he came back in and he started stealing from the houses, he'd break into them and steal stuff. In some cases, apparently, kids had given him codes to be able to enter houses. It's amazing.
It reminds us again of another, a best practice. That we should be exercised in business and you need to exercise in your home as well. That is when someone leaves a job. What do you do? You shut down their accounts, do it all automatically. That's the way it should work. You archived their data so they can't get back in. Now we've seen instances where network people who had been doing network work at a business left and stole just tons of things, shut down networks, change passwords because that hadn't happened.
And in this case, It's a good idea to change the code on your door lock pretty frequently. Keep track of who has what code, right? Doesn't that make sense to you? Then on top of that, with these fancier new ones where you can use the Bluetooth, the cell phone To program it.
So you just bring the phone close to the door and it automatically unlocks, it gets more complicated. It's easy to set up, but we've got to make sure we erase them.
So number one, don't share personal information. The next one, obvious as heck. We talk about it all the time but take care of your home network. Don't do what my son did and put in a cheap router. My son's roommate did make sure it's secured using multi-factor authentication. Now there are some ways around some of this, so that's why I recommend you do not use texting for multi-factor authentication. Use something like DUO or 1password or Last Pass or Google Authenticator. It's really going to help.
Stay away from chats. Now, this is difficult because much of the social stuff that goes on with gaming is over chats that are built into these games. So just be careful when they're in chats because it is used by these honeypots and others to get personal information. Kids don't realize, Hey, listen, dad is a high up in this company and I probably shouldn't be talking about that because honeypot to go after our kids, to get at us.
Avoid third party stores, apps, turn off Universal Plug And Play. (UPNP) If you still have it on your network and beware of scams when playing online. So some good tips for the kids.
This latest declaration of war as it's been called may be bad enough for government agencies and bigger companies, and 22,000 managed services providers. But man ransomware.
Then follow up to our last hour, DNI, the Director of National Intelligence Ratcliffe was supposed to have come out with a report as of yesterday about the elections and about foreign interference. Because of disagreement within the National Intelligence Community, it did not get released, at least not yet. It should be out fairly soon.
The big talk and the disagreement between various people who are in the organization, one of those jobs for life things, right? The deep state as President Trump has called it. Is that how much involvement did China really have? How much involvement did Russia have? I strongly suspect. Russia had a lot of involvement here in hacking. In fact, even our voting machines, as we talked about in the last hour because of the SolarWinds hack. How about China? They're saying it looks like it could be a major influence and have had a big impact on the election, in a number of ways, but we're not going to get into that right now.
Those big hacks have been very successful against larger companies all, but one, of the Fortune 500 apparently was affected and some 22,000 managed services providers countrywide use it according to SolarWinds, about 18,000 businesses. Were using the affected or infected, depending on how you want to look at this, but using the affected software. That's a real big deal, frankly. How about you and me? What does it mean to us as business people, as home users, et cetera? I want you guys to understand this a little better, so I'm going to explain it and I appreciate all the comments I've had about how much you guys appreciate me doing a little deeper dive into this far deeper than most anyone else can. You get these guys on the radio that just talk about absolute fluff in technology. Mainly because they don't know any better. I've just been doing this for too long.
One of these commentators, a lady who's had her own radio show for years. Just amuses me to know she was a marketer for years before she got on the radio. Maybe that's why she's a lot more successful on the radio than I am, but I'm much more successful in tech than she is.
You as a regular end-user, you're probably not badly affected by this hack, this SolarWinds hack, and all of the subsequent hacks that happened. It's probably not a huge deal for you because your home computers were not running this Orion software from SolarWinds, and you're probably not using any of the other software that's out there. I'm continually reminding everybody and I'm covering this as well in my Windows Hardening Course, which's coming up soon.
When I was recording this week, it made me think about this a little bit, that you and I, as home users know better than to buy things like Norton and try and use them or some of these other antivirus products, because in this day and age with Windows 10, just not considering anything else in the network, but just the computer itself, you are probably best off using Windows Defender and making sure your computer stays up to date.
You also know if you want to spend a couple of bucks. There is some other good stuff out there that's going to help and one of those is Malwarebytes. In fact, I'm going to try and include a link to some of them Malwarebytes stuff this week. Malwarebytes is another good little piece of software to have, and how much I like Umbrella.
You'll find that online, of course, umbrella.com and you can get the free version. You can get the paid version. If you are a business, you need to talk to a reseller, like me, and have them set you up with the business version. Those three things are going to go a very long way.
Obviously, you need to lock down Windows and harden it. That's why we're doing this whole little course coming up here soon. If you are a business now you might be in some trouble. I have been saying now for three, four years, as well as the FBI has been saying this and I covered it in some of the FBI InfraGard webinars that I hosted. If you're an MSP, if you're a managed services provider or break-fix shop, in other words, if you take care of other peoples and more particularly businesses computers, you are a major target. You have to pull up your socks.
Now, the Department of Defense with this cybersecurity maturity thing that they've come out with CMMC. They have made it very obvious because he specifically says it that if you are a managed services provider, you have to meet the requirements that the Department of Defense is putting on to their customers or their suppliers. I think that makes a lot of sense.
If you are a managed services provider, you probably have pretty much, if not completely full access to your customer's computers and networks. So if you have a customer, that deals with the Portsmouth Naval shipyard, for instance, that is a Federal Government DOD facility and if those DOD contractors that are out there on base have to meet certain requirements for cybersecurity, you would expect that you as a managed services provider have to meet those same requirements.
The answer is yes, absolutely you do. We're talking about some serious policies and procedures, some serious hardware to help make sure everything's working right. Some serious monitoring of the hardware and the software and the alerts. It's a lot of work.
We've talked about it before. Basically, if you have less than 200 people, you probably can't afford it. There is no easy button when it comes to the NIST 800-171 or the CMMC standards. So you turn to one organization, that's a managed service security services provider and you expect that they are going to be able to take care of you. I don't think that's unreasonable.
What should you be doing? How can you have these guys take care of you? The answer is almost none of them can. No, they'll say so. They'll put a nice little logo up on their site and, Oh my gosh, aren't we just, Mr. Wonderful, Mrs. Wonderful. In reality, many of these companies know the buzz words. They know the key phrases, but they are not up to snuff when it comes to doing security or including their own security.
So they'll go to other vendors. They go to distributors, try and get some help. This goes back to how I started out here, talking about these tech shows, where the host really knows very little about the actual technology. You want someone that understands. If you want a good meal, you're going to go to one of these celebrity chefs. They know the business and they know the business from the start to the end. You're not going to go to a fry cook for Wendy's, in order to get a great meal. Now, you might get a decent meal.
So the Department of Defense is now pushing all of these standards down to the MSSP's. This is why we are actually a Master Managed Security Services provider. We provide security services through and for these Managed Services Providers, I think that just makes a whole lot of sense, but these companies have access to other businesses.
Computer networks have been under attack forever and this now proves my point I've been trying to make for years. Which is the SolarWinds attack was directed at 22,000 companies that call themselves Managed Services Providers. Why? Because that's where the money is, that's where the access, the keys to the kingdom are for so many companies and so many government agencies are these managed services provider.
Now, this is difficult because I promise this week to get something out about selecting a managed services provider. I have something, if you want a copy of it, make sure you email me [email protected] because I got a little checklist that I put together. It's one of these generic ones.
I'm not trying to say, Hey, you got to hire me. You know how that goes? Where they put out an RFP, requests for proposal and there's only one company in the whole world that could possibly meet all of those specific requirements. Been in business for 30.6 years, is located within two miles of us, et cetera, et cetera. No, that's not what this is. This is a real nice generic list that you can use to help evaluate anyone out there that is going to be helping you out with your security.
So whoever it was, the Russians, most likely knew what they were doing. So they got not only the 22,000 managed services providers that got them in their site, but they also got all of these government agencies, and all, but one, of the Fortune 500 is right there in their sites.
They are not stupid. This was a very difficult hack and they pulled it off. They would have been continuing to pull it off, frankly, for a very long time.
So if you outsource your IT, which you have to do, because that's the only easy way to get some real talent part-time, which is what most small businesses need. They don't need necessarily full-time on their staff, but they need full-time attention. and you got to pay attention.
Drop me an email. [email protected]. I'll be sure to get it back to you.
Ransomware is no longer just the domain of basic hackers or even NationStates. Like what we saw with this massive SolarWinds hacks and targeting managed services provider. It is now changing ransomware in a big way.
What is behind the headlines and really helping people to try and understand it a little bit better? I've always been told I'm good at and something I do enjoy doing. I guess that's a good thing, right? For you guys, as well as for me.
Ransomware has been evolving over the years. We've talked about it here on the show before, but the idea behind ransomware that those people who aren't familiar with has changed from really one idea, now, to two core ideas.
So the first idea is the one you may be familiar with which is they get some malware on your computer. However, it might be, they might be sending an email phishing email, trying to trick you into clicking on something and then installing some software. It might be via a worm or a remote hack, right? It could be a little virus that gets in, but the idea behind ransomware is that it gets on your machine and then it phones home.
Some of this stuff is very fancy. You can go onto the dark web and you can find ransomware for cheap money. You can even buy ransomware as a service. So what you do is you send out the ransomware to email addresses, right? The ones you've bought or stolen or harvested from the internet. Another reason, by the way, you should never have your email addresses up on a website where it's easy for software to grab.
Ransomware as a service does everything. Some of these companies, my gosh, you pay them either a fixed fee or a fixed fee plus a percentage of your take and they'll run the whole gamut for you. They'll provide tech support for people who get ransomware.
Here's what will happen. That person clicked on that email. They installed that software that got the virus. There was a drive-by worm, whatever it might be and in the background now starts encrypting all of the major files. It looks for things like word docs and Excel spreadsheets, et cetera and it encrypts them all. It calls home first, nowadays, for instructions and tells the bad guys, "Hey, here's the key I'm using to do the encryption." It gets really fancy today. We'll get into that one in a minute.
Then it pops up on your screen. "Hey, all your files are encrypted. You got ransomware to contact us." It gives you an email address or something else to contact them with. It has a big takeaway. It says, "Hey, you've only got so many hours to contact us, or the ransom goes up and goes up" To try and get you to move, and then you will pay via Bitcoin. Almost always.
Which, by the way, has been driving up the value of Bitcoin. Because people have been buying it in order to pay ransoms. So that's what we're used to.
The newer ransomware does things a little bit differently. So it gets onto your machine in much the same way. But the next step that it takes once it's on your machine, is it starts looking at files and finding files and usually it'll wait because what it's doing at that point now is it's pumping, poking a hole out of your network, back to the main controller for the ransomware guys.
So it gets on your machine. It grabs the names of some of the files. It then connects back to home. It calls home. Once it's called home, it sends the names of your files and then it sits there. Now the ransomware guys are pretty busy actually. Cause so many people to fall for this stuff and haven't done what they needed to do to keep the ransomware out. The ransomware guys, usually within a few days, will then remote control your computer and they'll poke around and they'll find, Oh wow, here's client lists. Oh my gosh, personal information. I can sell that for as much as $20 a record. That's a lot of money, right? Especially for someone in Eastern Europe, which is where most of these things come from. Then what will happen is they will look around some more and they'll start trying to spread laterally, East, West, inside your network. So now they're inside your network and they say, Oh my gosh, there's 20, 30, 40, 50 machines in here. It'll try and infect these other machines using the same or different techniques where it tries to spread like a worm, or a little virus, going around inside your network. And then it says, Oh my gosh, this is a medical office. Oh my gosh, this is a Department of Defense manufacturer. It's. Oh, wow. Wow.
When they got all of these records, all of these data. They might find things like also bank account numbers and transfer numbers, ACH accounts. All of this stuff. That's what it's looking for. Now. It's doing all of this in the background. You don't realize what's happening. Your computers just work in a way at this point that is probably not even slow. Then the next step that they take is they decide, okay, what are we going to do? You know what? I think that we can extort money from this person if we pull these files. So they'll grab a bunch of files. They don't remove them from your computer. They just make a copy of them from the computer, from your file server or wherever they are in your network. It may be all of your files and may just be a few of them. Once they're done with that, they will either encrypt everything and hold for normal ransom or not.
If they hold you for normal ransom, the same normal stuff applies a little red screen comes up. Oh, you've got ransomware. We can help you fix it. Contact us, give us a copy of this number. Take a picture of the screen and then off you go buying Bitcoin and paying them off.
Remembering because you listened to this show that the Department of Justice may come after you if you pay the ransom for supporting terrorists and terrorist demands, but that's a separate issue.
Now you get your key to decrypt and according to the FBI, about half of the time, you'll get all your files back.
Okay. So far that all sounds pretty normal, but the next part is what they've been doing more recently, which is. Okay guys, thanks for paying that, by the way. We are a different company. We're a different group of bad guys, and we have copies of some of your files and unless you pay us. We're going to release those files out on the internet, the dark web, or maybe the regular web put them up in a paste bin or wherever they might want to put them.
Pastebin is a website that hosts these files, zip files, and other things with all kinds of information in it. That is obviously sensitive because why would you pay extortion otherwise? So that's what they do.
Secondarily, they try and get you to pay them to not release your data. Okay. So in many cases, you have paid twice, you paid once to decrypt the data you paid a second time in order to gain access to that data. Or excuse me, just stop other people from gaining access to your data.
Does that make sense to you guys? That's what they've been doing.
Now we've got a new scale that these ransomware guys have. They are really catching up quickly with the Nation States that we've been talking about earlier. These are called advanced persistent threat groups. Just the regular gangs now have stepped it up.
You can get this show and many others via podcast. Just go to my website, Craig peterson.com.
Ransomware has gone from being opportunistic over to the other side, where they may spend months or even years on a network and a business and a government. So we're going to talk about the East-West spread of ransomware.
We've had a major hack this week that has affected federal government agencies, all but one of the Fortune 500 agencies. It's affected 22,000 of these managed services providers potentially at least 18,000 organizations are confirmed with being affected by this.
We're thinking it's Russia, but who knows? You cannot really tell. In the last segment, we went through the major changes in ransomware over the years. As I mentioned, the intro, opportunism, that's been the name of the game. They just send out a lot of feelers. They do a lot of scanning and they find somebody that is just vulnerable. That's the bottom line. They want vulnerable businesses. Once they find a vulnerable business, they move to the next step. That next step in the past has been just encrypting everything so that you and I really have no way to respond to it.
It has gotten fancier. These advanced persistent threats are what the name implies. They're an advanced attack method. They're persistent. In other words, once they're on a network or on a machine, they stay there and there is a threat because of these ransomware groups, such as DAPL, painter, and revival. Have gotten on to the networks have been very targeted at what networks are trying to get onto.
They want networks of businesses and these cyber-criminal hackers find vulnerabilities on the networks as they move around inside the network. That's what East to West is moving around inside finding other vulnerabilities. They often spend months laying the groundwork to compromise the systems with ransomware before finally unleashing the attack and encrypting the network.
They've found that phase two, which was let's get on the network. Let's find the valuable files. Let's hold them for ransom. That just takes a long time. If they've stolen people's credentials, if they've stolen, social security, numbers, bank, account numbers, credit card numbers, et cetera. It takes a long time to sell them and get their money back. So they really aren't trying and to speed things up, frankly, spending months on a network isn't unheard of and it's become more and more common.
These threat groups will hide for even years before they are detected, if they're detected at all, their goal is surveillance of the network. Finding all of the weaknesses and then stealing sensitive data, rather than just making money right off the bat with ransomware. These groups are making millions of dollars per attack. It's become so effective that many businesses if you look at their filings with the security and exchange commissions, are buying Bitcoin in preparation for a ransom. Isn't that something, in other words, they expect a ransom to happen. So they're just buying Bitcoin. So they have it to pay if it happens. Okay.
So the there's been this transition from being opportunistic. Into the types of threats, we've seen from NationStates here for years. It is much more profitable for these bad guys to completely cover an organization with ransomware. Now, remember that's not necessarily the primary target, but it's also a really good cover for them because now you're trying to deal with the ransomware threat.
So what do you do if you have ransomware? The best thing is don't get it in the first place. We've gone over that quite a few times here on the show, but the basics: Make sure you're running windows defender, Make sure that you are using Umbrella, so they have a hard time calling home.
Make sure you go on to the next stage as well. Maybe add Malwarebytes.
You also have to protect that network. I am a Cisco reseller and we have techs that are fire jumper certified. We know what happens. We can come in afterward and do clean up. This, unfortunately, is how we pick up most of our customers. Or we can go in beforehand and help to protect you because you want to stop them from getting in.
The regular email filters just aren't enough. So we run it through just all kinds of tasks. We had an email from one of our clients here just about a week ago saying, Oh, I got this email. It seems to be fishing. How did that get through? Yeah, we stopped a thousand of those. It's types of emails and one snuck through. Nothing's perfect.Â
We've got to remember that as well. So if it does get in someone bringing in a thumb drive from home or using the VPN into the office, that hasn't been properly protected. Most of them aren't, by the way, everybody that gets in, what do you do then? Hopefully, you have a good backup. You're probably going to have to wipe all of your machines. Depending on the threat involved, that might be pretty difficult because they can get into different parts of the machine that you just can't get them out of.
The next evolution of ransomware is that these groups gain more experience with these successful attacks. That time where they're taking between that initial compromise could be months or even years, that amount of time will become much shorter. Meaning there's less time to potentially detect this suspicious activity before it's too late.
We know from what Talos has been reporting, as well as others, that the compromise timeframe where they poke around inside your network is nowadays somewhere between three and five days. So you have a few days to catch them in your network.
Now, if you don't notice them, well it's probably a little bit too late, but again, hopefully, have good backups.
Having good backups means, by the way, the three, two, one principle on backups. It means that you need to be testing them as well. Make sure you can restore your business from backup and you might even want to do what we've done for our bigger clients, a one a multi-national where we had backup hardware there at their facilities. So if something were to happen, let's say that there was a fire in the front part of their building, where their main data center was, we could transfer all operations to the back part of the building, where we had our own servers sitting there that could take over at an instant notice. Then we also have servers in the cloud that have all of their data. In an attempt to keep them up to date in almost real-time so they can stay in business. That's what you need to do. If you're going to survive ransomware.
Now there are also normal things. Make sure you're applying security patches to everything. Make sure you are using multiple network segments that can not communicate with each other. So for instance, your building control systems should be on a completely different network than your office workers' computers, and those computers should be on a completely different network than this server. They should be going through a firewall to get to the server and an internal one.
You should have multiple layers of firewalls. In this company, I'm thinking of, this multi-national, we have seven layers of firewalls that you have to pass through in some cases, depending on where you are. That helps keep them out. Okay.
The security patches you got to do, you've got to patch all of your internet of things devices.
You cannot let people bring personal devices in. It just goes on and on.
These are the types of controls, the best practices that we need to have. All right.
You've probably heard of contact-tracing apps. Who knows what's going to happen with that virus over the next year or two years or what viruses might be coming after that. We're going to talk about the safety of the apps themselves.
One of the big things that have been pushed in many parts of the world is contact tracing. Some states require us if we go to a restaurant to give our name, right? To give our phone number for contact. If there was someone at the restaurant who calls up the restaurant and says, "yeah, Hey, I came down with COVID-19 symptoms", then the restaurant's supposed to call up everybody who was there at the restaurant. Now, how effective is that? I really don't know.
It's people, I would not want to give my information to people. I think we should just assume that we're living in a world with viruses and we should take precautions. If I was in the groups, one of the groups that were very susceptible to the virus. I think I would take a lot more precautions and frankly, isn't that the way it should be. If you are susceptible, then maybe you should lockdown. Not shut down - locked down, everybody else.
We've never done anything quite this way before. You find typhoid Mary, and she gets quarantined, not everybody else. That's always the way we've done it. And it just makes a lot of sense.
One of the proposals that have come out that they're saying, Hey, this is going to help us in the today and into the future, are these contact tracing apps? I'm looking at an article right now that was over on dark reading saying that they tested nearly 100 contact tracing apps. Now, these are apps that are on your smartphone that might use Bluetooth for proximity detection to another phone. They might use some other technologies. I've seen some that actually start to squeal and make noise. If you get close to somebody else that's running one of these apps. So that, okay, I'm within the one-meter limit.
Of the nearly a hundred they tested, they found 40% had significant security issues. Either using GPS locations or Bluetooth proximity detection in order to determine your potential exposure to somebody else. Now, these are mostly apps that are not using this new Apple and Google exposure notifications protocol. I found that kind of interesting Apple has been very good at trying to preserve our privacy. In fact, there's a huge fight already going on between Facebook and Apple. If you have the latest version of iOS, you can go into the app store, look at an app, and I would challenge you to do that.
If you've got your phone right now, iOS phone, and you're up to date, open up the app store search for the Facebook app. Then once you're on the Facebook app page, scroll down a little bit and it'll have a section in there on security that goes on for pages and pages. Yeah. More button. Okay. Read more of what it is that Facebook is doing with your data. So Facebook's pretty upset about that saying this is going to hurt small businesses who need to micro-target, and they're not wrong about that. Apple is saying, Hey, we're trying to preserve the privacy and security of people who use Apple equipment, which I absolutely do agree with.
Well, a company known as Guardsquare, which is a mobile security firm analyzed 75 contact tracing apps, 52 Android apps, and 43 iOS apps and found that 40% did not use the Apple Google protocol that Apple and Google worked together on this to come out with.
The bottom line here, what is it is going to be safe? How can we protect user privacy? This protocol is designed to protect it. Most of those applications used GPS system data too. Figure out your location of other people and linked it to the phone numbers or in some cases, passport identifiers.
Now, GPS can be fairly accurate, but if you want it really accurate, you have to add to some other data that is transmitted by all major airports, because there's a variance. The density of the atmosphere, which can vary depending on whether it's raining, how much water is in the air, snow, and other things. They transmit variances that can be used in conjunction with GPS to get an actual, accurate location. Once you get into a building or have you ever been inside a big city and found all of a sudden your GPS data is just terrible. Your automatic map stuff just isn't working, right? Those big buildings are blocking the signals from some of the satellites that you are depending on. That's what they have found with these apps. Many of them are trying to use GPS. They are gathering that and keeping the information and selling the information, which is a bad thing. It's not terribly accurate. Okay.
So first off don't use these apps at all. If you're in one of the risk groups, You are also now relying on other people to have the same app or the same protocol being used in order for your app to do any good at all, because they are combining the data from everyone that's self-reporting in an area to figure out if there's potential exposure. If they're not self-reporting, if they don't have that same app, you're not going to get any information.
So in June, Guardsquare looked at 17 different Android apps and found only one that fully encrypted and obfuscated data.
They have done a survey here in the last month and it has gotten a little bit better, but of those 95 apps, they found 32 Android apps and 25 iOS apps actually use the official API of the exposure notification system created by Apple and Google.
So bottom line, don't use these contract contact tracing apps. They're not useful. They're not useful, if not enough, people are using them. Then to top it off, they are not encrypting the data and anonymizing the data.
FireEye, man, this is the company that found out about that SolarWinds breach that we spent the first hour talking about today. FireEye is a security research company. Part of what you should be doing and is required to do is to have red team blue team exercises. What that means is you have people who are attacking your network, and then you have people who are defending the network. So you have a team of people whose goal is to break in and another team whose goal is to defend. You might remember. I talked to him about a company that hadn't been hired to do this out. Where was it? Missouri or something. They tried to break into the courthouse that they had been hired to test. Then there was a dispute over turf and everything else, and these guys went to jail and they had to go to court. The whole thing was quite the mass. Okay.
That's a red team- blue team type strategy. We don't do physical incursions ourselves. It's just a little bit too risky for us. It takes more people more time, but we do the type of Computer incursions and FireEye has red team tools that are used to break in. That is a problem because FireEye was compromised as part of this SolarWinds hack. Their tools were stolen. These are the FireEye red team tools that are used by their security teams to break into businesses. This is the gift that's going to keep on giving.
You might remember the NSA was broken into and their red team tools were stolen. The tools they use to monitor foreign governments and officials hack into computers. Well, this is a real problem. Okay. Many of these red team tools that were stolen from FireEye have already been released to the community and there's even an open-source virtual machine called commandoVM. Just absolutely unreal.
Apparently, none of the red team tools that were stolen by the attacker contain zero-day exploits and they apply well-known methods to break in. In other words, if you had been patching your systems, taking care of it, unlike what happened with so many companies out there. Right?
Home Depot, what happened to them? The TJX community of businesses, Equifax on and on Who did not keep up with best practices or even patches you might be okay. But if you are more of a security guy, like I am they have released hundreds of countermeasures that you can use, including things like Open IOC, Yara, Snort, ClamAV, all tools that we use here as well. There's a whole FireEye git hub repository. Git Hub is where people can distribute software and things. It's usually used by the open-source community and they've got directions and what you can do and everything else. So I think FireEye has responded extremely well to this. It's going to hurt their business. No doubt. It's going to hurt a lot of other businesses. No doubt, but I really like what they have done and you can look it all up online.
If you want a little more information. Just email me [email protected] and it might be time for me to put together with other, a little course, Oh, maybe a big course on how to use these tools to test your own security as well as to defend your security.
That's it for today. Thanks for joining me. Make sure you join me online as well. craigpeterson.com.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about the Lockdown and the effects it is having on our kids and the amount of time they are spending online. I shared some tips about staying safe online, for kids, yourself, and our senior parents. Here we go with Chris.
These and more tech tips, news, and updates visit.
- CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Bad guys know this as well. And they've been taking this as an opportunity to get our kids to do things that, as parents, we really don't want them to do.
Hello everybody, Craig Peterson here. I was on this morning on New Hampshire today. I didn't realize it. There are actually got five stations or six stations in the network. It's pretty good.
Chris Ryan. He is a new host here. I don't know that he's permanent. I'm not sure they've found one permanent, yet. He's been doing radio for a lot of years. Pretty good guy. I've been listening to him this morning.
We had a quick chat about what should be going on with our kids and what are they doing online?
Many of us are looking to get them some of these online games and gaming. What should you do to really protect yourself. What's the one thing that you could do that's going to make all of the difference from a security standpoint, whether you are a home user or a business user.
So here we go with Mr. Ryan.
Chris Ryan: [00:01:02] Joined right now on the program by Craig Peterson joins us to discuss what's taking place in regards to technology, as well as, gaming here on the program today. Your kids, boys, and girls, or anything like mine, the appropriate screen time went from one hour to 12 hours per day during the course of the pandemic. As Craig joins us.
Craig, how are you?
Craig Peterson: [00:01:23] Hey, good morning. There's a whole lot of screen time going on. A lot of bandwidth getting eaten up.
Chris Ryan: [00:01:28] There is. It's been both a blessing and a curse I think for most parents. It's been great that my 10 year has been able to talk with his friends and maintain levels of communication as they have not been able to partake in activities. But most parents have very little idea as to what their kids are doing. They're doing such at a much younger age with kids have tablets. They have the ability to communicate via the Xbox or PlayStation, in addition, to using messenger or other items as well. Parents or grandparents are mostly just in the dark and they don't know what to do about it.
Do you embrace it? Technology is so important. Kids learning how to code and to utilize those skill sets can be extremely beneficial down the road. Many times I think of our parents or grandparents, when they don't understand something. They want to be apprehensive about it.
Craig Peterson: [00:02:19] Well, first of all here, we've got the little gift-giving season coming up. Many people are looking for these video game consoles. The bottom line is pretty much all of them are sold out already. So if you're looking to get someone one of these video game consoles to play online, you might have a very hard time getting them. Many of them are being sold at a substantial premium over even the list price.
When we're talking about these kids and going online and being younger and younger. We actually have a problem starting primarily with generation Z, which is now in their twenties and going all the way down where they just don't understand the reality of the world. Their world is very, very focused on this online world.
Talking with friends, chatting with friends while they are on playing these games and they are ready to share information. In fact, Chris, you or I, we would look at giving away our email address twice or three times, our personal private information. But studies have shown that these younger kids would give away their email address in exchange for a donut.
So, yeah, you're right. We gotta be very careful about what they're doing online and the basic tips of don't share your personal information. Make sure that your home network is relatively safe, that means to keep everything up to date. Have a good firewall. Use multi-factor authentication. This is a hard one because, man, I don't know what's going to happen to these poor kids because of the lockdown. They want to reach out. They want to chat. Bottom line, bad guys know this as well and they've been taking this as an opportunity to get our kids to do things as parents we really don't want them to do.
Chris Ryan: [00:04:14] And I think that's across the board. In some cases, I think that I trust kids more with maintaining information and not talking to individuals than I trust my dad to be in cyberspace and exposing himself.
Not exposing himself physically, but exposing his information and things of that nature to various individuals. I think that's a good point and not just for kids, but across the board, as we have moved into a virtual environment. You have individuals in many different business aspects working from home.
I think that we all have to be cognizant of making sure that our information is safe. So what in your view are some of the best ways to do so. Basically cause I think that hackers, as you mentioned, a tremendous knowledge of what's taking place. What's vulnerable and things of that nature. What can we do to protect ourselves in your view?
Craig Peterson: [00:05:04] Well, you mentioned for instance, your father. And I had an instance with my dad who was having problems with his computer and he had gone online. He did some searches and he called a phone number. It turned out it was hackers who had a website up that looked like it was Microsoft support. It wasn't. They got onto his machine with his help. He keeps all of his usernames, passwords, bank account information in a spreadsheet, which is such a no-no. That's what these guys were looking for.
My stepmother called me up almost right away and said, wait a minute, this is what your dad is doing. We had them cut the conversation. We got on his machine, remotely, and removed this malware that was grabbing all of his documents and spreadsheets and everything. It would have been absolutely horrible.
I think that's one of the biggest tips I have for people, besides all of the normal up-to-date and good firewalls is to use multi-factor authentication. Use a password manager. I recommend looking at LastPass is one of them. The other one, the one that I use, and I use for my business is called one password.
Both of those will generate passwords for you for each website. They will store the passwords, highly encrypted. So that it's almost impossible for the bad guys to get access to it. You only have to remember one password and that's the password to this little vault that has been created, and they also provide this multifactor or two-factor authentication.
So that's probably the best tip for the holidays. Do yourself a favor Last Pass and one password, both have free versions. Start putting all of your passwords into that kind of a vault. Have it generate a random password for you and you'll be much, much safer.
Chris Ryan: [00:07:01] Well, Craig, I appreciate your time. Look forward to chatting again soon.
Craig Peterson: [00:07:03] All right. Take care. Chris
Chris Ryan: [00:07:04] Craig Peterson, joining us here on Hampshire today. I am Chris Ryan. Justin McIssac joining across the great state of New Hampshire.
Craig Peterson: [00:07:12] Karen and I spend time this weekend going through some of the coursework. What we should be doing. You probably noticed some changes in the newsletter. I did not get one out. I'm so sorry on Saturday, but it's just been absolutely crazy around here.
we're trying to do some new things for the new year. We'll be starting as soon as we possibly can. Including some of these courses that we've been talking about you. Might've noticed last week in my newsletter, I talked about the new hardening courses.
We're also, by the way, this is something new. We're what's called a Master Managed Security Services Provider. What that means is we are providing security services through these break-fix shops and these managed services providers for their clients. We've been doing this now, effectively for a room six months, maybe a bit longer, and have had just amazing results. Have really helped our partners that are providing security services. we're kind of the man behind the curtain if you will. Because the cybersecurity stuff can just be very, very difficult to do.
We're going to have a newsletter for those people who are following me, and that's going to be a different one than the main one.
If you are interested in this security partner newsletter where we're going to be doing some basic training, but specifically on providing security services for businesses. If you're interested in that, let me know, just email me M [email protected] and I'll get back to you soon.
Take care, everybody, and we'll be talking again real soon.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about the Lockdown and the effects it is having on our kids and the amount of time they are spending online. I shared some tips about staying safe online, for kids, yourself, and our senior parents. Here we go with Chris.Â
These and more tech tips, news, and updates visit.
-Â CraigPeterson.com
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Bad guys know this as well. And they've been taking this as an opportunity to get our kids to do things that, as parents, we really don't want them to do.
Hello everybody, Craig Peterson here. I was on this morning on New Hampshire today. I didn't realize it. There are actually got five stations or six stations in the network. It's pretty good.
Chris Ryan. He is a new host here. I don't know that he's permanent. I'm not sure they've found one permanent, yet. He's been doing radio for a lot of years. Pretty good guy. I've been listening to him this morning.
We had a quick chat about what should be going on with our kids and what are they doing online?
Many of us are looking to get them some of these online games and gaming. What should you do to really protect yourself. What's the one thing that you could do that's going to make all of the difference from a security standpoint, whether you are a home user or a business user.
So here we go with Mr. Ryan.
Chris Ryan: [00:01:02] Joined right now on the program by Craig Peterson joins us to discuss what's taking place in regards to technology, as well as, gaming here on the program today. Your kids, boys, and girls, or anything like mine, the appropriate screen time went from one hour to 12 hours per day during the course of the pandemic. As Craig joins us.
Craig, how are you?
Craig Peterson: [00:01:23] Hey, good morning. There's a whole lot of screen time going on. A lot of bandwidth getting eaten up.
Chris Ryan: [00:01:28] There is. It's been both a blessing and a curse I think for most parents. It's been great that my 10 year has been able to talk with his friends and maintain levels of communication as they have not been able to partake in activities. But most parents have very little idea as to what their kids are doing. They're doing such at a much younger age with kids have tablets. They have the ability to communicate via the Xbox or PlayStation, in addition, to using messenger or other items as well. Parents or grandparents are mostly just in the dark and they don't know what to do about it.
Do you embrace it? Technology is so important. Kids learning how to code and to utilize those skill sets can be extremely beneficial down the road. Many times I think of our parents or grandparents, when they don't understand something. They want to be apprehensive about it.
Craig Peterson: [00:02:19] Well, first of all here, we've got the little gift-giving season coming up. Many people are looking for these video game consoles. The bottom line is pretty much all of them are sold out already. So if you're looking to get someone one of these video game consoles to play online, you might have a very hard time getting them. Many of them are being sold at a substantial premium over even the list price.
When we're talking about these kids and going online and being younger and younger. We actually have a problem starting primarily with generation Z, which is now in their twenties and going all the way down where they just don't understand the reality of the world. Their world is very, very focused on this online world.
Talking with friends, chatting with friends while they are on playing these games and they are ready to share information. In fact, Chris, you or I, we would look at giving away our email address twice or three times, our personal private information. But studies have shown that these younger kids would give away their email address in exchange for a donut.
So, yeah, you're right. We gotta be very careful about what they're doing online and the basic tips of don't share your personal information. Make sure that your home network is relatively safe, that means to keep everything up to date. Have a good firewall. Use multi-factor authentication. This is a hard one because, man, I don't know what's going to happen to these poor kids because of the lockdown. They want to reach out. They want to chat. Bottom line, bad guys know this as well and they've been taking this as an opportunity to get our kids to do things as parents we really don't want them to do.
Chris Ryan: [00:04:14] And I think that's across the board. In some cases, I think that I trust kids more with maintaining information and not talking to individuals than I trust my dad to be in cyberspace and exposing himself.
Not exposing himself physically, but exposing his information and things of that nature to various individuals. I think that's a good point and not just for kids, but across the board, as we have moved into a virtual environment. You have individuals in many different business aspects working from home.
I think that we all have to be cognizant of making sure that our information is safe. So what in your view are some of the best ways to do so. Basically cause I think that hackers, as you mentioned, a tremendous knowledge of what's taking place. What's vulnerable and things of that nature. What can we do to protect ourselves in your view?
Craig Peterson: [00:05:04] Well, you mentioned for instance, your father. And I had an instance with my dad who was having problems with his computer and he had gone online. He did some searches and he called a phone number. It turned out it was hackers who had a website up that looked like it was Microsoft support. It wasn't. They got onto his machine with his help. He keeps all of his usernames, passwords, bank account information in a spreadsheet, which is such a no-no. That's what these guys were looking for.
My stepmother called me up almost right away and said, wait a minute, this is what your dad is doing. We had them cut the conversation. We got on his machine, remotely, and removed this malware that was grabbing all of his documents and spreadsheets and everything. It would have been absolutely horrible.
I think that's one of the biggest tips I have for people, besides all of the normal up-to-date and good firewalls is to use multi-factor authentication. Use a password manager. I recommend looking at LastPass is one of them. The other one, the one that I use, and I use for my business is called one password.
Both of those will generate passwords for you for each website. They will store the passwords, highly encrypted. So that it's almost impossible for the bad guys to get access to it. You only have to remember one password and that's the password to this little vault that has been created, and they also provide this multifactor or two-factor authentication.
So that's probably the best tip for the holidays. Do yourself a favor Last Pass and one password, both have free versions. Start putting all of your passwords into that kind of a vault. Have it generate a random password for you and you'll be much, much safer.
Chris Ryan: [00:07:01] Well, Craig, I appreciate your time. Look forward to chatting again soon.
Craig Peterson: [00:07:03] All right. Take care. Chris
Chris Ryan: [00:07:04] Craig Peterson, joining us here on Hampshire today. I am Chris Ryan. Justin McIssac joining across the great state of New Hampshire.
Craig Peterson: [00:07:12] Karen and I spend time this weekend going through some of the coursework. What we should be doing. You probably noticed some changes in the newsletter. I did not get one out. I'm so sorry on Saturday, but it's just been absolutely crazy around here.
we're trying to do some new things for the new year. We'll be starting as soon as we possibly can. Including some of these courses that we've been talking about you. Might've noticed last week in my newsletter, I talked about the new hardening courses.
We're also, by the way, this is something new. We're what's called a Master Managed Security Services Provider. What that means is we are providing security services through these break-fix shops and these managed services providers for their clients. We've been doing this now, effectively for a room six months, maybe a bit longer, and have had just amazing results. Have really helped our partners that are providing security services. we're kind of the man behind the curtain if you will. Because the cybersecurity stuff can just be very, very difficult to do.
We're going to have a newsletter for those people who are following me, and that's going to be a different one than the main one.
If you are interested in this security partner newsletter where we're going to be doing some basic training, but specifically on providing security services for businesses. If you're interested in that, let me know, just email me M [email protected] and I'll get back to you soon.
Take care, everybody, and we'll be talking again real soon.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
This week I am spending a bit of time discussing H1B Visas and Facebook's war on American Workers, Extortionware, and how it is the death knell for Companies. We have a Cybersecurity Pandemic underway courtesy of the Covid-19 pandemic and More so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
---
Facebook Hires Foreign Workers Over US Workers - Breaking the Law
Security's Worst Fore? Adobe Flash Finally Killed
Business Email Comprise vs Email Account Compromise
Extortionware Gains Traction and Kmart is Hit
Alaskan Voting Servers Hacked
Local Police Live-Streaming Amazon Ring Cameras
A Cyber Security Pandemic Has Started
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Feds are saying that Facebook broke US immigration laws. Flash, finally dying. Goodbye and good riddance Adobe. We're going to talk about business email compromise versus something a little bit newer and different, EACs.
Hi everybody Craig Peterson here. No, we're not going to get crazy with talking about some of the problems we're having with email. I really want to talk a bit about this because fear only goes so far.
A great, great article this week in the Wall Street Journal. We will be getting into it in a little bit.
How we can really help our family and our business associates when it comes to security. We're always hearing about, Oh my gosh, business email compromise. It's just been terrible. It's destroying our businesses, which it is. But the problem that we've been facing because of the way we've responded is that people are much less able really to get the work done because they have fears every time they turn around.
So we'll get into that a little bit more as well. I love this thing about the Nazi Enigma cipher machine that was found in the Baltic sea. At the end of world war two, the boats, the submarines particularly were all ordered to destroy them. So they threw them overboard thinking that would probably be good enough. Of course, we already had broken their cipher, no big deal there.
Kmart here. National business got a lot smaller and it just suffered a ransomware attack from a new form of ransomware. We'll talk a little bit about that.
We've got hackers now breaking into an Alaskan voter database. Grabbing information on a hundred thousand voters. Very big deal. We'll talk about that.
We'll also be talking about police and this program in one community. We talked about something about six months ago, that was spreading a little more nationally. One community and what they're going to be doing with ring cameras and live streaming your doorbell to the police department.
Then we are going to get into the next global crisis, which is a cybersecurity pandemic. It has gotten really bad out there. a shame, frankly.
Hey, you're listening to Craig Peterson. welcome. Did you know if you have one of those smart home devices you can listen right from there? I've got my Amazon echo tied in via Bluetooth speakers that we put into the roof of the kitchen. We had a water leak. We had to replace the roof in the kitchen. So while I was in there, let's put in some good speakers and I did. I've got a little Bluetooth module that I got in fact from Amazon that hooks right up to an amplifier that drives the speakers. I have an Amazon echo there in the kitchen too. very handy. So I've got it configured to use Bluetooth so that it uses the speakers up in the roof.
it's just, it's phenomenal. I do that all of the time.
let's get into our friends here over at Facebook. I have been talking for years about this whole H1B visa problem. It's been a problem in the tech industry. Primarily now there are other types of temporary worker visas that are used in other industries. For the most part, I think in most other industries, they're not misused. But in the US, it is very misused. It's crazy, frankly, when you get right down to it.
We have some of the top consulting companies in the country bringing in foreign workers. When we have US citizens that really could do the job, should do the job. By law, it has to be given to our US citizens versus these foreign workers. So really what is going on? Well, the justice department, just this Tuesday, alleged that Icon systems were routinely discriminating against US workers by posting job ads specifying a preference for applicants with temporary work visas. That company failed to consider at least a single US citizen applicant. This one person who applied to this discriminatory advertisement. It's a very big deal. Last week, the feds come out and sued Facebook in a very big way. They were arguing that Facebook hiring practices truly discriminated against US workers.
Now you might be asking yourself, first of all, why would they discriminate against US workers in preference for a foreign worker? the big answer to that, number one is these workers don't fall under all of the same rules and regulations that US workers do. You can mistreat them pretty badly. I've seen it done many times. That poor person who has been brought over from overseas at some potentially third world country, most likely a third world country is afraid to say anything because they don't want to lose their job. We know of cases that have been reported online again and again, where there were half a dozen, even a dozen people staying in a single apartment, working for some of these major giants. We're talking about big companies that can and do pay good money for US workers and certainly charge a lot.
I have really ranted and raved about some of these consulting firms who have gone in, have overbid on some of the stuff. This one that I'm thinking of, there was a proposal out, an RFP, basically from a company that had been a client of mine for 20 years. They were looking for someone to run their Microsoft infrastructure if you will. Mainly, their email server. They wanted this email server to be hosted by the company and maintained by the company.
Now, if you know how to do that stuff, it's pretty darn easy. This one consulting firm whose name you would recognize if you're in the computer business came in and bid twice. what we bid, twice as much. I really had to question it. I poked around and I found that, yeah, indeed, they were out golfing with the head of the division and we're buddy with them. So they got the job. Then I dug into it more and found out that they had one of the top rates of bringing in foreign workers on H1B visas. Those foreign workers were being paid up a fraction of what the US workers would have been paid then I would have paid.
So there they are charging twice what I was going to charge and paying their people about a fifth of what I had to pay my people.
In my case, my people are somewhere around a third of their time is spent in classes. Is spent on training. Is spent on exercises, red team, blue team stuff.
In these cases, they bring somebody who probably lied on their application. I certainly know a couple of them that absolutely misrepresented their skills. Can you tell, I'm just spitting mad here.
Off they go now saying, yeah, we can do all of this. Then they bring in the people to do the job cause they didn't even have the skills in-house.
come two months later, they, after having had that contract awarded this firm, had still not been able to get Microsoft's email server working. Two months later.
If much about this, it is not that hard. A few months after that, they finally had it all working and they were bouncing emails and wondering why are we bouncing emails?
They had us have a look at it. It was completely misconfigured. They didn't have some of the stuff done that needed to be done, like double reverse lookups and things because people don't want spam.
So if your email server is not properly configured, your emails are going to bounce. My head is throbbing just thinking about this, something we could have had up and running for them in a matter of a couple of weeks and would not have had any of the problems that they had.
Oh and by the way, their system crashed this exchange server, this email server, and they had no good backup at all.
What we had proposed to them was a complete failover where if one of the exchange servers went down, the other one would take over. They would actually both be running in parallel the rest of the time. So performance would have been better and we were still half the price. It just drives me crazy.
In this lawsuit against Facebook, that justice arguing that even though there are requirements to advertise the job, make sure Americans can apply and do apply for the job. You need to hire Americans first, apparently, that's not what they did. are required to place ads for permanent jobs in print publications. Candidates are supposed to submit their applications and they go into HR, that whole trick right?
The jobs had an average salary of more than 156,000 dollars a year, which by the way, is the poverty level out in the Bay area. Yet out of 1100 jobs posted between July 2018 and April 2019, 99% received no applicants or just a single applicant, which means, yes indeed, they were hiding these specific jobs.
It's just crazy. They had another one where they had done it correctly and they had more than 2,600 applications for 22 jobs shows you what's going on over there. All right.
We've got a lot to cover today, but we're going to talk about something that changed the internet and is now going away.
Hey consider this, we're now close to the end of Flash. That software that we've used to watch little videos online and even training and two and a half percent of internet users are still using it every day.
Craig Peterson here. Thanks for being with me. I appreciate the time you're spending today.
A little bit of breaking news as the day turns here is a way to look at it apparently. I don't have a lot of information on this right now. We'll probably have a lot more next week, but the Federal Trade Commission along with 48 other States has filed suits to break up Instagram and WhatsApp from Facebook. Facebook bought both of those companies. We'll see what happens, This is probably not something that would change under a Biden administration, since it is 48 States that are suing. This is not the federal government suing them.
This has really been long-awaited. This whole antitrust lawsuit against Facebook because the allegations I think are pretty clear that Facebook has abused its power in the marketplace. It has neutralized competitors by acquisitions, as we have just seen here. I just mentioned, WhatsApp and Instagram. Buys them and then prevents anybody else from getting really into the market. What are you going to do? have a competitor that's great for Facebook and if you do, I'd love to hear from you.
But wow. How do you do this? Facebook isn't going to sell you information about their customers. How are you going to advertise? Facebook will take some advertisements for some competitive things, but overall there's been a lot of allegations that Facebook in fact will basically block any competitors from advertising.
So here's a quote from it. "By using its vast troves of data and money. Facebook has quashed or hindered what the company perceived as potential threats". That's from New York attorney general Letitia Ann "Tish" James who was the head of this 47 state coalition quote in an effort to maintain its market dominance.
Facebook has employed a strategy to impede competing services. Man, this goes back, right? Does it flashback here a hundred years ago? 150 years ago. What was going on? I would love to see this happen. I think the biggest problem, frankly, and this is my opinion, but the biggest problem is we bail out these big companies when they fail. Right too big to fail, we can't let GM go under, because just think of all of the people there, the union people, the employees. So instead of that, we keep these companies that should be failing alive and on life support. With somebody like Facebook, they have really just grown too far, too fast.
We've talked a lot about what should happen with their immunity from the prosecution about things that people post on their sites. Did you realize that in Europe, there are laws that require them to take down content that's offensive or that might be a little slanderous?
That's true here too. You can sue someone and have it taken down, but over there, it's government regulators. So this is an interesting story. I just wanted to pop that up cause that just broke mid-week this week. I think it was Wednesday. We do want to cover that in a lot more detail. It's going to be interesting.
Next, up here we are going to really delve into this whole Flash story. This was a technology that was badly needed in the day, and I'm afraid that the model that developed Flash. As I recall Adobe ended up buying Flash and then it took it over and ran with it. The business model that developed it, developed from something that is all too common, which is, Oh, wow, there is a market window we need to jump on this and we need to jump on this hard and fast. So people jump on it and they don't pay attention. In fact, when they first came out with this, they paid zero attention to Flash's security implications.
It's just absolutely. Terrible. It Flash is one of the worst pieces of software ever to plague our security. Our cybersecurity. Flash and Java both have had just horrific histories. Flash has become a software security killer. This is going to happen again and again, and it's what I've been bemoaning with Microsoft forever.
I remember working when it would have been in the nineties on the replacement, Microsoft operating system called Windows NT, their next technology. I worked on it in pre 1.0 days in some of the kernel stuff. It was patterned after an operating system called VMS, which was an operating system that DEC, digital equipment, had made.
It was designed to be secure. It had security holes, everything does, Some worse than others. Nowadays security is much better than it ever used to be, but it was designed after a real operating system versus just the quick get to market let's add every feature under the sun because of the way people buy things.
We should talk about that sometime too. It is a little infuriating. People look to eliminate things as opposed to looking for things they want. So if you're trying to buy a piece of software, if you want a word processor, are you going to buy one that has a hundred features, or are you going to buy one that has 20 features?
I don't probably want a hundred features. That's how most people do it. Even though Microsoft for decades, until you got to version four, it was said Microsoft software was pretty much useless because most of the features didn't work, but they were there.
Versus maybe you liked one of the alternatives I used to use WordStar way back in the day that just worked and worked well. It was innovative in so many ways that Microsoft just wasn't. Anyhow. We have been plagued by that Microsoft symptom for years and the same thing's true with Flash. Everybody knew Flash was bad. 10 years ago, Steve Jobs came out when he announced the iPhone had said, we will not run Flash.
There were a couple of reasons for it. It had to do with Postscript or PDF, if you will, files that Adobe had some patents on. Apple butting heads with it. You might remember that pre OS10 days, the Apple equipment all used postscript and in fact, it still does. Postscript still much better language in many ways than some of these others. Like what HP uses for printers. Anyhow. We're going down at another angle on another road here. They had some fights, but Steve Jobs was really adamant that because Flash was a major security problem, he says, I'm going to ban it from iOS devices. The letter was called thoughts on flash. It's still available online. If you'd be interested. And it came out in I think it was June of 2010, but it really pointed out how abysmal security track record Flash had even in 2010, and it's gotten worse.
Nowadays, if you are using Flash in your business, you need to move to HTML five, a much more modern, much more secure way of having little moving things or quizzes and things on your website. Take a look at it. There are ways to move.
I was talking with a friend of mine who was saying that all of their training is done using flash. It's been a real problem for them since they are a training company. We've gotta be careful. Developers need to be more careful. If you have software that you make or you distribute, you really got to look into it and make sure that they are paying attention to security.
We have a client that has third-party-developed software for their hardware and they weren't paying any attention to it and that lent some liability to them.
According to the FBI business, email compromise attacks were responsible for more than $26 billion in damages over the last three years. What is BEC? What has it evolved into nowadays?
You're listening to Craig Peterson here.
Getting down into business email compromises, two things I want to get to here. I'm going to talk about this BEC as well as email account compromise, which is also called the takeover. I also want to get into this great article that the Wall Street Journal had out this week on what you should do.
As a company and basically they're saying you should stop scaring employees, but I think you got to know the numbers. So we'll go through a little bit of that.
Email. We've been using it for years. I've had emails since 81, I think it was. So I've had email for a very long time on the internet since the early eighties, myself, and have just been around this stuff forever. I guess I grew up around it. talk about generation Z and millennials growing up around technology. I've been around it a very long time.
I remember way back in 1970 designing and making my own little computer from scratch that played chess? It was mostly switches, lights, and release. It has come a long way since then, but it's fascinating how it's evolved, and way back when, email was fun.
We used it to announce, Hey, we're doing to get together. We used it for some of the information sharing. So what do I do with this? I remember in some of the earlier days of the web saying, I'm having this problem with Sendmail, how do I get that working? Just so many things, it's been very useful. We had all kinds of fun threads over usenet and things. Man, the memories.
Nowadays email really can be awful. It is still the number one way we communicate, but there are so many varieties of spam now that are getting through to our email boxes. We have some filters, we have some special filters that have been designed by Cisco.
Even our clients who are using Microsoft exchange online version, where they're now calling it, what Microsoft Three 60 as opposed to Office Three 60, but Microsoft does not do a great job at eliminating spam and some pretty nasty stuff gets through. Even with those guys, we route it through our system Cisco email filter which just does a bang-up job and allows individuals to control it themselves.
Then it sends it off to Microsoft servers for that cloud email service Microsoft office offers as well as we filter it and we send it to other email servers.
We use Zimbra as one of them, and there are many others. We'll send them right to the customer. If the customer has their email on site, and there are legitimate reasons to still have it on-site and very legitimate ones.
This is important, everyone, because frankly if Email is coming through and it has spam in it, what are you going to do?
What are you going to do as a business, right? You want your workers to be vigilant. What do you do? The Wall Street Journal had some great examples. I've heard of these before, where there are people whose businesses have cyber awareness training.
And the employee knows. Okay. Well, this could be a phishing message, et cetera. Then, they will send out little tasks to see if someone opened this email. In some cases you open it three times, you open three of these spam emails, you're out of a job, they fire you. In some cases, some of these businesses are fining employees as much as half of their annual salaries. If you can imagine that it is just crazy.
There's a little study here that was done on the use of the fear factor when it comes to cybersecurity. Should you be just scaring your employees? Should you tell your employees, listen, you, we're going to trick you up, and if you fall for it three times, you're fired. What they're saying is no, don't do that. I do so agree with this.
I should come up with a little program on that. Hey here's what's going on. You really scare the heck out of an employee and it's going to leave them in a permanent state of uncertainty. It's almost like PTSD, frankly. Certainly, nothing like our men and women or the military can get from being in combat, but it is a type of post-traumatic stress disorder. The productivity's likely to plummet because the employees go to mistrust every email that arrives in the email box. And they're not sure if they click on a link, is it safe?
Am I being scammed here? really going on? Fear-based approaches do not encourage genuine watchfulness. Even when you look at these stats, $26 billion that was lost stolen in most cases over the last three years, that's still a very small percentage of how much income all of the businesses have when you put them all together.
Getting right down to it in the classic business email compromise, what they're trying to do is convince an email recipient that a message is coming from a legitimate trusted source, when in fact it's coming from a bad guy. They might have a misspelling in the domain name or something out that looks legitimate at first glance.
But most people, if you just spend an extra five seconds having a closer look at it, you'll see, Oh, wait a minute. Now, this is not legitimate. Okay. And I'm going to tell you what should happen as the next step here. But the other one and this is frankly, more of a problem because we're talking with this next one, about it, a legitimate email address where you've got an email account compromised where someone's email account has been taken over.
How do they take over the email account? they go in and look on the dark web and they find email addresses and password names, physical addresses, business names, Put it all together and then they try and log in as you. Using the passwords that they found online. So they might go to Gmail and login as your Gmail account using your passwords that you've used for the Gmail account on other services that have been compromised.
So now they've got access to your Gmail account. Now it could be your company x.com email account as well. They're doing it again and again. So they might be doing a password spray. They might be doing fishing malware to compromise email accounts. Okay. But ultimately they're gaining access to legitimate email boxes.
So once an attacker has access to the accounts, they can do all kinds of stuff. They can grab the emails that are in there with all of their attachments and. Download them. And technically that's called exfiltrating data. Sounds like a spy thing, but it read frankly, yes, they can change forwarding emails.
They might even put a silent forward in there that you never notice. And it's forwarding to them. You can see, they can now see emails between you and the other people in the office, knowing that you're going to be out on vacation and they use that against you. It goes. On and on. So a business, email compromise, and an email account compromise are related, but they're different threats.
And I want to tell you what the Wall Street Journal had to say here and add my two bets as to what you shouldn't be doing when it comes to. Emails and fishing and employee training and hanging them out to dry as some of these businesses that are obviously doing.
should we be scaring our employees to death over emails and phishing and account compromises? Or are there some better ways to do it, or maybe it really is a middle of the road solution that'll work? that's what we'll talk about right now.
Craig Peterson here. Thanks for joining me. If you're just tuning in.
We were just talking about the basics here of business email compromise, each account compromise, and how it has cost industry worldwide here over $26 billion. That's what the damage estimate is over the last three years, it is a very big deal.
You can also. Of course, just follow me on any of the major podcasting apps. Just look for Craig Peterson. You should find me on that good-looking guy. And, and then you can listen for about two hours every week.
If you subscribe to my podcasts. I mentioned our friends over at the Wall Street Journal. They had a very good article written by Karen Reno. And I assume she pronounces it the French way. Maybe it's reneod. I'm not sure how she pronounces it.
So we'll stick with the French way. Karen said that the problem is fear. Does not work. And she quotes a number of discoveries, including from Mark dupli, from the University of Washington. Yeah. Wow. French name again? about how it works. Yeah. In the short-term at the moment, but scare tactics, don't get people invested in security over the term.
And she was involved as well with Mark on this research that came out, I'm looking right now at it. You can actually grab it online. it's fascinating what they had to say here, but, a comprehensive look at what really motivates people, what motivates and behavioral changes, and how cybersecurity researchers are really starting to experiment with these fear appeals and what.
Will work for them, what can work from them? So let's get into that right now. I, of course, I fear makes sense to me as a business owner because frankly, I want to know what the stats are. I want to know what the hard numbers are. Is this something I need to be concerned about? I would say more than fearful of and what they found Karen and Mark is that fear can have the opposite effect on people than what's intended, because fear can leave employees in this continual state of anxiety. And that's in the last segment when I was mentioning post-traumatic stress disorder, that's along the same lines here. So when you are in that anxious state, You cannot think clearly about the threats.
So having the heavy-handed scare messaging can also take those employees to the point where they're very disgruntled and frankly, completely uninterested in security. People think the threats are exaggerated. Look at what's happened with all this over and over again. People seem to be. You just numb now to the security threats that are out there.
So let's dig first here into why they say fear does not work. And number one is it's a short-term emotion. And what we're really looking for is a long term solution, right? You work at home. You were working with, other people in the office, you as a business owner, what do you need to do? And it's long-term vigilance.
It's the real point of cybersecurity so that after this initial surge, the fear's going to wear off and convert to an understating of anxiety. we were constantly talking about using strong passwords. Using password managers like last pass and one password using multifactor authentication, like DUO or some of the others.
Okay. So they go into, I think, a great solution here, but. They say, consider Jane's told Jerry awareness training that any email could be an efficient message. That's true. Of course, it is. So if she clicks on an embedded link or opens an attached Tatcha and she learns that malware could be installed and she will lose all of the files on her machine and be the cause of a major cyber incident at her workplace.
Okay. So now she's in this permanent fear state too. She has uncertainty. She has anxiety. Her productivity is going to drop off the cliff because she mistrusts every email that arrives in your inbox. And she's not sure if she clicks a link in a message that she's not going to cause the whole business to fail.
So just looking at it from that aspect, the authors are saying that this fear-based approach does not encourage genuine watchfulness. And I can see that, frankly, I can see that's a really big point here. There's a book out there by Paul Brown and Joan Kingsley and Sue Patterson. And it's called the fear-free organization.
And they've got some great points in there about how the brains get fully occupied in dealing with this fear emotion, and it's like fight or flight. You lose your fine motor coordination when you're in fight or flight mode because you are now pumping adrenaline and you're ready to fight her or run okay.
Much the same things. True here. And then people also don't believe these fear appeals and Tony 20 in hindsight, there's gotta be a good phrase for that one, but, what a terrible year it's been, we all have fear in the government and the media. I've been continually putting more and more fear into us to the point where we just don't trust other people.
Because of the lockdown because of the fear they've engendered over this latest Coronavirus. one of the issues that emerged during their study was that while many people might believe in fear-based appeals too much, others think that the appeals exaggerate the risk in order to give the message more power.
So I, I mentioned this UK organization up to 50% of employees, salaries find for clicking on it. their organizations, you click on one of these little tests, messages that they send in three times and you're fired. It is terrible. David rock is suggesting in his research into the neuroscience of collaboration that any employee who's singled out already feels bad about being deceived and now gets what's the equivalent of the physical pain of being shamed.
One of these businesses even posted names of people who had fallen for these little tests and clicked on something, they shouldn't have clicked on that the business had sent out. They're even posting their names on the communal refrigerator. Okay. It's pretty sad what they're doing. And these businesses just don't seem to understand the harm they're doing to the employer, employee relationship.
So what works better? And I'm so glad the wall street journal put this in here and you know what I'm agreeing with this. And this article was forwarded to me by a friend who's in one of my masterminds, Walt. He was just phenomenal. And, my mom. Thoughts and prayers go out to Walt is his dad just passed away this week as well.
But, he must've been doing some reading and for this along, but what's the alternative. What is the other side of the coin to fear? And they're saying creativity and trust. So here's the trick giving you and employees more leeway and giving them the support that they need. Works a lot better than building up anxiety and creating frankly aversions to doing their jobs because whose job does not include opening emails.
They all don't they? So here's a more productive three-pronged approach. And this is from professor Sydney, Decker, the Griffith University in Australia. He's a former submarine captain, leadership expert, David Marquette as well here. They've all put it all together. And. They're saying create a buddy system.
Yeah. It's just like when we were kids and we were outside, And we were going on a trip to the museum or walking down the street to the park, that teachers, they assigned us all buddies and we stuck with our buddy. They're saying don't put people in a room and talk at them for hours about security.
Give them a buddy. Who's there to help them in the office every day to help them carry out the actions you want in the system. Instead of trying to train everybody. One employee in each department is appointed to serve as a cybersecurity expert. This employee is close by to support colleagues.
Day-to-day available to answer questions about things like potential phishing messages. And if the message does turn out to be a phishing message, the buddy can warn the rest of the department immediately, or they could help somebody with a question about how to send files outside the company. Securely many of our businesses, we have restrictions too on things like thumb drives and whether you can use them, if you can bring them in, I would, by the way, recommend if you are using thumb drives to get the drives that have encryption built-in that little thumbprint.
So I think this is phenomenal. The authors say that they have talked to some businesses that were doing this and he says, it's really worked well. They spoke to one of these cybersecurity experts. I don't remember. Experts right there, but they are the person that's been designated the expert within bat group within the business.
So he says first, he always thinks of the people that come to him for consulting with him. If the email's not a fish, he lets them know it's safe to click on the link, open the attachment. If it is a fish, he praises them. Their alertness. Now, all of this can also be mostly solved by really good email filters.
I'm talking about the cheap stuff, the stuff from Barracuda or some of these others that are out there. I'm talking about all levels of high-end email filters so that you rarely get. Any of these phishing emails. In fact, nowadays from our clients and we have hundreds of thousands of emails reprocess every week, we get maybe one fishing plain to every few weeks, maybe once a month, it can be done.
Take that pressure off your employees.
Coming up in this hour, we're going to talk about some old-school encryption, the Nazi enigma, cipher machine. Another one was found.
Kmart just suffered another major attack using a new way of doing this stuff.
We'll talk about Alaska's voter database stolen. You listening to Craig Peterson. Thanks for being with me today.
My thoughts about a massively open election system. I think part of the problem we have with the elections is the fact that it's really quite closed. We had complaints in some States of Republican poll Watchers, not being able to do their duty and see those ballots as they were counted and were put in with one candidate or another, or this scanning that happened when all of the observers had been sent home, along with the media. It is not a good thing at all.
Then there's, of course, were the machines tampered with? I heard all kinds of stuff. I saw stories about every vote for President Trump counted for 0.75 of a vote. Every vote for Biden counted for 1.25 and on. I think there is an extremely transparent way to do this.
That will actually save the states a ton of money. We're talking about tens of millions of dollars per state saved and will dramatically increase the confidence that people have in the vote. What really happened with the vote? Let me just explain this simply. Simple's best, I grew up in the mainframe world and then the Unix world, and in the Unix world, rather than having one program that does everything, the whole idea is you have small programs that are very good at what they do. They're optimized for performing a certain function like sorting for instance. They might show you the date or who knows what? There are thousands of these little programs that are available in the Unix world, and you can tie them together.
Now. Microsoft tried to adapt and adopt the same type of technology using pipes and it has it, but it's not the same as a Unix world. Classic Unix is how long tail? How narrow can we make the function of this one little program? For instance, let's just use GREP as an example. GREP is a global regular expression program. So the idea is if you want to look for a pattern in a file, you can just say grep space and the pattern you're looking for, like Biden, for instance, and poof out of the standard output right there on your screen will come to every record with the word Biden in it.
It was very good at doing what it was doing. It was programmed in C, some of it in fact, would have been programmed in machine language. Particularly some of the library routines to make them very efficient. People wanted the more fancy stuff, so we ended up with FGREP and EGREP all these different commands that did a different variation of searching for this pattern. But added things like Unix regular expressions, which have been adopted in many parts of the world.
What has not been adopted in Windows or now in the voting systems is that same concept. You get a machine like one of these ballot marking devices that are being sold and were used in the election this year that are far more complicated than certainly, these Unix commands we're just talking about.
So my proposal is let's go back to the basics and let's open it all up and make it so that the elections can be observed massively. Here's what my thinking is. This would absolutely work. If the State House wants me to go up and testify and put together some stuff, I'd be more than glad to.
Here are the basics. You've got your sheet to vote on. That sheet is the bubble sheet that many of us are used to. That bubble sheet you just fill it in with your little flair pen or whatever it might be. You fill in that little bubble for the person or people that you're looking to vote for or the cause you're supporting in a referendum or whatever it might be.
Then the State, County, or whoever's doing the counting uses a simple scanning machine. Now it could be a fancy one, right? It could be one of these machines that'll scan a thousand per second. I don't really care. I'll actually probably get that fast, hard to handle the paper that fast, but it could be a very fast scanner.
It could be something that's very simple as well, depending on how many of these votes you need to count. So you've got the card, you're feeding it into the scanner.
We're talking about commercial off-the-shelf, regular scanners that are creating images. So the scanner spits out a PNG image or whatever it might be. I don't really care. It's probably better not to have it compressed. Just have the raw image and use a very standard image format that anybody can read and understand. So that's part one.
We're not talking about these fancy ballot marking devices, where you've got an Android tablet that may not have been updated or Windows Seven or heaven forbid some are still kicking around Windows XP voting machines. And then you. You touch the screen and Oh, magical out comes a paper tape with the people you voted for with a little scanning UPC type code over on the side that you then take, and it's run through the other machine and now your votes been validated.
There are so many things that could go wrong with that. So many things it's, first of all, it's really expensive, cause we were talking about a specially built machine to tabulate votes.
It isn't just a scanner. It has been set up. It is looking for the votes in specific places and then it tabulates them. Do you know how many things can go wrong with that? Even with the ballot marking device that I mentioned you are now relying on that ballot marking device to have been correct. How many times have we heard voters say my vote was changed from Trump to Gore. Wow. You probably ever heard that one. It was interim Trump to Biden or whatever might be. This would eliminate that you've got the card.
So now the secretary state's office or the County, or the city, whoever might be doing this particular plebiscite, this particular election, whatever it might now have all of these images. So let's say it's got a million, just for lack of a better number of these images in there. So these are the votes.
What happens next is. All of those images are posted online and they're posted online so that anybody can grab a copy of those images and look at them.
So now we can look for identical votes. We can look for these votes that have been fed through the machine dozens of times, right? You've heard those allegations.
We can look for the votes that were pre-printed, the votes that were copied on a machine, and then run through. We can look for all of these. very easily. If we have the images of the vote is available of the ballots.
So obviously you keep the ballots. Obviously, you're going to want to do some hand counts just to verify everything.
We have images of all of these votes available to us. The Secretary of State or whomever now can run two or three different pieces of tabulation software that aren't going to cost them a hundred thousand dollars or millions as in the case of some of these, we're talking about 800 bucks to buy the software, buy a license, use the software.
So I'm saying use two or three different pieces of software because it's different. People are going to code it up differently. Make sure it really is different, not like dominion, where all of these different systems are using the exact same software under the hood with maybe a few modifications to make it work with their hardware.
Completely different systems. So there's going to be some value judgments that are made by the software saying, Oh, this looks like a smudge more than a vote. So software A says that and then it flags it as I don't know what the hell this is. Then software B looks at it, it says, Oh, this is clearly a vote for Craig and chalks up to Craig. Then what can happen is people can be sitting at a terminal and every one of these questionable votes can then be shown to them and they can figure it out. If the initial ballots were all serialized without some sort of a good check digit on them, you can actually dig them up and look at the original if you needed to.
Talking about just disclosing everything. Now people can download all of the images of all of the votes that were cast. They can easily write software that looks for all kinds of discrepancies and tabulate it themselves. Of course, there's going to be now a bunch of people that are going to say, Oh, no, that was wrong my software did it better, whatever it is, but at least there's something to discuss.
If votes are fed into the system, especially if they're all serialized with a really good checksum on them, we'll know. It'll be obvious to even the most casual of observers. We're no longer counting on software that may have been written in Venezuela. Maybe tabulated in Germany, whatever. It's run locally, and you and I can check and double-check the results of the election.
That's my proposal. Anyways. I haven't heard it anywhere else, but I think this makes a lot of sense.
We've got a lot more to talk about.
Hey, we really are going to get to it. Now, the old technology that almost helped the Nazis, the national socialists win the war in World War II, the German enigma cipher. Another machine was just found.
Craig Peterson here.
Let's get into this whole rusty story. This is very cool. There's a story that's out there right now about some guys that were out dragging the Baltic sea. Now, if you're not familiar with dragging and what that's all about.
A lot of fishermen drag the bottom with their nets in order to catch fish, right? Certain types of fish. And in this case, there were divers that were going around the bottom of the Baltic sea, looking for discarded fishing nets. Those draggers often they'll get caught on something. Subterranean might be a mountain, might be a ship.
It might be who knows what? It might even be a World war two national socialist encryption machine, which is exactly what happened. This is one of the rarest of finds down there an Enigma encryption machine.
These things were absolutely amazing. I remember reading about them, studying them. Trying to understand how this all worked way back when I was very young and I, in fact, was just so enthralled with it. I wrote some software that basically did the same sort of thing.
This was basically like a typewriter, think of it, like a typewriter. If you haven't seen one it's electromechanical. The idea with encryption is that you have to obscure or the meaning of something, So how do you do that? And there are many different types of encryption and you can bury messages, even in the clear, inside of other things. pictures have been used a lot. Video has been used a lot. There are a lot of ways to hide messages.
Of course, if you're a fan of some of the different spy books out there, you're familiar with the idea of a cold drop.
There are many ways to, get a message across. Let's just leave it at that now.
There have been ciphers like the railroad cipher. You guys might've heard of that. The idea behind the railroad cipher is that, just a simplified version. If the tech says A really means G. we, for years on Unix, if we had something that might be considered offensive, we would post it on there in what's called rot 13. Rot 13 is just shifting the alphabet, remember 26 letters in our alphabet. So A through N I think it was L M N a would become, M through Z or whatever the right split is. I don't even remember anymore. It's so you would type something up. You'd send it out. It was encrypted by rot 13. Now anybody could break this encryption.
It's very easy to do. In fact, the readers who we were using at the time, just you just hit one button and it would rot 13, eight again, because of course, if you split the alphabet in the middle, And you use the last half of the alphabet, meaning the first half and the first half translating to the last half. You just have to do that again to see what's going on.
So there've been a lot of simple ciphers used over the years. Some of the best ciphers of course are book ciphers or one-time pads, but those are not particularly useful in wartime, back in the day.
Nowadays we're using them a lot more. So what the Germans did is they invented this machine and it had three or more of these rotors in the machine. And as I said, it looked like a typewriter. So you would hit the letter a, if it was a railroad cipher that we talked about, it might come out as a G every time. So if I said, how are you today? If someone typed enough in the message was long enough when we had enough examples in order to break that encryption, all we'd have to do is look at the repeats here. How many times does the letter G show up? it shows up at the same frequency as a letter A, therefore we can assume that letter G and the encryption is really an A and solve it. The national socialists knew this, right? They didn't want other countries to know what the socialist government was doing and where they were directing the Wolfpack submarines to sink the British and American ships.
So what the socialists did is they had these three rotors and every time you typed a letter, the rotors would turn. So basically what you were doing is like the railroad cipher, where a is G, but the next time you, for instance, you typed two A's in the row. The next time you typed a letter, those rotors would've moved.
So a would no longer necessarily be G a might be Q. Now. And so what would happen is that little typewriter and Enigma device would have a little light that would show up under the letter Q so you'd know. Okay. Q. So they'd write it down and then they'd usually be sending it off by a Morris code. A is much easier to send than Q is, by the way. But they would send that out in Morse code, which is really neat.
The idea was they would start the rotors. Those three rotors would be started in a certain position. And that way, if you typed in that message, now that queue would become an E, et cetera. So there'd be a nice direct translation. They also were supposed to change those initial settings every so often in the codebooks, So the initial settings would be one way for a week. And then the next week they'd be a different way, but they got lazy and they stopped changing the codes. You might know that the whole story of what happened and how we broke the socialist code and how we were able to then defeat the socialists in World war II, which is just a phenomenal thing. Where they were trying to just gain power, gain power, gain power, and eventually try and take over the war world. So very cool.
And if you aren't familiar with this, if this is something that intrigues you, you do look it up. There are videos, it was a machine you can actually buy. I saw one on eBay, a German enigma machine that was not a real one. It was a reproduction, but they worked then and they still work. Now. They're actually pretty good.
We're doing much better now with our encryption, believe me. But it's funny, looking at this lead diverse statement, Florian Huber who told the DPA news agencies as a colleague swam up and said, there's a net with an old typewriter in it. They pulled it up and, had a look and the diver said that I've made many exciting and strange discoveries in the past 20 years, but I never dreamt, we would one day find one of the legendary enigma machines. The divers suspecting, and I think correctly here, that the enigma was lost shortly before the German socialists surrendered in May 1945.
At that time, the Nazi leaders issued an order for the submarines to be scuttled up in this Bay to prevent their capture by allied forces. They also tossed all of these enigma machines overboard.
So credit to Alan Turing, a phenomenal man, brilliant man, very troubled man, as well, but he was able to break the encryption. It's a fascinating story. Watch the movie about it. If you haven't. I absolutely enjoyed that movie. It was all kinds of breakthroughs that were made by scientists from the Polish Cipher Bureau that made it possible for the allies to decipher the messages about the German military movements. Absolutely fascinating.
Then of course you get into the second part of the problem. How do we use this information? Because we don't want the socialists to know. But we know what they're going to do next. It's fascinating.
We've got more coming right up. We're going to talk about a newer type of ransomware attack and how Kmart fell victim.
Hopefully, you got my email last week, my newsletter, where I went through the steps that the latest types of ransomware are taking in order to get even more money out of you. They got Kmart too. So here we go. I guess I don't have an I told you, so isn't it.
Craig Peterson here. Thanks for sharing your time with me this afternoon. I appreciate it. And if you have any questions, by all means, drop me a line. One of the questions I do have for you though, is what is it you enjoy most about the show? Let me know. Cause that's going to help me, help you with the show. Just email me [email protected]. What is it that you enjoy the most about the show? I've had lots of feedback from you guys over the years, and I'd love more. Make sure I keep up to date and get you guys the information you're interested in.
By the way, I also have some training courses coming up, so I'll make sure you keep an eye out for that. You'll find them in my newsletter when I have them. So make sure you're on that list. Craig peterson.com. If you want a copy of last week's newsletter about ransomware, just drop me a note. I'd be glad to forward you a copy. Just email me [email protected], and you'll get it. Me. Yeah. Just as the name implies.
Man, the poor guys at Kmart. Who remembers it, K-Mart used to be the place to go. The blue light specials. You'd keep an eye out for that. While you're in the store. It was really fun.
Reminds me of Sears in the day, going there. Do you remember, are you old enough to remember getting dressed up to go to Sears. Now, Oh my gosh, these poor companies. Sears owned, what was effectively the online shopping business, 120 years ago. The Sears catalog. Every year for Christmas or for birthdays or other special events. We would get a copy of the Sears catalog and we'd go through, we'd dog-ear pages, where there was stuff that we wanted.
Do kids even know what dog-ear pages are anymore? But dog-ear those pages and just enjoy dreaming of it. You could order a house on Sears catalog back in the day. Sears completely missed the online shopping revolution. They could have owned it. They had the distribution in place. They had the catalog technology in place. I knew how to do all of this stuff, but they decided they would stick with the old ways and, that didn't work out so well for them, but they still were doing better than Kmart. Kmart was going under and Sears bought them. Well, Sears holding company originally owned both Kmart and Sears.
Sears Holding Corp filed for bankruptcy in 2018. It was bought by this transform co in 2019 K-Mart, which was a household name that was multinational. I remember them in Canada. Is now down to 34 stores remaining. Isn't that amazing? I'm thinking about our local, K-Mart just, Oh my gosh. But it is still open. They still have the stores. They had originally over 2100 stores in all 50 States. It's a very sad time for Kmart. It really is. I'm looking at some pictures of some of the stores that are open right now. It's a problem. It's a real problem.
Now they've had another problem.
Bleeping computers reporting, and they also have some great articles. You can check them [email protected] that Kmart suffered a cyber attack by the Egregor ransomware operation this week. Now they found at bleeping computer because they went to Transform Co human resources site, which is 88sears.com.
Now I went there this morning and it is online. It is their human resources page, but then when they brought it up, they found that indeed they were suffering an outage and they have posted bleeping computer on their website, a screenshot of that outage now, Egregor is known for stealing un-encrypted files before deploying the ransomware.
The bottom line is they're going to nail your twice. A lot of these bad guys. Nowadays, what they'll do is they'll grab your files. They'll download them and then they will encrypt them. And that isn't what Egregor does. And then they will put up then all too familiar, ransomware notice. You've seen it before, That red screen, demanding payment, and almost always in Bitcoin. And you can then hopefully find some Bitcoin, send them some money and you're off and running. And remember, I reported this a couple of weeks ago. If you pay a ransom, you could be in big trouble with the feds. And the reason for that is you are supporting terrorist organizations.
So you could indeed end up not only being sued by the Feds but going to jail over, paying a ransom. So think about that one. But they've escalated it now. So even if you pay the ransom or you don't pay the ransom, some other guy's going to come along. it's really the same people.
Okay. Some other guy's going to come along and say, Oh, guess what? I have your files. And they'll send you a list of the files and they'll probably send you some samples of some of the word docs or spreadsheets. And then they'll say, Pay up now, they're extorting you saying if you don't pay up. We are going to post your data online onto one of these data leaks sites.
And there are many of them. I'm looking at a list of them right now that bleeping computer is published, a through Z, and believe me, there are a lot of them out there. And so many of these look absolutely legitimate. Man alive. Do they ever, but with the Gregor, they will now say, I want to say, thanks for paying us the ransom on the encryption.
but they'll say, okay, now you owe us money or we'll post it on one of these sites and they do, and it's legitimate. Okay. What happened here apparently is that the bad guys targeted Kmart human resources website. And if it, if all of this is correct, Egregor would have stolen all of the data that was on that web server, about all of the employees within this.
Company. Okay. This transform co full name is Transformhold Co, LLC. So they are in some trouble. I'm sure if this really happened. And I've got to also add into all of this, that most of the time, these businesses don't actually know what was stolen because they don't have logs sufficient enough for logs at all.
To tell them exactly what happened. So a very big deal. It's a scary thing. And I went into it as well as what you can do about to help stop it in my newsletter last weekend. So if you miss that, have a look in your email box. If you need me to send another copy to you, just drop me a note me M E at Craig Peterson.
And I'd be glad to do that. But this is the next evolution and it works really well for businesses because think of the other angle, these bad guys have, they can get money from you. To give you the decryption key. They can get money from you in order to not release your data, which they may release anyway.
But they know who you are because they have your files. So they know you are a doctor's office and they'll charge you more. Or they know that you're a manufacturer in the DOD department of the defense supply chain. And so they'll extort even more out of view. Okay. very bad. yeah, it's a shame.
Good old Kmart. Oh, she's still around, I guess it'll be around for a little bit longer, but this sort of stuff is really happening. This can be the death nail and it is the death knell to the majority of companies. It happens too. Hey, stick around when we get back. Oh my goodness. I can't believe this.
We're going to talk about the Alaska voter database hack and more including police live streaming your Amazon Ring camera.
I guess our election system isn't as safe from hackers as we might've thought. We're going to talk about hackers breaking into an Alaska voter database.
We'll be talking about police piloting a program to live stream Amazon ring cameras and more.
Craig Peterson here. I talked about what I think the answer is to technology and the elections. In fact, what I described at the top of the hour would completely eliminate some of these major technology problems without a doubt.
This is a different type of problem from the gateway pundit.com, which you can find online.
Alaska state officials reported that hackers stole personal information for more than 100,000 individuals from the state voter database, that's a very big deal. Alaska is saying that information included birthdates driver's license numbers of more than a hundred thousand Alaskan voters.
If you think about these voting databases in most States, they are also going to contain your signature. They're going to have your home address. They're going to have a lot of information from you. Okay.
Now they stressed that there was no effect on the results of last month's election. Oh, okay. But your personal data was stolen and that's part of the reason I have such a problem with the driver's license databases as they are in most States. They also include things like your social security number now and think of these real ID licenses that are now being issued. I don't even want one of the silly things, but in most States, you're being forced into having one.
I've already got a passport, which is good enough for me to get in and out of the country. Why do I need one of these tamper-proof supposedly driver's licenses with all of the data that they're collecting? Think of what you have to do to get one of those things. You have to prove your residency. You have to prove all of this other stuff. I don't know. Maybe it's going to be a good thing for voting anyway, because if you have to present this type of ID, at least we know that you're legitimate.
Then there's California and that's a whole other issue.
It says the hackers gain unauthorized access to the data and the state's online voter registration system. It was built and maintained by a contractor and operated by the Alaska division of elections, goes on and on talks about the sad news.
So officials said the flaw that exposes the data has been fixed and Alaskan's information is now secure. Isn't that wonderful?
Now that the horse is out of the barn, they're going to close the doors, but it's still not known exactly which records were stolen. Again, that's a real problem. Most regulations that are out there for the private sector require us to know was stolen.
Oh, gay. let's keep all of that in mind. Just don't trust this stuff. I don't trust it to, the government. I don't trust it to, private companies. Look at what happened with Equifax. Basically, all of our personal information was stolen probably by the way, by the Chinese government. Anyhow, we talked about something similar to this next article fairly recently, and this is from eff.org electronic frontier foundation. They're very much a very pro-free speech place to a degree. As long as your speech agrees with them. But they want open software and, they do want to help keep more basic information safe, the civil libertarian side of things.
Let's see. So the police surveillance center in Jackson, Mississippi is going to be conducting a 45-day pilot program to live stream the security cameras in Jackson, Mississippi, including the Amazon ring cameras from residents who are participating. The idea behind this is it gives the police department real visibility, live visibility into neighborhoods.
So they can record it as well. They can play it back. If there are porch pirates, those people that are stealing our Amazon packages out there, they can hopefully find them. Of course, if there's a porch pirate that just stole your package. you've probably got them on tape, right?
So you can do a little bit of something about that. I have multiple cameras out there doing it, but the police want this live stream. Now there've been stories out there in the past about ring cameras being used by the police. in some cases, these stories have said that in the, in fact, the police departments, according to these guys have been doing it without a warrant.
in fact, that's going to be the case here again in Jackson, Mississippi, because people are going to be able to opt in to this program. So it sounds like they're trying to do some of the right things. There are concerns here from the EFF about rings 1000 plus partnerships with local police departments.
And that's kinda what I was talking about back in June this year, but there are a lot of people that are concerned about the police department, and you've probably heard of this socialist-communist in fact group called black lives matter. That has been out there protesting the police, defund the police, all of the things that have been promised to us about just drawing a lot of the local police departments. This is a real concern because people are buying ring cameras and these other cameras and putting them on the front door effectively to help keep the packages safe. The police are using them to build these comprehensive closed-circuit TV camera networks that are blanketing whole neighborhoods and it allows the police departments to get that type of video feed without having to buy surveillance equipment.
Think about what some of our local cities have done to put in surveillance cameras. It's really rather expensive. Then the second point here that E FF is making, is that evades the natural reaction of fear and distrust that many people would have if they saw cameras up on the street lights.
By the way, some of these new street lights do include cameras that are fed to the police department. Okay. So they are there, but they're hidden away. It's Oh, it's Joe's doorbell is basically what it is and it's supposedly. Going to be a little bit safer, but the police and these thousand different partnerships with different police departments now are allowing them to set up an array of cameras without anybody really noticing, by the way, Jackson.
Was the first city in the Southern United States to bland banned police use of face recognition technology. So they understand this invasive surveillance technology, but, in this case, maybe they've overstepped their bounds. They've got, also by the way, this national movement called community control over police surveillance.
See cops. These are different ordinances. The residents have put through legislatures in different States that have more say in whether or not please can build a program like this. I also have had concerns over the years about the ability to videotape or record, official police or otherwise in the performance of their duties.
Main is what is known as a single-party state, which means only one person who is part of that recording needs to be aware of the recording. And they, one person has to say, yeah, okay. I'm going to record, but the other person on the other end of the line or the other end of the camera doesn't have to say anything.
New Hampshire and many other states are two-party States. In other words, Both parties or all parties that are part of that recording have to consent to be recorded. So something like this ring system really could be a bit of a problem. And depending on the state you're in Maine, wouldn't be because you knew you had a camera up.
I think in most States, including New Hampshire, you would, which is a two-party state. I think you're are going to be safe enough because. You got a Ring doorbell with a camera. I think most people nowadays know that it could be recording what's going on and I have security cameras up as well. And you might want to do the same thing.
I use security cameras that meet the federal department of defense standards. Okay. they ain't feeding ring or anybody else out there, but it's something to seriously consider. the last article here before we disappear is about the cybersecurity pandemic that's going on right now. This is a scary thing.
It's a big thing. The next war is really worldwide going to be a hybrid war. We're already seeing that where businesses and governments are targeted by cyber attacks. There's espionage going on. I've told you about some of the clients I've picked up because something weird was happening and we looked into it and we found.
Direct evidence of espionage and got the FBI involved. That it's amazing what's going on. But the threat from hostile nations like China, Russia, Iran, and North Korea is really growing. And we've got our critical national infrastructure. Now such as your water, electricity plants that are relying on network connections and also.
for changing valves, opening, closing them as well as for monitoring, we've got these SCADA systems, which are also used for monitoring and control in our manufacturing plant. This is a bit of a problem. And particularly when we think now about all of these people that are at home, working from home, that may be connected to a business.
That is part of our critical national infrastructure and they don't have the right kinds of security. It's it is mind-blowing. Anyway, I'm thinking about doing something about this article we talked about earlier from the wall street journal, the buddy system. Where you can really increase the security of your business by using it.
I'm thinking, how can I help with that? I'm not sure yet we'll figure out how I can help you with that sort of thing. Maybe we should just have a little report line where you can send stuff and let me know, and I can respond. Let me know at [email protected] and we'll be back next week.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed