
Sign up to save your podcasts
Or


Â
Welcome! Â
This week I am spending a bit of time discussing H1B Visas and Facebook's war on American Workers, Extortionware, and how it is the death knell for Companies. We have a Cybersecurity Pandemic underway courtesy of the Covid-19 pandemic and More so be sure to Listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
---
Facebook Hires Foreign Workers Over US Workers - Breaking the Law
Security's Worst Fore? Adobe Flash Finally Killed
Business Email Comprise vs Email Account Compromise
Extortionware Gains Traction and Kmart is Hit
Alaskan Voting Servers Hacked
Local Police Live-Streaming Amazon Ring Cameras
A Cyber Security Pandemic Has Started
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Feds are saying that Facebook broke US immigration laws. Flash, finally dying. Goodbye and good riddance Adobe. We're going to talk about business email compromise versus something a little bit newer and different, EACs.
Hi everybody Craig Peterson here. No, we're not going to get crazy with talking about some of the problems we're having with email. I really want to talk a bit about this because fear only goes so far.
A great, great article this week in the Wall Street Journal. We will be getting into it in a little bit.
How we can really help our family and our business associates when it comes to security. We're always hearing about, Oh my gosh, business email compromise. It's just been terrible. It's destroying our businesses, which it is. But the problem that we've been facing because of the way we've responded is that people are much less able really to get the work done because they have fears every time they turn around.
So we'll get into that a little bit more as well. I love this thing about the Nazi Enigma cipher machine that was found in the Baltic sea. At the end of world war two, the boats, the submarines particularly were all ordered to destroy them. So they threw them overboard thinking that would probably be good enough. Of course, we already had broken their cipher, no big deal there.
Kmart here. National business got a lot smaller and it just suffered a ransomware attack from a new form of ransomware. We'll talk a little bit about that.
We've got hackers now breaking into an Alaskan voter database. Grabbing information on a hundred thousand voters. Very big deal. We'll talk about that.
We'll also be talking about police and this program in one community. We talked about something about six months ago, that was spreading a little more nationally. One community and what they're going to be doing with ring cameras and live streaming your doorbell to the police department.
Then we are going to get into the next global crisis, which is a cybersecurity pandemic. It has gotten really bad out there. a shame, frankly.
Hey, you're listening to Craig Peterson. welcome. Did you know if you have one of those smart home devices you can listen right from there? I've got my Amazon echo tied in via Bluetooth speakers that we put into the roof of the kitchen. We had a water leak. We had to replace the roof in the kitchen. So while I was in there, let's put in some good speakers and I did. I've got a little Bluetooth module that I got in fact from Amazon that hooks right up to an amplifier that drives the speakers. I have an Amazon echo there in the kitchen too. very handy. So I've got it configured to use Bluetooth so that it uses the speakers up in the roof.
it's just, it's phenomenal. I do that all of the time.
let's get into our friends here over at Facebook. I have been talking for years about this whole H1B visa problem. It's been a problem in the tech industry. Primarily now there are other types of temporary worker visas that are used in other industries. For the most part, I think in most other industries, they're not misused. But in the US, it is very misused. It's crazy, frankly, when you get right down to it.
We have some of the top consulting companies in the country bringing in foreign workers. When we have US citizens that really could do the job, should do the job. By law, it has to be given to our US citizens versus these foreign workers. So really what is going on? Well, the justice department, just this Tuesday, alleged that Icon systems were routinely discriminating against US workers by posting job ads specifying a preference for applicants with temporary work visas. That company failed to consider at least a single US citizen applicant. This one person who applied to this discriminatory advertisement. It's a very big deal. Last week, the feds come out and sued Facebook in a very big way. They were arguing that Facebook hiring practices truly discriminated against US workers.
Now you might be asking yourself, first of all, why would they discriminate against US workers in preference for a foreign worker? the big answer to that, number one is these workers don't fall under all of the same rules and regulations that US workers do. You can mistreat them pretty badly. I've seen it done many times. That poor person who has been brought over from overseas at some potentially third world country, most likely a third world country is afraid to say anything because they don't want to lose their job. We know of cases that have been reported online again and again, where there were half a dozen, even a dozen people staying in a single apartment, working for some of these major giants. We're talking about big companies that can and do pay good money for US workers and certainly charge a lot.
I have really ranted and raved about some of these consulting firms who have gone in, have overbid on some of the stuff. This one that I'm thinking of, there was a proposal out, an RFP, basically from a company that had been a client of mine for 20 years. They were looking for someone to run their Microsoft infrastructure if you will. Mainly, their email server. They wanted this email server to be hosted by the company and maintained by the company.
Now, if you know how to do that stuff, it's pretty darn easy. This one consulting firm whose name you would recognize if you're in the computer business came in and bid twice. what we bid, twice as much. I really had to question it. I poked around and I found that, yeah, indeed, they were out golfing with the head of the division and we're buddy with them. So they got the job. Then I dug into it more and found out that they had one of the top rates of bringing in foreign workers on H1B visas. Those foreign workers were being paid up a fraction of what the US workers would have been paid then I would have paid.
So there they are charging twice what I was going to charge and paying their people about a fifth of what I had to pay my people.
In my case, my people are somewhere around a third of their time is spent in classes. Is spent on training. Is spent on exercises, red team, blue team stuff.
In these cases, they bring somebody who probably lied on their application. I certainly know a couple of them that absolutely misrepresented their skills. Can you tell, I'm just spitting mad here.
Off they go now saying, yeah, we can do all of this. Then they bring in the people to do the job cause they didn't even have the skills in-house.
come two months later, they, after having had that contract awarded this firm, had still not been able to get Microsoft's email server working. Two months later.
If much about this, it is not that hard. A few months after that, they finally had it all working and they were bouncing emails and wondering why are we bouncing emails?
They had us have a look at it. It was completely misconfigured. They didn't have some of the stuff done that needed to be done, like double reverse lookups and things because people don't want spam.
So if your email server is not properly configured, your emails are going to bounce. My head is throbbing just thinking about this, something we could have had up and running for them in a matter of a couple of weeks and would not have had any of the problems that they had.
Oh and by the way, their system crashed this exchange server, this email server, and they had no good backup at all.
What we had proposed to them was a complete failover where if one of the exchange servers went down, the other one would take over. They would actually both be running in parallel the rest of the time. So performance would have been better and we were still half the price. It just drives me crazy.
In this lawsuit against Facebook, that justice arguing that even though there are requirements to advertise the job, make sure Americans can apply and do apply for the job. You need to hire Americans first, apparently, that's not what they did. are required to place ads for permanent jobs in print publications. Candidates are supposed to submit their applications and they go into HR, that whole trick right?
The jobs had an average salary of more than 156,000 dollars a year, which by the way, is the poverty level out in the Bay area. Yet out of 1100 jobs posted between July 2018 and April 2019, 99% received no applicants or just a single applicant, which means, yes indeed, they were hiding these specific jobs.
It's just crazy. They had another one where they had done it correctly and they had more than 2,600 applications for 22 jobs shows you what's going on over there. All right.
We've got a lot to cover today, but we're going to talk about something that changed the internet and is now going away.
Hey consider this, we're now close to the end of Flash. That software that we've used to watch little videos online and even training and two and a half percent of internet users are still using it every day.
Craig Peterson here. Thanks for being with me. I appreciate the time you're spending today.
A little bit of breaking news as the day turns here is a way to look at it apparently. I don't have a lot of information on this right now. We'll probably have a lot more next week, but the Federal Trade Commission along with 48 other States has filed suits to break up Instagram and WhatsApp from Facebook. Facebook bought both of those companies. We'll see what happens, This is probably not something that would change under a Biden administration, since it is 48 States that are suing. This is not the federal government suing them.
This has really been long-awaited. This whole antitrust lawsuit against Facebook because the allegations I think are pretty clear that Facebook has abused its power in the marketplace. It has neutralized competitors by acquisitions, as we have just seen here. I just mentioned, WhatsApp and Instagram. Buys them and then prevents anybody else from getting really into the market. What are you going to do? have a competitor that's great for Facebook and if you do, I'd love to hear from you.
But wow. How do you do this? Facebook isn't going to sell you information about their customers. How are you going to advertise? Facebook will take some advertisements for some competitive things, but overall there's been a lot of allegations that Facebook in fact will basically block any competitors from advertising.
So here's a quote from it. "By using its vast troves of data and money. Facebook has quashed or hindered what the company perceived as potential threats". That's from New York attorney general Letitia Ann "Tish" James who was the head of this 47 state coalition quote in an effort to maintain its market dominance.
Facebook has employed a strategy to impede competing services. Man, this goes back, right? Does it flashback here a hundred years ago? 150 years ago. What was going on? I would love to see this happen. I think the biggest problem, frankly, and this is my opinion, but the biggest problem is we bail out these big companies when they fail. Right too big to fail, we can't let GM go under, because just think of all of the people there, the union people, the employees. So instead of that, we keep these companies that should be failing alive and on life support. With somebody like Facebook, they have really just grown too far, too fast.
We've talked a lot about what should happen with their immunity from the prosecution about things that people post on their sites. Did you realize that in Europe, there are laws that require them to take down content that's offensive or that might be a little slanderous?
That's true here too. You can sue someone and have it taken down, but over there, it's government regulators. So this is an interesting story. I just wanted to pop that up cause that just broke mid-week this week. I think it was Wednesday. We do want to cover that in a lot more detail. It's going to be interesting.
Next, up here we are going to really delve into this whole Flash story. This was a technology that was badly needed in the day, and I'm afraid that the model that developed Flash. As I recall Adobe ended up buying Flash and then it took it over and ran with it. The business model that developed it, developed from something that is all too common, which is, Oh, wow, there is a market window we need to jump on this and we need to jump on this hard and fast. So people jump on it and they don't pay attention. In fact, when they first came out with this, they paid zero attention to Flash's security implications.
It's just absolutely. Terrible. It Flash is one of the worst pieces of software ever to plague our security. Our cybersecurity. Flash and Java both have had just horrific histories. Flash has become a software security killer. This is going to happen again and again, and it's what I've been bemoaning with Microsoft forever.
I remember working when it would have been in the nineties on the replacement, Microsoft operating system called Windows NT, their next technology. I worked on it in pre 1.0 days in some of the kernel stuff. It was patterned after an operating system called VMS, which was an operating system that DEC, digital equipment, had made.
It was designed to be secure. It had security holes, everything does, Some worse than others. Nowadays security is much better than it ever used to be, but it was designed after a real operating system versus just the quick get to market let's add every feature under the sun because of the way people buy things.
We should talk about that sometime too. It is a little infuriating. People look to eliminate things as opposed to looking for things they want. So if you're trying to buy a piece of software, if you want a word processor, are you going to buy one that has a hundred features, or are you going to buy one that has 20 features?
I don't probably want a hundred features. That's how most people do it. Even though Microsoft for decades, until you got to version four, it was said Microsoft software was pretty much useless because most of the features didn't work, but they were there.
Versus maybe you liked one of the alternatives I used to use WordStar way back in the day that just worked and worked well. It was innovative in so many ways that Microsoft just wasn't. Anyhow. We have been plagued by that Microsoft symptom for years and the same thing's true with Flash. Everybody knew Flash was bad. 10 years ago, Steve Jobs came out when he announced the iPhone had said, we will not run Flash.
There were a couple of reasons for it. It had to do with Postscript or PDF, if you will, files that Adobe had some patents on. Apple butting heads with it. You might remember that pre OS10 days, the Apple equipment all used postscript and in fact, it still does. Postscript still much better language in many ways than some of these others. Like what HP uses for printers. Anyhow. We're going down at another angle on another road here. They had some fights, but Steve Jobs was really adamant that because Flash was a major security problem, he says, I'm going to ban it from iOS devices. The letter was called thoughts on flash. It's still available online. If you'd be interested. And it came out in I think it was June of 2010, but it really pointed out how abysmal security track record Flash had even in 2010, and it's gotten worse.
Nowadays, if you are using Flash in your business, you need to move to HTML five, a much more modern, much more secure way of having little moving things or quizzes and things on your website. Take a look at it. There are ways to move.
I was talking with a friend of mine who was saying that all of their training is done using flash. It's been a real problem for them since they are a training company. We've gotta be careful. Developers need to be more careful. If you have software that you make or you distribute, you really got to look into it and make sure that they are paying attention to security.
We have a client that has third-party-developed software for their hardware and they weren't paying any attention to it and that lent some liability to them.
According to the FBI business, email compromise attacks were responsible for more than $26 billion in damages over the last three years. What is BEC? What has it evolved into nowadays?
You're listening to Craig Peterson here.
Getting down into business email compromises, two things I want to get to here. I'm going to talk about this BEC as well as email account compromise, which is also called the takeover. I also want to get into this great article that the Wall Street Journal had out this week on what you should do.
As a company and basically they're saying you should stop scaring employees, but I think you got to know the numbers. So we'll go through a little bit of that.
Email. We've been using it for years. I've had emails since 81, I think it was. So I've had email for a very long time on the internet since the early eighties, myself, and have just been around this stuff forever. I guess I grew up around it. talk about generation Z and millennials growing up around technology. I've been around it a very long time.
I remember way back in 1970 designing and making my own little computer from scratch that played chess? It was mostly switches, lights, and release. It has come a long way since then, but it's fascinating how it's evolved, and way back when, email was fun.
We used it to announce, Hey, we're doing to get together. We used it for some of the information sharing. So what do I do with this? I remember in some of the earlier days of the web saying, I'm having this problem with Sendmail, how do I get that working? Just so many things, it's been very useful. We had all kinds of fun threads over usenet and things. Man, the memories.
Nowadays email really can be awful. It is still the number one way we communicate, but there are so many varieties of spam now that are getting through to our email boxes. We have some filters, we have some special filters that have been designed by Cisco.
Even our clients who are using Microsoft exchange online version, where they're now calling it, what Microsoft Three 60 as opposed to Office Three 60, but Microsoft does not do a great job at eliminating spam and some pretty nasty stuff gets through. Even with those guys, we route it through our system Cisco email filter which just does a bang-up job and allows individuals to control it themselves.
Then it sends it off to Microsoft servers for that cloud email service Microsoft office offers as well as we filter it and we send it to other email servers.
We use Zimbra as one of them, and there are many others. We'll send them right to the customer. If the customer has their email on site, and there are legitimate reasons to still have it on-site and very legitimate ones.
This is important, everyone, because frankly if Email is coming through and it has spam in it, what are you going to do?
What are you going to do as a business, right? You want your workers to be vigilant. What do you do? The Wall Street Journal had some great examples. I've heard of these before, where there are people whose businesses have cyber awareness training.
And the employee knows. Okay. Well, this could be a phishing message, et cetera. Then, they will send out little tasks to see if someone opened this email. In some cases you open it three times, you open three of these spam emails, you're out of a job, they fire you. In some cases, some of these businesses are fining employees as much as half of their annual salaries. If you can imagine that it is just crazy.
There's a little study here that was done on the use of the fear factor when it comes to cybersecurity. Should you be just scaring your employees? Should you tell your employees, listen, you, we're going to trick you up, and if you fall for it three times, you're fired. What they're saying is no, don't do that. I do so agree with this.
I should come up with a little program on that. Hey here's what's going on. You really scare the heck out of an employee and it's going to leave them in a permanent state of uncertainty. It's almost like PTSD, frankly. Certainly, nothing like our men and women or the military can get from being in combat, but it is a type of post-traumatic stress disorder. The productivity's likely to plummet because the employees go to mistrust every email that arrives in the email box. And they're not sure if they click on a link, is it safe?
Am I being scammed here? really going on? Fear-based approaches do not encourage genuine watchfulness. Even when you look at these stats, $26 billion that was lost stolen in most cases over the last three years, that's still a very small percentage of how much income all of the businesses have when you put them all together.
Getting right down to it in the classic business email compromise, what they're trying to do is convince an email recipient that a message is coming from a legitimate trusted source, when in fact it's coming from a bad guy. They might have a misspelling in the domain name or something out that looks legitimate at first glance.
But most people, if you just spend an extra five seconds having a closer look at it, you'll see, Oh, wait a minute. Now, this is not legitimate. Okay. And I'm going to tell you what should happen as the next step here. But the other one and this is frankly, more of a problem because we're talking with this next one, about it, a legitimate email address where you've got an email account compromised where someone's email account has been taken over.
How do they take over the email account? they go in and look on the dark web and they find email addresses and password names, physical addresses, business names, Put it all together and then they try and log in as you. Using the passwords that they found online. So they might go to Gmail and login as your Gmail account using your passwords that you've used for the Gmail account on other services that have been compromised.
So now they've got access to your Gmail account. Now it could be your company x.com email account as well. They're doing it again and again. So they might be doing a password spray. They might be doing fishing malware to compromise email accounts. Okay. But ultimately they're gaining access to legitimate email boxes.
So once an attacker has access to the accounts, they can do all kinds of stuff. They can grab the emails that are in there with all of their attachments and. Download them. And technically that's called exfiltrating data. Sounds like a spy thing, but it read frankly, yes, they can change forwarding emails.
They might even put a silent forward in there that you never notice. And it's forwarding to them. You can see, they can now see emails between you and the other people in the office, knowing that you're going to be out on vacation and they use that against you. It goes. On and on. So a business, email compromise, and an email account compromise are related, but they're different threats.
And I want to tell you what the Wall Street Journal had to say here and add my two bets as to what you shouldn't be doing when it comes to. Emails and fishing and employee training and hanging them out to dry as some of these businesses that are obviously doing.
should we be scaring our employees to death over emails and phishing and account compromises? Or are there some better ways to do it, or maybe it really is a middle of the road solution that'll work? that's what we'll talk about right now.
Craig Peterson here. Thanks for joining me. If you're just tuning in.
We were just talking about the basics here of business email compromise, each account compromise, and how it has cost industry worldwide here over $26 billion. That's what the damage estimate is over the last three years, it is a very big deal.
You can also. Of course, just follow me on any of the major podcasting apps. Just look for Craig Peterson. You should find me on that good-looking guy. And, and then you can listen for about two hours every week.
If you subscribe to my podcasts. I mentioned our friends over at the Wall Street Journal. They had a very good article written by Karen Reno. And I assume she pronounces it the French way. Maybe it's reneod. I'm not sure how she pronounces it.
So we'll stick with the French way. Karen said that the problem is fear. Does not work. And she quotes a number of discoveries, including from Mark dupli, from the University of Washington. Yeah. Wow. French name again? about how it works. Yeah. In the short-term at the moment, but scare tactics, don't get people invested in security over the term.
And she was involved as well with Mark on this research that came out, I'm looking right now at it. You can actually grab it online. it's fascinating what they had to say here, but, a comprehensive look at what really motivates people, what motivates and behavioral changes, and how cybersecurity researchers are really starting to experiment with these fear appeals and what.
Will work for them, what can work from them? So let's get into that right now. I, of course, I fear makes sense to me as a business owner because frankly, I want to know what the stats are. I want to know what the hard numbers are. Is this something I need to be concerned about? I would say more than fearful of and what they found Karen and Mark is that fear can have the opposite effect on people than what's intended, because fear can leave employees in this continual state of anxiety. And that's in the last segment when I was mentioning post-traumatic stress disorder, that's along the same lines here. So when you are in that anxious state, You cannot think clearly about the threats.
So having the heavy-handed scare messaging can also take those employees to the point where they're very disgruntled and frankly, completely uninterested in security. People think the threats are exaggerated. Look at what's happened with all this over and over again. People seem to be. You just numb now to the security threats that are out there.
So let's dig first here into why they say fear does not work. And number one is it's a short-term emotion. And what we're really looking for is a long term solution, right? You work at home. You were working with, other people in the office, you as a business owner, what do you need to do? And it's long-term vigilance.
It's the real point of cybersecurity so that after this initial surge, the fear's going to wear off and convert to an understating of anxiety. we were constantly talking about using strong passwords. Using password managers like last pass and one password using multifactor authentication, like DUO or some of the others.
Okay. So they go into, I think, a great solution here, but. They say, consider Jane's told Jerry awareness training that any email could be an efficient message. That's true. Of course, it is. So if she clicks on an embedded link or opens an attached Tatcha and she learns that malware could be installed and she will lose all of the files on her machine and be the cause of a major cyber incident at her workplace.
Okay. So now she's in this permanent fear state too. She has uncertainty. She has anxiety. Her productivity is going to drop off the cliff because she mistrusts every email that arrives in your inbox. And she's not sure if she clicks a link in a message that she's not going to cause the whole business to fail.
So just looking at it from that aspect, the authors are saying that this fear-based approach does not encourage genuine watchfulness. And I can see that, frankly, I can see that's a really big point here. There's a book out there by Paul Brown and Joan Kingsley and Sue Patterson. And it's called the fear-free organization.
And they've got some great points in there about how the brains get fully occupied in dealing with this fear emotion, and it's like fight or flight. You lose your fine motor coordination when you're in fight or flight mode because you are now pumping adrenaline and you're ready to fight her or run okay.
Much the same things. True here. And then people also don't believe these fear appeals and Tony 20 in hindsight, there's gotta be a good phrase for that one, but, what a terrible year it's been, we all have fear in the government and the media. I've been continually putting more and more fear into us to the point where we just don't trust other people.
Because of the lockdown because of the fear they've engendered over this latest Coronavirus. one of the issues that emerged during their study was that while many people might believe in fear-based appeals too much, others think that the appeals exaggerate the risk in order to give the message more power.
So I, I mentioned this UK organization up to 50% of employees, salaries find for clicking on it. their organizations, you click on one of these little tests, messages that they send in three times and you're fired. It is terrible. David rock is suggesting in his research into the neuroscience of collaboration that any employee who's singled out already feels bad about being deceived and now gets what's the equivalent of the physical pain of being shamed.
One of these businesses even posted names of people who had fallen for these little tests and clicked on something, they shouldn't have clicked on that the business had sent out. They're even posting their names on the communal refrigerator. Okay. It's pretty sad what they're doing. And these businesses just don't seem to understand the harm they're doing to the employer, employee relationship.
So what works better? And I'm so glad the wall street journal put this in here and you know what I'm agreeing with this. And this article was forwarded to me by a friend who's in one of my masterminds, Walt. He was just phenomenal. And, my mom. Thoughts and prayers go out to Walt is his dad just passed away this week as well.
But, he must've been doing some reading and for this along, but what's the alternative. What is the other side of the coin to fear? And they're saying creativity and trust. So here's the trick giving you and employees more leeway and giving them the support that they need. Works a lot better than building up anxiety and creating frankly aversions to doing their jobs because whose job does not include opening emails.
They all don't they? So here's a more productive three-pronged approach. And this is from professor Sydney, Decker, the Griffith University in Australia. He's a former submarine captain, leadership expert, David Marquette as well here. They've all put it all together. And. They're saying create a buddy system.
Yeah. It's just like when we were kids and we were outside, And we were going on a trip to the museum or walking down the street to the park, that teachers, they assigned us all buddies and we stuck with our buddy. They're saying don't put people in a room and talk at them for hours about security.
Give them a buddy. Who's there to help them in the office every day to help them carry out the actions you want in the system. Instead of trying to train everybody. One employee in each department is appointed to serve as a cybersecurity expert. This employee is close by to support colleagues.
Day-to-day available to answer questions about things like potential phishing messages. And if the message does turn out to be a phishing message, the buddy can warn the rest of the department immediately, or they could help somebody with a question about how to send files outside the company. Securely many of our businesses, we have restrictions too on things like thumb drives and whether you can use them, if you can bring them in, I would, by the way, recommend if you are using thumb drives to get the drives that have encryption built-in that little thumbprint.
So I think this is phenomenal. The authors say that they have talked to some businesses that were doing this and he says, it's really worked well. They spoke to one of these cybersecurity experts. I don't remember. Experts right there, but they are the person that's been designated the expert within bat group within the business.
So he says first, he always thinks of the people that come to him for consulting with him. If the email's not a fish, he lets them know it's safe to click on the link, open the attachment. If it is a fish, he praises them. Their alertness. Now, all of this can also be mostly solved by really good email filters.
I'm talking about the cheap stuff, the stuff from Barracuda or some of these others that are out there. I'm talking about all levels of high-end email filters so that you rarely get. Any of these phishing emails. In fact, nowadays from our clients and we have hundreds of thousands of emails reprocess every week, we get maybe one fishing plain to every few weeks, maybe once a month, it can be done.
Take that pressure off your employees.
Coming up in this hour, we're going to talk about some old-school encryption, the Nazi enigma, cipher machine. Another one was found.
Kmart just suffered another major attack using a new way of doing this stuff.
We'll talk about Alaska's voter database stolen. You listening to Craig Peterson. Thanks for being with me today.Â
My thoughts about a massively open election system. I think part of the problem we have with the elections is the fact that it's really quite closed. We had complaints in some States of Republican poll Watchers, not being able to do their duty and see those ballots as they were counted and were put in with one candidate or another, or this scanning that happened when all of the observers had been sent home, along with the media. It is not a good thing at all.
Then there's, of course, were the machines tampered with? I heard all kinds of stuff. I saw stories about every vote for President Trump counted for 0.75 of a vote. Every vote for Biden counted for 1.25 and on. I think there is an extremely transparent way to do this.
That will actually save the states a ton of money. We're talking about tens of millions of dollars per state saved and will dramatically increase the confidence that people have in the vote. What really happened with the vote? Let me just explain this simply. Simple's best, I grew up in the mainframe world and then the Unix world, and in the Unix world, rather than having one program that does everything, the whole idea is you have small programs that are very good at what they do. They're optimized for performing a certain function like sorting for instance. They might show you the date or who knows what? There are thousands of these little programs that are available in the Unix world, and you can tie them together.
Now. Microsoft tried to adapt and adopt the same type of technology using pipes and it has it, but it's not the same as a Unix world. Classic Unix is how long tail? How narrow can we make the function of this one little program? For instance, let's just use GREP as an example. GREP is a global regular expression program. So the idea is if you want to look for a pattern in a file, you can just say grep space and the pattern you're looking for, like Biden, for instance, and poof out of the standard output right there on your screen will come to every record with the word Biden in it.
It was very good at doing what it was doing. It was programmed in C, some of it in fact, would have been programmed in machine language. Particularly some of the library routines to make them very efficient. People wanted the more fancy stuff, so we ended up with FGREP and EGREPÂ all these different commands that did a different variation of searching for this pattern. But added things like Unix regular expressions, which have been adopted in many parts of the world.
What has not been adopted in Windows or now in the voting systems is that same concept. You get a machine like one of these ballot marking devices that are being sold and were used in the election this year that are far more complicated than certainly, these Unix commands we're just talking about.
So my proposal is let's go back to the basics and let's open it all up and make it so that the elections can be observed massively. Here's what my thinking is. This would absolutely work. If the State House wants me to go up and testify and put together some stuff, I'd be more than glad to.Â
Here are the basics. You've got your sheet to vote on. That sheet is the bubble sheet that many of us are used to. That bubble sheet you just fill it in with your little flair pen or whatever it might be. You fill in that little bubble for the person or people that you're looking to vote for or the cause you're supporting in a referendum or whatever it might be.
Then the State, County, or whoever's doing the counting uses a simple scanning machine. Now it could be a fancy one, right? It could be one of these machines that'll scan a thousand per second. I don't really care. I'll actually probably get that fast, hard to handle the paper that fast, but it could be a very fast scanner.
It could be something that's very simple as well, depending on how many of these votes you need to count. So you've got the card, you're feeding it into the scanner.
We're talking about commercial off-the-shelf, regular scanners that are creating images. So the scanner spits out a PNG image or whatever it might be. I don't really care. It's probably better not to have it compressed. Just have the raw image and use a very standard image format that anybody can read and understand. So that's part one.
We're not talking about these fancy ballot marking devices, where you've got an Android tablet that may not have been updated or Windows Seven or heaven forbid some are still kicking around Windows XP voting machines. And then you. You touch the screen and Oh, magical out comes a paper tape with the people you voted for with a little scanning UPC type code over on the side that you then take, and it's run through the other machine and now your votes been validated.
There are so many things that could go wrong with that. So many things it's, first of all, it's really expensive, cause we were talking about a specially built machine to tabulate votes.
It isn't just a scanner. It has been set up. It is looking for the votes in specific places and then it tabulates them. Do you know how many things can go wrong with that? Even with the ballot marking device that I mentioned you are now relying on that ballot marking device to have been correct. How many times have we heard voters say my vote was changed from Trump to Gore. Wow. You probably ever heard that one. It was interim Trump to Biden or whatever might be. This would eliminate that you've got the card.
So now the secretary state's office or the County, or the city, whoever might be doing this particular plebiscite, this particular election, whatever it might now have all of these images. So let's say it's got a million, just for lack of a better number of these images in there. So these are the votes.
What happens next is. All of those images are posted online and they're posted online so that anybody can grab a copy of those images and look at them.
So now we can look for identical votes. We can look for these votes that have been fed through the machine dozens of times, right? You've heard those allegations.
We can look for the votes that were pre-printed, the votes that were copied on a machine, and then run through. We can look for all of these. very easily. If we have the images of the vote is available of the ballots.
So obviously you keep the ballots. Obviously, you're going to want to do some hand counts just to verify everything.
We have images of all of these votes available to us. The Secretary of State or whomever now can run two or three different pieces of tabulation software that aren't going to cost them a hundred thousand dollars or millions as in the case of some of these, we're talking about 800 bucks to buy the software, buy a license, use the software.
So I'm saying use two or three different pieces of software because it's different. People are going to code it up differently. Make sure it really is different, not like dominion, where all of these different systems are using the exact same software under the hood with maybe a few modifications to make it work with their hardware.
Completely different systems. So there's going to be some value judgments that are made by the software saying, Oh, this looks like a smudge more than a vote. So software A says that and then it flags it as I don't know what the hell this is. Then software B looks at it, it says, Oh, this is clearly a vote for Craig and chalks up to Craig. Then what can happen is people can be sitting at a terminal and every one of these questionable votes can then be shown to them and they can figure it out. If the initial ballots were all serialized without some sort of a good check digit on them, you can actually dig them up and look at the original if you needed to.
Talking about just disclosing everything. Now people can download all of the images of all of the votes that were cast. They can easily write software that looks for all kinds of discrepancies and tabulate it themselves. Of course, there's going to be now a bunch of people that are going to say, Oh, no, that was wrong my software did it better, whatever it is, but at least there's something to discuss.
If votes are fed into the system, especially if they're all serialized with a really good checksum on them, we'll know. It'll be obvious to even the most casual of observers. We're no longer counting on software that may have been written in Venezuela. Maybe tabulated in Germany, whatever. It's run locally, and you and I can check and double-check the results of the election.
That's my proposal. Anyways. I haven't heard it anywhere else, but I think this makes a lot of sense.
We've got a lot more to talk about.
Hey, we really are going to get to it. Now, the old technology that almost helped the Nazis, the national socialists win the war in World War II, the German enigma cipher. Another machine was just found.
Craig Peterson here.
Let's get into this whole rusty story. This is very cool. There's a story that's out there right now about some guys that were out dragging the Baltic sea. Now, if you're not familiar with dragging and what that's all about.
A lot of fishermen drag the bottom with their nets in order to catch fish, right? Certain types of fish. And in this case, there were divers that were going around the bottom of the Baltic sea, looking for discarded fishing nets. Those draggers often they'll get caught on something. Subterranean might be a mountain, might be a ship.
It might be who knows what? It might even be a World war two national socialist encryption machine, which is exactly what happened. This is one of the rarest of finds down there an Enigma encryption machine.
These things were absolutely amazing. I remember reading about them, studying them. Trying to understand how this all worked way back when I was very young and I, in fact, was just so enthralled with it. I wrote some software that basically did the same sort of thing.
This was basically like a typewriter, think of it, like a typewriter. If you haven't seen one it's electromechanical. The idea with encryption is that you have to obscure or the meaning of something, So how do you do that? And there are many different types of encryption and you can bury messages, even in the clear, inside of other things. pictures have been used a lot. Video has been used a lot. There are a lot of ways to hide messages.
Of course, if you're a fan of some of the different spy books out there, you're familiar with the idea of a cold drop.
There are many ways to, get a message across. Let's just leave it at that now.
There have been ciphers like the railroad cipher. You guys might've heard of that. The idea behind the railroad cipher is that, just a simplified version. If the tech says A really means G. we, for years on Unix, if we had something that might be considered offensive, we would post it on there in what's called rot 13. Rot 13 is just shifting the alphabet, remember 26 letters in our alphabet. So A through N I think it was L M N a would become, M through Z or whatever the right split is. I don't even remember anymore. It's so you would type something up. You'd send it out. It was encrypted by rot 13. Now anybody could break this encryption.
It's very easy to do. In fact, the readers who we were using at the time, just you just hit one button and it would rot 13, eight again, because of course, if you split the alphabet in the middle, And you use the last half of the alphabet, meaning the first half and the first half translating to the last half. You just have to do that again to see what's going on.
So there've been a lot of simple ciphers used over the years. Some of the best ciphers of course are book ciphers or one-time pads, but those are not particularly useful in wartime, back in the day.
Nowadays we're using them a lot more. So what the Germans did is they invented this machine and it had three or more of these rotors in the machine. And as I said, it looked like a typewriter. So you would hit the letter a, if it was a railroad cipher that we talked about, it might come out as a G every time. So if I said, how are you today? If someone typed enough in the message was long enough when we had enough examples in order to break that encryption, all we'd have to do is look at the repeats here. How many times does the letter G show up? it shows up at the same frequency as a letter A, therefore we can assume that letter G and the encryption is really an A and solve it. The national socialists knew this, right? They didn't want other countries to know what the socialist government was doing and where they were directing the Wolfpack submarines to sink the British and American ships.
So what the socialists did is they had these three rotors and every time you typed a letter, the rotors would turn. So basically what you were doing is like the railroad cipher, where a is G, but the next time you, for instance, you typed two A's in the row. The next time you typed a letter, those rotors would've moved.
So a would no longer necessarily be G a might be Q. Now. And so what would happen is that little typewriter and Enigma device would have a little light that would show up under the letter Q so you'd know. Okay. Q. So they'd write it down and then they'd usually be sending it off by a Morris code. A is much easier to send than Q is, by the way. But they would send that out in Morse code, which is really neat.
The idea was they would start the rotors. Those three rotors would be started in a certain position. And that way, if you typed in that message, now that queue would become an E, et cetera. So there'd be a nice direct translation. They also were supposed to change those initial settings every so often in the codebooks, So the initial settings would be one way for a week. And then the next week they'd be a different way, but they got lazy and they stopped changing the codes. You might know that the whole story of what happened and how we broke the socialist code and how we were able to then defeat the socialists in World war II, which is just a phenomenal thing. Where they were trying to just gain power, gain power, gain power, and eventually try and take over the war world. So very cool.
And if you aren't familiar with this, if this is something that intrigues you, you do look it up. There are videos, it was a machine you can actually buy. I saw one on eBay, a German enigma machine that was not a real one. It was a reproduction, but they worked then and they still work. Now. They're actually pretty good.
We're doing much better now with our encryption, believe me. But it's funny, looking at this lead diverse statement, Florian Huber who told the DPA news agencies as a colleague swam up and said, there's a net with an old typewriter in it. They pulled it up and, had a look and the diver said that I've made many exciting and strange discoveries in the past 20 years, but I never dreamt, we would one day find one of the legendary enigma machines. The divers suspecting, and I think correctly here, that the enigma was lost shortly before the German socialists surrendered in May 1945.
At that time, the Nazi leaders issued an order for the submarines to be scuttled up in this Bay to prevent their capture by allied forces. They also tossed all of these enigma machines overboard.
So credit to Alan Turing, a phenomenal man, brilliant man, very troubled man, as well, but he was able to break the encryption. It's a fascinating story. Watch the movie about it. If you haven't. I absolutely enjoyed that movie. It was all kinds of breakthroughs that were made by scientists from the Polish Cipher Bureau that made it possible for the allies to decipher the messages about the German military movements. Absolutely fascinating.
Then of course you get into the second part of the problem. How do we use this information? Because we don't want the socialists to know. But we know what they're going to do next. It's fascinating.
We've got more coming right up. We're going to talk about a newer type of ransomware attack and how Kmart fell victim.
Hopefully, you got my email last week, my newsletter, where I went through the steps that the latest types of ransomware are taking in order to get even more money out of you. They got Kmart too. So here we go. I guess I don't have an I told you, so isn't it.
Craig Peterson here. Thanks for sharing your time with me this afternoon. I appreciate it. And if you have any questions, by all means, drop me a line. One of the questions I do have for you though, is what is it you enjoy most about the show? Let me know. Cause that's going to help me, help you with the show. Just email me [email protected]. What is it that you enjoy the most about the show? I've had lots of feedback from you guys over the years, and I'd love more. Make sure I keep up to date and get you guys the information you're interested in.
By the way, I also have some training courses coming up, so I'll make sure you keep an eye out for that. You'll find them in my newsletter when I have them. So make sure you're on that list. Craig peterson.com. If you want a copy of last week's newsletter about ransomware, just drop me a note. I'd be glad to forward you a copy. Just email me [email protected], and you'll get it. Me. Yeah. Just as the name implies.
Man, the poor guys at Kmart. Who remembers it, K-Mart used to be the place to go. The blue light specials. You'd keep an eye out for that. While you're in the store. It was really fun.
Reminds me of Sears in the day, going there. Do you remember, are you old enough to remember getting dressed up to go to Sears. Now, Oh my gosh, these poor companies. Sears owned, what was effectively the online shopping business, 120 years ago. The Sears catalog. Every year for Christmas or for birthdays or other special events. We would get a copy of the Sears catalog and we'd go through, we'd dog-ear pages, where there was stuff that we wanted.
Do kids even know what dog-ear pages are anymore? But dog-ear those pages and just enjoy dreaming of it. You could order a house on Sears catalog back in the day. Sears completely missed the online shopping revolution. They could have owned it. They had the distribution in place. They had the catalog technology in place. I knew how to do all of this stuff, but they decided they would stick with the old ways and, that didn't work out so well for them, but they still were doing better than Kmart. Kmart was going under and Sears bought them. Well, Sears holding company originally owned both Kmart and Sears.
Sears Holding Corp filed for bankruptcy in 2018. It was bought by this transform co in 2019 K-Mart, which was a household name that was multinational. I remember them in Canada. Is now down to 34 stores remaining. Isn't that amazing? I'm thinking about our local, K-Mart just, Oh my gosh. But it is still open. They still have the stores. They had originally over 2100 stores in all 50 States. It's a very sad time for Kmart. It really is. I'm looking at some pictures of some of the stores that are open right now. It's a problem. It's a real problem.
Now they've had another problem.
Bleeping computers reporting, and they also have some great articles. You can check them [email protected] that Kmart suffered a cyber attack by the Egregor ransomware operation this week. Now they found at bleeping computer because they went to Transform Co human resources site, which is 88sears.com.
Now I went there this morning and it is online. It is their human resources page, but then when they brought it up, they found that indeed they were suffering an outage and they have posted bleeping computer on their website, a screenshot of that outage now, Egregor is known for stealing un-encrypted files before deploying the ransomware.
The bottom line is they're going to nail your twice. A lot of these bad guys. Nowadays, what they'll do is they'll grab your files. They'll download them and then they will encrypt them. And that isn't what Egregor does. And then they will put up then all too familiar, ransomware notice. You've seen it before, That red screen, demanding payment, and almost always in Bitcoin. And you can then hopefully find some Bitcoin, send them some money and you're off and running. And remember, I reported this a couple of weeks ago. If you pay a ransom, you could be in big trouble with the feds. And the reason for that is you are supporting terrorist organizations.
So you could indeed end up not only being sued by the Feds but going to jail over, paying a ransom. So think about that one. But they've escalated it now. So even if you pay the ransom or you don't pay the ransom, some other guy's going to come along. it's really the same people.
Okay. Some other guy's going to come along and say, Oh, guess what? I have your files. And they'll send you a list of the files and they'll probably send you some samples of some of the word docs or spreadsheets. And then they'll say, Pay up now, they're extorting you saying if you don't pay up. We are going to post your data online onto one of these data leaks sites.
And there are many of them. I'm looking at a list of them right now that bleeping computer is published, a through Z, and believe me, there are a lot of them out there. And so many of these look absolutely legitimate. Man alive. Do they ever, but with the Gregor, they will now say, I want to say, thanks for paying us the ransom on the encryption.
but they'll say, okay, now you owe us money or we'll post it on one of these sites and they do, and it's legitimate. Okay. What happened here apparently is that the bad guys targeted Kmart human resources website. And if it, if all of this is correct, Egregor would have stolen all of the data that was on that web server, about all of the employees within this.
Company. Okay. This transform co full name is Transformhold Co, LLC. So they are in some trouble. I'm sure if this really happened. And I've got to also add into all of this, that most of the time, these businesses don't actually know what was stolen because they don't have logs sufficient enough for logs at all.
To tell them exactly what happened. So a very big deal. It's a scary thing. And I went into it as well as what you can do about to help stop it in my newsletter last weekend. So if you miss that, have a look in your email box. If you need me to send another copy to you, just drop me a note me M E at Craig Peterson.
And I'd be glad to do that. But this is the next evolution and it works really well for businesses because think of the other angle, these bad guys have, they can get money from you. To give you the decryption key. They can get money from you in order to not release your data, which they may release anyway.
But they know who you are because they have your files. So they know you are a doctor's office and they'll charge you more. Or they know that you're a manufacturer in the DOD department of the defense supply chain. And so they'll extort even more out of view. Okay. very bad. yeah, it's a shame.
Good old Kmart. Oh, she's still around, I guess it'll be around for a little bit longer, but this sort of stuff is really happening. This can be the death nail and it is the death knell to the majority of companies. It happens too. Hey, stick around when we get back. Oh my goodness. I can't believe this.
We're going to talk about the Alaska voter database hack and more including police live streaming your Amazon Ring camera.
I guess our election system isn't as safe from hackers as we might've thought. We're going to talk about hackers breaking into an Alaska voter database.
We'll be talking about police piloting a program to live stream Amazon ring cameras and more.
Craig Peterson here. I talked about what I think the answer is to technology and the elections. In fact, what I described at the top of the hour would completely eliminate some of these major technology problems without a doubt.
This is a different type of problem from the gateway pundit.com, which you can find online.
Alaska state officials reported that hackers stole personal information for more than 100,000 individuals from the state voter database, that's a very big deal. Alaska is saying that information included birthdates driver's license numbers of more than a hundred thousand Alaskan voters.
If you think about these voting databases in most States, they are also going to contain your signature. They're going to have your home address. They're going to have a lot of information from you. Okay.
Now they stressed that there was no effect on the results of last month's election. Oh, okay. But your personal data was stolen and that's part of the reason I have such a problem with the driver's license databases as they are in most States. They also include things like your social security number now and think of these real ID licenses that are now being issued. I don't even want one of the silly things, but in most States, you're being forced into having one.
I've already got a passport, which is good enough for me to get in and out of the country. Why do I need one of these tamper-proof supposedly driver's licenses with all of the data that they're collecting? Think of what you have to do to get one of those things. You have to prove your residency. You have to prove all of this other stuff. I don't know. Maybe it's going to be a good thing for voting anyway, because if you have to present this type of ID, at least we know that you're legitimate.
Then there's California and that's a whole other issue.
It says the hackers gain unauthorized access to the data and the state's online voter registration system. It was built and maintained by a contractor and operated by the Alaska division of elections, goes on and on talks about the sad news.
So officials said the flaw that exposes the data has been fixed and Alaskan's information is now secure. Isn't that wonderful?
Now that the horse is out of the barn, they're going to close the doors, but it's still not known exactly which records were stolen. Again, that's a real problem. Most regulations that are out there for the private sector require us to know was stolen.
Oh, gay. let's keep all of that in mind. Just don't trust this stuff. I don't trust it to, the government. I don't trust it to, private companies. Look at what happened with Equifax. Basically, all of our personal information was stolen probably by the way, by the Chinese government. Anyhow, we talked about something similar to this next article fairly recently, and this is from eff.org electronic frontier foundation. They're very much a very pro-free speech place to a degree. As long as your speech agrees with them. But they want open software and, they do want to help keep more basic information safe, the civil libertarian side of things.
Let's see. So the police surveillance center in Jackson, Mississippi is going to be conducting a 45-day pilot program to live stream the security cameras in Jackson, Mississippi, including the Amazon ring cameras from residents who are participating. The idea behind this is it gives the police department real visibility, live visibility into neighborhoods.
So they can record it as well. They can play it back. If there are porch pirates, those people that are stealing our Amazon packages out there, they can hopefully find them. Of course, if there's a porch pirate that just stole your package. you've probably got them on tape, right?
So you can do a little bit of something about that. I have multiple cameras out there doing it, but the police want this live stream. Now there've been stories out there in the past about ring cameras being used by the police. in some cases, these stories have said that in the, in fact, the police departments, according to these guys have been doing it without a warrant.
in fact, that's going to be the case here again in Jackson, Mississippi, because people are going to be able to opt in to this program. So it sounds like they're trying to do some of the right things. There are concerns here from the EFF about rings 1000 plus partnerships with local police departments.
And that's kinda what I was talking about back in June this year, but there are a lot of people that are concerned about the police department, and you've probably heard of this socialist-communist in fact group called black lives matter. That has been out there protesting the police, defund the police, all of the things that have been promised to us about just drawing a lot of the local police departments. This is a real concern because people are buying ring cameras and these other cameras and putting them on the front door effectively to help keep the packages safe. The police are using them to build these comprehensive closed-circuit TV camera networks that are blanketing whole neighborhoods and it allows the police departments to get that type of video feed without having to buy surveillance equipment.
Think about what some of our local cities have done to put in surveillance cameras. It's really rather expensive. Then the second point here that E FF is making, is that evades the natural reaction of fear and distrust that many people would have if they saw cameras up on the street lights.
By the way, some of these new street lights do include cameras that are fed to the police department. Okay. So they are there, but they're hidden away. It's Oh, it's Joe's doorbell is basically what it is and it's supposedly. Going to be a little bit safer, but the police and these thousand different partnerships with different police departments now are allowing them to set up an array of cameras without anybody really noticing, by the way, Jackson.
Was the first city in the Southern United States to bland banned police use of face recognition technology. So they understand this invasive surveillance technology, but, in this case, maybe they've overstepped their bounds. They've got, also by the way, this national movement called community control over police surveillance.
See cops. These are different ordinances. The residents have put through legislatures in different States that have more say in whether or not please can build a program like this. I also have had concerns over the years about the ability to videotape or record, official police or otherwise in the performance of their duties.
Main is what is known as a single-party state, which means only one person who is part of that recording needs to be aware of the recording. And they, one person has to say, yeah, okay. I'm going to record, but the other person on the other end of the line or the other end of the camera doesn't have to say anything.
New Hampshire and many other states are two-party States. In other words, Both parties or all parties that are part of that recording have to consent to be recorded. So something like this ring system really could be a bit of a problem. And depending on the state you're in Maine, wouldn't be because you knew you had a camera up.
I think in most States, including New Hampshire, you would, which is a two-party state. I think you're are going to be safe enough because. You got a Ring doorbell with a camera. I think most people nowadays know that it could be recording what's going on and I have security cameras up as well. And you might want to do the same thing.
I use security cameras that meet the federal department of defense standards. Okay. they ain't feeding ring or anybody else out there, but it's something to seriously consider. the last article here before we disappear is about the cybersecurity pandemic that's going on right now. This is a scary thing.
It's a big thing. The next war is really worldwide going to be a hybrid war. We're already seeing that where businesses and governments are targeted by cyber attacks. There's espionage going on. I've told you about some of the clients I've picked up because something weird was happening and we looked into it and we found.
Direct evidence of espionage and got the FBI involved. That it's amazing what's going on. But the threat from hostile nations like China, Russia, Iran, and North Korea is really growing. And we've got our critical national infrastructure. Now such as your water, electricity plants that are relying on network connections and also.
for changing valves, opening, closing them as well as for monitoring, we've got these SCADA systems, which are also used for monitoring and control in our manufacturing plant. This is a bit of a problem. And particularly when we think now about all of these people that are at home, working from home, that may be connected to a business.
That is part of our critical national infrastructure and they don't have the right kinds of security. It's it is mind-blowing. Anyway, I'm thinking about doing something about this article we talked about earlier from the wall street journal, the buddy system. Where you can really increase the security of your business by using it.
I'm thinking, how can I help with that? I'm not sure yet we'll figure out how I can help you with that sort of thing. Maybe we should just have a little report line where you can send stuff and let me know, and I can respond. Let me know at [email protected] and we'll be back next week.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Good morning everybody!
I was on WGAN this morning with Matt Gagnon and started this morning talking about a radical new way to assure transparency and validity in our Elections. Then we got into the Cybersecurity Pandemic we are facing and how the COVID-19 pandemic brought it about. Here we go with Matt.
And more tech tips, news, and updates, visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Matt called it a radical idea this morning, and frankly, I think it is. I think I've come up with a way to fix one of our elections and technology's biggest problems.
Hey, Craig Peterson here. I was on with Mr. Matt Gagnon this morning over on WGAN and carried on other stations throughout Maine and down in New Hampshire. Anyhow, here we go with Matt.
I think this is an excellent idea. I'm going to have to do a little more about this thing.
Matt Gagnon: [00:00:36] Let's turn to Craig Peterson, our tech guru, and let's get some thoughts here on technology. Craig, how are you? This one?
Craig Peterson: [00:00:43] A good morning. And you know what? I've got some fonts on how to make this election go way more smoothly in the future.
Matt Gagnon: [00:00:49] Do you now?
Craig Peterson: [00:00:51] Yeah. We've got the internet today, and part of the problem, I'm not going to get into all of this, but we've got these machines in some States called ballot marking devices just on the technology side.
We have other machines that are just basic touchscreens, but a BMD, A ballot marking device, is one where you've got a tablet, and some of these are Android. Many of them are Android-based, which you already know. I'm not too fond of it from a security standpoint, and they will spit out a little ballot, a paper ballot that you can take. That ballot now says, Oh, you just voted for Joe Biden and Joan and Jane and whomever, and it has a bar code. That bar code is what's actually read by the machines for your vote.
There are so many questions. Yeah. It says, I voted for Biden but did my vote actually counts for him? I don't know what the barcode names. We've got the problems. Potentially the device, whether it's windows seven, which is used in a lot of these machines, Windows XP is still. Android et cetera.
Let's make this simple. These machines are costly. States are spending tens or even hundreds of millions of dollars. Buying them.
All we need to do is have a card just like we're used to voting on where you fill in the bubble. Then buy normal every day scanners, just off the shelf things, and make sure they're up to date. People do their voting. The machines then read the votes and now have an image. Obviously, there has to be a chain of custody, and everything else like you'd normally have. But most of the images now can just be run through some very inexpensive software. I found a company out there that has $800 software. That software does the grading.
Here's where the confidence in the vote I think would come in. You could then post all the ballots online for anyone, basically, to download that wants to download them.
Maybe even like to do a check on ballots where you have a couple of different people manually counting to make sure the machines are right. Why not use two or three?
Craig Peterson:[00:03:11] Three different pieces of software to grade those ballots. Then have people have a look at them. Have any voter that wants to examine the ballots examine them digitally, with, of course, all of the right chains of custody,
Matt Gagnon: [00:03:24] Radical transparency then is what's your,
Craig Peterson: [00:03:27] Absolutely, and it's cheap. It is way cheaper than what we're paying right now for these various machines.
Matt Gagnon: [00:03:34] Yeah, I remember I don't know how many years ago this was, but probably 2013, maybe even earlier than that. Yeah, no, it was earlier than that. It might've been like 2009. Now that I'm thinking of it.
When I was living in Virginia, I went to vote. The machine that I had there to vote on, I was blown away by it because I was used to the Maine system where you, you fill in bubbles on a piece of paper, and you feed it into the machine, and it does basically, what you just said outside of providing you images and stuff.
It had a scroll wheel. I felt like I was playing like Golden Tee or something. I had a scroll wheel and digital thing where I made my selections for whichever office it was, and I selected it. I pushed the button, and I had no physical interaction with a piece of paper or anything. It basically just said, thank you for voting.
Then I left. At the same time, I didn't really actually doubt that my vote was counted and all that other stuff. It did skeeze me out a little bit. It didn't feel real to me.
Craig Peterson: [00:04:20] I'd move beyond that. I think radical transparency is a way to do it. Even the machines that we use in Maine. They are special, dedicated, purpose-built voting machines. We don't need that. We really don't.
Anyhow. My opinion on it.
People could have a lot more confidence in the votes if we did something this simple and really observable by anybody.
Matt Gagnon: [00:04:45] That's a good suggestion. Oftentimes we try, in terms of simplicity here, we try to go more complicated and have more machines do more crazy things when something like this should be as easy and simple as possible with as much verifiable tracking as you could have.
To verify it is what it is, right? Yeah. But it's a, and it's a big topic. There's got to be some congressional action on voting in general soon. Whether you thought the election was stolen or you don't think it was stolen?
I would hope that most regular people, rational people, know that whatever we just lived through, it was probably not the best way to do it. So we'll see. We'll see.
So Craig, before I let you go, we got a couple of other topics to get to, that we've been talking about a pandemic, in our health, of course, for a while now. Is there also a cybersecurity pandemic that is running rampant around us now?
Craig Peterson: [00:05:30] Yeah, it's really become a huge problem because of the lockdowns, frankly. People working from home, the systems were never designed for this. Our cable carriers carrying most of our internet data from our homes are saying they've seen a four X increase in the amount of use. We've got machines at home that have who knows what, if any security or security stuff on them.
It's become a huge problem that the bad guys are really leveraging right now. They have, as you saw in my newsletter, this last weekend just changed their tactics. They are going, still for some of the ransom stuff, but now they're not just holding your data hostage by saying, Hey, listen, if you want your data back, pay up because it's all encrypted.
Now they're saying, Hey, if you don't pay up. We're going to release all of your data onto the internet. They may do it anyway.
During this whole lockdown crisis, we have really taken some major leaps forward in going online. I'd say probably 10 to 15 years in advance of what we would have done previously.
We not only have those bad guys, those criminals, but we've also now got Russia, China, and North Korea, and Iran that are all growing their capabilities, and they have been using it to attack us. As I've said before, we really have fired the first shots on world war three, and they are digital. They are probing for weaknesses, frankly.
In this day and age, we really do have a cybersecurity pandemic in our businesses. And a lot of it's caused by the lockdown and people working from home when the systems just were not set up for it.
Matt Gagnon: [00:07:20] Well, Craig Peterson, our tech guru, joins us at this time every week to go over technology in the world of technology.
He has a show on Saturdays. If you want to hear more, make sure you tune in for that on Saturday at one o'clock, where you can hear this and so many more topics gone into in greater depth.
Craig, I appreciate it as always, and we'll talk to you next week.
Craig Peterson: [00:07:38] Take care.
Matt Gagnon: [00:07:39] You bet.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Good morning everybody!Â
I was on WGAN this morning with Matt Gagnon and started this morning talking about a radical new way to assure transparency and validity in our Elections. Then we got into the Cybersecurity Pandemic we are facing and how the COVID-19 pandemic brought it about. Here we go with Matt.
And more tech tips, news, and updates, visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Matt called it a radical idea this morning, and frankly, I think it is. I think I've come up with a way to fix one of our elections and technology's biggest problems.
Hey, Craig Peterson here. I was on with Mr. Matt Gagnon this morning over on WGAN and carried on other stations throughout Maine and down in New Hampshire. Anyhow, here we go with Matt.
I think this is an excellent idea. I'm going to have to do a little more about this thing.
Matt Gagnon: [00:00:36] Let's turn to Craig Peterson, our tech guru, and let's get some thoughts here on technology. Craig, how are you? This one?
Craig Peterson: [00:00:43] A good morning. And you know what? I've got some fonts on how to make this election go way more smoothly in the future.
Matt Gagnon: [00:00:49] Do you now?
Craig Peterson: [00:00:51] Yeah. We've got the internet today, and part of the problem, I'm not going to get into all of this, but we've got these machines in some States called ballot marking devices just on the technology side.
We have other machines that are just basic touchscreens, but a BMD, A ballot marking device, is one where you've got a tablet, and some of these are Android. Many of them are Android-based, which you already know. I'm not too fond of it from a security standpoint, and they will spit out a little ballot, a paper ballot that you can take. That ballot now says, Oh, you just voted for Joe Biden and Joan and Jane and whomever, and it has a bar code. That bar code is what's actually read by the machines for your vote.
There are so many questions. Yeah. It says, I voted for Biden but did my vote actually counts for him? I don't know what the barcode names. We've got the problems. Potentially the device, whether it's windows seven, which is used in a lot of these machines, Windows XP is still. Android et cetera.
Let's make this simple. These machines are costly. States are spending tens or even hundreds of millions of dollars. Buying them.
All we need to do is have a card just like we're used to voting on where you fill in the bubble. Then buy normal every day scanners, just off the shelf things, and make sure they're up to date. People do their voting. The machines then read the votes and now have an image. Obviously, there has to be a chain of custody, and everything else like you'd normally have. But most of the images now can just be run through some very inexpensive software. I found a company out there that has $800 software. That software does the grading.
Here's where the confidence in the vote I think would come in. You could then post all the ballots online for anyone, basically, to download that wants to download them.
Maybe even like to do a check on ballots where you have a couple of different people manually counting to make sure the machines are right. Why not use two or three?
Craig Peterson:[00:03:11] Three different pieces of software to grade those ballots. Then have people have a look at them. Have any voter that wants to examine the ballots examine them digitally, with, of course, all of the right chains of custody,
Matt Gagnon: [00:03:24] Radical transparency then is what's your,
Craig Peterson: [00:03:27] Absolutely, and it's cheap. It is way cheaper than what we're paying right now for these various machines.
Matt Gagnon: [00:03:34] Yeah, I remember I don't know how many years ago this was, but probably 2013, maybe even earlier than that. Yeah, no, it was earlier than that. It might've been like 2009. Now that I'm thinking of it.
When I was living in Virginia, I went to vote. The machine that I had there to vote on, I was blown away by it because I was used to the Maine system where you, you fill in bubbles on a piece of paper, and you feed it into the machine, and it does basically, what you just said outside of providing you images and stuff.
It had a scroll wheel. I felt like I was playing like Golden Tee or something. I had a scroll wheel and digital thing where I made my selections for whichever office it was, and I selected it. I pushed the button, and I had no physical interaction with a piece of paper or anything. It basically just said, thank you for voting.
Then I left. At the same time, I didn't really actually doubt that my vote was counted and all that other stuff. It did skeeze me out a little bit. It didn't feel real to me.
Craig Peterson: [00:04:20] I'd move beyond that. I think radical transparency is a way to do it. Even the machines that we use in Maine. They are special, dedicated, purpose-built voting machines. We don't need that. We really don't.
Anyhow. My opinion on it.
People could have a lot more confidence in the votes if we did something this simple and really observable by anybody.
Matt Gagnon: [00:04:45] That's a good suggestion. Oftentimes we try, in terms of simplicity here, we try to go more complicated and have more machines do more crazy things when something like this should be as easy and simple as possible with as much verifiable tracking as you could have.
To verify it is what it is, right? Yeah. But it's a, and it's a big topic. There's got to be some congressional action on voting in general soon. Whether you thought the election was stolen or you don't think it was stolen?
I would hope that most regular people, rational people, know that whatever we just lived through, it was probably not the best way to do it. So we'll see. We'll see.
So Craig, before I let you go, we got a couple of other topics to get to, that we've been talking about a pandemic, in our health, of course, for a while now. Is there also a cybersecurity pandemic that is running rampant around us now?
Craig Peterson: [00:05:30] Yeah, it's really become a huge problem because of the lockdowns, frankly. People working from home, the systems were never designed for this. Our cable carriers carrying most of our internet data from our homes are saying they've seen a four X increase in the amount of use. We've got machines at home that have who knows what, if any security or security stuff on them.
It's become a huge problem that the bad guys are really leveraging right now. They have, as you saw in my newsletter, this last weekend just changed their tactics. They are going, still for some of the ransom stuff, but now they're not just holding your data hostage by saying, Hey, listen, if you want your data back, pay up because it's all encrypted.
Now they're saying, Hey, if you don't pay up. We're going to release all of your data onto the internet. They may do it anyway.
During this whole lockdown crisis, we have really taken some major leaps forward in going online. I'd say probably 10 to 15 years in advance of what we would have done previously.
We not only have those bad guys, those criminals, but we've also now got Russia, China, and North Korea, and Iran that are all growing their capabilities, and they have been using it to attack us. As I've said before, we really have fired the first shots on world war three, and they are digital. They are probing for weaknesses, frankly.
In this day and age, we really do have a cybersecurity pandemic in our businesses. And a lot of it's caused by the lockdown and people working from home when the systems just were not set up for it.
Matt Gagnon: [00:07:20] Well, Craig Peterson, our tech guru, joins us at this time every week to go over technology in the world of technology.
He has a show on Saturdays. If you want to hear more, make sure you tune in for that on Saturday at one o'clock, where you can hear this and so many more topics gone into in greater depth.
Craig, I appreciate it as always, and we'll talk to you next week.
Craig Peterson: [00:07:38] Take care.
Matt Gagnon: [00:07:39] You bet.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed the current Cybersecurity Pandemic and Phishing and what happened to Jim Polito, the host, this past week and then hit on travesty to the American worker through the H1B Visa program and how Facebook and other Big Tech is front and center with it. Here we go with Jim.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Automated Machine Generated Transcript:
Jim Polito: [00:00:00] I was afraid to answer the email. Cause I, I said, wow, has this been hacked. Have they been hacked? No, it was a valid email. Then I got some other emails from Google saying somebody used one of your email accounts, so I sent it to Craig. I said Craig help me here.
Craig Peterson: [00:00:21] Good morning, everybody.
Craig Peterson on with Mr. Jim Polito looks like we've picked up another station. That's kinda cool. W H J J, I think it is down in Rhode Island. Well, Jim picked it up, but I'm along for the ride. So that's kind of fun. We talked a little bit about that this morning. Jim's problem where he got hacked so we went into that.
We also got into H1B visas and how they are hurting badly the US job market, and between you and me, I'm very concerned about what Joe Biden's going to do if he takes office with this whole program. So we got into all of that this morning. And here we go with Mr. Jim Polito.
Jim Polito: [00:01:05] Here he is the man. Every Tuesday at this time he joins us. Boy, he got me out of a jam last week. I am talking about our tech talk guru and good friend, Craig Peterson, Craig say hello to Rhode Island. We are now the network has expanded to W H J J, a landmark and legacy station in Rhode Island.
Craig Peterson: [00:01:33] Hey, good morning, everybody. Man, Rhode Island, of course, Central, Western mass parts of Vermont today. New England tomorrow, The world.
Jim Polito: [00:01:44] Well, I don't know about that. The guy who, kind of, coined that expression, I don't know if I want to be affiliated with him, but, Craig, just so folks, I can introduce you to Craig Peterson, in Rhode Island and we don't make this up. Craig Peterson actually wrote code that is still being used on the internet. So unlike Al Gore, he truly did play a role. In inventing the internet.
Now he has his own company and he graces us out of the goodness of his heart, with a great, great visit once a week. And he's got a show on T A G and H Y N. That is fantastic on the weekends. But the best thing is that he's here with us and I'm his shall we say lab experiment because boy, Craig, did you help me out last week? Saved me.
Craig Peterson: [00:02:38] Oh, thanks. You know what Jim what happened to you, happens every day to people. So many people just don't understand some of the things. I look at it as the basics, right?
There's something that's known in expert circles. I'm going to put it this way. Knowing too much and not remembering too to not know this stuff.
I'm so glad to be able to be on every weekend. Talk about this stuff and really explain it in ways that I hope people can understand a little better.
Jim Polito: [00:03:10] Yeah. So let me just tell everybody what happened. I got an email from someone in corporate human resources. Now, remember iHeart is a very big company. We are very local in all of our stations and the iHeart radio app can go from the big, big stuff, like concerts right down to local with us. But here's the thing about getting an email from a company. I'm looking at it saying, is this real? I looked up the person in the directory Oh, okay, that person does work for the company. But it said someone has applied for unemployment. We have something here that you've applied for. I'm like, Oh my God.
Well, first of all, Craig. My first reaction was, wow, I'm already out. That's it. This is how the company is telling me. Then the other reaction was, I was afraid to answer. Because I said, wow, has this been hacked? Have they been hacked, but no, it was a valid email.
I got some other emails from Google saying somebody used one of your email accounts, so I sent it to Craig. I said Craig help me here. Lo and behold Craig, it was real. Somebody got my information and applied for unemployment.
Craig Peterson: [00:04:35] We looked up your email addresses and I found them in a whole boatload of breaches of other information out there. I think Jim didn't we find your name, your home address, obviously your email password? Weren't what, all of those in there, as I recall.
Jim Polito: [00:04:53] I think so. Yeah. I mean, somebody had really, somebody really got in there. Um, and you know, uh, I responded to human resources. They were great and right away, they sent me back an email, which was very helpful, Jim.
Here's what you need to do, get to your credit right now and freeze it, all of it, lock it down, you know?
And, uh, luckily so far, I don't think anything, you know, has been an issue. Um, but Craig, we talked about it, Massachusetts. It was an issue. In other states like Rhode Island, it's been an issue.
Um, you see it in the news, they're talking about people, uh, trying to take advantage of the, um, the benefits that came out earlier in relation to COVID and to scam, take someone else's identity and do something with it.
Craig Peterson: [00:05:47] Absolutely, we're calling it now a pandemic. This is a cybersecurity pandemic that's really been triggered by the lockdown, by the fear of COVID trying to understand that. Also of course the big deal with the lockdown is so many people are working from home, look at you, and pop they're at home. Right.
You've got the technology to connect to the radio station. But because of that, now employees are on insecure devices in their homes, utilizing their own networks. We now have seen this massive pandemic of identities being stolen of all kinds of fraud, not just what we've known for a while called business email compromise, where you get an email and it's trying to trick you.
Into doing something, but it's not necessarily from someone you know.
Now we're seeing email account compromise where the bad guys are taking over an email account, using the information that they have found on the dark web about each one of us. Now you will get a legitimate email that is from someone legitimately in HR.
And in fact, it's really not a legitimate email, but everything about was. They took over HR's email account.
Jim Polito: [00:07:08] Yeah. I mean, the other thing I did is, you know, folks who don't have, you know, access to a lot of other, uh, checks and, you know, um, I called, you know, the best thing to do is, okay, I got an email from this person I called and said, Hey, what's going on here?
So that's always a good backup, but you know, I get so much of that email in accounts, you know, I'll have an, uh, an email come to me, you know? Uh, and then, uh, and then, uh, I've got about one, two, three, well with work and then like three other emails. And it's just because I've had them for so long. I just keep them.
But. Um, they're not as active, but I'll get an email to one of those accounts saying, Hey you need to reset your Amazon password. I was like, this is not the account I set up Amazon with, like good try guys. This is not the account, but you do worry about some other things. You take a look at it and say, I don't know for sure.
I'm worried. And a phone call is always a good thing for people to do. And I know you've recommended that in the past too. Unless the person on the other end of the line has an Eastern European accent. Right. And it could just be a coincidence that the woman in HR is from, I don't know, one of the Eastern European nations.
She, she could be Moldovan. Right. you never know, so, that's a good thing. And that's something people have to look out for.
But you know what I want to, I want to really discuss with you, other than bringing the attention of what happened to me, to everybody to be mindful of it. Watch out, somebody may try to get unemployment in your name.
Hey, what's this thing about Facebook hiring foreign workers over US workers, and isn't ole "Zucky" breaking the law by doing this.
Craig Peterson: [00:09:08] This has been a soapbox subject of mine forever. You talked about these people trying to deceive you. My daughter got a voicemail from the IRS. They called her out of the blue and you're absolutely right. Don't respond to the email by all means. Don't click on the email. Pick up the phone. You did such the right thing.
The Zuck here, this has been one of the things I've been talking about, not specifically with Facebook, but for well over a decade.
We put a program into place to allow immigrants to come to the United States to do specific jobs. So here in New England, we have a lot of people that come to our Ski Hills, for instance, to work in the winters. Many of them are from in fact Eastern European countries and they come here, they get exposure to the US and there we're able to bring those workers in because we can't find enough. People to work here on some of the ski Hills with these seasonal jobs, people want permanent jobs and I can understand that sort of thing. So that made a lot of sense.
Congress decided, Hey, you know what? We need tech workers because it happened forbid we just don't have enough tech workers in the US. Even though right now, there are many of US that are out of work and have been for ages.
So here's what's happened just on Thursday less than a week ago, the Department of Justice sued Facebook because apparently what they have been doing is they've been bringing in foreign workers to work in the US.
You say, wait a minute, Craig is isn't it people looking for work and the answer to that is yes.
And they might even want one of these jobs. Jim, did you see the average salary of more than $156,000 a year?
Jim Polito: [00:11:02] That's what they say is a good job at a good wage.
Craig Peterson: [00:11:05] Yeah, exactly. So what Facebook apparently has been doing, and this is the allegation in the suit is they've been advertising these positions as being open, which they're required to do under the law. Let's Americans know about the jobs and what the qualifications are, and then they can apply.
Well, apparently what they've been doing is advertising the jobs in little local newspapers that no one reads and looking at the statistics, the job between July 2018 and April 2019. Okay. 81% of these 1100 jobs, 81% did not receive a single applicant while another 18% received just one applicant such add that up 81 plus 18%. Oh my gosh. 99% of the jobs didn't get applicants.
So my gosh, we've got to go overseas to find people to work here.
Jim Polito: [00:12:05] That is that's so sleazy.
Craig Peterson: [00:12:09] Isn't that something. Well, yeah, the deal Jay said also earlier in 2018, Facebook advertised 22 openings for art director jobs and they had more than 2,600 applications for those jobs.
Okay. So obviously if they advertise in the right place, maybe even on their own platform, they get applications.
Jim Polito: [00:12:34] You know, I love that. So what you're saying is today, I need to pick up a copy of the penny saver if it still exists or the want ad advertiser and all those other things, uh, You know, like the automobile, uh, and boat and recreational vehicle one, you know, at the, at the convenience store, I got to grab one of those and all of a sudden I'll say, Oh, you know, what's open the position for the chief financial officer at Facebook.
I'm going to apply.
Uh,
Craig Peterson: [00:13:04] Make sure you go to Bath, Maine to pick that one up. Right.
Jim Polito: [00:13:07] I know, right, right. Our good friend, Craig Peterson, tech talk guru. Now listen, you can get him on WTAG and W H Y N, I believe Sundays at 11:00 AM. Um, and you can listen to my Rhode Island friends with the iHeart radio app, and then Craig, if people want to get in touch with you, how do they do it?
Craig Peterson: [00:13:31] Well, if you go to Craig peterson.com, you'll find lots of great information there.
I'm going to start a course on hardening windows. After the first of the year, we're going to get back to the basics. So we'll be doing some free webinars and other things, and you want to know about it. So the best way to learn about this is just going to Craig peterson.com and you'll see at the bottom of the page that you can subscribe, they'll get my newsletter.
Hey, I'm not some marketer out there hammering you all of the time. I just don't do that. I want to get the information out so you can sign up right there. You'll get my show notes and you'll find out about all of these pieces of training.
Jim Polito: [00:14:09] All right. Thank you so much, sir. And we'll catch up with you next week.
Craig Peterson: [00:14:14] All right. Take care of Jim.
Yes, it's true. I really am going to be doing the hardening windows course after the first of the year, we've got it all laid out. Karen and I have been working hard on that and making sure it's all in place. So keep an eye out for that. I had a lot of responses I can have casually mentioned it in a PS in my email this weekend.
And I got a lot of responses. I was really, really surprised. I anyhow, that's that?
And we'll be back in tomorrow. With a W G A N up there in Maine. We're talking to Mainers. All right guys, take care. Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed the current Cybersecurity Pandemic and Phishing and what happened to Jim Polito, the host, this past week and then hit on travesty to the American worker through the H1B Visa program and how Facebook and other Big Tech is front and center with it. Here we go with Jim.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---Â
Automated Machine Generated Transcript:
Jim Polito: [00:00:00] I was afraid to answer the email. Cause I, I said, wow, has this been hacked. Have they been hacked? No, it was a valid email. Then I got some other emails from Google saying somebody used one of your email accounts, so I sent it to Craig. I said Craig help me here.
Craig Peterson: [00:00:21] Good morning, everybody.
Craig Peterson on with Mr. Jim Polito looks like we've picked up another station. That's kinda cool. W H J J, I think it is down in Rhode Island. Well, Jim picked it up, but I'm along for the ride. So that's kind of fun. We talked a little bit about that this morning. Jim's problem where he got hacked so we went into that.
We also got into H1B visas and how they are hurting badly the US job market, and between you and me, I'm very concerned about what Joe Biden's going to do if he takes office with this whole program. So we got into all of that this morning. And here we go with Mr. Jim Polito.
Jim Polito: [00:01:05] Here he is the man. Every Tuesday at this time he joins us. Boy, he got me out of a jam last week. I am talking about our tech talk guru and good friend, Craig Peterson, Craig say hello to Rhode Island. We are now the network has expanded to W H J J, a landmark and legacy station in Rhode Island.
Craig Peterson: [00:01:33] Hey, good morning, everybody. Man, Rhode Island, of course, Central, Western mass parts of Vermont today. New England tomorrow, The world.
Jim Polito: [00:01:44] Well, I don't know about that. The guy who, kind of, coined that expression, I don't know if I want to be affiliated with him, but, Craig, just so folks, I can introduce you to Craig Peterson, in Rhode Island and we don't make this up. Craig Peterson actually wrote code that is still being used on the internet. So unlike Al Gore, he truly did play a role. In inventing the internet.
Now he has his own company and he graces us out of the goodness of his heart, with a great, great visit once a week. And he's got a show on T A G and H Y N. That is fantastic on the weekends. But the best thing is that he's here with us and I'm his shall we say lab experiment because boy, Craig, did you help me out last week? Saved me.
Craig Peterson: [00:02:38] Oh, thanks. You know what Jim what happened to you, happens every day to people. So many people just don't understand some of the things. I look at it as the basics, right?
There's something that's known in expert circles. I'm going to put it this way. Knowing too much and not remembering too to not know this stuff.
I'm so glad to be able to be on every weekend. Talk about this stuff and really explain it in ways that I hope people can understand a little better.
Jim Polito: [00:03:10] Yeah. So let me just tell everybody what happened. I got an email from someone in corporate human resources. Now, remember iHeart is a very big company. We are very local in all of our stations and the iHeart radio app can go from the big, big stuff, like concerts right down to local with us. But here's the thing about getting an email from a company. I'm looking at it saying, is this real? I looked up the person in the directory Oh, okay, that person does work for the company. But it said someone has applied for unemployment. We have something here that you've applied for. I'm like, Oh my God.
Well, first of all, Craig. My first reaction was, wow, I'm already out. That's it. This is how the company is telling me. Then the other reaction was, I was afraid to answer. Because I said, wow, has this been hacked? Have they been hacked, but no, it was a valid email.
I got some other emails from Google saying somebody used one of your email accounts, so I sent it to Craig. I said Craig help me here. Lo and behold Craig, it was real. Somebody got my information and applied for unemployment.
Craig Peterson: [00:04:35] We looked up your email addresses and I found them in a whole boatload of breaches of other information out there. I think Jim didn't we find your name, your home address, obviously your email password? Weren't what, all of those in there, as I recall.
Jim Polito: [00:04:53] I think so. Yeah. I mean, somebody had really, somebody really got in there. Um, and you know, uh, I responded to human resources. They were great and right away, they sent me back an email, which was very helpful, Jim.
Here's what you need to do, get to your credit right now and freeze it, all of it, lock it down, you know?
And, uh, luckily so far, I don't think anything, you know, has been an issue. Um, but Craig, we talked about it, Massachusetts. It was an issue. In other states like Rhode Island, it's been an issue.
Um, you see it in the news, they're talking about people, uh, trying to take advantage of the, um, the benefits that came out earlier in relation to COVID and to scam, take someone else's identity and do something with it.
Craig Peterson: [00:05:47] Absolutely, we're calling it now a pandemic. This is a cybersecurity pandemic that's really been triggered by the lockdown, by the fear of COVID trying to understand that. Also of course the big deal with the lockdown is so many people are working from home, look at you, and pop they're at home. Right.
You've got the technology to connect to the radio station. But because of that, now employees are on insecure devices in their homes, utilizing their own networks. We now have seen this massive pandemic of identities being stolen of all kinds of fraud, not just what we've known for a while called business email compromise, where you get an email and it's trying to trick you.
Into doing something, but it's not necessarily from someone you know.
Now we're seeing email account compromise where the bad guys are taking over an email account, using the information that they have found on the dark web about each one of us. Now you will get a legitimate email that is from someone legitimately in HR.
And in fact, it's really not a legitimate email, but everything about was. They took over HR's email account.
Jim Polito: [00:07:08] Yeah. I mean, the other thing I did is, you know, folks who don't have, you know, access to a lot of other, uh, checks and, you know, um, I called, you know, the best thing to do is, okay, I got an email from this person I called and said, Hey, what's going on here?
So that's always a good backup, but you know, I get so much of that email in accounts, you know, I'll have an, uh, an email come to me, you know? Uh, and then, uh, and then, uh, I've got about one, two, three, well with work and then like three other emails. And it's just because I've had them for so long. I just keep them.
But. Um, they're not as active, but I'll get an email to one of those accounts saying, Hey you need to reset your Amazon password. I was like, this is not the account I set up Amazon with, like good try guys. This is not the account, but you do worry about some other things. You take a look at it and say, I don't know for sure.
I'm worried. And a phone call is always a good thing for people to do. And I know you've recommended that in the past too. Unless the person on the other end of the line has an Eastern European accent. Right. And it could just be a coincidence that the woman in HR is from, I don't know, one of the Eastern European nations.
She, she could be Moldovan. Right. you never know, so, that's a good thing. And that's something people have to look out for.
But you know what I want to, I want to really discuss with you, other than bringing the attention of what happened to me, to everybody to be mindful of it. Watch out, somebody may try to get unemployment in your name.
Hey, what's this thing about Facebook hiring foreign workers over US workers, and isn't ole "Zucky" breaking the law by doing this.
Craig Peterson: [00:09:08] This has been a soapbox subject of mine forever. You talked about these people trying to deceive you. My daughter got a voicemail from the IRS. They called her out of the blue and you're absolutely right. Don't respond to the email by all means. Don't click on the email. Pick up the phone. You did such the right thing.
The Zuck here, this has been one of the things I've been talking about, not specifically with Facebook, but for well over a decade.
We put a program into place to allow immigrants to come to the United States to do specific jobs. So here in New England, we have a lot of people that come to our Ski Hills, for instance, to work in the winters. Many of them are from in fact Eastern European countries and they come here, they get exposure to the US and there we're able to bring those workers in because we can't find enough. People to work here on some of the ski Hills with these seasonal jobs, people want permanent jobs and I can understand that sort of thing. So that made a lot of sense.
Congress decided, Hey, you know what? We need tech workers because it happened forbid we just don't have enough tech workers in the US. Even though right now, there are many of US that are out of work and have been for ages.
So here's what's happened just on Thursday less than a week ago, the Department of Justice sued Facebook because apparently what they have been doing is they've been bringing in foreign workers to work in the US.
You say, wait a minute, Craig is isn't it people looking for work and the answer to that is yes.
And they might even want one of these jobs. Jim, did you see the average salary of more than $156,000 a year?
Jim Polito: [00:11:02] That's what they say is a good job at a good wage.
Craig Peterson: [00:11:05] Yeah, exactly. So what Facebook apparently has been doing, and this is the allegation in the suit is they've been advertising these positions as being open, which they're required to do under the law. Let's Americans know about the jobs and what the qualifications are, and then they can apply.
Well, apparently what they've been doing is advertising the jobs in little local newspapers that no one reads and looking at the statistics, the job between July 2018 and April 2019. Okay. 81% of these 1100 jobs, 81% did not receive a single applicant while another 18% received just one applicant such add that up 81 plus 18%. Oh my gosh. 99% of the jobs didn't get applicants.
So my gosh, we've got to go overseas to find people to work here.
Jim Polito: [00:12:05] That is that's so sleazy.
Craig Peterson: [00:12:09] Isn't that something. Well, yeah, the deal Jay said also earlier in 2018, Facebook advertised 22 openings for art director jobs and they had more than 2,600 applications for those jobs.
Okay. So obviously if they advertise in the right place, maybe even on their own platform, they get applications.
Jim Polito: [00:12:34] You know, I love that. So what you're saying is today, I need to pick up a copy of the penny saver if it still exists or the want ad advertiser and all those other things, uh, You know, like the automobile, uh, and boat and recreational vehicle one, you know, at the, at the convenience store, I got to grab one of those and all of a sudden I'll say, Oh, you know, what's open the position for the chief financial officer at Facebook.
I'm going to apply.
Uh,
Craig Peterson: [00:13:04] Make sure you go to Bath, Maine to pick that one up. Right.
Jim Polito: [00:13:07] I know, right, right. Our good friend, Craig Peterson, tech talk guru. Now listen, you can get him on WTAG and W H Y N, I believe Sundays at 11:00 AM. Um, and you can listen to my Rhode Island friends with the iHeart radio app, and then Craig, if people want to get in touch with you, how do they do it?
Craig Peterson: [00:13:31] Well, if you go to Craig peterson.com, you'll find lots of great information there.
I'm going to start a course on hardening windows. After the first of the year, we're going to get back to the basics. So we'll be doing some free webinars and other things, and you want to know about it. So the best way to learn about this is just going to Craig peterson.com and you'll see at the bottom of the page that you can subscribe, they'll get my newsletter.
Hey, I'm not some marketer out there hammering you all of the time. I just don't do that. I want to get the information out so you can sign up right there. You'll get my show notes and you'll find out about all of these pieces of training.
Jim Polito: [00:14:09] All right. Thank you so much, sir. And we'll catch up with you next week.
Craig Peterson: [00:14:14] All right. Take care of Jim.
Yes, it's true. I really am going to be doing the hardening windows course after the first of the year, we've got it all laid out. Karen and I have been working hard on that and making sure it's all in place. So keep an eye out for that. I had a lot of responses I can have casually mentioned it in a PS in my email this weekend.
And I got a lot of responses. I was really, really surprised. I anyhow, that's that?
And we'll be back in tomorrow. With a W G A N up there in Maine. We're talking to Mainers. All right guys, take care. Bye-bye.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Craig Peterson here. I was on with Jeff Chidester on NH Today. We really got into a topic that has been a soapbox topic for me, and that is H1B Visas, and the outright fraud that has been going on with this program, especially in the Tech sector and I have to assume other sectors as well although I have not reviewed other sectors. H1B Visas are being used to take jobs from American Technology workers and replace them with wholly unqualified workers who are marketed by basically "third world slave traders." These large "third-world consulting firms" represent their candidates with outrageous resumes and charge an arm and a leg" for almost incompetent workers to tech companies and pay their worker's one-fifth to one-sixth of what an American worker would be paid and then pile them into an apartment 12-15 at a time. These people are afraid to rock the boat, or they will lose their job and be sent back. It is a modern-day tech equivalent to the slave trade. We must stop it. But the US Legislature led by a "good-hearted but quite misinformed" Senator named Mike Lee pushed for H1B Visa renewal this week. Then we talked about the demise of Adobe Flash -- to which I say Good Riddance. It was horribly insecure software that had outlived its usefulness and purpose. Here we go with Jeff.
These and more tech tips, news, and updates visit.
- CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] This was a bit of a tough one this morning. Craig Peterson here. I was on with Mr. Jeff Chidester, of course, on December 7th, Pearl Harbor day. How could I not? My father-in-law was there in the war. I talk a little bit about it. I had to stop talking because I couldn't just talk.
we talked a little bit this morning about this whole H1B thing. Man. It really is upsetting to me. What has happened to us? What has happened in the country, frankly? Flash. Adobe Flash, may it rest in peace. Jeff's company relies on Flash for some of the training they've put together. But that is all going down the tubes. Anyways, here we go.
Jeff Chidester: [00:00:45] Seven 38 in the morning. Of course, Jeff Chidester with you, December 7th, as always. We're pleased to be joined by this next gentleman. He joins us at this time, every Monday, you can also catch him on the weekends. We call him Craig Peterson. He calls himself Craig Peterson, as well.
Craig. How are you doing this morning?
Craig Peterson: [00:00:59] It's weird how that all fits together.
Jeff Chidester: [00:01:02] You see how to seamlessly. I just said it without even hiccuping, right? The silliness of Monday. Craig, we're all kind of euphoric that the Patriots not only won, but they won so big that, we're just, we're letting that euphoria carry us through the day as it just so happens.
Hey, Facebook hires foreign workers. This is an interesting thing. There Is this bill going through the Senate and the house right now from Mike Lee, and it's disappointing about H1B. Please talk a little bit about that. Facebook actually got caught on this, and there are some issues with that.
Craig Peterson: [00:01:35] Oh, there are all kinds of issues. I've been talking about this whole H1B thing for years and years, Here's what's been going on in many of the larger tech firms rather than pay Americans to do jobs. They have been using what has lately been a loophole in the law that allows them to bring in foreign workers. So they've been bringing in workers from all kinds of countries that they can pay a lot less to.
Now they're supposed to pay equal wages to Americans. They are supposed to be advertising in places where Americans will find out about the jobs and apply for those jobs. It's called the H1B visa program.
However, what's just happened now is the Department of Justice sued Facebook on Thursday. They're saying that Facebook has discriminated against US workers. They've been giving preferences to Facebook workers on H1B visas. That means a temporary worker. It's a worker that they couldn't find in the United States. No one in the whole United States has the skills that they needed. So they had to go to a foreign worker. It brought them into the country. In many of these places, these workers live in one apartment with as many as a dozen from some of the reports that I've read. They're already working there at Facebook. They're already underpaid. They've taken jobs that should have been given to an American by law.
Apparently, they're advertising their outreach to try and get Americans to apply for the jobs. Is to put them in a newspaper that nobody reads anymore. These are jobs with an average salary of more than $156,000. Out of some 1100 jobs that Facebook posted between July 2018 and April 2019, 81% did not receive a single applicant. Another 18% received, just one applicant.
You add those numbers up, and that's 99% of the jobs, not a single American applied for a $156,000 job.
Jeff Chidester: [00:03:55] Craig too, if not for you, if you didn't tell us those facts, Facebook and other companies that participate in these kinds of practices, just come back and say, we just can't find qualified American workers, which is just hogwash.
Craig Peterson: [00:04:08] It's totally hogwash because the DOJ noted that earlier in 2018, Facebook advertised 22 openings for this is an art director job. 22 openings, and they did it legitimately, right? They put it up online. They put it where people could find it. Facebook had more than 2,600 Americans apply for those jobs.
Jeff Chidester: [00:04:32] Unbelievable
Craig Peterson: [00:04:32] There's some really nasty stuff going on. I've come up against this before. You might've as well. Jeff, because you're in the tech business. Where I've had problems is with one big company. It is a massive consulting firm. They have all kinds of H1B visa holders. It's like the third most of any company in the country.
We're talking about thousands of these H1B holders within this one single company. We were up against them on a bid, and we lost the bid because they were able to undercut us. When we did more research and talked to some of these completely incompetent people, that they had brought in from overseas who had generated diplomas, showing that they had a Ph.D. yet I know high school kids that knew more about computers than these people did. They were being paid about a sixth, one-sixth of what a normal American would be paid.
The abuse is just going on and on.
Then last week, the US Senate just voted on an extension here, this whole H1B program. Instead of having Republican senators and Democrat senators saying, we need these jobs for Americans, look at the unemployment rate. They just sat on their hands and let it pass.
Jeff Chidester: [00:05:56] Oh yeah, there was no open debate on it. And of course, that's Mike Lee, the one I was talking about, and I was surprised that Mike Lee allowed this. And once again, the bi-partisan killing of American jobs is just insane. We will certainly have to see how that progresses through, but buyer beware too. If you're hiring these tech companies are hiring these companies that help in that area ask. How many employees are actually H1B employees? How many are Americans? It's just a thing we should be thinking about.
Hey, Flash is going away. I'm dealing with this. I've been dealing with this issue for a while because I do a lot of online training. A lot of our old courses were built into Flash. Flash, it's dead. Dead at the end of the month. Isn't it.
Craig Peterson: [00:06:34] Thank goodness. I was going to have Justin cue up some trumpets blaring. Flash has been one of the worst things that ever happened for security. Now it was great. Yeah. Because when it first came out or an Adobe product now has been for years, it gave us the ability to have moving graphics, to program stuff like your training courses.
You just mentioned where people could click on things, move through them. It was great, but it was designed by I swear it was 10,000 monkeys on typewriters. Okay. They managed to develop this little programming language. It has been terrible. It's Java, and it is now completely removed. It has never been on a single iOS device in history in the 10 years that my phones have been out. Because Steve jobs, it's a complicated story, but he saw the security problems. He said, you can't do this. You've gotta be kidding. Plus, he had a little fight going on with Adobe at the time.
So it's gone. It's over with, at the end of the year. Good riddance. Adobe has been pushing updates for your browser for Flash that actually removes it from your systems.
Jeff Chidester: [00:07:51] Yeah. It's interesting as I go through this process too, Craig, there was no easy fix to fix those courses. So some are actually going to be retired.
We'll have to rethink how we present them, but you're right. It was something that we were all warned about long ago.
Last thing I want to talk about, extortion. Where gains traction and Kmart gets hits, I'm always surprised, Craig.
Once again, you can catch Craig, Saturdays, and Sundays on the station, as well as other stations.
I'm always surprised these big companies just get hammered. We always think it's the little companies, and they should be careful, but these big companies keep getting nailed by this stuff.
Craig Peterson: [00:08:20] Yeah, absolutely.
And I want to, and also, before I get into that real quick, if I could just some honor here, my father-in-law was on a submarine in Pearl Harbor when it was attacked on to state many years ago. He was just an amazing man, a big-time boy scouter. He did everything with these boys and these kids. He never talked about his experience and could never have breakfast, with eggs and orange juice, because all he ever did, was taste diesel.
There are so many of our veterans, two of my kids, did military service as well. I know you did. Thanks for your service. We're talking today freely because of what these people sacrificed in memory of my father-in-law. I had to bring it up, Gerry.
Jeff Chidester: [00:09:12] Oh, that's very nice. We're going to be talking about, Pearl Harbor during the eight o'clock hour, too. and look it back in remembrance as well.
We actually have to break. Next time we'll catch up on some of those other topics that we want to catch up on as well
Craig Peterson: [00:09:22] Very Good and take care
Thanks, Jeff.
Jeff Chidester: [00:09:24] You as well. Thanks a lot, Craig Peterson. Once again, you can check him out, Saturdays and Sundays on these stations and the other stations. Also, all of his podcasts are up on his website to Craig peterson.com. Craigpeterson.com and catch up on all those as well. A great podcast.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Craig Peterson here. I was on with Jeff Chidester on NH Today. We really got into a topic that has been a soapbox topic for me, and that is H1B Visas, and the outright fraud that has been going on with this program, especially in the Tech sector and I have to assume other sectors as well although I have not reviewed other sectors. H1B Visas are being used to take jobs from American Technology workers and replace them with wholly unqualified workers who are marketed by basically "third world slave traders." These large "third-world consulting firms" represent their candidates with outrageous resumes and charge an arm and a leg" for almost incompetent workers to tech companies and pay their worker's one-fifth to one-sixth of what an American worker would be paid and then pile them into an apartment 12-15 at a time. These people are afraid to rock the boat, or they will lose their job and be sent back. It is a modern-day tech equivalent to the slave trade. We must stop it. But the US Legislature led by a "good-hearted but quite misinformed" Senator named Mike Lee pushed for H1B Visa renewal this week. Then we talked about the demise of Adobe Flash -- to which I say Good Riddance. It was horribly insecure software that had outlived its usefulness and purpose. Here we go with Jeff.Â
These and more tech tips, news, and updates visit.
-Â CraigPeterson.com
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] This was a bit of a tough one this morning. Craig Peterson here. I was on with Mr. Jeff Chidester, of course, on December 7th, Pearl Harbor day. How could I not? My father-in-law was there in the war. I talk a little bit about it. I had to stop talking because I couldn't just talk.
we talked a little bit this morning about this whole H1B thing. Man. It really is upsetting to me. What has happened to us? What has happened in the country, frankly? Flash. Adobe Flash, may it rest in peace. Jeff's company relies on Flash for some of the training they've put together. But that is all going down the tubes. Anyways, here we go.
Jeff Chidester: [00:00:45] Seven 38 in the morning. Of course, Jeff Chidester with you, December 7th, as always. We're pleased to be joined by this next gentleman. He joins us at this time, every Monday, you can also catch him on the weekends. We call him Craig Peterson. He calls himself Craig Peterson, as well.
Craig. How are you doing this morning?
Craig Peterson: [00:00:59] It's weird how that all fits together.
Jeff Chidester: [00:01:02] You see how to seamlessly. I just said it without even hiccuping, right? The silliness of Monday. Craig, we're all kind of euphoric that the Patriots not only won, but they won so big that, we're just, we're letting that euphoria carry us through the day as it just so happens.
Hey, Facebook hires foreign workers. This is an interesting thing. There Is this bill going through the Senate and the house right now from Mike Lee, and it's disappointing about H1B. Please talk a little bit about that. Facebook actually got caught on this, and there are some issues with that.
Craig Peterson: [00:01:35] Oh, there are all kinds of issues. I've been talking about this whole H1B thing for years and years, Here's what's been going on in many of the larger tech firms rather than pay Americans to do jobs. They have been using what has lately been a loophole in the law that allows them to bring in foreign workers. So they've been bringing in workers from all kinds of countries that they can pay a lot less to.
Now they're supposed to pay equal wages to Americans. They are supposed to be advertising in places where Americans will find out about the jobs and apply for those jobs. It's called the H1B visa program.
However, what's just happened now is the Department of Justice sued Facebook on Thursday. They're saying that Facebook has discriminated against US workers. They've been giving preferences to Facebook workers on H1B visas. That means a temporary worker. It's a worker that they couldn't find in the United States. No one in the whole United States has the skills that they needed. So they had to go to a foreign worker. It brought them into the country. In many of these places, these workers live in one apartment with as many as a dozen from some of the reports that I've read. They're already working there at Facebook. They're already underpaid. They've taken jobs that should have been given to an American by law.
Apparently, they're advertising their outreach to try and get Americans to apply for the jobs. Is to put them in a newspaper that nobody reads anymore. These are jobs with an average salary of more than $156,000. Out of some 1100 jobs that Facebook posted between July 2018 and April 2019, 81% did not receive a single applicant. Another 18% received, just one applicant.
You add those numbers up, and that's 99% of the jobs, not a single American applied for a $156,000 job.
Jeff Chidester: [00:03:55] Craig too, if not for you, if you didn't tell us those facts, Facebook and other companies that participate in these kinds of practices, just come back and say, we just can't find qualified American workers, which is just hogwash.
Craig Peterson: [00:04:08] It's totally hogwash because the DOJ noted that earlier in 2018, Facebook advertised 22 openings for this is an art director job. 22 openings, and they did it legitimately, right? They put it up online. They put it where people could find it. Facebook had more than 2,600 Americans apply for those jobs.
Jeff Chidester: [00:04:32] Unbelievable
Craig Peterson: [00:04:32] There's some really nasty stuff going on. I've come up against this before. You might've as well. Jeff, because you're in the tech business. Where I've had problems is with one big company. It is a massive consulting firm. They have all kinds of H1B visa holders. It's like the third most of any company in the country.
We're talking about thousands of these H1B holders within this one single company. We were up against them on a bid, and we lost the bid because they were able to undercut us. When we did more research and talked to some of these completely incompetent people, that they had brought in from overseas who had generated diplomas, showing that they had a Ph.D. yet I know high school kids that knew more about computers than these people did. They were being paid about a sixth, one-sixth of what a normal American would be paid.
The abuse is just going on and on.
Then last week, the US Senate just voted on an extension here, this whole H1B program. Instead of having Republican senators and Democrat senators saying, we need these jobs for Americans, look at the unemployment rate. They just sat on their hands and let it pass.
Jeff Chidester: [00:05:56] Oh yeah, there was no open debate on it. And of course, that's Mike Lee, the one I was talking about, and I was surprised that Mike Lee allowed this. And once again, the bi-partisan killing of American jobs is just insane. We will certainly have to see how that progresses through, but buyer beware too. If you're hiring these tech companies are hiring these companies that help in that area ask. How many employees are actually H1B employees? How many are Americans? It's just a thing we should be thinking about.
Hey, Flash is going away. I'm dealing with this. I've been dealing with this issue for a while because I do a lot of online training. A lot of our old courses were built into Flash. Flash, it's dead. Dead at the end of the month. Isn't it.
Craig Peterson: [00:06:34] Thank goodness. I was going to have Justin cue up some trumpets blaring. Flash has been one of the worst things that ever happened for security. Now it was great. Yeah. Because when it first came out or an Adobe product now has been for years, it gave us the ability to have moving graphics, to program stuff like your training courses.
You just mentioned where people could click on things, move through them. It was great, but it was designed by I swear it was 10,000 monkeys on typewriters. Okay. They managed to develop this little programming language. It has been terrible. It's Java, and it is now completely removed. It has never been on a single iOS device in history in the 10 years that my phones have been out. Because Steve jobs, it's a complicated story, but he saw the security problems. He said, you can't do this. You've gotta be kidding. Plus, he had a little fight going on with Adobe at the time.
So it's gone. It's over with, at the end of the year. Good riddance. Adobe has been pushing updates for your browser for Flash that actually removes it from your systems.
Jeff Chidester: [00:07:51] Yeah. It's interesting as I go through this process too, Craig, there was no easy fix to fix those courses. So some are actually going to be retired.
We'll have to rethink how we present them, but you're right. It was something that we were all warned about long ago.
Last thing I want to talk about, extortion. Where gains traction and Kmart gets hits, I'm always surprised, Craig.
Once again, you can catch Craig, Saturdays, and Sundays on the station, as well as other stations.
I'm always surprised these big companies just get hammered. We always think it's the little companies, and they should be careful, but these big companies keep getting nailed by this stuff.
Craig Peterson: [00:08:20] Yeah, absolutely.
And I want to, and also, before I get into that real quick, if I could just some honor here, my father-in-law was on a submarine in Pearl Harbor when it was attacked on to state many years ago. He was just an amazing man, a big-time boy scouter. He did everything with these boys and these kids. He never talked about his experience and could never have breakfast, with eggs and orange juice, because all he ever did, was taste diesel.
There are so many of our veterans, two of my kids, did military service as well. I know you did. Thanks for your service. We're talking today freely because of what these people sacrificed in memory of my father-in-law. I had to bring it up, Gerry.
Jeff Chidester: [00:09:12] Oh, that's very nice. We're going to be talking about, Pearl Harbor during the eight o'clock hour, too. and look it back in remembrance as well.
We actually have to break. Next time we'll catch up on some of those other topics that we want to catch up on as well
Craig Peterson: [00:09:22] Very Good and take care
Thanks, Jeff.
Jeff Chidester: [00:09:24] You as well. Thanks a lot, Craig Peterson. Once again, you can check him out, Saturdays and Sundays on these stations and the other stations. Also, all of his podcasts are up on his website to Craig peterson.com. Craigpeterson.com and catch up on all those as well. A great podcast.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
This week I am spending a bit of time discussing Faces that are designed to deceive, Dangerous Printers, Multifactor Authentication, Shopping Securely on and offline. Why you must update ALL your devices and More so listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
Designed to Deceive: Do These People Look Real to You?
Printers' Cybersecurity Threats Too Often Ignored
What's in Store for Privacy in 2021
Alexa, Disarm the Victim's Home Security System
HOLIDAY ONLINE SHOPPING SECURITY - From the Cybersecurity & Infrastructure Security Agency
Latest Version of TrickBot Employs Clever New Malware Obfuscation Trick
Artificial Intelligence can run your work meetings now
Facebook's libra currency to launch next year in limited format
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hey, what's up for privacy coming over the next year. We'll be talking about that design to deceive. How about your printer? When was the last time you actually checked that printer to make sure that well, everything was legit, as it were?
Hey everybody. Craig Peterson here. We've had a problem with fakes.
You've heard about fake news. Of course, President Trump's been talking about it. I think it was actually Hillary Clinton that had coined the phrase fake news, but there is all kinds of fake stuff going on right now, out there.
One of the big things that really concerns me is the fake identities that are right now being used in order to rip people off. That's a huge problem. When you get right down to it, we have a lot of people who are lonely.
Think about people who might be divorced, particularly elderly people, someone that's lost a lifetime mate. Nowadays, they don't see anybody anymore. they might have someone come in with a face mask on and a big shield and gloves and it's just not human touches, it's not human interaction. They're not interacting with their family face to face.
They of course, hopefully, have some way to do it virtually, maybe using Zoom, which, isn't safe. You should never use that as a business, but it is fine for family connection type of stuff. And I've used it before for different types of business conversations. I'll admit that. And in fact, when I was doing all of the webinars for the FBI's training program, as part of the whole InfoGard stuff. I was indeed using Zoom because that's what they told me to use. I approached them. I said, Hey guys, we should really be using WebEx because they have versions that are safe. That can be used by people like us that are trying to keep our information safe and keep people out we don't want to have in it. The response I got back was, no, the FBI has authorized the use of Zoom. We can't use anything else.
Of course, once again, Craig's proven, right? About a year, actually about two years later, what happens? We find out that Zoom was routing data through China, that they have developers in China, and that it was anything but safe. A real problem, frankly. okay. That was an, I told you.
But how about when you're going onto the dating site and you're not so concerned about people finding out about you. In fact, that's the reason you are on the dating site. Do you want people to find out about you and you go there and you're trying to figure out okay? Is this somebody that I can trust? Is this somebody that I should trust? I know many people who have found some of these dating entries, if you will, the posts we'll put up to be highly deceptive.
That is the problem that we're seeing all of the time. Now, when it comes to security. The bad guys are highly deceptive. And that's a huge problem because when you're on that dating site, they, might not even meet data insight. It might just be your Facebook page or something. And you find someone with some common interests and you start to talk to them and you build a relationship, all good stuff.
It's all stuff you and I need to do, we all need to do, isn't it? How do you verify whether or not that's a real person? Let me give you a hint. If you go to the Google homepage. I'm going to bring it up right now for me, myself. So we can talk along and you can see it has Google search on it.
I'm feeling lucky if you go to the upper right-hand corner, you'll see a little thing called images to a little line. You click on images and now up comes Google image search. So this is a bar you can type in just like you would any sort of a regular Google search. But it has a little camera. Did you notice that over on the right-hand side of the bar, you click on search by image.
This is where it gets interesting because if you're on Facebook or Instagram or one of these dating sites and you want to see, is this a stolen picture? Is this really a picture of John or a picture of Mary, whoever it might be. You just get the URL to that picture in the way to do that is either you can save it to your disk. If you can download it or you can right-click and copy the URL of the image, and then you paste it here into the paste image URL.
That you see right there on Google images and then you click on search by image. So I'm going to do it right now. I'm going to go to Craig, Craig Peterson.com. And I am going to grab my picture.
I'm sure I'm on here somewhere. Okay. We've got all my latest podcasts. Got questions? Subscribe for email updates. You know what? I don't have my picture on there, but I'm going to grab the U R L and you say open image and hub. And this is my logo. Okay. It's not like a phase. Yeah. Good and find a picture of my face right there on the website. I should probably fix that.
I'm going to copy, I've pasted it now into the paste image URL on Google. I click on search by image. Now, remember I was looking for my watch. It's looking for my logo and it's telling me, okay, here we go. Oh my gosh. Oh my gosh. So my logo does come back with my website a whole bunch of times, which is what you'd expect. But it also comes up with this. I'm not seeing here, come up with crude. The real price of oils. It says it's an epic story of one of the largest and most controversial legal cases on the planet. a $27 billion Amazon Chernobyl lawsuit pitting 30,000 rainforest dwellers. So it must have something to do with crude oil. That's interesting because their logo is similar to mine, but that's what we're looking for here.
Is the person whose pictures on that Facebook page or Instagram or dating site or whatever it might be? Is that person real? So when you look them up, you're going to see multiple times. results hopefully. and just kinda show them all. Yeah. This is a picture of them at home. This is, Oh, wow.
That's where they work. It's got a picture of them at the office. It's got pictures all over the place. Okay. That's obviously a legit person. what happens if it comes back with. Only maybe one match and that's their Facebook page or their dating page, et cetera. that's what I'm concerned about right now because so many people are being deceived and it's one of the things that the. FBI has sent us notices about. They are mostly seniors, all the way on, down through generation Z, the youngest adult generation we're falling for it. So if you go right now, there's a website called this person does not exist. Okay. So while you're listening, go there, this person does not exist.com and you will see an amazing picture. So I'm looking at one right now and it varies. Okay.
This was generated by an adversarial network is what it's called. You can find out how it works and you can do all kinds of stuff. And the picture I'm looking at right now is actually a young lady. I would say she's probably around 30 years old and that's based on some wrinkles around her eyes and under her eyes, mine puffy under my eyes and the cheeks. Just little tiny wrinkles. So she's in her thirties somewhere and a really pretty I would say it's been a little bit, bleached hair is Brown and they at the roots and then as you get further down, it's more bleached out as more like mine, a dirty blonde, very interesting stuff.
So you can go and you can go to right there grab a picture of a person that is not real. This person does not exist and you can even manipulate it there on the website. You can go to other places like generated.photos. That's the whole domain generated.photos. And once you're there, you can get what they call unique worry-free model photos.
What's a whole worry-free thing about? The bottom line is if you are a business and you buy a photo of a model and you can get them a lot of places online, I subscribe to some services that provide those for me. So you can get all kinds of different pictures, photos, but you can end up getting sued because maybe the release wasn't quite right. Or they signed the release, but they never got paid. The check bounced as it were. Or the transfer didn't happen over on Apple pay. Whatever they were using Samsung paid failed on them. So they have removed their permission and yet that picture is still being sold.
We've seen more and more, some of these places online that are selling our personal pictures that we've posted up on the websites. Obviously, not the best idea in the world is it frankly. So you can just go to generated photos.com, browse photos they're made by AI, these AI systems. What are you looking for?
You can search for anything I'm seeing right now. It says white woman, young adult, Asian toddler, infant, or so cute, elderly. This guy doesn't actually look that old. maybe it's because I'm older. I don't know, but, you can get them all there. You can buy a whole for three bucks or you can go and buy if you need a lot of them, a thousand for a thousand bucks.
So how do you use that? obviously, there's this legitimate purpose.
Unfortunately, there's also illegitimate slash illegal purposes out there. That is to use these pictures to con people to make them think that you have a legitimate presence or they have a legitimate presence online, and then they build a relationship and that turns out they need some money to save their Aunt who needs this surgery.
All of that stuff. So be very careful out there.
There are a lot of cybersecurity threats that we just don't deal with. It's gotten too difficult. It's overwhelming. How can I keep up on all of this stuff? you think it's bad enough with your windows machine, your main computer. Hey, I got some news for you.
You're listening to Craig Peterson. We have a lot of devices in our networks and I've talked about this quite a bit.
It's one of my soapbox subjects, right? What's called the whole internet of things. We have all kinds of devices hooked up to our networks. I'm sitting in front of well, within my view, probably two dozen different devices right here in my studio. That's frankly, that's a lot of devices and many of those devices could be hacked.
Now my network is completely set up so different things are isolated. I have multiple segments, multiple physical segments, as well as virtual segments. And one of the ways to do a virtual segment. Is to have some special stuff on that wire where you have what's called a VLAN or virtual local area network. That's getting a down into the mud here. Something I cover in some of my courses.
When we're talking about networks, segmentation is absolutely critical. You have to make sure that your home computers are on a different network or at least a different network segment than your work computer. Now what I'm talking about in-network segment, I'm not, I don't mean, Hey, I've got a switch, or right at the router that the Comcast or an internet provider gave me. I have maybe two, three, four, Ethernet ports. And so plugging in a switch to one of those ethernet ports and then putting your home computers on that switch and then putting another switch on and plugging it into the second port on that router that you got from your ISP, your internet service provider that is not segmenting your network at all because that's typically a flat network.
If you have a fancier router firewall at the edge, you may be able to segment it that way. For instance, we sell a lot of the Cisco Go equipment, which is the low end, very good stuff, but it's very basic. It's inexpensive. It does let you do real segmentation. So you can have a guest network on the wifi.
You could have a business network and the wifi, you can have multiple what are called SSIDs that's the name of the network you're connecting to. You've probably seen that if you've gone in and configured Joe or router and SSID so you can have multiple of those on some of this hardware, like the Go hardware, for instance.
There are some others out there. I think I might end up in my emails here. In fact, it is planned. To come out with something, talking about these SSIDs and what equipment you can buy. So it should be pretty simple. Keep your eyes out on that in my newsletter that you're hopefully getting every, Saturday ish.
It depends on where I am, what I'm doing that week as to when I get it out. I just try and get it out on the weekend before my weekend show airs. But, here's the bottom line. You don't want your home computers to be able to talk to your business computers. With so many of us working at home, this is a very big deal.
So how do you do that? If they're both plugged in two separate switches that are then plugged into your router? They can probably still see each other. But if you have a more advanced router that lets you have different network segments and make it, so the one network cannot talk to the other network. Then you're really cooking with gas because now they're not going to be able to spread infections.
I've talked before about VPNs and the proper way to use them. I really think I should have a whole course on working from home again for everybody out there to help. Understand some of these basics.
Make sure you're on my email list. Craig peterson.com and then subscribe on that little subscription form that comes up. Be glad to send you these things because I will let you know when I'm going to do that because there's a lot of confusion about all of this sort of thing. One of the devices everybody has in their home and certainly in their businesses, Is a printer, and we buy the printers and we buy ink and then we buy more ink and then we buy more ink. It's just a constant buy more ink it, sometimes it drives me crazy. You're buying ink for these printers, but are you connecting them to the network? Now some of the printers, especially the lower end ones are just connected via USB port to our computer. And when they're connected directly to our computer. It's really handy but it's difficult to share that printer. You can share it from Windows. You can share from Mac. So other. devices on your network can see it. That's probably the safest configuration of all of these devices bar none really. you can get safer, but it gets very expensive, very quickly.
If you have now taken that printer and instead of plugging in the via USB port, and this is typical of shared printers like we have three shared printers here. And they're all on the network and they are all self-updating. That is the next thing, to be concerned with. In fact, self-updating is probably a very good thing.
So we have some higher-end Xerox printers. These are what we sell to our clients. These are what we use internally and those printers. Call home order supplies. in fact, you can buy these printers if you're a business and you just pay by the page, you print or photocopy, and everything's taken care of all of your supplies, the machine itself, absolutely everything and that's a great way to go for many businesses out there. That way you don't have to manage it. You don't have to worry about the expensive repairs that are almost inevitable with some of these printers, but they are hooked up to the network and that means that they could potentially become infected.
I like the idea that these things are self-updating and as self-updating printers that means one, they are going to get the latest security patches, et cetera.
If you have connected a printer to your network and it does not update its firmware automatically, or frankly, even if it's supposed to be, you got to check it. You've got to check which level of firmware that's the software that's running on the printer because nowadays everything's a computer, right? Especially a printer. Find out what version of the software it has. Go to the manufacturer's site. Make sure you have the most recent release of the software. If you do life is good. If you don't, you're going to have to follow the instructions from the manufacturer on how to load in that new software, because that printer is a computer and because it's hooked up to your network, any malware that gets on your network, and it could just be the kid's friend who came over for the evening or the night or whatever, and plug their laptop into your network or connected to your wifi. and that laptop he brought over was infected.
So now it's going to try and infect everything on the network. It finds a vulnerable printer on your network and it infects it. So now due to almost no fault of your own, your network right now has a device cause he's going to leave. He's finally going to go home. Thank goodness. Now you have a printer that is acting as a launching pad for the bad guys to be able to get into the other computers on your network. So keep that in mind.
We know that we're supposed to do something, but we don't always do it. And in this case, we're talking about your printer it's firmware, but also I mentioned that router that's sitting at the edge of the network. Do the same thing with that router, make sure it has the latest versions of firmware.
That's part of what I like about those cisco Go stuff that you can buy through me. You can find it on Amazon. Go equipment, self-updates, which is very nice.
Believe it or not, 2020 will eventually come to an end. And then we've got next year, 2021, which shouldn't be an interesting year as well, but what's in store for privacy in 2021.
2021 is going to be a turbulent year, according to dark reading, you might want to check them out. They've got some great articles, but there are changes coming in the privacy landscape.
We've seen a few over the last few years, for instance, in Europe, they come up with the GDPR, which is this data protection law. They have something similar for consumers and their data over in California.
Massachusetts has something similar. New York too.
We're expecting certainly under a Biden administration to have many more standards put in place. They'll end up being federal standards as opposed to the state set standards and whether or not you like that idea. I've got to say, I think it's a very bad idea, but it's good that we're talking about it because our privacy has been under assault for a very long time.
I had this conversation with my wife earlier in the week. And she was just fed up with the lack of privacy in the online world. Not that I can blame her for that. that's not where the issues came up. The issues really were surrounding. What privacy should you have? What privacy do you want now?
Ultimately, we know that when it comes to the government, Privacy on our part needs to be absolute. There are no two ways about it, right? It's one of the Bills of Rights. We have the right to be secure in our papers. We have the right to be secure in our homes. The government cannot just willy-nilly start monitoring us, recording our conversations, tracking who we call. Actually, they did that. Under the Obama administration, they did it more than ever. They dramatically increased all of that spine on us citizens. huge increases. And under the Trump administration, they drop that back pretty dramatically. under a Biden administration, I'm afraid it will actually increase.
There are two types of people in the world. there's them and then there's us, right? There are many more of us than there are of them, the people in power, but the people in power want to force standards on us that say you cannot store certain types of information or track things on people.
However, for them. The double standard just doesn't really apply, because for them they can do even more monitoring and spying on us. Pulling together the intelligence and buying it from these commercial data brokers who pulled together, all of this information that's available publicly and all the information that they can buy about us in many States and includes driver's license information.
It certainly includes everything in the registry of deeds. The secretary of state's filings like UCC ones, et cetera. So they've got a real good picture of you. They can tell from all of this information, Hey, he's driving an 11-year-old car or, Oh wow.
He's got a brand new, $150,000 car. You expect different things from those people. It's one thing for businesses to be collecting that and it's entirely another thing for governments to be collecting that. So what my wife and I were discussing was, is it a good thing or a bad thing that businesses are collecting?
it really is a double-edged sword. It's not something that's obviously bad are obviously good. For instance, if I'm in the market to buy a new truck, I'm all for seeing ads from truck manufacturers. These are cool new electric trucks, Ford of course, GM, Chrysler, whomever, it might be. I want to see it.
If I'm not in the mood for buying a new truck, I don't want to see the ads. It's a total waste of my time. So broadcast TV, for instance, doesn't know much about us. You might've noticed if you're listening via one of these streaming services to me on a podcast or a live stream, the ads that are inserted are specific for you.
I think that's generally a good thing, frankly. But there is one company out there that has been very good in trying to keep, quite a bit of privacy for you and me, and that's Apple. And I want to talk about them in just a minute.
I also want to warn you that the Department of Justice has signed a letter along with other businesses out there calling for what we call back doors. So they want some technological solutions to give law enforcement access to specific communications.
I personally call that a threat. Now you might say, Oh, that's the Trump administration. That's Bill Barr. terrible man. Terrible man. this has been going on forever. I remember talking about this back in the days of bill Clinton and the clipper chip and how they had come up with this.
Chip, the Doug does encryption and it should be used by everyone and they were going to mandate it and it turned out I had a backdoor in it, just I think it was the Jupiter foams that, Saddam Hussein and his sons were using that were actually made in the UK. And we're encrypted phones. So that they could carry on their nefarious deeds, no one could track them.
No one knew what they were saying, et cetera. Except it had a back door and the Brit shared it with us and we could listen to all of their communications. We could track where they were with who. As they were going, et cetera. Okay. as of December 8th, this year 2020, Apple's requiring developers to disclose all of the data it's apps collect from users, including data that's collected by third-party advertising frameworks that are included or linked into their code.
Now, this is really a big deal, because remember I was talking about how the government is collecting data on us and it's restricted in collecting certain types of information.
It can't do it. However, we have found now that the IRS, the immigration people over at Homeland security, and others have been buying data from these app developers. So they've got these frameworks that are for advertising and I'm using air quotes here, and those frameworks are used in those free games you have.
Why is the game free? how can it be free? How could you afford to give away these games? All of the work you put into them? They're not they're including these little frameworks and these frameworks now track where you are? Where you're going? Where you're playing the game? Some of them like Google maps try to track you all of the time.
Google, of course, makes its money primarily off of selling your information. So Apple doing this I think is a huge win for Apple and for the consumers again, how many times have I said, don't use Android. Java. One of the biggest security problems that we have in information technology is these Java runtimes.
That's all Android does. Plus the fact that it can be six months or in most cases, never until you get security patches because your phone's no longer, the latest, greatest, they just don't care about you anymore. Use an iPhone, get an iPhone. Even if you get, you do like me right now, I'm using an iPhone eight who cares?
It works. It does the job. Get the older release. It's going to save you a lot of money.
We're going into Alexa. This is interesting. Disarm - the victim's home security system. If you want to see these articles are more, I don't know. I have a lot more listening to my podcasts.
As in any of these segments, I do just visit Craig peterson.com and make sure you sign up for my free newsletter.
Many of us have Alexa. Maybe Google home. Maybe some of these other assistants that have either Google Home or Alexa built right into them. I guess it would echo, but did you know that there is a very interesting way to hack them?
Hey, you're listening to Craig Peterson.
Anyway, if you have one of these wonderful little home assistants, you may not be aware of it, but a light can be used to hack these things. I don't know if you watch some of these really cool spy movies. I think they did this with one of the Tom Cruise movies, but they might take out a laser and point it at a piece of glass and then use that to listen
to the discussions or whatever's going on inside the room. Now that does happen. That's very easy to do. There are devices you can buy out there for very cheap that'll do that. So it takes the light from the laser it's modulating by the vibration of the glass and they can listen to what's being said. So there have been times where I was in meetings that we needed to keep very private and unfortunately, We were well aware that there were people who would do anything to listen in to the meeting, and because of that, we ended up putting some vibration, some speakers with some Brown noise right there at the windows, so that they couldn't be listened to by laser.
So maybe I'm paranoid. At least when we were, but there was a big lawsuit going on. And there's, when you're talking about millions or hundreds of millions, even billions of dollars, some of these people will do almost anything.
And for private investigators, it's really cheap and really easy to just use that laser too. Listened to the vibration on the window from across the street. And it doesn't have to be like one of those pointer types, where it's red and you can see it. You can use all kinds of wavelengths of light, even invisible wavelengths of life, light invisible to us, Our eyes, but not invisible to the equipment that they're using. So there can be very sneaky about it. there's a team being reported here in dark reading from researchers over the university of Michigan and the University of electoral communications over in Tokyo that they were able to use modulator.
Laser beams in order to inject command into the microphones on Amazon Alexa and Google homes and other digital voice assistant devices via laser pointers. Yes indeed modified laser pointers. Now, this is very intriguing to me because the physics involved actually are not understood very well. these digital assistants have built-in microphones and in the case of I have an Alexa or an Amazon echo dot.
It has multiple microphones and you can see the light on the top that moves around and tells you which one of the microphones is listening to. Right then it's really very cool. It's a very nice way to do things. And the same is true for some of these Google devices and other devices. So they have multiple microphones and usually, these are microphones that are mounted right on the printed circuit boards inside, but they are called memes.
Microphones. And these are often kind of surface mounted and are usable by anybody who wants to buy it. These aren't like made specifically for Amazon or anybody out, but they're microelectromechanical systems, MEMS microphones, and you put them right on the printed circuit board. And off you go, it's really that easy for these guys to put the microphones on.
What was fascinating here is that these researchers used the light beam, some the laser pointers to send invisible to the naked eye and inaudible commands to the digital voice assistance. As well as by the way, voice-controlled smartphones and tablets, even through glass windows as far away as a football field.
In fact, a little bit further. So think about that. Okay. Let's say that you've got your Google assistant or your Amazon Alexa or whatever it might be your Siri set up to control. The devices in your house. So turn on and off the light, maybe turn on and off your security system. Maybe open the garage doors all through these smart devices.
And all they would have to do is send a command disarm. The home security system, open the garage door, unlock the front door, turn off the alarm you getting where I'm going here now. Okay. So now they've taken the research to the next phase because there's still some real mystery. Around what's actually causing this physically, how is it working?
And that is just phenomenal. So there's a Ph.D. student by the name of Benjamin Cyr over at Michigan, who, along with another researcher, Sarah Rampazzi is presenting the latest illustration of the research that they are doing at Black Hat Europe coming up on the 10th. So the big question is why are the microphones responding to light as if it's sound?
They're trying to nail it down on a physical level so that future hardware designs can protect them from these light injection attacks. Now, apparently our friends over at Amazon. heard must have heard about this. I don't know if these guys reported it or not, but there are some other people who have found out, there's a researcher, an assistant professor at the university of Florida.
Another one at the University of Michigan who are planning to show how a security camera could be manipulated by a hijacked voice assistant. So they're going to show it and they're using it against the Amazon echo three, which is a newer model of the smart speaker. There was not available last year when they first detected, detected this problem.
Echo's series Facebook portal, Google home, basically anything that has one of these memes microphones in it. And they are saying that apparently they all care. We go, yeah, they did share their findings with Amazon and Google and other vendors and Amazon at least have put a little block in front of the microphone so that, lasers can get and get inside to the microphone.
But the researchers spent just $2,000 in equipment in order to conduct this attack. And that included the laser pointers, a laser driver sound amplifier, but they said it couldn't be done for as little as a hundred bucks. Including a low-end laser printer for cats. Pointer, I should say for cats that can be bought on Amazon.
So there you go. Cat toys, a longer range attack, apparently, they purchased a $200 telephoto lens and that let them shoot the light beam down a long hallway and they encode the signal to the microphone. It gets modulated by the light. It's pretty darn simple. To carry out this attack.
I don't know. We'll see what happens. Apparently, the new generation of devices from all of these manufacturers are going to have a cover.
Amazon made some slight updates to the Alexa software so that an attacker would be unable to brute force a device pin. If you have a pin set on your device, which is probably a really good idea, if you're using it to open doors or turn on or off alarms, I'm not as worried about turning on my lights right in the house.
But this is just absolutely fascinating and once we figured out the physics behind it, maybe there are some good things that could come of this. But, there were thinking about making the mic and susceptible to the light, adding authentication to the software, many other things, but it is absolutely fascinating.
So there you go. Something we never expected. Something no one could have predicted that is frankly an absolute problem.
We're going to get into some shopping tips here. We've got a special emergency, a bit of information here from the cybersecurity and infrastructure security agency.
CISA as it's known C I S A and we'll be talking about that as well.
I want to just take a minute here for businesses. If you have security requirements. And there is a lot that, listen, in on my show that has these new DOD requirements called CMMC. There are five levels. I'm going to be doing some special training on this stuff. So we're going to be going through everything from level one, through level five and explaining each one of the controls. There are over 170 controls now, and we're going to go through each one of them. So if you're struggling with this and I don't know a soul that isn't struggling with it. Even these huge military contractors whose whole life is doing military contracts. They're all struggling with it. So how do you deal with it? So we'll start with, how do you know if you have to comply? If you're selling something that is sold to a defense department, subcontractor, or contractor, You may have to follow these new guidelines. I know companies that make just passive filters, power supplies, wiring harnesses that do fall under these various categories. Now it could be as easy. If you are the guy mowing the lawn for the facility, it could be as simple as a few thousand dollars to get yourself up to snuff as to where he needed to be.
If you are, however, making something that goes into something that goes, boom, and it is truly not commercial off the shelf and buys that commercial off the shelf. They mean it really is just off the shelf. You have no idea that it's a military use. You have no idea what contract it might be under. You don't know that it's a military subcontractor. then you're okay.
But if you know that one of these subcontractors or contractors is buying something to go into something that is used by the department of defense, well, now you have to worry about compliance. So yeah. I'm going to be doing a whole series of training on this, and we're going to have some free stuff. There are going to be some paid ads, but I want to make sure that you subscribe to my newsletter so you can find out about it.
We'll be starting that up after the first of the year. So make sure you check it out. Go to Craig peterson.com. Slash subscribe. You can subscribe right there. I'm not going to harass you or anything else, or fill out the form on the bottom of my page.
Craig peterson.com.
Hello, everybody. you are probably fairly familiar with all of the normal tips about shopping online. We're going to get into a little more detail here and what you should do while you're shopping and after you have been shopping.
Hey, this is Craig Peterson. you can find almost all of this stuff up on my [email protected]. And if you are not subscribed to my newsletter or my podcast, please take a minute to do that on your favorite podcasting application.
There are a lot of tricks that are going on right now when it comes to online shopping things that we have to be very aware of. You've probably heard about many of them before. There are, of course, all kinds of nasty people out there that are trying to trick us into maybe given a credit card where we shouldn't.
I want to play a little bit of audio as well from my daughter. This is really sad, but, she got this phone call and it came through on her phone. Regarding some fallbacks activities in the state of Washington. Do we need to talk to you as soon as possible? This call is from the social security administration. I'm literally trying to the department (509) 524-9631. I think it's (509) 524-9631. Thank you.
Now I usually don't play the phone number when someone leaves a message. But in this case, I don't know. I, if I was you, I probably would not call it. Cause now they know that you are a person who is potentially going to be open for fraud. So don't call those numbers.
I think that's an important thing for us all to remember. But in case you couldn't quite make it, how it was the social security administration calling and they were calling because they saw some fraudulent activity in Washington. And they wanted to follow up with you and you, they wanted you to call back. So obviously don't do that.
My daughter got this phone call just this Thursday. It was in her voicemail. Don't call these people back.
I have a friend who will see a phone number coming in, a call comes in. Oh, I don't recognize that call. He'll just let it go to voicemail and he doesn't listen to the voicemail. He just calls the number back. Hi, you called.
Don't do that. There's a couple of reasons. One is in the, in most of these cases, they are trying to get information about you so they know you'll call them. So they might be able to trick you. But in most cases, that caller ID is fake. So they're sending you a caller ID and it says some phone numbers. Sometimes they even use phone numbers of police departments, which is really funny.
There's a video online of a police captain getting one of these fraud calls and she keeps this fraudster on the phone and who's telling her that he's going to report her to the local police. They're going to come by and arrest her unless she pays him right now. She's just doing everything she can to not laugh because she's the chief of police. Are you kidding me? She knew it was a fraudster. We have to be very careful with these people. So many of us, particularly the older generations, are trusting, and that can be a bad thing, but it's not just them. It's the young people too.
I am shocked at what they will do, what they'll get away with, and how they just don't care about cybersecurity. Really don't care. I had a discussion with one of my sons and he didn't care. He was just pushing back as hard as he possibly could. So maybe it's a Dad thing. Cause I'm his dad and I'm into cybersecurity. It's what I've done for a living for decades and he is just rebelling. He's how old is he now? He's probably 24 or something like that. I know a lot of us rebel and push back against this stuff.
Just like I talked about earlier with the printers, we know we should be keeping our firmware up to date, but we just don't. So watch out for those scammers.
One time I was on the floor of a trade show. I was actually exhibiting there at the trade show and talking with people and everything back and forth. I thought it was going pretty well. Then I got a phone call and I answered it and it was a lady from the IRS or at least that's what she said she was and I knew it was just totally fake because the IRS doesn't just call you out of the blue. The social security administration doesn't just call you out of the blue. They will send you a letter. It's really that simple. So I hung up on her and she called back like six times and I told her, listen, this is a scam. I know it's a scam. She was asking for I think it was Apple gift cards. Really Apple gift cards. I can see Amazon gift cards, but Apple's a little more limited, I don't know. I don't know. Maybe they'd just buy apple phones with those gift cards and then sell them on the gray market or the black market once they got the hands-on. I just don't know.
So it is happening and it is going to happen even more this year. And many people ask why would someone do that? In many cases, they don't really know what they're doing. They're just calling from a call center and they've got a script to read and they are told that it's legitimate, right?
In another case, the people who are running this scam know it's not legitimate. And then other cases, they're an active participant, but they're making money. And it's the only way they know how to make money is to rip people off, which is just a shame.
Between you and I see this all the time in the IT world, where there are a lot of businesses out there that are scam artists. They put up a shingle saying I'm a managed services provider, or I'm an IT professional because there's money in it and they're not.
We have a client. This was absolutely fantastic on Thursday this week. One of our techs. One of our senior techs was out there. He said that we were the best, IT support people he has ever seen. He's been in business for about 40 years and he was just ever so grateful for everything that we're doing for him and his team, his company, helping him to grow and solving all of these it problems. He doesn't even have to think about them. He doesn't even hear about them because many times we solve them before they even know about it. But we're right on top of it. We're helping them, we get the right equipment. So he doesn't have to buy it again when it breaks and he doesn't have to do with the downtime that you always have to deal with when something breaks or something fails. So he is very grateful and so am I frankly, for what he's done for us, which is pay his bill it's right. They're very good people and made me feel very good about that. But anyhow, okay. So I am going on and on here.
Let's talk about online shopping and the safety of online shopping. There is a great article that I picked up from CISA. Which is a federal government agency called the cybersecurity and infrastructure security agency.
CISA.gov is where you'll find a lot of this online, but let's go through some of the tips. The first one is the best defense there is, frankly, which is be aware. Before you do anything, stop and look.
I do that all of the time. I get an email from someone. It might be a legitimate email. It might be legit from Amazon or from Walmart or whatever online store. I always stop and look at it.
The number one thing to look for is grammar. Good English grammar, at least good enough. English grammar that you think that they're probably a native English speaker.
Now you say, there are all kinds are wonderful people who aren't here, English speakers in. That's true. There are multiple things to look at. We're just talking about one of them here right now, which is are they native English speakers or is this very poor or grammar?
Because most businesses are not going to send out an email just full of grammatical mistakes or spelling mistakes. Does that make sense to you? They're not going to do that because frankly it just reflects very badly on them. That's not something that you want to have happened. So that's the first thing to do.
Next double-check all of the URLs. So that email from the address should be absolutely correct. Is it absolutely amazon.com or is it AMA dash Z O N.com or is it a M Z O N.com?
Any of these misspellings, common misspellings, things that you might just overlook normally, does that email contain any of those types of things? That's all a part of Awareness. What we're trying to prevent here is what is called phishing attacks, or even spear-phishing attacks, where they are sending us something that looks legitimate on its surface, but obviously is not when you get right into it.
So in most cases, when I get an email from somebody, what whoever they might be, I look at it and say, is this a legitimate communication? Am I expecting it? If it's from a bank of mine or some other vendor, I rarely ever click on the link in there. I usually go to their website directly.
You don't call back a phone number. If they say they're calling from the local police department, you look them up in the book, and yet, and you look them up online, right? Who has books anymore? You call that number, not the number that they gave him. All right.
We've got a lot more about shopping safely online this year.
Visit Craig Peterson.com.
Now that we know the basics, let's get into the details of what are some of the things you can do. In addition, we're going to get into multi-factor authentication and much more. So here we go.
So let's talk about these devices that we're going to be buying this year and next year.
2020 is going to come to an end. Some of this stuff's going to spill over into next year. There are a few things you really should be doing, especially with your Bank or Amazon, anywhere where you have financial data.
One of those things is called multifactor authentication.
A lot of these businesses have this called also two-factor authentication. You might see it abbreviated as. 2FA or MFA.
So what is this two-factor authentication? In many cases, businesses are using a text message that they'll send you when you log in. So you go into your account, normally it's where you would set your password, and you'll see something there about multi-factor authentication or two-factor authentication.
You'll go to that and in most cases, they'll ask for your phone number and they'll send you a text message to verify it. And you're off and running. So now the next time you go to log in to that site, it's going to want your username or email address, and it's going to want also your password. And hopefully, you're using a different password on every website out there.
And then it's going to send you a text message and that text message will have a number that you can then type in on the website. Okay, this is really you. Now you gotta be careful with this because there are a number of people who have been bamboozled by this. One of the ways they got bamboozled was where yes, indeed people stole their phone number.
So an attacker knows that you have something valuable, they want to get into your bank account, or maybe it's getting into your Bitcoin account, whatever it might be. They find out what your cell phone number is and then they call up your cell phone provider and they say, Hey, I've got a new phone and then they give all of the information for the new phone and they can bamboozle them to get them to switch.
Before you know it, 'cause you're not getting to notice, Hey, I just didn't get any phone calls. Not a big deal. It's wonderful that people haven't been bothering me on the phone. But what has actually ended up happening is they now have your email address. I assume that they have your password because most people use the same password on multiple sites, or it's an easy to guess a password, easy enough to find the breached passwords on the dark web. I do it all of the time when I'm looking for dark web stuff for my clients, but now they have your phone number.
So when they go to log into that bank account, They've got the email address. They got your password. Cause you have used that same password elsewhere. When the bank sends a text message to your phone, it doesn't go to your phone and you don't even know it went to your phone.
So here's an important tip. Contact your cell provider and have them use a pin or a password with you so that when you call up, they're going to ask you, what's the password for the account. Now, this is going to be a different password than you'd use on the website. But it's going to be a password, in some cases, it's a pin.
So come up with something that you don't use anywhere else and set it up with your cell phone provider. That way, if they are going to hijack your SMS or text messages, it doesn't matter because even then they can't get through, but there's a better way. Okay. There's a better way to do all of this. There are some paid and some free two-factor authentication apps. What I use personally, and what we use with our customers is called duo D U O.
We've been using them for years. Cisco of course bought them because they were the best in the business. That's what Cisco does.
So DUO allows you to have a different type of two-factor authentication. You can also use Google authenticator, which is free. You can use Lastpass. In fact, I got an email this week from one of the subscribers to my email list, thanking me for the recommendation for Lastpass. And by the way, if you want a copy. I have my special report. I'd be glad to send it to you. That talks about passwords talks about 1password and Lastpass and what you should do a little bit about two-factor authentication.
So I use DUO. I also have Google authenticator, although I don't really use that at all. I tend to use Google or I should say. what happens with that is they'll display a QR code when you're setting up the two-factor authentication. That's one of those square things that has all of the little squares inside of it that you can use to go to a website is typically what you'd use it for in this case, it then syncs up a special Countdown a few seconds, and it'll give you a six-digit code that you can use. That code is only good for 30 seconds. So now when you go to log in, you're going to give you a user-name or email. You're going to give your password. And then it's going to ask you for that. Code so you can use.
Again with DUO, I have adjusted automatically. It comes up, it's integrated with my one password as well. So I can now log in and I know it's extra safe because even if someone steals my phone number, It's not going to do them any good because I do not use my phone for verification, for two-factor authentication.
Now there's one more trick that you could play if you wanted to. And I have done this more than once. Some websites do not allow you to use an authenticator app. Yeah, I know behind the times, aren't they? So you have to use SMS. If you want to use two-factor authentication, in other words, you have to have a text message sent to you. So what I do with those sites is I have a phone number that isn't a real phone. So I have a phone number that I got years ago from a company that Google bought. Nowadays, Google calls it Google voice. So I have a Google voice number and I will give them that number. Now, why would I give him that number? first of all, I can filter calls that are coming in and text messages and everything out. Google will forward the text message to my phone. Remember it's Google, so it's not terribly private, but that's okay because those numbers are usually only good for a number of minutes. Okay. So it's not a very big deal, but the reason I use something like Google Voice is it's not a real phone number, so they can't call up T-Mobile or Verizon or whoever you have your phone through pretending to be you and get them to transfer that phone number because they can't and they won't. Okay. It's very important.
The SIM card that you have on your phone nowadays, some of these devices have virtual SIM cards. that SIM card that's in your phone can not be stolen or duplicated or anything else either if you're using one of these Google voice numbers. So some really important tips there.
I hope you took some notes. If you didn't, you can find this online. I post these as podcasts, you'll find right on my [email protected]. You can listen to them, take notes. And my wife even provides a transcription of these things most of the time. bless her heart.
She spends a lot of time doing that, and she'd appreciate it. Check it out online. Craig peterson.com.
We're talking about how to keep your devices safe that you're buying this year things you're getting for family, for friends, maybe for yourself as well. And we're going to get into it more. Now we've got some really surprising things for you guys.
One of the things that we have to do, and this is again, over and over again but better than 60% of Windows computers are not up to date. Remember we're buying nine devices that are basically computers.
Do you remember that whole Barbie thing from not too long ago? I was on TV with this thing and it was sending audio up to the internet and we were able to intercept it. We did a whole thing on television about this. Obviously, it's a very big problem because it's your kid's information, voices being sent up, in the Barbie was interactive. Now Mattel cleaned some of that stuff up and that's always a good thing. But the point behind this whole computer in a toy or other device thing is that their computers. We're talking about mobile phones and Android phones, just not getting security updates. If you're going to insist on using an Android phone, make sure you get the latest model every two years, because even Samsung only supports their phones. They're top of the line phones for two years. Okay. Versus your iPhone, which is good for five or more years. So keep those phones up to date.
In fact, when you first get the phone, probably the first thing you should do is check for a software update. Computers are the same thing. Whether you're getting one of these Chromebooks, which are very good, generally speaking, I'll remember it's Google okay. But the Chromebooks tend to be kept up-to-date because it's pretty much automatic. And I know a lot of security researchers use Chromebooks and use them exclusively because they don't have the same security problems as Windows. What's one of the reasons Apples don't get attacked as much as windows computers because the Macs, frankly, are not as common. They're only about 8% of the market out there, depending on whose numbers you're listening to. So why would they go after it? Plus it's a little more hardened than windows is. In fact, it's a lot more hardened than Windows is. Microsoft is starting to fall-in behind Apple's lead, which I think is a good thing.
So those computers, update them immediately. If you're still running Windows seven, make sure you get 10. Cause seven isn't getting the updates anymore. If you're running Windows eight, 8.1, make sure again, you upgrade to windows 10.
But brand new computers shouldn't come with those. Another quick word of warning about computers that you're buying. The home edition of Windows does not have the same features as the business additions or enterprise additions of Windows. So you might want to when you're buying something, look for Windows professional, it has more options. One of the options that could save your bacon is the ability to put off updates.
Now, you're I hear you saying Craig, you're always telling us to update early and update often. yeah, that's very true because many times when you get that patch, it's because there is something going on in the wild. Bad guys are actively using it to exploit you. To exploit your faults. Okay. So there are some very good reasons to stay up to date.
But, here's a problem. I had a law office call me up because right in the middle of them putting together some documents for the court that were due in less than two hours. Windows and they were running home edition, decided it was going to force them to do an update. You can imagine the trouble that ensued because they weren't going to be able to get the paperwork filed with the court in time. Very big problem.
Even if you're not an attorney, you're not dealing with the court. Windows professional does give you the option to schedule the dates, you can push them off for a week and then you can get into the more advanced stuff too, with the device management, MDM type stuff where you can now manage that device and make that device, secure, most, if not all of the time.
Okay. So let's move on next to tablets. Again, look at something like the Amazon Kindle. Here's my watch talking, hit the Siri button accidentally. So the Amazon Kindle fire that is an Android tablet. Now, one of the advantages is it is updated by Amazon automatically. It gets all of these security updates and other things. That's a very good thing, and it gets them for a fair length of time and they are cheap. You can get them for 50 bucks, 70 bucks brand new from Amazon. I got one a year or two ago, probably a couple of years ago. And it wasn't well packaged and it's shipping and the front screen was just cracked all the way down. So I returned it, they shipped me another one, and that one wasn't cracked. So that's good, but I've kept an eye on it and it has been very good. I also got with the amazon fire tablet, one of these stands that you can put it in, it's a charging stand, but when you place it in the charging, stand it then becomes an Amazon Alexa.
Little kids come over, grandkids, and they want me to play baby shark, which is an annoying song that, the grandkids, every generation has this. I remember a slightly older grandchild. A granddaughter who used to love, ah, jeepers. What was a gummy bear? That's what it was. Gummy bear. Remember, that song was incredibly annoying too. I ended up getting the guy who wrote the song on the radio show with me to talk a little bit about it. It was fun actually.
Those of us who needed to be kept up to date all of those tablets, because they are real computers, but nowadays we're buying appliances. I remember five years ago, I think it was out of the consumer electronics show. I saw another one that you put into your home and it had an Android operating system in it, it connected to wifi and it allowed you remotely to say, Oh, you know that steak or roast. It told you to cook in the oven at 5:00 PM, I'm going to be late. So you just go online and I type it into my phone and ta-da, I am now all set. There we go. And it's not going to start cooking it until six 30. that's all well and good.
That appliance has a computer in it and it's sent into wifi. Have you updated it? And does it self update? How long are they going to be providing updates for that oven? I'm sure five years later, there are no more updates for it. Now have an appliance, a device, that is frankly dangerous on your network because if somebody comes over to your house, they've got a laptop, they connect to your wifi and it now infects your appliance.
Okay. Whether it's your washer or your dryer. Those are the two most common, I think right now that are internet-connected or your oven or your microwave or your garage doors or your security system or your lights, those can all get infected. They are used as launching points to infect everything else on your network.
Check the update, make sure everything's up to date. And in some cases, it's pretty hard to update, but it's worth it. You have to do it even with your children's toys. One of the things I do is I put them on a network segment that has no access to anything else. I have an IoT wifi network, the internet of things.
You're listening to Craig Peterson. Make sure you visit me online. Craig peterson.com and sign up for my newsletter.
We've talked about, multi-factor authentication, we've talked about, of course, protecting your devices by keeping your software up to date and that's everything nowadays, really, and how to do that. What's up for that. And now we're going to go into a couple more good points.
Of course, you're listening to Craig Peterson.
Now, once you've purchased an internet-connected device, no matter what it is, if it's a router or firewall, if it's a Barbie doll, change the default password. In most cases you can connect to the device, just using a web browser that makes it very simple.
So you use the web browser, you connect to the device. Most of them have web servers on them. If you can imagine that, A little doll with a web server on it, but yeah, that's what happens. Your refrigerator probably has one of his internet-connected and your washer, dryer, light bulbs have little web servers built into them and you want to connect to them and change the default password.
Look up the manual. It's probably not going to tell you how to do it with the information that's in the packing. If you go online and search for that device, you can find out how to change it. Use different passwords for every device.
Always use complex passwords. Now complex doesn't mean that it has to have special symbols in this upper case, that lowercase, et cetera, it can just be three or four words strung together. That's all it needs to be. You might want to throw a digit or two in there, maybe a special character too, but a phrase is the best.
In order to do that, you're probably best off using a password manager to help out. So that means using something like one password or LastPass. Once you've got that in place, it'll generate these passwords for you, automatically. It'll remember them. It keeps them encrypted. So you only have to remember one password and that's the password you have set for the password manager.
Now, in my case, I've got it set up with DUO again. So I'll go into one password and one password is going to ask me for my password and it's also going to authenticate me via DUO on my smartphone. So there's multifactor, three-factor authentication. Okay. So important for all of these devices that connect to the internet.
Also check the devices, privacy, and security settings. A lot of times the manufacturer will let you set up an account on their website. From there, you can tell it what information you want to share and don't want to share.
Now, remember what I was talking about in the last hour with Apple, they are being very good about this and they are now demanding that all of the app developers disclose to you that you have indeed given consent for this information or that information to be used by that app developer and sold.
You can go to the Mattel website, set up an account for your device, or the Samsung or whatever it might be. And right there, you can examine your privacy settings and what do I want to allow the vendor to gain access to?
Make sure you're not sharing more information you absolutely need to provide, they're not going to ask you for social security numbers or other things. There's no reason to write that stuff that the bank or the IRS is going to want. Not these guys, at least, hopefully. Make sure you're enabling automatic software updates, wherever you can.
The latest version of the software usually tells you that it has the latest security fixes. Hopefully, it does but it also helps to ensure the manufacturer still supports it. If you've got automatic updates and they're sending updates to you and a hundred thousand of your closest friends who also have the same device, they're going to continue to support it and that way, the latest patches are going to be out there. If you're not getting the updates and nobody else is, the manufacturer is not going to have a lot of incentive to give you security updates. Then there's the normal stuff about, don't use public wifi. That's generally a good idea.
But if you're using a secure server connection, That's that little lock up in the URL bar. Then you are effectively creating a VPN between your web browser and that remote server, and that's going to be quite safe. So personally, I don't worry so much about that. I do worry about my machine being attacked, but I also have a very good firewall turned on and I have all of the services that I don't need to have shared turned off.
I am going to do a class on this, a little course on hardening windows. In fact, we've got it all written. We've got slides together. We'll probably be doing that after the first of the year. So keep an eye on your email for that. Cause anybody who gets my newsletter, I'll tell you about that.
How to harden windows, so that even if you are on public wifi somewhere, you're going to be relatively safe and the same thing's true. If you're. Using your phone for instance, and you're sharing your phone's network connection with your computer. It could still be used by bad guys to try and get into your phone.
These ISP internet service providers are not completely on top of all the security. Okay. all of the basic stuff don't provide personal information, financial information. I tend to use. These one-time credit card numbers. So every time, if I go to a site and I want to buy something, let's say I'm on GoDaddy buying a domain or I'm on Walmart side or Amazon site each one of those, I use a different credit card number. Check out your credit card provider, all of the major ones, Visa and MasterCard have the ability to create virtual credit card numbers. That way that credit card number can only be used on that website. So you create this credit card number. It's very easy to do. It's usually a plugin in your browser. You create a credit card number and it's for amazon.com. If somebody were to get that credit card number from Amazon and try and use it somewhere else, it will not work. It will only work on amazon.com. Isn't that cool. The other advantage is if someone starts misusing it, then you can just turn off that virtual credit card number. It's really that simple. So have a look at that. One-time use credit card numbers or these virtual credit card numbers, which is what I like where you can use it multiple times on that site, you don't have to create a new one every time available from most banks and all major credit card companies.
Also, be careful with the websites. You're going to make sure you type that URL correctly. As I said before, I always spend a few extra seconds whenever I'm on a website, I'm going to a website. I'm reading the email, just making sure that it is correct. I spelled Amazon or the email address that sent it to me is legitimate.
I can't believe how many times I get an email. It's a phishing email and it's from somebody@gmaildotcom as though a major business is going to use gmail.com. That's a word of warning too, to the small businesses that are trying to do online stuff. Make sure you have your own domain. That you're not using Gmail or Hotmail or Yahoo.
I've seen so many people doing that got even proton mail. Proton mail is quite secure and, it's really nice the way they're doing it. It's hosted in Switzerland. Check them out by the way. I put something about that in my newsletter a month ago with what that's all about. If you want it, just let me know, just email [email protected] and in the subject line mentioned proton mail or something, and I'll forward you that newsletter so that you have it. You can always search if you don't delete my newsletters, you can always search for that information.
You can have proton mail set you up with your own domain. So it's from Bob's country store.com instead of Bob's country store at gmail.com. Okay. It looks much more legitimate. let's see offers obviously, be careful with those who don't click links or download attachments unless you're really confident.
Again, I tend to go to the website as opposed to click on the email that I got. There always this warning or that other thing, just go to their website, make sure that it's all being encrypted again. That's that little padlock if it's closed or your information's encrypted, which is really good.
If you can use a credit card. Don't use a debit card. There are laws to limit your liability for fraudulent credit card charges, but you don't really have quite the same level of protection when you're using a debit card and the money will be taken out of your account with a debit card. If a bad guy. Is using your debit card and then you have to file a police report and then you have to file with the company that gave you the debit card and then you have to wait for the money to be credited back to your account.
In the meantime, your checks are bouncing or if you use the debit card for other things, it is being denied. Okay. So be very careful with that. insufficient funds are always going out there.
I would urge you to just be very careful, very cautious, just like Santa Claus, checks his list and checks it twice to the same thing all the time when you're online.
Hey, if you don't get my free newsletter right now, make sure you sign up. I have all kinds of tips. That's what it's about. You also get all of my podcasts segment that you can just click on right there in the emails makes your life easy and helps to keep you safe online.
Just visit me online. CraigPeterson.com. You can go look at anything you want. If you scroll down on the homepage, there's a little form you can fill out. If you have an explicit question for me, always glad to answer them. And then at the bottom of the page, a little subscribe box will show up as well.
Take care, have a great weekend. Join me again next week.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome! Â
This week I am spending a bit of time discussing Faces that are designed to deceive, Dangerous Printers, Multifactor Authentication, Shopping Securely on and offline. Why you must update ALL your devices and More so listen in.
For more tech tips, news, and updates, visit - CraigPeterson.com.
---
Tech Articles Craig Thinks You Should Read:
Designed to Deceive: Do These People Look Real to You?
Printers' Cybersecurity Threats Too Often Ignored
What's in Store for Privacy in 2021
Alexa, Disarm the Victim's Home Security System
HOLIDAY ONLINE SHOPPING SECURITY - From the Cybersecurity & Infrastructure Security Agency
Latest Version of TrickBot Employs Clever New Malware Obfuscation Trick
Artificial Intelligence can run your work meetings now
Facebook’s libra currency to launch next year in limited format
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hey, what's up for privacy coming over the next year. We'll be talking about that design to deceive. How about your printer? When was the last time you actually checked that printer to make sure that well, everything was legit, as it were?
Hey everybody. Craig Peterson here. We've had a problem with fakes.
You've heard about fake news. Of course, President Trump's been talking about it. I think it was actually Hillary Clinton that had coined the phrase fake news, but there is all kinds of fake stuff going on right now, out there.
One of the big things that really concerns me is the fake identities that are right now being used in order to rip people off. That's a huge problem. When you get right down to it, we have a lot of people who are lonely.
Think about people who might be divorced, particularly elderly people, someone that's lost a lifetime mate. Nowadays, they don't see anybody anymore. they might have someone come in with a face mask on and a big shield and gloves and it's just not human touches, it's not human interaction. They're not interacting with their family face to face.
They of course, hopefully, have some way to do it virtually, maybe using Zoom, which, isn't safe. You should never use that as a business, but it is fine for family connection type of stuff. And I've used it before for different types of business conversations. I'll admit that. And in fact, when I was doing all of the webinars for the FBI's training program, as part of the whole InfoGard stuff. I was indeed using Zoom because that's what they told me to use. I approached them. I said, Hey guys, we should really be using WebEx because they have versions that are safe. That can be used by people like us that are trying to keep our information safe and keep people out we don't want to have in it. The response I got back was, no, the FBI has authorized the use of Zoom. We can't use anything else.
Of course, once again, Craig's proven, right? About a year, actually about two years later, what happens? We find out that Zoom was routing data through China, that they have developers in China, and that it was anything but safe. A real problem, frankly. okay. That was an, I told you.
But how about when you're going onto the dating site and you're not so concerned about people finding out about you. In fact, that's the reason you are on the dating site. Do you want people to find out about you and you go there and you're trying to figure out okay? Is this somebody that I can trust? Is this somebody that I should trust? I know many people who have found some of these dating entries, if you will, the posts we'll put up to be highly deceptive.
That is the problem that we're seeing all of the time. Now, when it comes to security. The bad guys are highly deceptive. And that's a huge problem because when you're on that dating site, they, might not even meet data insight. It might just be your Facebook page or something. And you find someone with some common interests and you start to talk to them and you build a relationship, all good stuff.
It's all stuff you and I need to do, we all need to do, isn't it? How do you verify whether or not that's a real person? Let me give you a hint. If you go to the Google homepage. I'm going to bring it up right now for me, myself. So we can talk along and you can see it has Google search on it.
I'm feeling lucky if you go to the upper right-hand corner, you'll see a little thing called images to a little line. You click on images and now up comes Google image search. So this is a bar you can type in just like you would any sort of a regular Google search. But it has a little camera. Did you notice that over on the right-hand side of the bar, you click on search by image.
This is where it gets interesting because if you're on Facebook or Instagram or one of these dating sites and you want to see, is this a stolen picture? Is this really a picture of John or a picture of Mary, whoever it might be. You just get the URL to that picture in the way to do that is either you can save it to your disk. If you can download it or you can right-click and copy the URL of the image, and then you paste it here into the paste image URL.
That you see right there on Google images and then you click on search by image. So I'm going to do it right now. I'm going to go to Craig, Craig Peterson.com. And I am going to grab my picture.
I'm sure I'm on here somewhere. Okay. We've got all my latest podcasts. Got questions? Subscribe for email updates. You know what? I don't have my picture on there, but I'm going to grab the U R L and you say open image and hub. And this is my logo. Okay. It's not like a phase. Yeah. Good and find a picture of my face right there on the website. I should probably fix that.
I'm going to copy, I've pasted it now into the paste image URL on Google. I click on search by image. Now, remember I was looking for my watch. It's looking for my logo and it's telling me, okay, here we go. Oh my gosh. Oh my gosh. So my logo does come back with my website a whole bunch of times, which is what you'd expect. But it also comes up with this. I'm not seeing here, come up with crude. The real price of oils. It says it's an epic story of one of the largest and most controversial legal cases on the planet. a $27 billion Amazon Chernobyl lawsuit pitting 30,000 rainforest dwellers. So it must have something to do with crude oil. That's interesting because their logo is similar to mine, but that's what we're looking for here.
Is the person whose pictures on that Facebook page or Instagram or dating site or whatever it might be? Is that person real? So when you look them up, you're going to see multiple times. results hopefully. and just kinda show them all. Yeah. This is a picture of them at home. This is, Oh, wow.
That's where they work. It's got a picture of them at the office. It's got pictures all over the place. Okay. That's obviously a legit person. what happens if it comes back with. Only maybe one match and that's their Facebook page or their dating page, et cetera. that's what I'm concerned about right now because so many people are being deceived and it's one of the things that the. FBI has sent us notices about. They are mostly seniors, all the way on, down through generation Z, the youngest adult generation we're falling for it. So if you go right now, there's a website called this person does not exist. Okay. So while you're listening, go there, this person does not exist.com and you will see an amazing picture. So I'm looking at one right now and it varies. Okay.
This was generated by an adversarial network is what it's called. You can find out how it works and you can do all kinds of stuff. And the picture I'm looking at right now is actually a young lady. I would say she's probably around 30 years old and that's based on some wrinkles around her eyes and under her eyes, mine puffy under my eyes and the cheeks. Just little tiny wrinkles. So she's in her thirties somewhere and a really pretty I would say it's been a little bit, bleached hair is Brown and they at the roots and then as you get further down, it's more bleached out as more like mine, a dirty blonde, very interesting stuff.
So you can go and you can go to right there grab a picture of a person that is not real. This person does not exist and you can even manipulate it there on the website. You can go to other places like generated.photos. That's the whole domain generated.photos. And once you're there, you can get what they call unique worry-free model photos.
What's a whole worry-free thing about? The bottom line is if you are a business and you buy a photo of a model and you can get them a lot of places online, I subscribe to some services that provide those for me. So you can get all kinds of different pictures, photos, but you can end up getting sued because maybe the release wasn't quite right. Or they signed the release, but they never got paid. The check bounced as it were. Or the transfer didn't happen over on Apple pay. Whatever they were using Samsung paid failed on them. So they have removed their permission and yet that picture is still being sold.
We've seen more and more, some of these places online that are selling our personal pictures that we've posted up on the websites. Obviously, not the best idea in the world is it frankly. So you can just go to generated photos.com, browse photos they're made by AI, these AI systems. What are you looking for?
You can search for anything I'm seeing right now. It says white woman, young adult, Asian toddler, infant, or so cute, elderly. This guy doesn't actually look that old. maybe it's because I'm older. I don't know, but, you can get them all there. You can buy a whole for three bucks or you can go and buy if you need a lot of them, a thousand for a thousand bucks.
So how do you use that? obviously, there's this legitimate purpose.
Unfortunately, there's also illegitimate slash illegal purposes out there. That is to use these pictures to con people to make them think that you have a legitimate presence or they have a legitimate presence online, and then they build a relationship and that turns out they need some money to save their Aunt who needs this surgery.
All of that stuff. So be very careful out there.
There are a lot of cybersecurity threats that we just don't deal with. It's gotten too difficult. It's overwhelming. How can I keep up on all of this stuff? you think it's bad enough with your windows machine, your main computer. Hey, I got some news for you.
You're listening to Craig Peterson. We have a lot of devices in our networks and I've talked about this quite a bit.
It's one of my soapbox subjects, right? What's called the whole internet of things. We have all kinds of devices hooked up to our networks. I'm sitting in front of well, within my view, probably two dozen different devices right here in my studio. That's frankly, that's a lot of devices and many of those devices could be hacked.
Now my network is completely set up so different things are isolated. I have multiple segments, multiple physical segments, as well as virtual segments. And one of the ways to do a virtual segment. Is to have some special stuff on that wire where you have what's called a VLAN or virtual local area network. That's getting a down into the mud here. Something I cover in some of my courses.
When we're talking about networks, segmentation is absolutely critical. You have to make sure that your home computers are on a different network or at least a different network segment than your work computer. Now what I'm talking about in-network segment, I'm not, I don't mean, Hey, I've got a switch, or right at the router that the Comcast or an internet provider gave me. I have maybe two, three, four, Ethernet ports. And so plugging in a switch to one of those ethernet ports and then putting your home computers on that switch and then putting another switch on and plugging it into the second port on that router that you got from your ISP, your internet service provider that is not segmenting your network at all because that's typically a flat network.
If you have a fancier router firewall at the edge, you may be able to segment it that way. For instance, we sell a lot of the Cisco Go equipment, which is the low end, very good stuff, but it's very basic. It's inexpensive. It does let you do real segmentation. So you can have a guest network on the wifi.
You could have a business network and the wifi, you can have multiple what are called SSIDs that's the name of the network you're connecting to. You've probably seen that if you've gone in and configured Joe or router and SSID so you can have multiple of those on some of this hardware, like the Go hardware, for instance.
There are some others out there. I think I might end up in my emails here. In fact, it is planned. To come out with something, talking about these SSIDs and what equipment you can buy. So it should be pretty simple. Keep your eyes out on that in my newsletter that you're hopefully getting every, Saturday ish.
It depends on where I am, what I'm doing that week as to when I get it out. I just try and get it out on the weekend before my weekend show airs. But, here's the bottom line. You don't want your home computers to be able to talk to your business computers. With so many of us working at home, this is a very big deal.
So how do you do that? If they're both plugged in two separate switches that are then plugged into your router? They can probably still see each other. But if you have a more advanced router that lets you have different network segments and make it, so the one network cannot talk to the other network. Then you're really cooking with gas because now they're not going to be able to spread infections.
I've talked before about VPNs and the proper way to use them. I really think I should have a whole course on working from home again for everybody out there to help. Understand some of these basics.
Make sure you're on my email list. Craig peterson.com and then subscribe on that little subscription form that comes up. Be glad to send you these things because I will let you know when I'm going to do that because there's a lot of confusion about all of this sort of thing. One of the devices everybody has in their home and certainly in their businesses, Is a printer, and we buy the printers and we buy ink and then we buy more ink and then we buy more ink. It's just a constant buy more ink it, sometimes it drives me crazy. You're buying ink for these printers, but are you connecting them to the network? Now some of the printers, especially the lower end ones are just connected via USB port to our computer. And when they're connected directly to our computer. It's really handy but it's difficult to share that printer. You can share it from Windows. You can share from Mac. So other. devices on your network can see it. That's probably the safest configuration of all of these devices bar none really. you can get safer, but it gets very expensive, very quickly.
If you have now taken that printer and instead of plugging in the via USB port, and this is typical of shared printers like we have three shared printers here. And they're all on the network and they are all self-updating. That is the next thing, to be concerned with. In fact, self-updating is probably a very good thing.
So we have some higher-end Xerox printers. These are what we sell to our clients. These are what we use internally and those printers. Call home order supplies. in fact, you can buy these printers if you're a business and you just pay by the page, you print or photocopy, and everything's taken care of all of your supplies, the machine itself, absolutely everything and that's a great way to go for many businesses out there. That way you don't have to manage it. You don't have to worry about the expensive repairs that are almost inevitable with some of these printers, but they are hooked up to the network and that means that they could potentially become infected.
I like the idea that these things are self-updating and as self-updating printers that means one, they are going to get the latest security patches, et cetera.
If you have connected a printer to your network and it does not update its firmware automatically, or frankly, even if it's supposed to be, you got to check it. You've got to check which level of firmware that's the software that's running on the printer because nowadays everything's a computer, right? Especially a printer. Find out what version of the software it has. Go to the manufacturer's site. Make sure you have the most recent release of the software. If you do life is good. If you don't, you're going to have to follow the instructions from the manufacturer on how to load in that new software, because that printer is a computer and because it's hooked up to your network, any malware that gets on your network, and it could just be the kid's friend who came over for the evening or the night or whatever, and plug their laptop into your network or connected to your wifi. and that laptop he brought over was infected.
So now it's going to try and infect everything on the network. It finds a vulnerable printer on your network and it infects it. So now due to almost no fault of your own, your network right now has a device cause he's going to leave. He's finally going to go home. Thank goodness. Now you have a printer that is acting as a launching pad for the bad guys to be able to get into the other computers on your network. So keep that in mind.
We know that we're supposed to do something, but we don't always do it. And in this case, we're talking about your printer it's firmware, but also I mentioned that router that's sitting at the edge of the network. Do the same thing with that router, make sure it has the latest versions of firmware.
That's part of what I like about those cisco Go stuff that you can buy through me. You can find it on Amazon. Go equipment, self-updates, which is very nice.
Believe it or not, 2020 will eventually come to an end. And then we've got next year, 2021, which shouldn't be an interesting year as well, but what's in store for privacy in 2021.
2021 is going to be a turbulent year, according to dark reading, you might want to check them out. They've got some great articles, but there are changes coming in the privacy landscape.
We've seen a few over the last few years, for instance, in Europe, they come up with the GDPR, which is this data protection law. They have something similar for consumers and their data over in California.
Massachusetts has something similar. New York too.Â
We're expecting certainly under a Biden administration to have many more standards put in place. They'll end up being federal standards as opposed to the state set standards and whether or not you like that idea. I've got to say, I think it's a very bad idea, but it's good that we're talking about it because our privacy has been under assault for a very long time.
I had this conversation with my wife earlier in the week. And she was just fed up with the lack of privacy in the online world. Not that I can blame her for that. that's not where the issues came up. The issues really were surrounding. What privacy should you have? What privacy do you want now?
Ultimately, we know that when it comes to the government, Privacy on our part needs to be absolute. There are no two ways about it, right? It's one of the Bills of Rights. We have the right to be secure in our papers. We have the right to be secure in our homes. The government cannot just willy-nilly start monitoring us, recording our conversations, tracking who we call. Actually, they did that. Under the Obama administration, they did it more than ever. They dramatically increased all of that spine on us citizens. huge increases. And under the Trump administration, they drop that back pretty dramatically. under a Biden administration, I'm afraid it will actually increase.
There are two types of people in the world. there's them and then there's us, right? There are many more of us than there are of them, the people in power, but the people in power want to force standards on us that say you cannot store certain types of information or track things on people.
However, for them. The double standard just doesn't really apply, because for them they can do even more monitoring and spying on us. Pulling together the intelligence and buying it from these commercial data brokers who pulled together, all of this information that's available publicly and all the information that they can buy about us in many States and includes driver's license information.
It certainly includes everything in the registry of deeds. The secretary of state's filings like UCC ones, et cetera. So they've got a real good picture of you. They can tell from all of this information, Hey, he's driving an 11-year-old car or, Oh wow.
He's got a brand new, $150,000 car. You expect different things from those people. It's one thing for businesses to be collecting that and it's entirely another thing for governments to be collecting that. So what my wife and I were discussing was, is it a good thing or a bad thing that businesses are collecting?
it really is a double-edged sword. It's not something that's obviously bad are obviously good. For instance, if I'm in the market to buy a new truck, I'm all for seeing ads from truck manufacturers. These are cool new electric trucks, Ford of course, GM, Chrysler, whomever, it might be. I want to see it.
If I'm not in the mood for buying a new truck, I don't want to see the ads. It's a total waste of my time. So broadcast TV, for instance, doesn't know much about us. You might've noticed if you're listening via one of these streaming services to me on a podcast or a live stream, the ads that are inserted are specific for you.
I think that's generally a good thing, frankly. But there is one company out there that has been very good in trying to keep, quite a bit of privacy for you and me, and that's Apple. And I want to talk about them in just a minute.
I also want to warn you that the Department of Justice has signed a letter along with other businesses out there calling for what we call back doors. So they want some technological solutions to give law enforcement access to specific communications.
I personally call that a threat. Now you might say, Oh, that's the Trump administration. That's Bill Barr. terrible man. Terrible man. this has been going on forever. I remember talking about this back in the days of bill Clinton and the clipper chip and how they had come up with this.
Chip, the Doug does encryption and it should be used by everyone and they were going to mandate it and it turned out I had a backdoor in it, just I think it was the Jupiter foams that, Saddam Hussein and his sons were using that were actually made in the UK. And we're encrypted phones. So that they could carry on their nefarious deeds, no one could track them.
No one knew what they were saying, et cetera. Except it had a back door and the Brit shared it with us and we could listen to all of their communications. We could track where they were with who. As they were going, et cetera. Okay. as of December 8th, this year 2020, Apple's requiring developers to disclose all of the data it's apps collect from users, including data that's collected by third-party advertising frameworks that are included or linked into their code.
Now, this is really a big deal, because remember I was talking about how the government is collecting data on us and it's restricted in collecting certain types of information.
It can't do it. However, we have found now that the IRS, the immigration people over at Homeland security, and others have been buying data from these app developers. So they've got these frameworks that are for advertising and I'm using air quotes here, and those frameworks are used in those free games you have.
Why is the game free? how can it be free? How could you afford to give away these games? All of the work you put into them? They're not they're including these little frameworks and these frameworks now track where you are? Where you're going? Where you're playing the game? Some of them like Google maps try to track you all of the time.
Google, of course, makes its money primarily off of selling your information. So Apple doing this I think is a huge win for Apple and for the consumers again, how many times have I said, don't use Android. Java. One of the biggest security problems that we have in information technology is these Java runtimes.
That's all Android does. Plus the fact that it can be six months or in most cases, never until you get security patches because your phone's no longer, the latest, greatest, they just don't care about you anymore. Use an iPhone, get an iPhone. Even if you get, you do like me right now, I'm using an iPhone eight who cares?
It works. It does the job. Get the older release. It's going to save you a lot of money.Â
We're going into Alexa. This is interesting. Disarm - the victim's home security system. If you want to see these articles are more, I don't know. I have a lot more listening to my podcasts.
As in any of these segments, I do just visit Craig peterson.com and make sure you sign up for my free newsletter.
Many of us have Alexa. Maybe Google home. Maybe some of these other assistants that have either Google Home or Alexa built right into them. I guess it would echo, but did you know that there is a very interesting way to hack them?
Hey, you're listening to Craig Peterson.
Anyway, if you have one of these wonderful little home assistants, you may not be aware of it, but a light can be used to hack these things. I don't know if you watch some of these really cool spy movies. I think they did this with one of the Tom Cruise movies, but they might take out a laser and point it at a piece of glass and then use that to listen
to the discussions or whatever's going on inside the room. Now that does happen. That's very easy to do. There are devices you can buy out there for very cheap that'll do that. So it takes the light from the laser it's modulating by the vibration of the glass and they can listen to what's being said. So there have been times where I was in meetings that we needed to keep very private and unfortunately, We were well aware that there were people who would do anything to listen in to the meeting, and because of that, we ended up putting some vibration, some speakers with some Brown noise right there at the windows, so that they couldn't be listened to by laser.
So maybe I'm paranoid. At least when we were, but there was a big lawsuit going on. And there's, when you're talking about millions or hundreds of millions, even billions of dollars, some of these people will do almost anything.
And for private investigators, it's really cheap and really easy to just use that laser too. Listened to the vibration on the window from across the street. And it doesn't have to be like one of those pointer types, where it's red and you can see it. You can use all kinds of wavelengths of light, even invisible wavelengths of life, light invisible to us, Our eyes, but not invisible to the equipment that they're using. So there can be very sneaky about it. there's a team being reported here in dark reading from researchers over the university of Michigan and the University of electoral communications over in Tokyo that they were able to use modulator.
Laser beams in order to inject command into the microphones on Amazon Alexa and Google homes and other digital voice assistant devices via laser pointers. Yes indeed modified laser pointers. Now, this is very intriguing to me because the physics involved actually are not understood very well. these digital assistants have built-in microphones and in the case of I have an Alexa or an Amazon echo dot.
It has multiple microphones and you can see the light on the top that moves around and tells you which one of the microphones is listening to. Right then it's really very cool. It's a very nice way to do things. And the same is true for some of these Google devices and other devices. So they have multiple microphones and usually, these are microphones that are mounted right on the printed circuit boards inside, but they are called memes.
Microphones. And these are often kind of surface mounted and are usable by anybody who wants to buy it. These aren't like made specifically for Amazon or anybody out, but they're microelectromechanical systems, MEMS microphones, and you put them right on the printed circuit board. And off you go, it's really that easy for these guys to put the microphones on.
What was fascinating here is that these researchers used the light beam, some the laser pointers to send invisible to the naked eye and inaudible commands to the digital voice assistance. As well as by the way, voice-controlled smartphones and tablets, even through glass windows as far away as a football field.
In fact, a little bit further. So think about that. Okay. Let's say that you've got your Google assistant or your Amazon Alexa or whatever it might be your Siri set up to control. The devices in your house. So turn on and off the light, maybe turn on and off your security system. Maybe open the garage doors all through these smart devices.
And all they would have to do is send a command disarm. The home security system, open the garage door, unlock the front door, turn off the alarm you getting where I'm going here now. Okay. So now they've taken the research to the next phase because there's still some real mystery. Around what's actually causing this physically, how is it working?
And that is just phenomenal. So there's a Ph.D. student by the name of Benjamin Cyr over at Michigan, who, along with another researcher, Sarah Rampazzi is presenting the latest illustration of the research that they are doing at Black Hat Europe coming up on the 10th. So the big question is why are the microphones responding to light as if it's sound?
They're trying to nail it down on a physical level so that future hardware designs can protect them from these light injection attacks. Now, apparently our friends over at Amazon. heard must have heard about this. I don't know if these guys reported it or not, but there are some other people who have found out, there's a researcher, an assistant professor at the university of Florida.
Another one at the University of Michigan who are planning to show how a security camera could be manipulated by a hijacked voice assistant. So they're going to show it and they're using it against the Amazon echo three, which is a newer model of the smart speaker. There was not available last year when they first detected, detected this problem.
Echo's series Facebook portal, Google home, basically anything that has one of these memes microphones in it. And they are saying that apparently they all care. We go, yeah, they did share their findings with Amazon and Google and other vendors and Amazon at least have put a little block in front of the microphone so that, lasers can get and get inside to the microphone.
But the researchers spent just $2,000 in equipment in order to conduct this attack. And that included the laser pointers, a laser driver sound amplifier, but they said it couldn't be done for as little as a hundred bucks. Including a low-end laser printer for cats. Pointer, I should say for cats that can be bought on Amazon.
So there you go. Cat toys, a longer range attack, apparently, they purchased a $200 telephoto lens and that let them shoot the light beam down a long hallway and they encode the signal to the microphone. It gets modulated by the light. It's pretty darn simple. To carry out this attack.
I don't know. We'll see what happens. Apparently, the new generation of devices from all of these manufacturers are going to have a cover.
Amazon made some slight updates to the Alexa software so that an attacker would be unable to brute force a device pin. If you have a pin set on your device, which is probably a really good idea, if you're using it to open doors or turn on or off alarms, I'm not as worried about turning on my lights right in the house.
But this is just absolutely fascinating and once we figured out the physics behind it, maybe there are some good things that could come of this. But, there were thinking about making the mic and susceptible to the light, adding authentication to the software, many other things, but it is absolutely fascinating.
So there you go. Something we never expected. Something no one could have predicted that is frankly an absolute problem.
We're going to get into some shopping tips here. We've got a special emergency, a bit of information here from the cybersecurity and infrastructure security agency.
CISA as it's known C I S A and we'll be talking about that as well.
I want to just take a minute here for businesses. If you have security requirements. And there is a lot that, listen, in on my show that has these new DOD requirements called CMMC. There are five levels. I'm going to be doing some special training on this stuff. So we're going to be going through everything from level one, through level five and explaining each one of the controls. There are over 170 controls now, and we're going to go through each one of them. So if you're struggling with this and I don't know a soul that isn't struggling with it. Even these huge military contractors whose whole life is doing military contracts. They're all struggling with it. So how do you deal with it? So we'll start with, how do you know if you have to comply? If you're selling something that is sold to a defense department, subcontractor, or contractor, You may have to follow these new guidelines. I know companies that make just passive filters, power supplies, wiring harnesses that do fall under these various categories. Now it could be as easy. If you are the guy mowing the lawn for the facility, it could be as simple as a few thousand dollars to get yourself up to snuff as to where he needed to be.
If you are, however, making something that goes into something that goes, boom, and it is truly not commercial off the shelf and buys that commercial off the shelf. They mean it really is just off the shelf. You have no idea that it's a military use. You have no idea what contract it might be under. You don't know that it's a military subcontractor. then you're okay.
But if you know that one of these subcontractors or contractors is buying something to go into something that is used by the department of defense, well, now you have to worry about compliance. So yeah. I'm going to be doing a whole series of training on this, and we're going to have some free stuff. There are going to be some paid ads, but I want to make sure that you subscribe to my newsletter so you can find out about it.
We'll be starting that up after the first of the year. So make sure you check it out. Go to Craig peterson.com. Slash subscribe. You can subscribe right there. I'm not going to harass you or anything else, or fill out the form on the bottom of my page.
Craig peterson.com.
Hello, everybody. you are probably fairly familiar with all of the normal tips about shopping online. We're going to get into a little more detail here and what you should do while you're shopping and after you have been shopping.
Hey, this is Craig Peterson. you can find almost all of this stuff up on my [email protected]. And if you are not subscribed to my newsletter or my podcast, please take a minute to do that on your favorite podcasting application.
There are a lot of tricks that are going on right now when it comes to online shopping things that we have to be very aware of. You've probably heard about many of them before. There are, of course, all kinds of nasty people out there that are trying to trick us into maybe given a credit card where we shouldn't.
I want to play a little bit of audio as well from my daughter. This is really sad, but, she got this phone call and it came through on her phone. Regarding some fallbacks activities in the state of Washington. Do we need to talk to you as soon as possible? This call is from the social security administration. I'm literally trying to the department (509) 524-9631. I think it's (509) 524-9631. Thank you.
Now I usually don't play the phone number when someone leaves a message. But in this case, I don't know. I, if I was you, I probably would not call it. Cause now they know that you are a person who is potentially going to be open for fraud. So don't call those numbers.
I think that's an important thing for us all to remember. But in case you couldn't quite make it, how it was the social security administration calling and they were calling because they saw some fraudulent activity in Washington. And they wanted to follow up with you and you, they wanted you to call back. So obviously don't do that.
My daughter got this phone call just this Thursday. It was in her voicemail. Don't call these people back.
I have a friend who will see a phone number coming in, a call comes in. Oh, I don't recognize that call. He'll just let it go to voicemail and he doesn't listen to the voicemail. He just calls the number back. Hi, you called.
Don't do that. There's a couple of reasons. One is in the, in most of these cases, they are trying to get information about you so they know you'll call them. So they might be able to trick you. But in most cases, that caller ID is fake. So they're sending you a caller ID and it says some phone numbers. Sometimes they even use phone numbers of police departments, which is really funny.
There's a video online of a police captain getting one of these fraud calls and she keeps this fraudster on the phone and who's telling her that he's going to report her to the local police. They're going to come by and arrest her unless she pays him right now. She's just doing everything she can to not laugh because she's the chief of police. Are you kidding me? She knew it was a fraudster. We have to be very careful with these people. So many of us, particularly the older generations, are trusting, and that can be a bad thing, but it's not just them. It's the young people too.
I am shocked at what they will do, what they'll get away with, and how they just don't care about cybersecurity. Really don't care. I had a discussion with one of my sons and he didn't care. He was just pushing back as hard as he possibly could. So maybe it's a Dad thing. Cause I'm his dad and I'm into cybersecurity. It's what I've done for a living for decades and he is just rebelling. He's how old is he now? He's probably 24 or something like that. I know a lot of us rebel and push back against this stuff.
Just like I talked about earlier with the printers, we know we should be keeping our firmware up to date, but we just don't. So watch out for those scammers.
One time I was on the floor of a trade show. I was actually exhibiting there at the trade show and talking with people and everything back and forth. I thought it was going pretty well. Then I got a phone call and I answered it and it was a lady from the IRS or at least that's what she said she was and I knew it was just totally fake because the IRS doesn't just call you out of the blue. The social security administration doesn't just call you out of the blue. They will send you a letter. It's really that simple. So I hung up on her and she called back like six times and I told her, listen, this is a scam. I know it's a scam. She was asking for I think it was Apple gift cards. Really Apple gift cards. I can see Amazon gift cards, but Apple's a little more limited, I don't know. I don't know. Maybe they'd just buy apple phones with those gift cards and then sell them on the gray market or the black market once they got the hands-on. I just don't know.
So it is happening and it is going to happen even more this year. And many people ask why would someone do that? In many cases, they don't really know what they're doing. They're just calling from a call center and they've got a script to read and they are told that it's legitimate, right?
In another case, the people who are running this scam know it's not legitimate. And then other cases, they're an active participant, but they're making money. And it's the only way they know how to make money is to rip people off, which is just a shame.
Between you and I see this all the time in the IT world, where there are a lot of businesses out there that are scam artists. They put up a shingle saying I'm a managed services provider, or I'm an IT professional because there's money in it and they're not.
We have a client. This was absolutely fantastic on Thursday this week. One of our techs. One of our senior techs was out there. He said that we were the best, IT support people he has ever seen. He's been in business for about 40 years and he was just ever so grateful for everything that we're doing for him and his team, his company, helping him to grow and solving all of these it problems. He doesn't even have to think about them. He doesn't even hear about them because many times we solve them before they even know about it. But we're right on top of it. We're helping them, we get the right equipment. So he doesn't have to buy it again when it breaks and he doesn't have to do with the downtime that you always have to deal with when something breaks or something fails. So he is very grateful and so am I frankly, for what he's done for us, which is pay his bill it's right. They're very good people and made me feel very good about that. But anyhow, okay. So I am going on and on here.
Let's talk about online shopping and the safety of online shopping. There is a great article that I picked up from CISA. Which is a federal government agency called the cybersecurity and infrastructure security agency.
CISA.gov is where you'll find a lot of this online, but let's go through some of the tips. The first one is the best defense there is, frankly, which is be aware. Before you do anything, stop and look.
I do that all of the time. I get an email from someone. It might be a legitimate email. It might be legit from Amazon or from Walmart or whatever online store. I always stop and look at it.
The number one thing to look for is grammar. Good English grammar, at least good enough. English grammar that you think that they're probably a native English speaker.
Now you say, there are all kinds are wonderful people who aren't here, English speakers in. That's true. There are multiple things to look at. We're just talking about one of them here right now, which is are they native English speakers or is this very poor or grammar?
Because most businesses are not going to send out an email just full of grammatical mistakes or spelling mistakes. Does that make sense to you? They're not going to do that because frankly it just reflects very badly on them. That's not something that you want to have happened. So that's the first thing to do.
Next double-check all of the URLs. So that email from the address should be absolutely correct. Is it absolutely amazon.com or is it AMA dash Z O N.com or is it a M Z O N.com?
Any of these misspellings, common misspellings, things that you might just overlook normally, does that email contain any of those types of things? That's all a part of Awareness. What we're trying to prevent here is what is called phishing attacks, or even spear-phishing attacks, where they are sending us something that looks legitimate on its surface, but obviously is not when you get right into it.
So in most cases, when I get an email from somebody, what whoever they might be, I look at it and say, is this a legitimate communication? Am I expecting it? If it's from a bank of mine or some other vendor, I rarely ever click on the link in there. I usually go to their website directly.
You don't call back a phone number. If they say they're calling from the local police department, you look them up in the book, and yet, and you look them up online, right? Who has books anymore? You call that number, not the number that they gave him. All right.
We've got a lot more about shopping safely online this year.
Visit Craig Peterson.com.
Now that we know the basics, let's get into the details of what are some of the things you can do. In addition, we're going to get into multi-factor authentication and much more. So here we go.
So let's talk about these devices that we're going to be buying this year and next year.
2020 is going to come to an end. Some of this stuff's going to spill over into next year. There are a few things you really should be doing, especially with your Bank or Amazon, anywhere where you have financial data.
One of those things is called multifactor authentication.
A lot of these businesses have this called also two-factor authentication. You might see it abbreviated as. 2FA or MFA.
So what is this two-factor authentication? In many cases, businesses are using a text message that they'll send you when you log in. So you go into your account, normally it's where you would set your password, and you'll see something there about multi-factor authentication or two-factor authentication.
You'll go to that and in most cases, they'll ask for your phone number and they'll send you a text message to verify it. And you're off and running. So now the next time you go to log in to that site, it's going to want your username or email address, and it's going to want also your password. And hopefully, you're using a different password on every website out there.
And then it's going to send you a text message and that text message will have a number that you can then type in on the website. Okay, this is really you. Now you gotta be careful with this because there are a number of people who have been bamboozled by this. One of the ways they got bamboozled was where yes, indeed people stole their phone number.
So an attacker knows that you have something valuable, they want to get into your bank account, or maybe it's getting into your Bitcoin account, whatever it might be. They find out what your cell phone number is and then they call up your cell phone provider and they say, Hey, I've got a new phone and then they give all of the information for the new phone and they can bamboozle them to get them to switch.
Before you know it, 'cause you're not getting to notice, Hey, I just didn't get any phone calls. Not a big deal. It's wonderful that people haven't been bothering me on the phone. But what has actually ended up happening is they now have your email address. I assume that they have your password because most people use the same password on multiple sites, or it's an easy to guess a password, easy enough to find the breached passwords on the dark web. I do it all of the time when I'm looking for dark web stuff for my clients, but now they have your phone number.
So when they go to log into that bank account, They've got the email address. They got your password. Cause you have used that same password elsewhere. When the bank sends a text message to your phone, it doesn't go to your phone and you don't even know it went to your phone.
So here's an important tip. Contact your cell provider and have them use a pin or a password with you so that when you call up, they're going to ask you, what's the password for the account. Now, this is going to be a different password than you'd use on the website. But it's going to be a password, in some cases, it's a pin.
So come up with something that you don't use anywhere else and set it up with your cell phone provider. That way, if they are going to hijack your SMS or text messages, it doesn't matter because even then they can't get through, but there's a better way. Okay. There's a better way to do all of this. There are some paid and some free two-factor authentication apps. What I use personally, and what we use with our customers is called duo D U O.
We've been using them for years. Cisco of course bought them because they were the best in the business. That's what Cisco does.
So DUO allows you to have a different type of two-factor authentication. You can also use Google authenticator, which is free. You can use Lastpass. In fact, I got an email this week from one of the subscribers to my email list, thanking me for the recommendation for Lastpass. And by the way, if you want a copy. I have my special report. I'd be glad to send it to you. That talks about passwords talks about 1password and Lastpass and what you should do a little bit about two-factor authentication.
So I use DUO. I also have Google authenticator, although I don't really use that at all. I tend to use Google or I should say. what happens with that is they'll display a QR code when you're setting up the two-factor authentication. That's one of those square things that has all of the little squares inside of it that you can use to go to a website is typically what you'd use it for in this case, it then syncs up a special Countdown a few seconds, and it'll give you a six-digit code that you can use. That code is only good for 30 seconds. So now when you go to log in, you're going to give you a user-name or email. You're going to give your password. And then it's going to ask you for that. Code so you can use.
Again with DUO, I have adjusted automatically. It comes up, it's integrated with my one password as well. So I can now log in and I know it's extra safe because even if someone steals my phone number, It's not going to do them any good because I do not use my phone for verification, for two-factor authentication.
Now there's one more trick that you could play if you wanted to. And I have done this more than once. Some websites do not allow you to use an authenticator app. Yeah, I know behind the times, aren't they? So you have to use SMS. If you want to use two-factor authentication, in other words, you have to have a text message sent to you. So what I do with those sites is I have a phone number that isn't a real phone. So I have a phone number that I got years ago from a company that Google bought. Nowadays, Google calls it Google voice. So I have a Google voice number and I will give them that number. Now, why would I give him that number? first of all, I can filter calls that are coming in and text messages and everything out. Google will forward the text message to my phone. Remember it's Google, so it's not terribly private, but that's okay because those numbers are usually only good for a number of minutes. Okay. So it's not a very big deal, but the reason I use something like Google Voice is it's not a real phone number, so they can't call up T-Mobile or Verizon or whoever you have your phone through pretending to be you and get them to transfer that phone number because they can't and they won't. Okay. It's very important.
The SIM card that you have on your phone nowadays, some of these devices have virtual SIM cards. that SIM card that's in your phone can not be stolen or duplicated or anything else either if you're using one of these Google voice numbers. So some really important tips there.
I hope you took some notes. If you didn't, you can find this online. I post these as podcasts, you'll find right on my [email protected]. You can listen to them, take notes. And my wife even provides a transcription of these things most of the time. bless her heart.
She spends a lot of time doing that, and she'd appreciate it. Check it out online. Craig peterson.com.
We're talking about how to keep your devices safe that you're buying this year things you're getting for family, for friends, maybe for yourself as well. And we're going to get into it more. Now we've got some really surprising things for you guys.
One of the things that we have to do, and this is again, over and over again but better than 60% of Windows computers are not up to date. Remember we're buying nine devices that are basically computers.
Do you remember that whole Barbie thing from not too long ago? I was on TV with this thing and it was sending audio up to the internet and we were able to intercept it. We did a whole thing on television about this. Obviously, it's a very big problem because it's your kid's information, voices being sent up, in the Barbie was interactive. Now Mattel cleaned some of that stuff up and that's always a good thing. But the point behind this whole computer in a toy or other device thing is that their computers. We're talking about mobile phones and Android phones, just not getting security updates. If you're going to insist on using an Android phone, make sure you get the latest model every two years, because even Samsung only supports their phones. They're top of the line phones for two years. Okay. Versus your iPhone, which is good for five or more years. So keep those phones up to date.
In fact, when you first get the phone, probably the first thing you should do is check for a software update. Computers are the same thing. Whether you're getting one of these Chromebooks, which are very good, generally speaking, I'll remember it's Google okay. But the Chromebooks tend to be kept up-to-date because it's pretty much automatic. And I know a lot of security researchers use Chromebooks and use them exclusively because they don't have the same security problems as Windows. What's one of the reasons Apples don't get attacked as much as windows computers because the Macs, frankly, are not as common. They're only about 8% of the market out there, depending on whose numbers you're listening to. So why would they go after it? Plus it's a little more hardened than windows is. In fact, it's a lot more hardened than Windows is. Microsoft is starting to fall-in behind Apple's lead, which I think is a good thing.
So those computers, update them immediately. If you're still running Windows seven, make sure you get 10. Cause seven isn't getting the updates anymore. If you're running Windows eight, 8.1, make sure again, you upgrade to windows 10.
But brand new computers shouldn't come with those. Another quick word of warning about computers that you're buying. The home edition of Windows does not have the same features as the business additions or enterprise additions of Windows. So you might want to when you're buying something, look for Windows professional, it has more options. One of the options that could save your bacon is the ability to put off updates.
Now, you're I hear you saying Craig, you're always telling us to update early and update often. yeah, that's very true because many times when you get that patch, it's because there is something going on in the wild. Bad guys are actively using it to exploit you. To exploit your faults. Okay. So there are some very good reasons to stay up to date.
But, here's a problem. I had a law office call me up because right in the middle of them putting together some documents for the court that were due in less than two hours. Windows and they were running home edition, decided it was going to force them to do an update. You can imagine the trouble that ensued because they weren't going to be able to get the paperwork filed with the court in time. Very big problem.
Even if you're not an attorney, you're not dealing with the court. Windows professional does give you the option to schedule the dates, you can push them off for a week and then you can get into the more advanced stuff too, with the device management, MDM type stuff where you can now manage that device and make that device, secure, most, if not all of the time.
Okay. So let's move on next to tablets. Again, look at something like the Amazon Kindle. Here's my watch talking, hit the Siri button accidentally. So the Amazon Kindle fire that is an Android tablet. Now, one of the advantages is it is updated by Amazon automatically. It gets all of these security updates and other things. That's a very good thing, and it gets them for a fair length of time and they are cheap. You can get them for 50 bucks, 70 bucks brand new from Amazon. I got one a year or two ago, probably a couple of years ago. And it wasn't well packaged and it's shipping and the front screen was just cracked all the way down. So I returned it, they shipped me another one, and that one wasn't cracked. So that's good, but I've kept an eye on it and it has been very good. I also got with the amazon fire tablet, one of these stands that you can put it in, it's a charging stand, but when you place it in the charging, stand it then becomes an Amazon Alexa.
Little kids come over, grandkids, and they want me to play baby shark, which is an annoying song that, the grandkids, every generation has this. I remember a slightly older grandchild. A granddaughter who used to love, ah, jeepers. What was a gummy bear? That's what it was. Gummy bear. Remember, that song was incredibly annoying too. I ended up getting the guy who wrote the song on the radio show with me to talk a little bit about it. It was fun actually.
Those of us who needed to be kept up to date all of those tablets, because they are real computers, but nowadays we're buying appliances. I remember five years ago, I think it was out of the consumer electronics show. I saw another one that you put into your home and it had an Android operating system in it, it connected to wifi and it allowed you remotely to say, Oh, you know that steak or roast. It told you to cook in the oven at 5:00 PM, I'm going to be late. So you just go online and I type it into my phone and ta-da, I am now all set. There we go. And it's not going to start cooking it until six 30. that's all well and good.
That appliance has a computer in it and it's sent into wifi. Have you updated it? And does it self update? How long are they going to be providing updates for that oven? I'm sure five years later, there are no more updates for it. Now have an appliance, a device, that is frankly dangerous on your network because if somebody comes over to your house, they've got a laptop, they connect to your wifi and it now infects your appliance.
Okay. Whether it's your washer or your dryer. Those are the two most common, I think right now that are internet-connected or your oven or your microwave or your garage doors or your security system or your lights, those can all get infected. They are used as launching points to infect everything else on your network.
Check the update, make sure everything's up to date. And in some cases, it's pretty hard to update, but it's worth it. You have to do it even with your children's toys. One of the things I do is I put them on a network segment that has no access to anything else. I have an IoT wifi network, the internet of things.
You're listening to Craig Peterson. Make sure you visit me online. Craig peterson.com and sign up for my newsletter.
We've talked about, multi-factor authentication, we've talked about, of course, protecting your devices by keeping your software up to date and that's everything nowadays, really, and how to do that. What's up for that. And now we're going to go into a couple more good points.
Of course, you're listening to Craig Peterson.
Now, once you've purchased an internet-connected device, no matter what it is, if it's a router or firewall, if it's a Barbie doll, change the default password. In most cases you can connect to the device, just using a web browser that makes it very simple.
So you use the web browser, you connect to the device. Most of them have web servers on them. If you can imagine that, A little doll with a web server on it, but yeah, that's what happens. Your refrigerator probably has one of his internet-connected and your washer, dryer, light bulbs have little web servers built into them and you want to connect to them and change the default password.
Look up the manual. It's probably not going to tell you how to do it with the information that's in the packing. If you go online and search for that device, you can find out how to change it. Use different passwords for every device.
Always use complex passwords. Now complex doesn't mean that it has to have special symbols in this upper case, that lowercase, et cetera, it can just be three or four words strung together. That's all it needs to be. You might want to throw a digit or two in there, maybe a special character too, but a phrase is the best.
In order to do that, you're probably best off using a password manager to help out. So that means using something like one password or LastPass. Once you've got that in place, it'll generate these passwords for you, automatically. It'll remember them. It keeps them encrypted. So you only have to remember one password and that's the password you have set for the password manager.
Now, in my case, I've got it set up with DUO again. So I'll go into one password and one password is going to ask me for my password and it's also going to authenticate me via DUO on my smartphone. So there's multifactor, three-factor authentication. Okay. So important for all of these devices that connect to the internet.
Also check the devices, privacy, and security settings. A lot of times the manufacturer will let you set up an account on their website. From there, you can tell it what information you want to share and don't want to share.
Now, remember what I was talking about in the last hour with Apple, they are being very good about this and they are now demanding that all of the app developers disclose to you that you have indeed given consent for this information or that information to be used by that app developer and sold.
You can go to the Mattel website, set up an account for your device, or the Samsung or whatever it might be. And right there, you can examine your privacy settings and what do I want to allow the vendor to gain access to?
Make sure you're not sharing more information you absolutely need to provide, they're not going to ask you for social security numbers or other things. There's no reason to write that stuff that the bank or the IRS is going to want. Not these guys, at least, hopefully. Make sure you're enabling automatic software updates, wherever you can.
The latest version of the software usually tells you that it has the latest security fixes. Hopefully, it does but it also helps to ensure the manufacturer still supports it. If you've got automatic updates and they're sending updates to you and a hundred thousand of your closest friends who also have the same device, they're going to continue to support it and that way, the latest patches are going to be out there. If you're not getting the updates and nobody else is, the manufacturer is not going to have a lot of incentive to give you security updates. Then there's the normal stuff about, don't use public wifi. That's generally a good idea.
But if you're using a secure server connection, That's that little lock up in the URL bar. Then you are effectively creating a VPN between your web browser and that remote server, and that's going to be quite safe. So personally, I don't worry so much about that. I do worry about my machine being attacked, but I also have a very good firewall turned on and I have all of the services that I don't need to have shared turned off.
I am going to do a class on this, a little course on hardening windows. In fact, we've got it all written. We've got slides together. We'll probably be doing that after the first of the year. So keep an eye on your email for that. Cause anybody who gets my newsletter, I'll tell you about that.
How to harden windows, so that even if you are on public wifi somewhere, you're going to be relatively safe and the same thing's true. If you're. Using your phone for instance, and you're sharing your phone's network connection with your computer. It could still be used by bad guys to try and get into your phone.
These ISP internet service providers are not completely on top of all the security. Okay. all of the basic stuff don't provide personal information, financial information. I tend to use. These one-time credit card numbers. So every time, if I go to a site and I want to buy something, let's say I'm on GoDaddy buying a domain or I'm on Walmart side or Amazon site each one of those, I use a different credit card number. Check out your credit card provider, all of the major ones, Visa and MasterCard have the ability to create virtual credit card numbers. That way that credit card number can only be used on that website. So you create this credit card number. It's very easy to do. It's usually a plugin in your browser. You create a credit card number and it's for amazon.com. If somebody were to get that credit card number from Amazon and try and use it somewhere else, it will not work. It will only work on amazon.com. Isn't that cool. The other advantage is if someone starts misusing it, then you can just turn off that virtual credit card number. It's really that simple. So have a look at that. One-time use credit card numbers or these virtual credit card numbers, which is what I like where you can use it multiple times on that site, you don't have to create a new one every time available from most banks and all major credit card companies.
Also, be careful with the websites. You're going to make sure you type that URL correctly. As I said before, I always spend a few extra seconds whenever I'm on a website, I'm going to a website. I'm reading the email, just making sure that it is correct. I spelled Amazon or the email address that sent it to me is legitimate.
I can't believe how many times I get an email. It's a phishing email and it's from somebody@gmaildotcom as though a major business is going to use gmail.com. That's a word of warning too, to the small businesses that are trying to do online stuff. Make sure you have your own domain. That you're not using Gmail or Hotmail or Yahoo.
I've seen so many people doing that got even proton mail. Proton mail is quite secure and, it's really nice the way they're doing it. It's hosted in Switzerland. Check them out by the way. I put something about that in my newsletter a month ago with what that's all about. If you want it, just let me know, just email [email protected] and in the subject line mentioned proton mail or something, and I'll forward you that newsletter so that you have it. You can always search if you don't delete my newsletters, you can always search for that information.Â
You can have proton mail set you up with your own domain. So it's from Bob's country store.com instead of Bob's country store at gmail.com. Okay. It looks much more legitimate. let's see offers obviously, be careful with those who don't click links or download attachments unless you're really confident.
Again, I tend to go to the website as opposed to click on the email that I got. There always this warning or that other thing, just go to their website, make sure that it's all being encrypted again. That's that little padlock if it's closed or your information's encrypted, which is really good.
If you can use a credit card. Don't use a debit card. There are laws to limit your liability for fraudulent credit card charges, but you don't really have quite the same level of protection when you're using a debit card and the money will be taken out of your account with a debit card. If a bad guy. Is using your debit card and then you have to file a police report and then you have to file with the company that gave you the debit card and then you have to wait for the money to be credited back to your account.
In the meantime, your checks are bouncing or if you use the debit card for other things, it is being denied. Okay. So be very careful with that. insufficient funds are always going out there.
I would urge you to just be very careful, very cautious, just like Santa Claus, checks his list and checks it twice to the same thing all the time when you're online.
Hey, if you don't get my free newsletter right now, make sure you sign up. I have all kinds of tips. That's what it's about. You also get all of my podcasts segment that you can just click on right there in the emails makes your life easy and helps to keep you safe online.
Just visit me online. CraigPeterson.com. You can go look at anything you want. If you scroll down on the homepage, there's a little form you can fill out. If you have an explicit question for me, always glad to answer them. And then at the bottom of the page, a little subscribe box will show up as well.
Take care, have a great weekend. Join me again next week.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Good morning everybody!
I was on WGAN this morning with Matt Gagnon and started off this morning talking about Fake Faces and the legitimate uses for them and then got into some of the seedier applications that they are being used for and what we can do to protect ourselves from being victims. Then we got into some things you can do to be sure you are shopping securely this holiday season. Here we go with Matt.
These and more tech tips, news, and updates just visit - CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Any of these internet-connected devices. So add to your list once you buy these things. Or even before you buy them. Do they self-update for security issues? Can I even get new firmware? Hey, I was on with Mr. Matt Gagnon this morning and we talked a little bit about our printer security, the security of the toys online. The shopping where you bought those toys, right. And being safe online. We also talked about, again, our little face generation, what's it being used for? Is it legit? Is it not? For three bucks you can get a little diversity on your website with fake people, which is just amazing. It's amazing how good it is. And it's amazing how cheap it is as well.
So here we go with Mr. Matt.
Matt Gagnon: [00:00:54] It's WGAN morning news on Wednesday, which is a great time as always to talk to Craig Peterson, our tech guru, Craig, how are you this morning, sir?
Craig Peterson: [00:01:02] Good morning. Doing well. Thank you.
Matt Gagnon: [00:01:05] Indeed. Craig Peterson also of course heard on this very station on the weekends, Saturdays at one o'clock.
If I'm not mistaken, Craig.
Craig Peterson: [00:01:12] Yes, that is correct.
Matt Gagnon: [00:01:14] And you'll be talking about many of these same issues when you've got the microphone all to yourself.
So let's get into them right now. cybersecurity, something that's often ignored and, something that's incredibly important. and, and I think this is a great time to talk about cybersecurity in general and this is something that I know you're passionate about.
Why don't you tell me what I should know about, printer cybersecurity threats that are often ignored?
Craig Peterson: [00:01:36] Yeah, this is a bigger deal than most people might realize. When we go into a business and start looking at the security, that's there. The first thing we typically do is do a little scan and we check to see what are the versions of software that are on the computers and the devices.
Now, we all know that we should be updating our Windows, machines, Macs, or our Android devices, et cetera. But. Most of the time we go in and in fact, I can't think of an exception. So I'm going to, I, most of the time, when we go in, we find that their printers have never been updated. Now, this becomes a very real problem because the printers are running a real computer inside of them, now. Especially these laser printers that are attached to your network and that particular little computer can be used and often is used to launch attacks. We've been into businesses that are saying, Hey, listen, something weird is going on. Our network is slow. The printer seems slower. We're not sure what's up. We've got some threats here. How did we get ransomware? In one case, that printer could be the source. So make sure that particularly in the shopping season, when we're online and more concerned about our finances. We've got taxes coming up again early next year. Quarterly's due at the end of this month. Make sure that your printers are up to date.
I would put that on my list to make sure this week you have to go to the printer. Many of them have a little webserver built right into them. So you can just use your web browser to connect to that printer, check the firmware version, which is the version of software on that printer.
Go to the manufacturer's website, find out what the latest version is. Download it and then install it on the printer. I know that seems like a lot of work and frankly, it is. The more advanced printers that are available out there. Do have the ability to automatically update their software. But it is key nowadays and too often, as you said, ignored.
Matt Gagnon: [00:03:52] Craig Peterson, our tech guru joins us at this time every Wednesday to go over what's happening in the world of technology.
Craig, I am interested in buying a unique worry-free fake person and I have about a $5 bill in my pocket right now. Can I pull that off? Can I get one?
Craig Peterson: [00:04:07] Yeah, you can even get one for free.
You can get them in for as little as a dollar. Many businesses now have been using these pictures on our websites for years and years. Oftentimes you'll go and hopefully buy one, right? Adobe has a service for that. There are many of them out there.
We have had problems in the past where those pictures didn't have the right release behind them and many companies especially, the SoHo small office home office. They'll just grab a photo online all the way through the big guys. Facebook is one of those that when you sign up, they say, all of your pictures, you upload basically bond to us. Some of these pictures have shown up on billboards and people have complained.
So number one, it's easy to use these types of pictures for our businesses and websites and things because these people just don't exist.
In fact, you can go online to this person does not exist.com and you can get your own fake person for free, which is amazing. You can buy them for as little as three bucks, just for one.
So yeah, your $5 bills do well. But there are also problems with this when it comes to just these dating sites. We've talked before, Matt, about people who are lonely. They go online, just trying to find maybe not full companionship, but at least someone to talk to.
There are many bad guys out there, all over the world who are more than happy to try and con us into sending money to help their, mother or whoever, who's supposedly is in the hospital and needs this surgery. There are so many excuses out there. Con us out of money.
If you generate one of these fake people and use that as your picture for your profile. Now, all of the standard techniques that are used to figure out if you stole a picture or from a site online and use that as your profile picture if didn't have to do a reverse lookup, but those types of techniques to see if you're a fake won't work because there, the picture doesn't exist anywhere.
So you've got to be very careful, online. And this is just another example of what's coming our way.
Matt Gagnon: [00:06:36] Craig Peterson, our tech guru joins us at this time every Wednesday.
Craig, before I let you go, obviously we are now. Fully and the holiday shopping season, December it's after Thanksgiving. So we now give permission to everybody to actually do this. so I think particularly given COVID, a lot of people are going to be going online. That's obviously been a trend anyway for recent years, but I think it's probably going to be even more pronounced this year. So in terms of keeping yourself secure while doing your holiday shopping online, what's some important stuff to keep on the top of your mind.
Craig Peterson: [00:07:05] Everyone knows the basics, right? We just mentioned keeping your computers up to date. You obviously want to look and make sure that it is what's called a secure site, which basically establishes a VPN from your browser to their site.
Unfortunately, that little lock in the corner of the website URL up there on your screen, that little lock doesn't mean your data is actually safe once it arrives. So make sure you are shopping at a legitimate store online.
Make sure while you are shopping that you also just look around take care make sure that deal is really a good deal. Do a little comparative shopping, just like in the old days.
Tying it back into the printer that you were asking about earlier, we're buying more and more internet-connected items. You might remember that. Barbie from a few years back that allowed interaction with it. You can talk to this little doll and it could talk back to you. It turned out it was sending all the audio straight to the internet. That's a computer inside that toy. That's a computer inside that washing machine.
Any of these internet-connected devices. So add to your list once you buy these things or even before you buy them, do they self-update for security issues? Can I even get new firmware for those devices? I want to encourage people to check out right now. Have I been pwned.com? That's spelled it. Have I been P W N E D. Have I been pwned.com put in your email address and find out has my account been breached? More or less? It probably has been. It'll tell you where it's been breached. It'll tell you if your credit card number was stolen, your password, your email. Whatever was stolen in that particular breach. Keep in mind that we need to change our passwords. We need to find out where they have been breached. And maybe be a little more cautious with that particular company in the future.
And as we go out there again, Stop. Think. Look at that email, that website make sure it really is legit.
Matt Gagnon: [00:09:33] Indeed. Craig Peterson, our tech guru with some great advice here as you head into your holiday shopping habits.
Appreciate it, Craig, as always. And we'll talk to you again next week.
Craig Peterson: [00:09:41] Take care, Matt.
Matt Gagnon: [00:09:42] All right.
Craig Peterson: [00:09:43] I had a little bit of noise there underneath my audio. Anyways, we'll have to see where we can fix that. Everybody have a great rest of the week. Hope you did have a fantastic Thanksgiving.
We'll be back on Saturday. Of course.
Take care. Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed