Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • AS HEARD ON NH Today WGIR-AM 610: Bitcoin, IRS, Silk Road and Implications for CryptoTraders, CA Prop 22 and the Gig Economy and More

    Welcome,

    Craig Peterson here. I was on with Jeff Chidester on NH Today. We hit a number of interesting tech topics this morning with Jeff Chidester.  We started off with Bitcoin, Silk Road, and the IRS, then we discussed California Prop 22 and the Gig Economy, then The Hammer and Scorecard Software developed by the CIA and how it may have been used in the election last week here in the USA. Then we got into business use of Cell Phones and Employees using their personal phones for business and the problem with misconfigured VPNs. Here we go with Jeff. 

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Two right now, if they're not paying a lot of attention to you, you're probably okay. But it's easy enough for them to track you down if they want to. They had fun this morning with Mr. Jeff Chidester, who was sitting in. We talked a little bit about elections, but we really got into this whole Uber and Lyft thing in California and what just happened.

    What happened with the silk road and the fed seizing a billion dollars worth of Bitcoin? What is that going to mean to you? If you own Bitcoin. So we went into that and the implications and the IRS and can you really be tracked?

    So, Hey, you're listening to Craig Peterson and we're going in here right now with Mr. Jeff. Chidester.

    Jeff Chidester: [00:00:45] Hi, welcome back to New Hampshire today. Jeff Chidester 37 past the hour. Craig Peterson. Of course, you can catch, Craig on his show tech talk Saturdays, 1130. Also, catch him over at his website. Craig peterson.com. Craig peterson.com. Good morning. Hey, I just talked to you on Friday. It's great to have you back on Monday, How ya doing man?

    Craig Peterson: [00:01:06] I'm doing really well,

    Jeff Chidester: [00:01:08] A lot of interesting news,  it got lost in all the political talk. One thing.  Bitcoin, I think is foreign to a lot of people, the concept of it, but a big thing. The feds had an action last week against silk road. Talk a little bit about that and the impact of that.

    Craig Peterson: [00:01:23] Bitcoin, for those that aren't aware of, it is one of these, what they call cryptocurrencies. It's designed to only have so many Bitcoin's ultimately available so that there's a limited market.  The way you find these Bitcoins is by what's called mining, which requires some very intensive computing stuff.

    What has really driven up the value of Bitcoin, according to many experts is the illegal world out there. Ransoms that are being paid online are often paid in Bitcoin. People think that the beauty of that is they cannot be tracked and that's been a big deal.  There was a site out there called the silk road, which I thought was a cool, clever name. The silk road was sitting there on what we call the dark web, which is an internet on top of the internet. It's encrypted. It is obfuscated. So it's difficult to figure out who's what and where.

    The silk road was a bazaar that sold everything. I mean everything. You could buy hard drugs on it. There were all kinds of nastiness is going on. So there were a whole bunch of investigations. I attended a presentation given by a secret service about what they did, how they tracked down the guy that was running the silk road.  They were able to do it, even though it was all Bitcoin and they use these special tumblers to try and mix it all up to make it hard to find out who it is and they were still able to find them.

    So right now he's serving two life sentences plus 40 years, but there was close to a billion dollars in Bitcoin, still sitting there. That the secret service was a hard time having a hard time, getting their hands on and just this week it is now in the hands of the federal government. A billion dollars in illegal proceeds that came from the silk road in Bitcoin cryptocurrency.

    Jeff Chidester: [00:03:31] Craig Peterson so once again, you can catch him on tech talk Saturday at 1130. Craig peterson.com. Craigpeterson.com. Many people like Bitcoin. They use it legitimately. Does this have an adverse effect on those who are trying to use this kind of currency legitimately?

    Craig Peterson: [00:03:48] That's such a great question.

    The IRS is supposed to be putting a question on the tax forms next year. At least they're planning on it saying, do you trade in cryptocurrency? They might even just say, do you trade in Bitcoin? Because the IRS is saying, Hey, you bought that coin for, believe it or not, a dollar per Bitcoin back in the day.

    Yeah. And now you just sold it for $7,000. Don't forget to pay the tax on that.

    Jeff Chidester: [00:04:20] What,

    Craig Peterson: [00:04:21] Yeah, because you're supposed to write it in. In fact, it's 20% or Joe Biden gets his way 30 or 40% tax. So this is going to be an interesting thing as we go forward here, but you're supposed to pay your taxes on Bitcoin.

    Does this affect normal people? Well, it does if they are looking at you right now, if they're not paying a lot of attention to you, you're probably okay.  It's easy enough for them to track you down if they want to.

    Yeah. I think it's amusing that people think that you could ever truly hide anything from the government, especially money.

    Jeff Chidester: [00:04:59] Cause they're going to get it. They're like bloodhounds when it comes to money. It's amazing.

    Hey, another thing that happened last week, Craig, that I thought was interesting. Everybody knows Uber Lyft. There has been this big conversation out in California about how to treat these types of employees and the voters had their say in this and it really not just affects Uber and Lyft, but it has a larger consideration for the economy as a whole. Tell us about that a little bit.

    Craig Peterson: [00:05:23] This is a very big deal now because we have had for a few years, something called the gig economy. So I can go to a website like Fiverr. And if you haven't checked it out, you should F I V E R R.com.

    I can hire someone to make me a new logo. To write an article for me to do almost any little task that I want to have done. It used to be five bucks a pop. Sometimes it is even more.

    should those people be considered employees? Of course, the IRS has had this test for a long time with these different States.

    Do you have to have a regular schedule? Do you have all of these different things as part of their tasks? Proposition 22 passed in California, which means that all of these Uber and Lyft drivers in California were trying to collect taxes on Uber and Lyft. Are now considered basically independent contractors. If you are an employer and I've been in this before in this potential problem, if you're an employer and you bring someone on, even if they sign a contract and you consider them a contractor, the IRS, if they're not paying their taxes will come after you as the employer. They'll just switch it all up. In California, of course, that a state government too. So this is going to have a ripple effect. Many States are looking at how do we classify the whole gig economy, let alone Uber and Lyft. I think they're going to look to California for this.

    I've been warning for the last probably 20 years on the air about what I see the weakness to be in our election system.  I have said the weakness is likely the secretaries of state offices and their websites where the final results are posted. I don't know if you saw this, you probably did. Cause you follow it closely. But what Sidney Powell is saying now an attorney involved with the Trump administration here.

    She's talking about two programs called the scorecard and hammer. I just wanted to put a little, I told you so in here because apparently, that's what she's looking into overall. So what we'll know more, we don't know all of the details yet, but it is precisely what I have been warning for decades could happen to our election.

    So there's some scary stuff still going on up there.

    Jeff Chidester: [00:07:51] Well, absolutely.  I think this process is going to continue regarding our election and transparency is the key to really stopping any kind of one distrust that may come. certainly that.

    One last thing, I use my cell phone and it's my cell phone, and I do not do any business on my cell phone. There are people who do use their cell phones for business, and also companies issue these types of mobile devices. There's a problem there isn't there?

    Craig Peterson: [00:08:14] There's a number of problems with that. Basically, if you're a business and you want to keep your data safe and that includes your customer list, if, think of everything that's part of your business, you might say, I don't have anything that's secret.

    Well, yes you do. You don't want your salespeople walking away. You need to own those phones. That's going to keep things a little clearer, do not allow your employees to use their personal devices and particularly personal computers. Because now you don't have control over the environment that the computer is used in.

    If you're using a VPN misusing them, which is by the way about 95% of businesses right now, then that home computer infections are going to come right across that VPN and hurt your business and much the same with mobile devices.

    Keep an eye on those.

    Jeff Chidester: [00:09:09] That's certainly a policy.

    Hey, so we've come to a hard break.  Once again, we'd been talking to Craig Peterson, of course, tech talks, Saturdays, 1130, Craig peterson.com. Craig peterson.com.

    Craig, thanks a lot, and have a great rest of the week.

    Craig Peterson: [00:09:20] Hey, take care, Jeff. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Fileless Malware, Credential Stuffing, Advanced Malware Protection plus more on this Tech Talk with Craig Peterson Podcast

    Welcome! This is a "best of Craig." I have included the current articles that you should read this week in the article section so check that out. In this podcast, we cover Fileless Malware is on the rise, How covid is affecting the financial traders, Why you must find out what is on your Enterprise network, and more.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Ransomware Demands are Doubling Every Six Months, Study Finds

    Teach Your Employees Well: How to Spot Smishing & Vishing Scams

    Mimecast Research: Half of all Workers Admit to Opening Emails They Considered Suspicious 'Check the Box' Awareness Training has Little Impact on an Organization's Security Posture

    MITRE Shield Matrix Highlights Deception & Concealment Technology

    Act of War - Clause Could Nix Cyber Insurance Payouts

    Most Businesses Vulnerable to Emerging Risks Not Covered by Their Cyber Insurance

    Oh Jeeeesus: Drivers react to Tesla's full self-driving beta release

    Rising Ransomware Breaches Underscore Cybersecurity Failures

    SANS Launches New CyberStart Program for All High School Students

    Traders set to don virtual reality headsets in their home offices

    What's on Your Enterprise Network? You Might Be Surprised

    Malware Attacks Declined But Became More Evasive in Q2

    One of this year's most severe Windows bugs is now under active exploit

    The VPN is dying. Long live zero trust

    Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

    Microsoft boots apps out of Azure used by China-sponsored hackers

    WannaCry Has IoT in Its Crosshairs

    Love in the time of Zoom: Why we're in the midst of a dating revolution

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Massive changes ahead. We've even got traders who used to be on the floor of the stock exchange, and on the floor of these massive financial companies. We've even got them at home. Now you're going to be shocked at what they're doing to replace that interaction.

    Hi everybody. Craig Peterson here. We're going to be talking about these traders and how virtual reality headsets have changed the way some of them are doing business. We're going to talk about what's on your enterprise network. I talked about this last week.

    Hopefully, you got my email. It came out on Wednesday this week. I'm going to try and do two of these a week. It's three minute little a coaching lesson, if you will, on security. This week we talked about your enterprise network. We're going to delve into that more today.

    Have look at an email make sure you got that. I know you're used to getting emails from me Saturday mornings. This last weekend we sent our weekly email on Sunday instead of Saturday. I'm not sure if that's better for you guys or not. We certainly didn't have quite as many people open it as usual.

    Usually, it's almost half of everybody that's on the list, and that's thousands of people open it but not as good on Sunday. We may switch back to Saturday. We'll see.

    It also has to do with our time, right? This is a labor of love, trying to get all this information out to everybody. So things can change.

    We're going to talk about some big changes in malware attacks this year, even though the decline a little bit in Q2. They got more potent, and we'll tell you why what's going on years.

    Most severe windows bugs is now under active exploit. We'll tell you about that. VPNs are dying. You know what my thinking is about these paid VPN and free VPN services. If you've been listening long enough, right? They do not increase your security. In fact, they decrease your security in some ways. Maybe you're going to stop your local ISP from tracking where you're going online, but you're you overall are much less secure.

    Shopify. We've got a huge theft of the hair, and turns out it kind of employees involved. We've got Microsoft booting more Chinese sponsored hackers out.

    Wanna Cry. That yeah yeah, that same one that brought the country and the world to its knees a couple of years ago. It's back. And love in the time of Zoom. So if I don't get to all of these today, make sure you check online, or if you're going to miss part of this, all of that available there, Craig peterson.com. We're trying to make sure all of the audio is up there so that you can listen to it in your time on any podcast app. Make sure you check it out, whatever your favorite app is.

    Technology has really changed everything, and we have seen that this year, they expect to be just an incredible online shopping season. Now that's good, and that's bad. You've got the local stores who are hurting very badly. I have gone out of my way lately to try and go to a local store as opposed to ending up online and buying stuff because I want to support them. They are part of the economy, obviously. They are where my kids got some of the first jobs in local stores. They are also the place where I can go to see things and play with things. It's not like where Amazon charges me sometimes to return something. That wasn't what I thought it was. That kind of always bothered me. So I like the local merchants and not just the restaurants, but the guys that sell the little electronic gear that we have and other things, but it's going to be a huge year this year.

    We're going to talk later on today. This is kind of low on the list, but virtual online Zoom dating. It is really changing at all. Now we have a story that came up from Ars Technica this week, Owen Walker of the Financial Times, talking about how we have moved our businesses into spare bedrooms in our homes, living rooms, and we've talked about this before.

    If you're working from home, make sure you have a spot where all you ever do is work from home. The brain kind of ends up associating, and you can become much more productive that way. Different parts of the room, maybe a different chair. Maybe all you do is turn the chair around just to let your brain know that it is time to get to work.

    I also use some apps. I've got vitamin R that I've used, and I don't really use it as much anymore. I've kind of grown disciplined over the years. You might check it out online. Vitamin R. It uses the Pomodoro Technique, which is an Italian name. Remember those little tomato clocks or countdown timers you have in the kitchen, or at least you used to have years ago where it just reminds you, Hey, uh, you're supposed to be working right now cause you hear it go tick tock, tick tock, tick tock, and then it goes off and okay, well, my 20 minutes is upon this particular task, and then you take a brief few minute breaks and then you get right back to it.

    There are all kinds of hacks to help us to be more productive when we're at home and ultimately more productive than maybe in the office in some ways. In other ways, you're not as productive, and you're not as productive because you're not around these other people who can come over and ask questions, and much of what we learn, much of what we do is just incidental communications. Where we are in a hallway, we bump into someone, or we go to a meeting. We have a side discussion. That's hard to do when you're on a WebEx team call because you're there, and so are 10 other people, two other people. It doesn't really matter how many other people, because you can't just lean over and say, Hey, what do you think of this or that?

    Now, obviously, on the WebEx teams, you can go ahead and type a message, right? You have that chat capability, and you can send it to a specific person. You can do that on Zoom as well, but I don't. I'm not going to talk about Zoom right now because you should not be using it for business. Just you really, really should not.

    So focus on that ability to communicate. Some companies are now going to happy hours online, and I've been invited to a Zoom happy hour, and the company's sending me three little bottles of wine. We're going to do it. Taste-testing and we'll just kind of chat while we're there online. It should be fun. It'll be interesting too.

    Many businesses are doing that, as well. They have a little happy hours and get-togethers because you're not going out after work for a drink to talk to people. You're not going out in the hallway and talking to people. It is such a different world.

    The whole thing with whether or not you're there physically is a whole other problem when it comes to traders. Think about traders. If you've seen some of these movies or TV shows where they're on the floor, I know Fox business, and some of these other business channels have a shot with a camera on the floor, the trading floor, and there just aren't the people there that they used to be. But it's again, it's the interaction, and that's what's been important in the past.

    Some banks UBS particularly has been issuing some of its traders over in London. These HoloLens from Microsoft. These are virtual reality headsets, and the idea behind this is to allow the staff to recreate the experience of working on a packed trading floor without ever leaving their homes. I don't know if you saw the video or pictures of this, but when Microsoft first introduced these virtual reality headsets, they had issued them to everybody who was in attendance at this conference room, and they started playing these videos. So you see all these people looking around, of course, they can't see beyond what's right in front of their eyes, which is this HoloLens. These virtual lenses and they're looking around and right up the aisle walks Bill Gates, of course, nobody notices him because he can't see him. They're all just caught up in this experience.

    That's what they're trying to do. Banks have been really desperate to bring workers back into the office. When you're talking about these regulatory sensitive roles or roles involving money, where banks will typically force employees to take vacations, which you should be doing, if you're a business person and you have a bookkeeper accountant, make sure they take a vacation, make sure they get out, and have somebody else fill in for them. That's going to help catch people who might be cheating with money. They really want to get these people back in. Trading is one of these, but because people are afraid of the Wuhan virus, they don't want to go into the office. So what they've done, and this is really cool, I'm looking at a picture of her right now is they've set it up so that the traders can be sitting there in their homes, and it looks like they have a bunch of different screens. You've seen this before, right where they have four or five, six screens in front of them, different data on different screens. They can look over, and they can pull up a screen, they can see everything out of the corner of their eye, just like they're used to. So I can see our market rise or drop in something. I think it's really cool. And that's a good use of that technology.

    Deutsche Bank, by the way, told its New York staff last week that they were not required to return to the office until mid 20, 21.

    Deutsche bank's going to be opening a whole new office. Many of these others are doing it as well, so we'll see what happens.

    This HoloLens by Microsoft was new surely seen as a gaming device, and these headsets cost three grand. Many companies using them as a communications tool. You might want to look at it as well, depending on your business and what you are doing.

    So coming up, we're going to talk about what's on your enterprise network. What's on the network, your house. You really might be surprised.

    We've talked about the security cameras on our networks before and, of course, the internet of things. A new study is out is really very, very concerning to business people and, frankly, to even homeowners. So we're going to get into that right now.

    Let's get into this big problem. Now that we have uncovered.

    There's a new survey that was done by a research firm called Vanson Bourne. And it was done on behalf of Palo Alto Networks. Now Palo Alto networks are one of the competitors for Cisco and others, who make network equipment. Palo Alto network stuff is pretty decent. They've certainly had their fair share of problems lately, but so has everybody else.

    I'm much more into things over at Cisco that has pretty much everything you need, and it's nicely integrated. Palo Alto networks, good people. I know a few people that will work for them. I know some people that absolutely swear by their stuff. So don't think you've got Palo Alto networks here you're completely out of luck cause you're not. They've got some pretty decent stuff.

    Let's get into the survey. I found it to be very interesting. When we go into a business, the first thing we typically have to do is scan the network. You must have to have an audit of the devices that are on your network? And then we scan the devices themselves. Typically that means their servers. Whether they're windows servers, Linux servers, we scan them. See what services they have running, which ports they have open on the local firewalls. We scan them all for any sort of malware that might be on them, spyware, et cetera.

    Then we move on to really identify the versions of software they're running. In many cases, if you're running Windows, you probably have done some patches, but some 50 ish percent, depending on the number you want to use and whose numbers you trust. About half of all windows computers are not patched up, and something like 30%, 40% of windows computers have never, ever been patched. But let's assume that they have. Let's assume that you're on top of your game. You are the person assigned to it in the business. Maybe you are an IT professional. You've had some training, and you have some certifications, so you're off and running. Things are going great for you, right. You have kept it up to date.

    We're moving to the next level, which is our, our macs or our macs up to date. Well, they just keep themselves up to date automatically for the most part.

    But remember windows are just the operating system. Mac iOS is just the operating system. How about all the other apps that you have on those computers? All of the applications. There are all a lot of them there, and it's everything from maybe the Microsoft office apps that hopefully you've got set up to do an automatic update. But it's also all of those other little apps that you've put on your computer over the years, that by the way, is another good reason to re-install your operating system every once in a while, make sure you have a good backup, make sure you test it before you do the reinstall and don't just, re-install everything.

    Don't just restore that backup blindly, but actually restore the software. That you need. Okay. The data files you need because there are so many pieces of software. We have not been keeping up to date.

    So you are the world's best IT administrator and you've got all of the computers up to date, all of the apps, only applications that you really need are actually there on the computer. You're not getting tainted by any of this other stuff that's going on, right? Oh, you are so, so good. Congratulations.

    But let's have a look at the other devices on your network. This is where the survey from the research from Vanson Bourne really raises some questions. They surveyed 1,350 IT, which is, of course, information technology decision-makers in the US and 13 other countries, so that's a pretty decent sized survey.

    I don't know if these people were self-identified or how exactly they came up with those numbers. You can find it this whole survey if you wanted to download it over on Palo Alto Networks. There's a lot of good information that you can glean from the survey. It's good stuff all the way around.

    It's the connected enterprise IoT security report for 2020 is what it's called. These decision-makers, these 1,350 decision-makers in IT, were asked questions to identify the strangest IoT devices they found connected to their organization's networks.

    Now let's define the internet of things devices here for a minute. We've already, and we've concluded here that you are the IT guru, right? You know enough to keep windows up today to remove the apps, to keep your macs up to date. How about some of the other devices that are on your network?

    I'm not going to mention security cameras because I talked about them all the time. Right.

    How about your printers? Have you updated the firmware in your printers? That's part of the reason we use higher-end Xerox printers. They all auto-update themselves, which is really nice, and we can delay the updates, et cetera because again, those printers are computers that are attached to your network. Even the ones that are attached by a USB cable, although they're a little bit less dangerous than something that's internet-connected or ethernet connected.

    How about some of the other devices? Do you have a scanner attached to your network? Do you have a fax machine attached to your network? I know a lot of doctor's offices you have to have a scanner, you have to have a fax machine.

    If you buy one nowadays, the odds are extremely high that they are connected to your network and maybe write directly to your file server. Have you restricted the access that they have on the file server to make sure they're not doing nasty stuff?

    44% of this 1,350 IT business, decision-makers almost half reported seeing wearable medical devices, 43% said they had encountered kettles coffee machines and other connected kitchen appliances. People are doing that all the time and remember that this isn't just in the business offices. This isn't our homes, right? 38. Percent said the same of IP enabled sports equipment. We see more and more of those. Have you seen the commercials for Peloton or this mirror thing? This mirror thing is really kind of cool. You hang it on the wall. It's kind of a mirror with a builtin display that lets you exercise with somebody remotely who is a coach, or maybe it's a prerecorded class.

    Some have had IP enabled sports equipment includes skipping ropes and weights. 34 present percent reported smart toys. 27% said they found smart vehicles on their network.

    I want to make sure you guys pay close attention to your networks or whether it's a home network or an office network. Make sure you segment the networks as I mentioned in my video this week. Hopefully, you got that training video on Wednesday. Keep an eye out for them. Make sure you click through. I also, if you don't want to watch the video, I also have the transcript there when you click through. So you can just read it pretty quickly. It's like a minute to two-minute read and a three-minute video. So enjoy it and be careful out there.

    Scan your networks and scan them frequently.

    What is going on with malware? There've been some major changes just over the last few months. That's what we're going to talk about right now. What do you need to watch out for? What should you be doing in your business as well as your home?

    We know that they're here. I have been a lot of attacks over the years. That's what we're trying to stop. Isn't it with our businesses, with our home users? That's why we buy antivirus software or why we have a firewall at the edge. Maybe we even upgraded your firewall. You got rid of that piece of junk that was provided by the internet service providers. Most of them are, frankly, pieces of junk. Maybe you're lucky and have a great internet service provider that is giving you really what you need. I have yet, by the way, to see any of those internet service providers out there that are really giving you what you need.

    So there is a lot to consider here when we're talking about preventing and preventing malware. What we have found is that malware attacks declined this year in the second quarter, but here's what's happening. Right? They are getting through more.

    Historically, we had things that have hit us that have been various types of malware. I remember when I first got nailed back in 91. I had a Unix server that I was running. As you probably know, I've been using Unix since the early eighties, 81, 82.

    I was using Unix, and I had my own Unix machines because I was helping to develop the protocols that later on became the internet about a decade or more later.

    The Unix world was on a rather open world. Was everybody on the internet was pretty friendly. Most people were involved in research, either government research or businesses doing research online, a lot of smart people, and we actually had some fun back in the day's puns and everything.

    We weren't that worried about security, unlike today, where security really is a top of mind thing for so many people. We weren't worried about who's going to do this to me or that to me.

    I had a Unix server that I was using, actually at a few of them that I was using for my business. Now, one of those servers was running emails, a program called Sendmail. That's still around today. It was the email package that was ruling the internet back at the time. I got nailed with something called a worm. It was the Morris Worm. In fact, it got onto my computer through no act of my own.

    I didn't click on anything. It got onto my computer because it came through the internet. That was back in the days when we really didn't have much in the line of firewalls, so it just talked to my mail server. One of these days, we'll have to tell some stories about how we really trusted everybody back then.

    You could query to see if an email address was good. You could get onto the machine and say, Hey guy, I noticed that you had this problem, so I went in and fixed it for you, and here's what I did. Much, much different world back then.

    But that's how malware used to spread. It was something, and it was just kind of automated. It went out, and they just checked everybody's machine to checked firewalls to see what they were to see if they were open.

    We've been doing that for a very long time, haven't we? We have been nailed with it. That's what the viruses were and are still, where it gets onto your computer.

    Maybe you installed some software that you shouldn't have, and that software now takes over part of your computer. It affects other files. It might be something that's part of a Word macro or an Excel macro. And it now spreads through your sharing of that file and other people opening it.

    Worms are like what I got nailed with. Just start crawling around through the internet. So they run some software on your machine, and that looks for other machines, and today things have changed again.

    They are changing pretty frequently out there. What we have seen so far here in 2020 is a decrease in malware detections. Now, just because there's been a decrease in malware detections, I don't want you to think that the threat has diminished because it hasn't. But the signature-based antivirus system are real problems.

    Now, what's a signature-based antivirus system. That's any antivirus software, like your McAfee's like your Norton's, the Symantec stuff, any antivirus software, that is working like your body's immune system.

    What happens with your body's immune system? You get a virus, and you're your body says, okay, what's going on here? It starts to multiply. Eventually, body figures it out. It develops antibodies for it. So the next time it sees that virus, you're likely to be pretty much immune from it. Your body's going to say, Whoa, that's a virus, and it goes in and kills it pretty darn quickly.

    That's the whole idea behind trying to stop the WuHan virus that is spreading out there. How do we stop it while we stop it by just developing antibodies? Right? That's herd immunity. We could also develop antibodies by an antivirus shot that is designed to stop that virus from spreading and prevents you from coming down with COVID-19 symptoms.

    In the computer world, it's much the same with most of the software signature-based antivirus software is exactly the same as the way your body's immune system has been working, in many, many ways.

    Here's what happens. Someone gets infected with a virus, and they reported to Symantec or Norton, or maybe the software reported itself. Usually, it's a third party that reports that, and they look at it, and they say, okay, so what does this virus look like? There is, in this program, the developers' names embedded, or the name of the hacker group is embedded in it. So we are going to now say any piece of software that it has this hacker group's name in it, we're going to ban. Right? It recognizes it. So when the file comes onto your computer, your computer looks at it. It looks at the signatures. These are called signatures. To say, okay, how does it match? Or it doesn't match at all, and it might be through a string that's somewhere embedded in there. So it might be through a name. It might be through a number of other things. That's signature-based.

    The malware that was not detectable by signature-based antivirus systems jumped 12% in the second quarter of 2020. That is amazing. Amazing, absolutely amazing. Seven in 10 attacks that organizations encountered in the second quarter this year. In fact, involved malware designed to circumvent anti-virus signatures.

    Most cyber-attacks last year, and this is probably going to be true in 2020 as well as we get into the fourth quarter. But most cyberattacks in 2019 came about without malware. That means that there were hackers behind this.

    We're going to talk about that. What's going on some of the data also from CrowdStrike and what they have found CrowdStrike is an anti-malware anti-hacker company. They've got a lot of great people working for them as well what they have found.

    It's like the bad old days of hacking, and they're back on us right now.

    We see more and more malware-free attacks. We also see attacks are completely evade a signature-based pieces of antivirus software. If you have antivirus, you think you're protected. You're you really aren't.

    Well, we were just talking about malware attacks declining, but what's really happening is that they are becoming more and more evasive. That is a scary, scary world out there right now.

    These hackers are no longer just using regular old viruses to try and get into your systems. Time was, the good old days, there might be a macro virus that comes in on one of your Microsoft Office document. You might've gotten a virus from some software. You downloaded some free software from a warez site, but in reality, what is happening right now is the attackers are getting smarter.

    Malware is designed now to circumvent completely, antivirus signatures. So that signature software that you had that you bought a few years ago that came with your computer, that junkware that was installed, that came up and said, Hey, you need to, to pay for it now. You had your 30, 60, 90-day free trial. It just isn't gonna work anymore. The antivirus signature code that you bought and paid for and have been using just isn't going to work.

    So what do you do? That's a really good question. What is the right thing to do? Well, first of all, we've got to make sure that we're no longer just using antivirus signatures. We've gotta be looking at the behavior of the software. There are companies out there that use white lists in particular. I can think of PC MATIC, and I've got to get them on the show and talk a little bit about this. The way they do it is interesting. There are drawbacks to white lists as well.

    The way we do it is a little bit different because we're doing it the Cisco way. We have antivirus signatures. We also have behavioral and analytics. So if. It's an old piece of malware, and an antivirus signature is going to pick it up. Well, our advanced malware platforms are going to pick it up, right? That's what Cisco does, and some others do as well.

    But if it doesn't have a signature that's recognized, it watches its behavior, and depending on what happens with the behavior, it might do a few different things.

    So, for instance, this week, we got a call from a client because what had happened was there was they got an email that had something that was flagged as suspicious by our software. Immediately that software was uploaded so that Cisco Talos. Talos has been around a long time; they are true experts in cybersecurity. There's a couple of hundred people that sit there and examine it. So that our software automatically sent this thing to Talos to be examined.

    We called up the customer and said, Hey, there's something suspicious in your email box. We are heavily filtering all of their emails as well before it even gets into the box. They said, okay, what email was it? The subject matter was an invoice, a specific invoice. We said, look for this and this invoice, and they couldn't find it in their inbox.

    Our technician had a look and said, Oh, wait a minute here.

    Now what had happened is our software had automatically sent it to Talos for an examination. Telos will look at it and said, wait a minute. This is something that looks very malicious.

    So it automatically puts it into a kind of a lockbox and examines it there.

    It looked malicious, and so they retroactively pulled that piece of email mail out of that email box all automatically. Joe, our client, had no idea. We didn't realize it had happened either until after it had happened. But the idea is if it's in question, they can remove it.

    The way it works, as well with the anti-malware platform that we have is if your computer gets some of the software on it and it starts to do something malicious, we can roll your computer back. So the malicious activity might be that your computer is now starting to probe other computers or probe other server servers that are there in your network. So we noticed that attempted lateral spread and our software would automatically shut off the network port that the computer is attached to. It's just phenomenal what you're able to do nowadays.

    Now, one of the security vendors that are out there called WatchGuard analyzed some of the malware attacks that were going on, and it looked at 42,000 firebox appliances that were at customer locations worldwide.

    Now, part of the reason I like Cisco is it's using billions of data points every day to figure this out. Right.

    So WatchGuard has 42,000. But they found that the devices were blocking 28 million malware samples representing 410 unique attack signatures, which is an increase. But there are all kinds of tools that are available now on the dark web for as little as $50 that can be used in attacks.

    When we delve into this a little bit more and look at some of the incident report data that came out of CrowdStrike, we see some very interesting things for the first time in CrowdStrike's research. They found that so-called malware-free attacks edged ahead of the malware based tool. 51 percent, in 2019, of attacks that were analyzed here by CrowdStrike, 51%, did not have malware.

    Now we've talked a little bit about this before I go into this in quite a bit of detail in my courses, in my more advanced cybersecurity stuff, but what's happening is the bad guys are using information that's being harvested from the dark web.

    You know how I'm always getting on your case about making sure you're using one password or last pass, right. I think it's important. Well, part of the reason for that is you should use a different username. I don't like websites that make you use it an email address. Cause that's currently insecure. But you should use a different username at every website, and for sure, you should be using a different password and use one password is great at generating them so's Last Pass. Those are the only two that I recommend. If you're a business, you really should be using 1password.

    The bad guys are now taking the information they find from the dark web, which is copies of your email addresses, copies of your passwords. They are using them to log in as a regular user in your network. If you have VPNs, for instance, that your business people, your employees are using to connect, they will find the VPN through a scan, the VPN access point, or the remote desktop access that you might be providing the old terminal services from Microsoft. Then they will do a credential stuffing. They will try and use a username and password from your organization.

    We just had this last week happening, and this was a government subcontractor. They did some work for DOD prime contractors, and there were people who were trying to use credentials that were found on the dark web to get in. It's happening all of the time, but now they're getting on.

    They have these hands-on keyboard methods. They're trying to use usernames and passwords that they have found on the dark web, and they are using PowerShell. Now, PowerShell is a rip off that Microsoft made from the Unix world, and Microsoft, of course, messed it up pretty badly, and there are all kinds of major security problems with it. Microsoft Windows were not designed with PowerShell in mind.

    Nowadays, you have to use PowerShell to do certain things. Microsoft has finally figured out, Oh, wait a minute. Command-line interfaces are wonderful. Maybe we should use them more. So what happens is they use PowerShell.

    They start it up, and now they use it to exploit your network, exploit your systems because it's not a virus, it's not a program, very hard to spot and they'll hide files and directories, and they will use these tools like PowerShell and act just like a regular system administrator acts nowadays on a windows machine. System administrators on Windows machines, they're using PowerShell, aren't they? Now, most organizations don't have the technology to be able to differentiate between a legitimate user and a legitimate employee or contractor or an attacker who has stolen credentials.

    This is about a very, very big problem out there that's been seen by Cisco, by CrowdStrike, Rapid seven is another one they're using. They're seeing hackers using valid credentials or reusing credentials from other breaches, i.e., credentials that are found on the dark web. So what do you do? How do you do this? That's our really big question right now.

    The bottom line, do not ever reuse passwords. If you're a home user, it's true. If you are a business, it's true. One of the things we do for our customers, and you can do for yourself is to go out to the dark web and search. Use tools, like Have I Been Pwned, very basic tools, and see if your users username slash email addresses are out on the dark web. Also, see if the password that's associated with that account out on the dark web is still in use by them.

    Just this week, we found another one of our customers where one of their primary users, one of the C-level people, Paul, was using the same email address and password for the business applications as he was in for one of these hacked accounts out on the dark web. So be very, very careful.

    Well, we've just been talking about some of the ways that the hackers are getting into us now, avoiding some of the software we've been using; these antivirus packages just don't work anymore. I'm going to talk about another problem. This is a massive windows bug.

    We're going to be getting into a couple of other things here. We'll talk about VPNs a little bit and how it's dying and going away. We've got another employee theft that's happened here, this time to Shopify. Microsoft, and what they've done with Azure. We'll talk a little bit about these cloud systems because they are problematic.

    Wanna cry is back and Love in the time of Zoom. Why we're in the midst of a dating revolution. So why don't we start with that one here - Zoom. You know how much I don't like Zoom for business. It is not considered secure or does not meet any of the standard security requirements. So that's a problem if you were to ask me.

    We are in the midst of a dating revolution. Do you remember that episode from Seinfeld where George is out doing speed dating, and they had these? What were they? 30 second or 60-second dates. I guess that's been the thing over the years, maybe a little longer than that.

    You spend two minutes, five minutes with someone and you're all there at the restaurant or whatever conference room. It's like musical chairs. Every time you move one. Usually, it's the woman sitting there, and the men move around, and it could be the other way around, I suppose. There was a good way to meet a lot of people. If that's what you're trying to do, see if there might be any chemistry. Usually, they charge for them, and yeah.

    Today, well, things have gotten higher-tech. They come about here in Zoom rooms as well. I mentioned earlier today some of the things that we're doing from a business standpoint on Zoom. Many people are now having business meetings obviously, or hopefully not on Zoom, but in the online world.

    But right now, what we're seeing is love and marriage. How people are connecting. It used to be, of course, accidental. Then some of us might go to the church we belong to and look for a companion or a mate. There are a lot of ways that things have changed, and they changed a lot, really in the 18th century with the industrial revolution.

    Now we're kind of back to the isolation days. Well, so what do we do now? I don't know if we'll ever really get back to normal. People have found that they can do business from home. They can work from home. Now they found that they can date from home as well.

    Already, we're seeing nearly 40% of heterosexual couples reporting that they have met online. Most of the time, that's being through a social media site like Facebook, or maybe some of the others that are out there. Same-sex couples are even a higher percentage here, more than 40% of heterosexuals that are meeting online.

    Of course, there is also the casual encounters that have been going on. I can't even believe it, but Dr. Fauci even mentioned that, right? Oh man, we're not getting into that right now.

    But this type of online interaction is absolutely surging during the time here of the Wuhan virus. Bars are closed. Restaurants are mostly closed churches can't meet you. Can't sing hymns, depending on where you are. They might only let a few people in. I know there's one state where you can go to a bar, but only one person can be in the congregation of a church. I, I just don't understand some of that stuff, obviously.

    So what do you do right now? We see a massive drop in the number of Americans that are married by the time they turn 30. Only about half of them are married by the time they turn 30. Fertility rates have plummeted to 1.7, meaning the average woman will give birth to 1.7 children over her lifetime, which means if that woman can be considered to be part of a couple. That is negative growth in our population. Something that some people have been trying to achieve for a very, very long time, but it is well, well below the natural rate of replacement, which is as I recall, what about 2.1 or 2.2? So that's pretty dramatic, and it is just continuing to go down more.

    Men aged 30 to 34 were living with their parents than with the romantic partner, and that's before the Wu Han virus pushed even more of a back into our homes as we've lost jobs and opportunities that are out there. It's just not very, very good, but the future isn't all of that bleak.

    I wonder, frankly, when we're talking about general social social media. So things like Facebook and messages and stuff, how much of what we see and we feel we have a connection with other people. How much of what's real. We already know much of what we see. Isn't it real. Some of these social media influencers you've admitted to taking as many as a thousand pictures before they found one that's worthy of posting where all the makeup was. Right. The pose was right. The hair was right. The background was right. The lighting was right. It leads to a false sense of, Oh, keeping up with the Joneses. If you will. There's an older expression. Where people see this, and they think that's the way their life is supposed to be. It's absolutely not.

    So how about where where we're trying to do one on one stuff. I think we all can remember going on dates and being a little braggadocious. Maybe inflating things just to ever so slightly. When we went out with somebody and then over time, we got to know them, and then we started to loosen up. I'm in a mastermind group, and I also have seen that in the mastermind group that as we got to know each other. We kind of relaxed, but we know each other's businesses now, and we can give each other good advice and a good kick in the pants when necessary.

    So I don't know. The future's not bleak. I think. Yeah. It might take a while for people to get to know each other when we're talking about meeting online, doing little Zoom meetings, or meetups online. But the whole courtship thing has really changed the whole structure of what it is. It is just absolutely amazing, but I think we are still going to be looking for those relationships. We're so going to be trying to find them online, and I think it might work, and I don't know. Maybe a breakup is even easier in the online world or maybe the whole fallacy behind the online world where people are literally making stuff up if the fallacy is going to make it even worse when it comes to breakups. I really don't know.

    I'm looking at an article here from Debora Spar. She's a professor of business administration at Harvard business school, and she's been very focused on issues of sex and technology and what's been happening with the technological change. She has a new book out called workmate. Marry Love, how machines shape our human destiny, which is kind of an interesting book. I think the romantic times are going to continue, but we're going to continue to look online for ways of meeting and doing stuff with people. So there you go. Zoom is not just for little family gatherings, but it's also for romance. I think that's kind of cool.

    Hey, if you like to listen to the radio, when you're driving around in your truck or your car, one of the things that I do, and here's a little tip for, in case you didn't know you do it is I have Bluetooth in all of my cars.

    Nowadays, there's Android play. For Android phones, not all of them, just some of the newer ones, and Apple also play for the newer Apple iPhones. What that allows you to do is run the app near a phone. And once that app is up and running, it will come out through your car stereo.

    Now, many of you guys, of course, you're the best and brightest. So you probably know how to do that already. I love the way car play works on the Apple side, Android. It works pretty well too, but the main concept behind it is to keep the interface simple, to keep the number of distractions down.

    We are right now under attack. This is the windows vulnerability that I mentioned live on the air here a couple of weeks ago, it's not patched up by most people, and it's really, really bad.

    Well, this is a big problem right now. This particular vulnerability is called a zero log on vulnerability. What that means is your computer is vulnerable to attack without the bad guy actually having to log on to the computer. Very, very, very. Bad. Okay.

    Now, this is an escalation of the privilege problem. Microsoft has come out and issued some patches. Apparently, it's not going to be fully fixed for a while, from everything I was reading.

    This is crazy because what's happening is they are using domain controllers and remote procedure call login servers to get in. So if you're just running a regular windows machine in your house, obviously you want to keep it up to date.

    But this particular exploit is against these servers that are out there. The servers specifically have exposed domain controllers, and remote procedure calls, also called RPC login servers.

    Why do you use those? Well, most businesses use those types of servers to allow people to log in remotely. Who logs in remotely? Well, its employees, right? We're there in our homes, and we're trying to get into the office. So we use a domain controller. We are sending RPC calls here for the login servers. You may not know what's actually going on behind the scenes, but that's what it actually is. Now there's a search that you can do on a line. There's a couple of different searches to find. These exposed servers, very, very big binary edge.io. There's a couple of others also let you know about it, but okay. They show more than 33,000 3 million networks that are exposing domain controllers. This is absolutely crazy here.

    If a single network has both resources exposed, and the combination can leave the network-wide open with no other requirements. Okay. It's very, very, very, very bad. I don't want to go much more into this. It is absolutely catastrophic. If you are a person who's responsible for the, IT resources within a business. You have to take care of this. Right, right, right away.

    The cybersecurity arm of the Department of Homeland security mandated all agencies will over the weekend. They put the mandate out on Friday, and then they had to be done by Monday. They had to apply the patch by Monday night or remove the controllers from the internet. Take that as a little bit of a hint that maybe it's something you should do too.

    So if you are a business owner, make sure you check with your managed security services provider and or your employees who are responsible for it. Okay. Cause it's very, very big. It's the year most severe Windows bug that we've seen this year, and who knows, maybe more on the way. So I'm not going to say it is the best or the worst.

    Now let's move on to another subject here that I think is worthy of the news here, and that is that VPNs are a risk.

    Now, one of the legitimate reasons to use a VPN would be so you don't expose those services on your server. In other words, they're not exposed to the whole internet. If they're not exposed to the internet, some guy or gal somewhere else in the world can't get to them. So how do you let your employees get to those services and keep them locked down for everybody else?

    You could do it by having your firewall only allow certain internet addresses to get through to those services. That's what I would advise as a quick stop-gap for you. Ensure that only the home computers that are supposed to be able to get at it can get at it.

    But remember too, that it is just a quick stop-gap, because those home computers could be infected and could be used as a launching point to come after your services. So you're letting that home computer through your firewall to get to the RPC services, the login services they need. If that computer is infected, that home computer, it could be used now to attack you. So it's just a stop-gap.

    Another way to do it is to use a VPN. Now, you know what I've been saying about VPNs for the longest time, where VPNs are, frankly, a little on the hazardous side, particularly for your security. There's a difference between privacy and security. At least if you ask me.

    The biggest difference is privacy means that advertisers don't know where you go, which means your internet service provider doesn't know where you go. That's privacy.

    Security is where you don't want that information sold, but even more so, you don't want to have your bank account information stolen or other things that really need to be secured. Okay.

    So that's the big difference here. If you get a VPN for your business so that people can connect to these log-in services, or maybe connect to your file server, that's a bit of a problem as well, because remember the VPN can be used both ways.

    It's like that saying, I love this old saying, but tracers work both ways. Right?

    You use tracer rounds when you're shooting at the enemy so that you can see where the bullets are going. By the way, that means the enemy can see where the bullets are coming from. The same thing's true with VPNs. You put a VPN in place so that home users can connect to those login services or maybe your SMB CIFS here, your file servers, right, the file shares. You open it up the VPN so they can get through, but now potentially, the bad guys can use it to get through as well. So it is a big problem.

    Because of that, VPNs need to be tracked very closely in your firewalls.

    We run all the VPNs that we have for clients or that are requiring security. We run them all through not just a basic firewall but one that reassembles everything. Examined all files that are being downloaded, et cetera, et cetera. Okay. That's what we do now.

    There is a new technique in place right now that is gaining a lot of momentum, and frankly, within the next few years, all businesses should be using this. We're doing this already, and it's something called Zerotrust. Zerotrust means in the case of a VPN. Okay, great. There's a VPN in place, but I don't trust that home computer to have full access to my network. In fact, not only mine, do I not trust it to have full access to the network, but I don't even want to have full access to this particular server.

    I only want it to have web access, let's say. Even then, I want to go to the next level. I want to make sure that that home computer is not being used to grab my client list. That an employee is about to take with them as they walk out the door to my competitor.

    That's where you start getting into Zero trust and what that's all about. We're going to talk a little bit about that. What Gartner's predicting is going to happen here by 2023 and how you can use it and how you shouldn't be using it right now, in fact, so stick around because we'll be right back.

    So we know a little bit about VPNs and what they are. So what's Zero trust and how's a Zero trust network run. What are we looking for here shortly? More than half of businesses will be Zero trust.

    I've started to do some three-minute training. So the first one went out on Wednesday, and I was really surprised just how much work it takes to make a three-minute training. But we did it, and we got it accomplished. We're going to try and have a couple of those a week, plus the weekend newsletter, which is, of course, a fair amount of work, but we're doing it for you. Hopefully, you got a lot out of it.

    I got a crazy number of responses to the first video. So thank you. Thank you. Thank you for respondeing. Hopefully, I got back to you in a reasonable amount of time here, and we're able to help you out a little bit. Anyhow, if you missed it, go look back on Wednesday this week. That's when I put out the first one. So it should have been in your email box Wednesday. As usual, it's from [email protected]. So if you're not getting them and you think you should be double-check, make sure I am on your contact list or whitelist me somehow so that you get those. They're important. I'm going to be doing more of those a week just to kind of a light touch. Let you guys know what's up.

    So VPNs have been around now for more than a couple of decades. They've been fantastic. They've saved a lot of businesses a lot of money. Now course, they tend to be kind of dangerous, particularly these free VPNs and the commercial ones that you're using, to somehow try and make yourself more secure. I just shake my head every time I hear these misleading ads. They are lying to you. It's really not going to protect you that much, frankly, if at all. It gives a little bit of privacy in certain situations, but not in others. I had a great call with Doug, in fact, this week. And he was having some problems. He is a small business guy been in business for a long time, sold his business, and now he's almost 80. I think he said he was 78. He's kind of back in business, again, keeping himself busy and occupied. He was wondering and worried about trying to keep some of this stuff secure. So we went through it a little bit with him.

    He uses macs, so it is definitely easier to keep secure. When he's on the road, he has one of these little devices he takes with him that allows him to connect to the internet from Verizon. One that directs you directly connects you to the internet, which is dangerous. Another one that provides you with what's called Nat or network address translation that's a little bit safer. So he's going to send me the model number in particulars of what he's using so that I can help him out a little bit.

    By doing that, he's no longer tying into the wifi at the airport or on the airplane or at the coffee shop, wherever he's going. He's got his daughter doing that too, which I think is a very good idea. I know a lot of people, as well that does it. I do it as well. I have one of those little devices. I just replaced the battery in mine because it started swelling. It's a lithium-ion battery. Some of them, when they start to swell, you've got to replace because what can happen is when they swell, they will short out and can start a fire. So be very careful about that.

    So he's smart enough to know that you don't want to use public wi-fi. He effectively brings his own little wifi device with him, which is, again, a great idea.

    Some people use VPNs when they are out there on the road and connecting back into the main office or their homes. I have that as well, and that lets me get directly in.

    Most of the time now, what we've been doing for our office and our customers is putting together zero trust networks. These are far more secure than anything else we have out there right now, as far as firewalls and everything else goes. The idea is, just like its name implies, that we're looking at everything. We're no longer just trying to do what's called a perimeter security approach where we have a firewall at the perimeter.

    Now we are trying to protect ourselves and our businesses from any kind of attack, including insider attacks, including the lateral movement that I've talked about so many times before. Where a bad guy gets a foothold inside of a network, and that bad guy immediately tries to start spreading things. Very dangerous. Very, very dangerous. There's several other flaws too. Perimeter security just doesn't do a good job of counting for any third parties, any vendors you might be working with contractors; all of your supply chain partners. If attackers steal somebody's VPN credentials, now the attacker can get into the network and roam freely. Like I've talked about many times.

    Many of us use the same username and password on pretty much every device out there. That's a problem because when it gets onto the dark web, now the bad guys have it. Plus, the VPNs over time have become a lot more complex and very difficult to manage.

    It's rare. I say rare, but I've never seen an exception. In other words, it seems that these businesses have misconfigured VPNs. It seems to be a pandemic out there, frankly—a lot of pain around VPNs.

    So this is going to change it all. You are. We're going to have different equipment internally. Your devices are not gonna be able to connect directly.

    So the way we have it set up all of the devices on a network, instead of speaking directly with each other, have to go through at least a firewall. The firewall watches what they're trying to do even inside the network. So it's no longer just out there at the perimeter. Frankly, what we've been doing with VPNs, it's just clunky. It's outdated. Frankly, kind of dangerous. So keep all of that in mind.

    All right, if you need a little help, if you have some questions, I am more than glad to get on the phone with you guys and chat a little bit and help steer you in the right direction. You can just email me M E @craigpeterson.com, and I'd be more than glad to get back to you. So keep all of that in mind. VPN is dying. Zero trust is what's coming down the road.

    Now, I just mentioned the problems of potential internal threats, and that can include bad guys that are in your network, spreading laterally, as I just mentioned, but it can also mean that your employees are the problem.

    I've seen that before. I had it happen to me, where I had an employee who took all of my customer records and took my customers with him. I could not believe it. I still can't believe it to this day. What he did, I don't understand it. What does he think he's doing? He may have built up a relationship with my customers. I don't think he brought a single customer in. In fact, he built up a relationship with my customers, and then he figured they're his customers now because he has a relationship with them.

    So forget it, Craig. They're his customers. It is just absolutely amazing.

    Shopify, which many of you have heard of before and many people are using. Has found that two of their support team employees were involved in a scheme to steal customer transaction records from specific merchants. It affected apparently fewer than 200 merchants, but there's an example of where Zero trust can really come into play. Do your sales guys have access to information they shouldn't have?

    How about some of your support people? We have to make sure we're monitoring where they're going and what people are doing within our networks. Okay.

    We're going to talk about Microsoft and the Azure store and president Trump and wanna cry. You remember that really bad piece of malware? It's back.

    I sent out a three-minute training, the first three-minute training. I'm going to be doing more and more of them here as time goes on. This training got just a plethora of responses from people. I'm so happy I could help out a lot of people this week, including a bunch of very small businesses, and that's what I love to do. That's why I do this, right. Help you guys out a little bit here.

    Now, obviously, I have customers, big paying customers, usually, companies that are regulated and actually need cybersecurity.

    But for the rest of you, I still will help you just as much as I can. Obviously, there are some things you need to do, and that's what this is all about.

    Well, you know already about the Apple app store. I've talked about it many times. Do you know about the Google play store? Both of those are stores that you go to buy or download little applications that you can use on your smart devices. They're both great little stores. Apple tends to do a better job when it comes to watching for security problems than Google does.

    Both of them tend to take about a 30% chunk of any money that you pay. Then of 75% or 70%, I should say to the developer. Well, Microsoft has a store, as well. You might have heard of Azure. That's a service that Microsoft has, and it is an online service. It's a cloud service. It lets you run Microsoft Windows in the cloud, in a data center.

    That's managed by Microsoft, run by Microsoft in most cases. Also, by the way, it'll let you run various types of Linux, and that was a bit of a surprise, but anyhow. That's the Microsoft Azure story. Then we also have stores that are over on Amazon, and that's called AWS Amazon web services. There is a lot of others too.

    We tend to use some of the IBM stores, including the IBM mainframe stuff, which has just been amazing to us, just how good those things are. The IBM mainframes, how fast they are, and how inexpensive they are for computing stuff. It's just amazing. Anyhow. Microsoft and IBM and Amazon, and anybody that has one of these cloud services also have a store.

    And it's much like the stores that you would expect to find for your smartphone. But in the stores where we're talking about here, Azure, or these cloud services, they actually are selling and leasing or renting fully configured machines. So you can go on, you can say, Hey, I want a new Ubuntu version, blah, blah, blah, or red hat enterprise Linux, which is what we tend to use, version this and such, and maybe you want to also use containerized stuff. And so they have all of these things pre-configured you can say, Hey, I want a database engine and Tada, poof, there is a database engine for you. It can be either poorly maintained by them. And you have no idea what it is. It acts like, mysequel, or whatever database you might want it to act like. Or maybe it really is one. Maybe it's your own version of that. Those types of apps are available in these cloud services just to use those terms loosely.

    Well, earlier this year, it turns out according to Dan Goodman, who wrote an article over at ARS Technica up on my site, but members of the Microsoft threat intelligence center suspended 18 Azure active directory applications because they determined they're part of this huge command and control network that was being run out of China.

    Now we can also talk here about commanding control because your computer might even be part of this. So if you have a computer and that computer gets hacked, one of the reasons they hack it is to use it as part of a command and control network.

    Now here's the idea behind command and control. They're not going to ransom your data. They're not going to try and do something nasty with it. In fact, these command and control guys don't really care that your computer can do anything other than connect to the internet.

    So one of the things they'll do with command and control is they will do what's called a denial of service attack against somebody. So there's some company they don't like, or maybe they're ransoming. This company says, Hey, listen, we'll shut down your website unless you pay us a million dollars.

    What they'll do is he'll use a thousand, 10,000, however many computers they have in their command and control network. They'll use them now to send off fake website requests to that company. Now that company's servers just get hammered and nowadays we see in the order of tens or even hundreds of thousands of requests. Per second coming into some of these data centers and that there are services out there to protect against. Those types of denial of service attacks. Okay.

    But here's where things really start getting interesting. That is, they all also use command and control systems to send out emails, to do phishing, even to research them. So command and control just as it sounds is they have control of your computer, right? They send commands to execute.

    So, in this case, what we're finding is that Microsoft had these apps that were in there as your active directory, their cloud service, that were part of this commanding control network. 18 different applications. Again, we're not just, we're not talking about an app, like an app that would be in the windows phone. If you are sad enough to have bought one and no longer getting support. So it is a difference. It's a pretty big difference.

    These are the types of applications that are used by businesses, database applications, web server applications. All right. It's not just the fortune 500 companies that are doing this anymore. We're talking about the smaller guys who really don't have the resources to check.

    You know, between the two of us, most of these fortune 500 companies aren't doing what they should be doing either. Hence all of the hacks that we've been seeing. So they had the cloud hook, hosted applications.

    This is a hacking group that Microsoft is calling gadolinium. They had also been storing stolen data in a Microsoft one drive account and used that account to execute various parts of their campaign. Now, Microsoft, Amazon, all these other cloud providers have been touting how secure it is, how fast these cloud services are. They're just so much cheaper. Oh, this scale that comes from renting computer resources. I remember describing what they were hoping for a way back when with cloud services, that it would be like the power company who cares where the electricity comes from as long as you just flick the switch and the light comes on.

    Believe me, and it is no longer like that. The hackers have realized now the benefits of hacking the cloud surfaces and, in this case, using them to share their stolen data to store it, et cetera, et cetera. And now there's so many free trial services and one-time payment accounts. Hackers have been able to quickly get these different things up and running.

    They, as I mentioned before, can even buy their own materials, their software to do the hacking, to do the phishing, to do the ransomware, to sell the decryption stuff. They even have banks that'll handle the transactions for them to in converting Bitcoin into the US or whatever dollars they want to. Very very big deal.

    Earlier in the show, I've talked about this some of these tools are in use right now in particularly in Windows PowerShell, that are not well secured and are legitimately used by the system. Administrators have become a huge, huge tool for the bad guys to use. They're so widely used for legitimate tasks. It's very hard to detect the reuse of these illegal tasks.

    This group, this gadolinium group, has recently started using a modified version of PowerShell empire post-exploitation framework. It's open-source. Can you believe this stuff that's going on? So it's very scary. Agility and scale, frankly, are working both ways here against us, and for us, I am very concerned about some of the stuff that's going to be happening.

    If we've got some of these bad guys that are out there, right? Some of these terrorist groups, domestic terrorist groups that are burning our cities right now and shooting people, shooting cops, et cetera, that these terrorists are going to be using—these same techniques shortly here in the US. You probably already are. We already know it is using them to finance and fund their operations. Very, very scary stuff.

    So one more thing real quick before we go. That is Wanna Cry. Very, very big deal. SonicWall is reporting a 109% increase in ransomware in the US during the first half of 2020. Keep your eyes out. This is very, very inexpensive for the bad guys to do. Get ransomware on your systems. They have high rates of return on it. There's hardly any risk for them. It's even outsourced. We've talked about that before. It is a preferred method of attack for cybercriminals. So be very, very careful out there.

    Get the right kind of security. I was talking with a couple of companies this week. We're going to be putting in place some of the prosumer Cisco stuff to help out a very small company and some of the commercial stuff that you need to have if you are a regulated industry. So we'll be doing some of that this week, too.

    You've been listening to Craig Peterson. Have a great week, and make sure you visit me online. [email protected].

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 19 min
  • Fileless Malware, Credential Stuffing, Advanced Malware Protection plus more on this Tech Talk with Craig Peterson Podcast

    Welcome!  This is a "best of Craig."  I have included the current articles that you should read this week in the article section so check that out.  In this podcast, we cover Fileless Malware is on the rise, How covid is affecting the financial traders, Why you must find out what is on your Enterprise network, and more.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    Ransomware Demands are Doubling Every Six Months, Study Finds

    Teach Your Employees Well: How to Spot Smishing & Vishing Scams

    Mimecast Research: Half of all Workers Admit to Opening Emails They Considered Suspicious ‘Check the Box’ Awareness Training has Little Impact on an Organization’s Security Posture

    MITRE Shield Matrix Highlights Deception & Concealment Technology

    Act of War - Clause Could Nix Cyber Insurance Payouts

    Most Businesses Vulnerable to Emerging Risks Not Covered by Their Cyber Insurance

    Oh Jeeeesus: Drivers react to Tesla’s full self-driving beta release

    Rising Ransomware Breaches Underscore Cybersecurity Failures

    SANS Launches New CyberStart Program for All High School Students

    Traders set to don virtual reality headsets in their home offices

    What's on Your Enterprise Network? You Might Be Surprised

    Malware Attacks Declined But Became More Evasive in Q2

    One of this year’s most severe Windows bugs is now under active exploit

    The VPN is dying. Long live zero trust

    Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

    Microsoft boots apps out of Azure used by China-sponsored hackers

    WannaCry Has IoT in Its Crosshairs

    Love in the time of Zoom: Why we’re in the midst of a dating revolution

     

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Massive changes ahead. We've even got traders who used to be on the floor of the stock exchange, and on the floor of these massive financial companies. We've even got them at home. Now you're going to be shocked at what they're doing to replace that interaction.

    Hi everybody. Craig Peterson here. We're going to be talking about these traders and how virtual reality headsets have changed the way some of them are doing business. We're going to talk about what's on your enterprise network. I talked about this last week.

    Hopefully, you got my email. It came out on Wednesday this week. I'm going to try and do two of these a week. It's three minute little a coaching lesson, if you will, on security. This week we talked about your enterprise network. We're going to delve into that more today.

    Have look at an email make sure you got that. I know you're used to getting emails from me Saturday mornings. This last weekend we sent our weekly email on Sunday instead of Saturday. I'm not sure if that's better for you guys or not. We certainly didn't have quite as many people open it as usual.

    Usually, it's almost half of everybody that's on the list, and that's thousands of people open it but not as good on Sunday. We may switch back to Saturday. We'll see.

    It also has to do with our time, right? This is a labor of love, trying to get all this information out to everybody. So things can change.

    We're going to talk about some big changes in malware attacks this year, even though the decline a little bit in Q2. They got more potent, and we'll tell you why what's going on years.

    Most severe windows bugs is now under active exploit. We'll tell you about that. VPNs are dying. You know what my thinking is about these paid VPN and free VPN services. If you've been listening long enough, right? They do not increase your security. In fact, they decrease your security in some ways. Maybe you're going to stop your local ISP from tracking where you're going online, but you're you overall are much less secure.

    Shopify. We've got a huge theft of the hair, and turns out it kind of employees involved. We've got Microsoft booting more Chinese sponsored hackers out.

    Wanna Cry. That yeah yeah, that same one that brought the country and the world to its knees a couple of years ago. It's back. And love in the time of Zoom. So if I don't get to all of these today, make sure you check online, or if you're going to miss part of this, all of that available there, Craig peterson.com. We're trying to make sure all of the audio is up there so that you can listen to it in your time on any podcast app. Make sure you check it out, whatever your favorite app is.

    Technology has really changed everything, and we have seen that this year, they expect to be just an incredible online shopping season. Now that's good, and that's bad. You've got the local stores who are hurting very badly. I have gone out of my way lately to try and go to a local store as opposed to ending up online and buying stuff because I want to support them. They are part of the economy, obviously. They are where my kids got some of the first jobs in local stores. They are also the place where I can go to see things and play with things. It's not like where Amazon charges me sometimes to return something. That wasn't what I thought it was. That kind of always bothered me. So I like the local merchants and not just the restaurants, but the guys that sell the little electronic gear that we have and other things, but it's going to be a huge year this year.

    We're going to talk later on today. This is kind of low on the list, but virtual online Zoom dating.  It is really changing at all. Now we have a story that came up from Ars Technica this week, Owen Walker of the Financial Times, talking about how we have moved our businesses into spare bedrooms in our homes, living rooms, and we've talked about this before.

    If you're working from home, make sure you have a spot where all you ever do is work from home. The brain kind of ends up associating, and you can become much more productive that way. Different parts of the room, maybe a different chair. Maybe all you do is turn the chair around just to let your brain know that it is time to get to work.

    I also use some apps. I've got vitamin R that I've used, and I don't really use it as much anymore. I've kind of grown disciplined over the years. You might check it out online. Vitamin R. It uses the Pomodoro Technique, which is an Italian name. Remember those little tomato clocks or countdown timers you have in the kitchen, or at least you used to have years ago where it just reminds you, Hey, uh, you're supposed to be working right now cause you hear it go tick tock, tick tock, tick tock, and then it goes off and okay, well, my 20 minutes is upon this particular task, and then you take a brief few minute breaks and then you get right back to it.

    There are all kinds of hacks to help us to be more productive when we're at home and ultimately more productive than maybe in the office in some ways. In other ways, you're not as productive, and you're not as productive because you're not around these other people who can come over and ask questions, and much of what we learn, much of what we do is just incidental communications. Where we are in a hallway, we bump into someone, or we go to a meeting. We have a side discussion. That's hard to do when you're on a WebEx team call because you're there, and so are 10 other people, two other people. It doesn't really matter how many other people, because you can't just lean over and say, Hey, what do you think of this or that?

    Now, obviously, on the WebEx teams, you can go ahead and type a message, right? You have that chat capability, and you can send it to a specific person. You can do that on Zoom as well, but I don't. I'm not going to talk about Zoom right now because you should not be using it for business. Just you really, really should not.

    So focus on that ability to communicate. Some companies are now going to happy hours online, and I've been invited to a Zoom happy hour, and the company's sending me three little bottles of wine. We're going to do it. Taste-testing and we'll just kind of chat while we're there online. It should be fun. It'll be interesting too.

    Many businesses are doing that, as well. They have a little happy hours and get-togethers because you're not going out after work for a drink to talk to people. You're not going out in the hallway and talking to people. It is such a different world.

    The whole thing with whether or not you're there physically is a whole other problem when it comes to traders. Think about traders. If you've seen some of these movies or TV shows where they're on the floor, I know Fox business, and some of these other business channels have a shot with a camera on the floor, the trading floor, and there just aren't the people there that they used to be. But it's again, it's the interaction, and that's what's been important in the past.

    Some banks UBS particularly has been issuing some of its traders over in London. These HoloLens from Microsoft. These are virtual reality headsets, and the idea behind this is to allow the staff to recreate the experience of working on a packed trading floor without ever leaving their homes. I don't know if you saw the video or pictures of this, but when Microsoft first introduced these virtual reality headsets, they had issued them to everybody who was in attendance at this conference room, and they started playing these videos. So you see all these people looking around, of course, they can't see beyond what's right in front of their eyes, which is this HoloLens. These virtual lenses and they're looking around and right up the aisle walks Bill Gates, of course, nobody notices him because he can't see him. They're all just caught up in this experience.

    That's what they're trying to do. Banks have been really desperate to bring workers back into the office. When you're talking about these regulatory sensitive roles or roles involving money, where banks will typically force employees to take vacations, which you should be doing, if you're a business person and you have a bookkeeper accountant, make sure they take a vacation, make sure they get out, and have somebody else fill in for them. That's going to help catch people who might be cheating with money. They really want to get these people back in. Trading is one of these, but because people are afraid of the Wuhan virus, they don't want to go into the office. So what they've done, and this is really cool, I'm looking at a picture of her right now is they've set it up so that the traders can be sitting there in their homes, and it looks like they have a bunch of different screens. You've seen this before, right where they have four or five, six screens in front of them, different data on different screens. They can look over, and they can pull up a screen, they can see everything out of the corner of their eye, just like they're used to. So I can see our market rise or drop in something. I think it's really cool. And that's a good use of that technology.

    Deutsche Bank, by the way, told its New York staff last week that they were not required to return to the office until mid 20, 21.

    Deutsche bank's going to be opening a whole new office. Many of these others are doing it as well, so we'll see what happens.

    This HoloLens by Microsoft was new surely seen as a gaming device, and these headsets cost three grand. Many companies using them as a communications tool. You might want to look at it as well, depending on your business and what you are doing.

    So coming up, we're going to talk about what's on your enterprise network. What's on the network, your house. You really might be surprised.

    We've talked about the security cameras on our networks before and, of course, the internet of things. A new study is out is really very, very concerning to business people and, frankly, to even homeowners. So we're going to get into that right now.

    Let's get into this big problem. Now that we have uncovered.

    There's a new survey that was done by a research firm called Vanson Bourne. And it was done on behalf of Palo Alto Networks. Now Palo Alto networks are one of the competitors for Cisco and others, who make network equipment. Palo Alto network stuff is pretty decent. They've certainly had their fair share of problems lately, but so has everybody else.

    I'm much more into things over at Cisco that has pretty much everything you need, and it's nicely integrated. Palo Alto networks, good people. I know a few people that will work for them. I know some people that absolutely swear by their stuff. So don't think you've got Palo Alto networks here you're completely out of luck cause you're not. They've got some pretty decent stuff.

    Let's get into the survey. I found it to be very interesting. When we go into a business, the first thing we typically have to do is scan the network. You must have to have an audit of the devices that are on your network? And then we scan the devices themselves. Typically that means their servers. Whether they're windows servers, Linux servers, we scan them. See what services they have running, which ports they have open on the local firewalls. We scan them all for any sort of malware that might be on them, spyware, et cetera.

    Then we move on to really identify the versions of software they're running. In many cases, if you're running Windows, you probably have done some patches, but some 50 ish percent, depending on the number you want to use and whose numbers you trust. About half of all windows computers are not patched up, and something like 30%, 40% of windows computers have never, ever been patched. But let's assume that they have. Let's assume that you're on top of your game. You are the person assigned to it in the business. Maybe you are an IT professional. You've had some training, and you have some certifications, so you're off and running. Things are going great for you, right. You have kept it up to date.

    We're moving to the next level, which is our, our macs or our macs up to date. Well, they just keep themselves up to date automatically for the most part.

    But remember windows are just the operating system. Mac iOS is just the operating system. How about all the other apps that you have on those computers? All of the applications. There are all a lot of them there, and it's everything from maybe the Microsoft office apps that hopefully you've got set up to do an automatic update. But it's also all of those other little apps that you've put on your computer over the years, that by the way, is another good reason to re-install your operating system every once in a while, make sure you have a good backup, make sure you test it before you do the reinstall and don't just, re-install everything.

    Don't just restore that backup blindly, but actually restore the software. That you need. Okay. The data files you need because there are so many pieces of software. We have not been keeping up to date.

    So you are the world's best IT administrator and you've got all of the computers up to date, all of the apps, only applications that you really need are actually there on the computer. You're not getting tainted by any of this other stuff that's going on, right? Oh, you are so, so good. Congratulations.

    But let's have a look at the other devices on your network. This is where the survey from the research from Vanson Bourne really raises some questions. They surveyed 1,350  IT, which is, of course, information technology decision-makers in the US and 13 other countries, so that's a pretty decent sized survey.

    I don't know if these people were self-identified or how exactly they came up with those numbers. You can find it this whole survey if you wanted to download it over on Palo Alto Networks. There's a lot of good information that you can glean from the survey. It's good stuff all the way around.

    It's the connected enterprise IoT security report for 2020 is what it's called. These decision-makers, these 1,350 decision-makers in IT, were asked questions to identify the strangest IoT devices they found connected to their organization's networks.

    Now let's define the internet of things devices here for a minute. We've already, and we've concluded here that you are the IT guru, right? You know enough to keep windows up today to remove the apps, to keep your macs up to date. How about some of the other devices that are on your network?

    I'm not going to mention security cameras because I talked about them all the time. Right.

    How about your printers? Have you updated the firmware in your printers? That's part of the reason we use higher-end Xerox printers. They all auto-update themselves, which is really nice, and we can delay the updates, et cetera because again, those printers are computers that are attached to your network. Even the ones that are attached by a USB cable, although they're a little bit less dangerous than something that's internet-connected or ethernet connected.

    How about some of the other devices? Do you have a scanner attached to your network? Do you have a fax machine attached to your network? I know a lot of doctor's offices you have to have a scanner, you have to have a fax machine.

    If you buy one nowadays, the odds are extremely high that they are connected to your network and maybe write directly to your file server. Have you restricted the access that they have on the file server to make sure they're not doing nasty stuff?

    44% of this 1,350 IT business, decision-makers almost half reported seeing wearable medical devices, 43% said they had encountered kettles coffee machines and other connected kitchen appliances. People are doing that all the time and remember that this isn't just in the business offices. This isn't our homes, right? 38. Percent said the same of IP enabled sports equipment. We see more and more of those. Have you seen the commercials for Peloton or this mirror thing? This mirror thing is really kind of cool. You hang it on the wall. It's kind of a mirror with a builtin display that lets you exercise with somebody remotely who is a coach, or maybe it's a prerecorded class.

    Some have had IP enabled sports equipment includes skipping ropes and weights. 34 present percent reported smart toys. 27% said they found smart vehicles on their network.

    I want to make sure you guys pay close attention to your networks or whether it's a home network or an office network. Make sure you segment the networks as I mentioned in my video this week. Hopefully, you got that training video on Wednesday. Keep an eye out for them. Make sure you click through. I also, if you don't want to watch the video, I also have the transcript there when you click through. So you can just read it pretty quickly. It's like a minute to two-minute read and a three-minute video. So enjoy it and be careful out there.

    Scan your networks and scan them frequently.

    What is going on with malware? There've been some major changes just over the last few months. That's what we're going to talk about right now. What do you need to watch out for? What should you be doing in your business as well as your home?

    We know that they're here. I have been a lot of attacks over the years. That's what we're trying to stop. Isn't it with our businesses, with our home users? That's why we buy antivirus software or why we have a firewall at the edge. Maybe we even upgraded your firewall. You got rid of that piece of junk that was provided by the internet service providers. Most of them are, frankly, pieces of junk. Maybe you're lucky and have a great internet service provider that is giving you really what you need. I have yet, by the way, to see any of those internet service providers out there that are really giving you what you need.

    So there is a lot to consider here when we're talking about preventing and preventing malware. What we have found is that malware attacks declined this year in the second quarter, but here's what's happening. Right? They are getting through more.

    Historically, we had things that have hit us that have been various types of malware. I remember when I first got nailed back in 91. I had a Unix server that I was running. As you probably know, I've been using Unix since the early eighties, 81, 82.

    I was using Unix, and I had my own Unix machines because I was helping to develop the protocols that later on became the internet about a decade or more later.

    The Unix world was on a rather open world. Was everybody on the internet was pretty friendly. Most people were involved in research, either government research or businesses doing research online, a lot of smart people, and we actually had some fun back in the day's puns and everything.

    We weren't that worried about security, unlike today, where security really is a top of mind thing for so many people. We weren't worried about who's going to do this to me or that to me.

    I had a Unix server that I was using, actually at a few of them that I was using for my business. Now, one of those servers was running emails, a program called Sendmail. That's still around today. It was the email package that was ruling the internet back at the time.  I got nailed with something called a worm. It was the Morris Worm. In fact, it got onto my computer through no act of my own.

    I didn't click on anything. It got onto my computer because it came through the internet. That was back in the days when we really didn't have much in the line of firewalls, so it just talked to my mail server. One of these days, we'll have to tell some stories about how we really trusted everybody back then.

    You could query to see if an email address was good. You could get onto the machine and say, Hey guy, I noticed that you had this problem, so I went in and fixed it for you, and here's what I did. Much, much different world back then.

    But that's how malware used to spread. It was something, and it was just kind of automated. It went out, and they just checked everybody's machine to checked firewalls to see what they were to see if they were open.

    We've been doing that for a very long time, haven't we? We have been nailed with it. That's what the viruses were and are still, where it gets onto your computer.

    Maybe you installed some software that you shouldn't have, and that software now takes over part of your computer. It affects other files. It might be something that's part of a Word macro or an Excel macro. And it now spreads through your sharing of that file and other people opening it.

    Worms are like what I got nailed with. Just start crawling around through the internet. So they run some software on your machine, and that looks for other machines, and today things have changed again. 

    They are changing pretty frequently out there. What we have seen so far here in 2020 is a decrease in malware detections. Now, just because there's been a decrease in malware detections, I don't want you to think that the threat has diminished because it hasn't. But the signature-based antivirus system are real problems.

    Now, what's a signature-based antivirus system. That's any antivirus software, like your McAfee's like your Norton's, the Symantec stuff, any antivirus software, that is working like your body's immune system.

    What happens with your body's immune system? You get a virus, and you're your body says, okay, what's going on here? It starts to multiply. Eventually, body figures it out. It develops antibodies for it. So the next time it sees that virus, you're likely to be pretty much immune from it. Your body's going to say, Whoa, that's a virus, and it goes in and kills it pretty darn quickly.

    That's the whole idea behind trying to stop the WuHan virus that is spreading out there. How do we stop it while we stop it by just developing antibodies? Right? That's herd immunity. We could also develop antibodies by an antivirus shot that is designed to stop that virus from spreading and prevents you from coming down with COVID-19 symptoms.

    In the computer world, it's much the same with most of the software signature-based antivirus software is exactly the same as the way your body's immune system has been working, in many, many ways.

    Here's what happens. Someone gets infected with a virus, and they reported to Symantec or Norton, or maybe the software reported itself. Usually, it's a third party that reports that, and they look at it, and they say, okay, so what does this virus look like? There is, in this program, the developers' names embedded, or the name of the hacker group is embedded in it. So we are going to now say any piece of software that it has this hacker group's name in it, we're going to ban. Right?  It recognizes it. So when the file comes onto your computer, your computer looks at it. It looks at the signatures. These are called signatures. To say, okay, how does it match? Or it doesn't match at all, and it might be through a string that's somewhere embedded in there. So it might be through a name. It might be through a number of other things. That's signature-based.

    The malware that was not detectable by signature-based antivirus systems jumped 12% in the second quarter of 2020. That is amazing. Amazing, absolutely amazing. Seven in 10 attacks that organizations encountered in the second quarter this year. In fact, involved malware designed to circumvent anti-virus signatures.

    Most cyber-attacks last year, and this is probably going to be true in 2020 as well as we get into the fourth quarter. But most cyberattacks in 2019 came about without malware. That means that there were hackers behind this.

    We're going to talk about that. What's going on some of the data also from CrowdStrike and what they have found CrowdStrike is an anti-malware anti-hacker company. They've got a lot of great people working for them as well what they have found.

    It's like the bad old days of hacking, and they're back on us right now.

    We see more and more malware-free attacks. We also see attacks are completely evade a signature-based pieces of antivirus software. If you have antivirus, you think you're protected. You're you really aren't.

    Well, we were just talking about malware attacks declining, but what's really happening is that they are becoming more and more evasive. That is a scary, scary world out there right now.

    These hackers are no longer just using regular old viruses to try and get into your systems. Time was, the good old days, there might be a macro virus that comes in on one of your Microsoft Office document. You might've gotten a virus from some software. You downloaded some free software from a warez site, but in reality, what is happening right now is the attackers are getting smarter.

    Malware is designed now to circumvent completely, antivirus signatures. So that signature software that you had that you bought a few years ago that came with your computer, that junkware that was installed, that came up and said, Hey, you need to, to pay for it now. You had your 30, 60, 90-day free trial. It just isn't gonna work anymore. The antivirus signature code that you bought and paid for and have been using just isn't going to work.

    So what do you do? That's a really good question. What is the right thing to do? Well, first of all, we've got to make sure that we're no longer just using antivirus signatures. We've gotta be looking at the behavior of the software. There are companies out there that use white lists in particular. I can think of PC MATIC, and I've got to get them on the show and talk a little bit about this. The way they do it is interesting. There are drawbacks to white lists as well.

    The way we do it is a little bit different because we're doing it the Cisco way. We have antivirus signatures. We also have behavioral and analytics. So if. It's an old piece of malware, and an antivirus signature is going to pick it up. Well, our advanced malware platforms are going to pick it up, right? That's what Cisco does, and some others do as well.

    But if it doesn't have a signature that's recognized, it watches its behavior, and depending on what happens with the behavior, it might do a few different things.

    So, for instance, this week, we got a call from a client because what had happened was there was they got an email that had something that was flagged as suspicious by our software. Immediately that software was uploaded so that Cisco Talos. Talos has been around a long time; they are true experts in cybersecurity. There's a couple of hundred people that sit there and examine it. So that our software automatically sent this thing to Talos to be examined.

    We called up the customer and said, Hey, there's something suspicious in your email box. We are heavily filtering all of their emails as well before it even gets into the box. They said, okay, what email was it? The subject matter was an invoice, a specific invoice. We said, look for this and this invoice, and they couldn't find it in their inbox.

    Our technician had a look and said, Oh, wait a minute here.

    Now what had happened is our software had automatically sent it to Talos for an examination. Telos will look at it and said, wait a minute. This is something that looks very malicious.

    So it automatically puts it into a kind of a lockbox and examines it there.

    It looked malicious, and so they retroactively pulled that piece of email mail out of that email box all automatically. Joe, our client, had no idea. We didn't realize it had happened either until after it had happened. But the idea is if it's in question, they can remove it.

    The way it works, as well with the anti-malware platform that we have is if your computer gets some of the software on it and it starts to do something malicious, we can roll your computer back. So the malicious activity might be that your computer is now starting to probe other computers or probe other server servers that are there in your network. So we noticed that attempted lateral spread and our software would automatically shut off the network port that the computer is attached to. It's just phenomenal what you're able to do nowadays.

    Now, one of the security vendors that are out there called WatchGuard analyzed some of the malware attacks that were going on, and it looked at 42,000 firebox appliances that were at customer locations worldwide.

    Now, part of the reason I like Cisco is it's using billions of data points every day to figure this out. Right.

    So WatchGuard has 42,000. But they found that the devices were blocking 28 million malware samples representing 410 unique attack signatures, which is an increase. But there are all kinds of tools that are available now on the dark web for as little as $50 that can be used in attacks. 

    When we delve into this a little bit more and look at some of the incident report data that came out of CrowdStrike, we see some very interesting things for the first time in CrowdStrike's research. They found that so-called malware-free attacks edged ahead of the malware based tool. 51 percent, in 2019, of attacks that were analyzed here by CrowdStrike, 51%, did not have malware.

    Now we've talked a little bit about this before I go into this in quite a bit of detail in my courses, in my more advanced cybersecurity stuff, but what's happening is the bad guys are using information that's being harvested from the dark web.

    You know how I'm always getting on your case about making sure you're using one password or last pass, right.  I think it's important. Well, part of the reason for that is you should use a different username. I don't like websites that make you use it an email address. Cause that's currently insecure. But you should use a different username at every website, and for sure, you should be using a different password and use one password is great at generating them so's Last Pass. Those are the only two that I recommend. If you're a business, you really should be using 1password.

    The bad guys are now taking the information they find from the dark web, which is copies of your email addresses, copies of your passwords. They are using them to log in as a regular user in your network. If you have VPNs, for instance, that your business people, your employees are using to connect, they will find the VPN through a scan, the VPN access point, or the remote desktop access that you might be providing the old terminal services from Microsoft. Then they will do a credential stuffing. They will try and use a username and password from your organization.

    We just had this last week happening, and this was a government subcontractor. They did some work for DOD prime contractors, and there were people who were trying to use credentials that were found on the dark web to get in. It's happening all of the time, but now they're getting on.

    They have these hands-on keyboard methods. They're trying to use usernames and passwords that they have found on the dark web, and they are using PowerShell. Now, PowerShell is a rip off that Microsoft made from the Unix world, and Microsoft, of course, messed it up pretty badly, and there are all kinds of major security problems with it. Microsoft Windows were not designed with PowerShell in mind.

    Nowadays, you have to use PowerShell to do certain things. Microsoft has finally figured out, Oh, wait a minute. Command-line interfaces are wonderful. Maybe we should use them more. So what happens is they use PowerShell.

    They start it up, and now they use it to exploit your network, exploit your systems because it's not a virus, it's not a program, very hard to spot and they'll hide files and directories, and they will use these tools like PowerShell and act just like a regular system administrator acts nowadays on a windows machine. System administrators on Windows machines, they're using PowerShell, aren't they? Now, most organizations don't have the technology to be able to differentiate between a legitimate user and a legitimate employee or contractor or an attacker who has stolen credentials.

    This is about a very, very big problem out there that's been seen by Cisco,  by CrowdStrike, Rapid seven is another one they're using. They're seeing hackers using valid credentials or reusing credentials from other breaches, i.e., credentials that are found on the dark web. So what do you do? How do you do this? That's our really big question right now.

    The bottom line, do not ever reuse passwords. If you're a home user, it's true. If you are a business, it's true. One of the things we do for our customers, and you can do for yourself is to go out to the dark web and search. Use tools, like Have I Been Pwned, very basic tools, and see if your users username slash email addresses are out on the dark web. Also, see if the password that's associated with that account out on the dark web is still in use by them.

    Just this week, we found another one of our customers where one of their primary users, one of the C-level people, Paul, was using the same email address and password for the business applications as he was in for one of these hacked accounts out on the dark web. So be very, very careful.

    Well, we've just been talking about some of the ways that the hackers are getting into us now, avoiding some of the software we've been using; these antivirus packages just don't work anymore. I'm going to talk about another problem. This is a massive windows bug.

    We're going to be getting into a couple of other things here. We'll talk about VPNs a little bit and how it's dying and going away. We've got another employee theft that's happened here, this time to Shopify. Microsoft, and what they've done with Azure. We'll talk a little bit about these cloud systems because they are problematic.

    Wanna cry is back and Love in the time of Zoom. Why we're in the midst of a dating revolution. So why don't we start with that one here - Zoom. You know how much I don't like Zoom for business. It is not considered secure or does not meet any of the standard security requirements. So that's a problem if you were to ask me.

    We are in the midst of a dating revolution. Do you remember that episode from Seinfeld where George is out doing speed dating, and they had these? What were they? 30 second or 60-second dates. I guess that's been the thing over the years, maybe a little longer than that.

    You spend two minutes, five minutes with someone and you're all there at the restaurant or whatever conference room.  It's like musical chairs. Every time you move one. Usually, it's the woman sitting there, and the men move around, and it could be the other way around, I suppose. There was a good way to meet a lot of people. If that's what you're trying to do, see if there might be any chemistry. Usually, they charge for them, and yeah.

    Today, well, things have gotten higher-tech. They come about here in Zoom rooms as well. I mentioned earlier today some of the things that we're doing from a business standpoint on Zoom. Many people are now having business meetings obviously, or hopefully not on Zoom, but in the online world.

    But right now, what we're seeing is love and marriage. How people are connecting. It used to be, of course, accidental. Then some of us might go to the church we belong to and look for a companion or a mate. There are a lot of ways that things have changed, and they changed a lot, really in the 18th century with the industrial revolution.

    Now we're kind of back to the isolation days. Well, so what do we do now?  I don't know if we'll ever really get back to normal. People have found that they can do business from home. They can work from home. Now they found that they can date from home as well.

    Already, we're seeing nearly 40% of heterosexual couples reporting that they have met online. Most of the time, that's being through a social media site like Facebook, or maybe some of the others that are out there. Same-sex couples are even a higher percentage here, more than 40% of heterosexuals that are meeting online.

    Of course,  there is also the casual encounters that have been going on.  I can't even believe it, but Dr. Fauci even mentioned that, right?  Oh man, we're not getting into that right now.

    But this type of online interaction is absolutely surging during the time here of the Wuhan virus. Bars are closed. Restaurants are mostly closed churches can't meet you. Can't sing hymns, depending on where you are. They might only let a few people in. I know there's one state where you can go to a bar, but only one person can be in the congregation of a church. I, I just don't understand some of that stuff, obviously.

    So what do you do right now? We see a massive drop in the number of Americans that are married by the time they turn 30. Only about half of them are married by the time they turn 30. Fertility rates have plummeted to 1.7, meaning the average woman will give birth to 1.7 children over her lifetime, which means if that woman can be considered to be part of a couple. That is negative growth in our population. Something that some people have been trying to achieve for a very, very long time, but it is well, well below the natural rate of replacement, which is as I recall, what about 2.1 or 2.2? So that's pretty dramatic, and it is just continuing to go down more.

    Men aged 30 to 34 were living with their parents than with the romantic partner, and that's before the Wu Han virus pushed even more of a back into our homes as we've lost jobs and opportunities that are out there. It's just not very, very good, but the future isn't all of that bleak.

    I wonder, frankly, when we're talking about general social social media. So things like Facebook and messages and stuff, how much of what we see and we feel we have a connection with other people. How much of what's real. We already know much of what we see. Isn't it real. Some of these social media influencers you've admitted to taking as many as a thousand pictures before they found one that's worthy of posting where all the makeup was. Right. The pose was right. The hair was right. The background was right. The lighting was right. It leads to a false sense of, Oh, keeping up with the Joneses. If you will. There's an older expression. Where people see this, and they think that's the way their life is supposed to be. It's absolutely not.

    So how about where where we're trying to do one on one stuff. I think we all can remember going on dates and being a little braggadocious. Maybe inflating things just to ever so slightly. When we went out with somebody and then over time, we got to know them, and then we started to loosen up. I'm in a mastermind group, and I also have seen that in the mastermind group that as we got to know each other. We kind of relaxed, but we know each other's businesses now, and we can give each other good advice and a good kick in the pants when necessary.

    So I don't know. The future's not bleak. I think. Yeah. It might take a while for people to get to know each other when we're talking about meeting online, doing little Zoom meetings, or meetups online. But the whole courtship thing has really changed the whole structure of what it is. It is just absolutely amazing, but I think we are still going to be looking for those relationships. We're so going to be trying to find them online, and I think it might work, and I don't know. Maybe a breakup is even easier in the online world or maybe the whole fallacy behind the online world where people are literally making stuff up if the fallacy is going to make it even worse when it comes to breakups. I really don't know.

    I'm looking at an article here from Debora Spar. She's a professor of business administration at Harvard business school, and she's been very focused on issues of sex and technology and what's been happening with the technological change. She has a new book out called workmate. Marry Love, how machines shape our human destiny, which is kind of an interesting book. I think the romantic times are going to continue, but we're going to continue to look online for ways of meeting and doing stuff with people. So there you go. Zoom is not just for little family gatherings, but it's also for romance. I think that's kind of cool.

    Hey, if you like to listen to the radio, when you're driving around in your truck or your car, one of the things that I do, and here's a little tip for, in case you didn't know you do it is I have Bluetooth in all of my cars.

    Nowadays, there's Android play. For Android phones, not all of them, just some of the newer ones, and Apple also play for the newer Apple iPhones. What that allows you to do is run the app near a phone. And once that app is up and running, it will come out through your car stereo.

    Now, many of you guys, of course, you're the best and brightest. So you probably know how to do that already. I love the way car play works on the Apple side, Android. It works pretty well too, but the main concept behind it is to keep the interface simple, to keep the number of distractions down.

    We are right now under attack. This is the windows vulnerability that I mentioned live on the air here a couple of weeks ago, it's not patched up by most people, and it's really, really bad.

    Well, this is a big problem right now. This particular vulnerability is called a zero log on vulnerability.  What that means is your computer is vulnerable to attack without the bad guy actually having to log on to the computer. Very, very, very. Bad. Okay.

    Now, this is an escalation of the privilege problem. Microsoft has come out and issued some patches. Apparently, it's not going to be fully fixed for a while, from everything I was reading.

    This is crazy because what's happening is they are using domain controllers and remote procedure call login servers to get in. So if you're just running a regular windows machine in your house, obviously you want to keep it up to date.

    But this particular exploit is against these servers that are out there. The servers specifically have exposed domain controllers, and remote procedure calls, also called RPC login servers.

    Why do you use those? Well, most businesses use those types of servers to allow people to log in remotely. Who logs in remotely? Well, its employees, right? We're there in our homes, and we're trying to get into the office. So we use a domain controller. We are sending RPC calls here for the login servers. You may not know what's actually going on behind the scenes, but that's what it actually is. Now there's a search that you can do on a line. There's a couple of different searches to find. These exposed servers, very, very big binary edge.io. There's a couple of others also let you know about it, but okay. They show more than 33,000 3 million networks that are exposing domain controllers. This is absolutely crazy here.

    If a single network has both resources exposed, and the combination can leave the network-wide open with no other requirements. Okay. It's very, very, very, very bad. I don't want to go much more into this. It is absolutely catastrophic. If you are a person who's responsible for the, IT resources within a business. You have to take care of this. Right, right, right away.

    The cybersecurity arm of the Department of Homeland security mandated all agencies will over the weekend. They put the mandate out on Friday, and then they had to be done by Monday. They had to apply the patch by Monday night or remove the controllers from the internet. Take that as a little bit of a hint that maybe it's something you should do too.

    So if you are a business owner, make sure you check with your managed security services provider and or your employees who are responsible for it. Okay. Cause it's very, very big. It's the year most severe Windows bug that we've seen this year, and who knows, maybe more on the way. So I'm not going to say it is the best or the worst.

    Now let's move on to another subject here that I think is worthy of the news here, and that is that VPNs are a risk.

    Now, one of the legitimate reasons to use a VPN would be so you don't expose those services on your server. In other words, they're not exposed to the whole internet. If they're not exposed to the internet, some guy or gal somewhere else in the world can't get to them. So how do you let your employees get to those services and keep them locked down for everybody else?

    You could do it by having your firewall only allow certain internet addresses to get through to those services. That's what I would advise as a quick stop-gap for you. Ensure that only the home computers that are supposed to be able to get at it can get at it.

    But remember too, that it is just a quick stop-gap, because those home computers could be infected and could be used as a launching point to come after your services. So you're letting that home computer through your firewall to get to the RPC services, the login services they need. If that computer is infected, that home computer, it could be used now to attack you. So it's just a stop-gap.

    Another way to do it is to use a VPN. Now, you know what I've been saying about VPNs for the longest time, where VPNs are, frankly, a little on the hazardous side, particularly for your security. There's a difference between privacy and security. At least if you ask me.

    The biggest difference is privacy means that advertisers don't know where you go, which means your internet service provider doesn't know where you go. That's privacy.

    Security is where you don't want that information sold, but even more so, you don't want to have your bank account information stolen or other things that really need to be secured. Okay.

    So that's the big difference here. If you get a VPN for your business so that people can connect to these log-in services, or maybe connect to your file server, that's a bit of a problem as well, because remember the VPN can be used both ways.

    It's like that saying, I love this old saying, but tracers work both ways. Right?

    You use tracer rounds when you're shooting at the enemy so that you can see where the bullets are going.  By the way, that means the enemy can see where the bullets are coming from. The same thing's true with VPNs. You put a VPN in place so that home users can connect to those login services or maybe your SMB CIFS here, your file servers, right, the file shares.  You open it up the VPN so they can get through, but now potentially, the bad guys can use it to get through as well. So it is a big problem.

    Because of that, VPNs need to be tracked very closely in your firewalls.

    We run all the VPNs that we have for clients or that are requiring security. We run them all through not just a basic firewall but one that reassembles everything. Examined all files that are being downloaded, et cetera, et cetera. Okay. That's what we do now.

    There is a new technique in place right now that is gaining a lot of momentum, and frankly, within the next few years, all businesses should be using this. We're doing this already, and it's something called Zerotrust. Zerotrust means in the case of a VPN. Okay, great. There's a VPN in place, but I don't trust that home computer to have full access to my network. In fact, not only mine, do I not trust it to have full access to the network, but I don't even want to have full access to this particular server.

    I only want it to have web access, let's say. Even then, I want to go to the next level. I want to make sure that that home computer is not being used to grab my client list. That an employee is about to take with them as they walk out the door to my competitor.

    That's where you start getting into Zero trust and what that's all about. We're going to talk a little bit about that. What Gartner's predicting is going to happen here by 2023 and how you can use it and how you shouldn't be using it right now, in fact, so stick around because we'll be right back. 

    So we know a little bit about VPNs and what they are. So what's Zero trust and how's a Zero trust network run. What are we looking for here shortly? More than half of businesses will be Zero trust.

    I've started to do some three-minute training. So the first one went out on Wednesday, and I was really surprised just how much work it takes to make a three-minute training. But we did it, and we got it accomplished. We're going to try and have a couple of those a week, plus the weekend newsletter, which is, of course, a fair amount of work, but we're doing it for you. Hopefully, you got a lot out of it.

    I got a crazy number of responses to the first video. So thank you. Thank you. Thank you for respondeing. Hopefully, I got back to you in a reasonable amount of time here, and we're able to help you out a little bit. Anyhow, if you missed it, go look back on Wednesday this week. That's when I put out the first one. So it should have been in your email box Wednesday. As usual, it's from [email protected]. So if you're not getting them and you think you should be double-check, make sure I am on your contact list or whitelist me somehow so that you get those. They're important. I'm going to be doing more of those a week just to kind of a light touch. Let you guys know what's up.

    So VPNs have been around now for more than a couple of decades. They've been fantastic. They've saved a lot of businesses a lot of money. Now course, they tend to be kind of dangerous, particularly these free VPNs and the commercial ones that you're using, to somehow try and make yourself more secure. I just shake my head every time I hear these misleading ads. They are lying to you. It's really not going to protect you that much, frankly, if at all. It gives a little bit of privacy in certain situations, but not in others. I had a great call with Doug, in fact, this week. And he was having some problems. He is a small business guy been in business for a long time, sold his business, and now he's almost 80. I think he said he was 78. He's kind of back in business, again, keeping himself busy and occupied. He was wondering and worried about trying to keep some of this stuff secure. So we went through it a little bit with him.

    He uses macs, so it is definitely easier to keep secure. When he's on the road, he has one of these little devices he takes with him that allows him to connect to the internet from Verizon. One that directs you directly connects you to the internet, which is dangerous.  Another one that provides you with what's called Nat or network address translation that's a little bit safer. So he's going to send me the model number in particulars of what he's using so that I can help him out a little bit.

    By doing that, he's no longer tying into the wifi at the airport or on the airplane or at the coffee shop, wherever he's going. He's got his daughter doing that too, which I think is a very good idea. I know a lot of people, as well that does it. I do it as well. I have one of those little devices. I just replaced the battery in mine because it started swelling. It's a lithium-ion battery. Some of them, when they start to swell, you've got to replace because what can happen is when they swell, they will short out and can start a fire. So be very careful about that.

    So he's smart enough to know that you don't want to use public wi-fi. He effectively brings his own little wifi device with him, which is, again, a great idea.

    Some people use VPNs when they are out there on the road and connecting back into the main office or their homes. I have that as well, and that lets me get directly in.

    Most of the time now, what we've been doing for our office and our customers is putting together zero trust networks. These are far more secure than anything else we have out there right now, as far as firewalls and everything else goes.  The idea is, just like its name implies, that we're looking at everything. We're no longer just trying to do what's called a perimeter security approach where we have a firewall at the perimeter.

    Now we are trying to protect ourselves and our businesses from any kind of attack, including insider attacks, including the lateral movement that I've talked about so many times before. Where a bad guy gets a foothold inside of a network, and that bad guy immediately tries to start spreading things. Very dangerous. Very, very dangerous. There's several other flaws too. Perimeter security just doesn't do a good job of counting for any third parties, any vendors you might be working with contractors; all of your supply chain partners. If attackers steal somebody's VPN credentials, now the attacker can get into the network and roam freely. Like I've talked about many times.

    Many of us use the same username and password on pretty much every device out there.  That's a problem because when it gets onto the dark web, now the bad guys have it. Plus, the VPNs over time have become a lot more complex and very difficult to manage.

    It's rare. I say rare, but I've never seen an exception. In other words, it seems that these businesses have misconfigured VPNs. It seems to be a pandemic out there, frankly—a lot of pain around VPNs.

    So this is going to change it all. You are. We're going to have different equipment internally. Your devices are not gonna be able to connect directly.

    So the way we have it set up all of the devices on a network, instead of speaking directly with each other, have to go through at least a firewall. The firewall watches what they're trying to do even inside the network. So it's no longer just out there at the perimeter. Frankly, what we've been doing with VPNs, it's just clunky. It's outdated. Frankly, kind of dangerous. So keep all of that in mind.

    All right, if you need a little help, if you have some questions, I am more than glad to get on the phone with you guys and chat a little bit and help steer you in the right direction. You can just email me M E @craigpeterson.com, and I'd be more than glad to get back to you. So keep all of that in mind. VPN is dying. Zero trust is what's coming down the road.

    Now, I just mentioned the problems of potential internal threats, and that can include bad guys that are in your network, spreading laterally, as I just mentioned, but it can also mean that your employees are the problem.

    I've seen that before. I had it happen to me, where I had an employee who took all of my customer records and took my customers with him. I could not believe it. I still can't believe it to this day. What he did, I don't understand it. What does he think he's doing? He may have built up a relationship with my customers. I don't think he brought a single customer in. In fact, he built up a relationship with my customers, and then he figured they're his customers now because he has a relationship with them.

    So forget it, Craig. They're his customers. It is just absolutely amazing.

    Shopify, which many of you have heard of before and many people are using. Has found that two of their support team employees were involved in a scheme to steal customer transaction records from specific merchants. It affected apparently fewer than 200 merchants, but there's an example of where Zero trust can really come into play. Do your sales guys have access to information they shouldn't have?

    How about some of your support people? We have to make sure we're monitoring where they're going and what people are doing within our networks. Okay.

    We're going to talk about Microsoft and the Azure store and president Trump and wanna cry. You remember that really bad piece of malware? It's back.

    I sent out a three-minute training, the first three-minute training. I'm going to be doing more and more of them here as time goes on. This training got just a plethora of responses from people. I'm so happy I could help out a lot of people this week, including a bunch of very small businesses, and that's what I love to do. That's why I do this, right. Help you guys out a little bit here.

    Now, obviously, I have customers, big paying customers, usually, companies that are regulated and actually need cybersecurity.

    But for the rest of you, I still will help you just as much as I can. Obviously, there are some things you need to do, and that's what this is all about.

    Well, you know already about the Apple app store.  I've talked about it many times. Do you know about the Google play store? Both of those are stores that you go to buy or download little applications that you can use on your smart devices. They're both great little stores. Apple tends to do a better job when it comes to watching for security problems than Google does.

    Both of them tend to take about a 30% chunk of any money that you pay. Then of 75% or 70%, I should say to the developer. Well, Microsoft has a store, as well. You might have heard of Azure. That's a service that Microsoft has, and it is an online service. It's a cloud service. It lets you run Microsoft Windows in the cloud, in a data center.

    That's managed by Microsoft, run by Microsoft in most cases.  Also, by the way, it'll let you run various types of Linux, and that was a bit of a surprise, but anyhow. That's the Microsoft Azure story. Then we also have stores that are over on Amazon, and that's called AWS Amazon web services. There is a lot of others too.

    We tend to use some of the IBM stores, including the IBM mainframe stuff, which has just been amazing to us, just how good those things are. The IBM mainframes, how fast they are, and how inexpensive they are for computing stuff. It's just amazing. Anyhow. Microsoft and IBM and Amazon, and anybody that has one of these cloud services also have a store.

    And it's much like the stores that you would expect to find for your smartphone. But in the stores where we're talking about here, Azure, or these cloud services, they actually are selling and leasing or renting fully configured machines. So you can go on, you can say, Hey, I want a new Ubuntu version, blah, blah, blah, or red hat enterprise Linux, which is what we tend to use, version this and such, and maybe you want to also use containerized stuff. And so they have all of these things pre-configured you can say, Hey, I want a database engine and Tada, poof, there is a database engine for you. It can be either poorly maintained by them. And you have no idea what it is. It acts like, mysequel, or whatever database you might want it to act like. Or maybe it really is one. Maybe it's your own version of that. Those types of apps are available in these cloud services just to use those terms loosely.

    Well, earlier this year, it turns out according to Dan Goodman, who wrote an article over at ARS Technica up on my site, but members of the Microsoft threat intelligence center suspended 18 Azure active directory applications because they determined they're part of this huge command and control network that was being run out of China.

    Now we can also talk here about commanding control because your computer might even be part of this. So if you have a computer and that computer gets hacked, one of the reasons they hack it is to use it as part of a command and control network.

    Now here's the idea behind command and control. They're not going to ransom your data. They're not going to try and do something nasty with it. In fact, these command and control guys don't really care that your computer can do anything other than connect to the internet.

    So one of the things they'll do with command and control is they will do what's called a denial of service attack against somebody. So there's some company they don't like, or maybe they're ransoming. This company says, Hey, listen, we'll shut down your website unless you pay us a million dollars.

    What they'll do is he'll use a thousand, 10,000, however many computers they have in their command and control network. They'll use them now to send off fake website requests to that company. Now that company's servers just get hammered and nowadays we see in the order of tens or even hundreds of thousands of requests. Per second coming into some of these data centers and that there are services out there to protect against. Those types of denial of service attacks. Okay.

    But here's where things really start getting interesting. That is, they all also use command and control systems to send out emails, to do phishing, even to research them. So command and control just as it sounds is they have control of your computer, right? They send commands to execute.

    So, in this case, what we're finding is that Microsoft had these apps that were in there as your active directory, their cloud service, that were part of this commanding control network. 18 different applications. Again, we're not just, we're not talking about an app, like an app that would be in the windows phone. If you are sad enough to have bought one and no longer getting support. So it is a difference. It's a pretty big difference.

    These are the types of applications that are used by businesses, database applications, web server applications. All right. It's not just the fortune 500 companies that are doing this anymore. We're talking about the smaller guys who really don't have the resources to check.

    You know, between the two of us, most of these fortune 500 companies aren't doing what they should be doing either. Hence all of the hacks that we've been seeing. So they had the cloud hook, hosted applications.

    This is a hacking group that Microsoft is calling gadolinium. They had also been storing stolen data in a Microsoft one drive account and used that account to execute various parts of their campaign. Now, Microsoft, Amazon, all these other cloud providers have been touting how secure it is, how fast these cloud services are. They're just so much cheaper. Oh, this scale that comes from renting computer resources. I remember describing what they were hoping for a way back when with cloud services, that it would be like the power company who cares where the electricity comes from as long as you just flick the switch and the light comes on.

    Believe me, and it is no longer like that. The hackers have realized now the benefits of hacking the cloud surfaces and, in this case, using them to share their stolen data to store it, et cetera, et cetera. And now there's so many free trial services and one-time payment accounts. Hackers have been able to quickly get these different things up and running.

    They, as I mentioned before, can even buy their own materials, their software to do the hacking, to do the phishing, to do the ransomware, to sell the decryption stuff. They even have banks that'll handle the transactions for them to in converting Bitcoin into the US or whatever dollars they want to. Very very big deal.

    Earlier in the show, I've talked about this some of these tools are in use right now in particularly in Windows PowerShell, that are not well secured and are legitimately used by the system. Administrators have become a huge, huge tool for the bad guys to use. They're so widely used for legitimate tasks. It's very hard to detect the reuse of these illegal tasks.

    This group, this gadolinium group, has recently started using a modified version of PowerShell empire post-exploitation framework. It's open-source. Can you believe this stuff that's going on? So it's very scary. Agility and scale, frankly, are working both ways here against us, and for us, I am very concerned about some of the stuff that's going to be happening.

    If we've got some of these bad guys that are out there, right? Some of these terrorist groups, domestic terrorist groups that are burning our cities right now and shooting people, shooting cops, et cetera, that these terrorists are going to be using—these same techniques shortly here in the US. You probably already are. We already know it is using them to finance and fund their operations. Very, very scary stuff.

    So one more thing real quick before we go. That is Wanna Cry. Very, very big deal. SonicWall is reporting a 109% increase in ransomware in the US during the first half of 2020. Keep your eyes out. This is very, very inexpensive for the bad guys to do. Get ransomware on your systems. They have high rates of return on it. There's hardly any risk for them. It's even outsourced. We've talked about that before. It is a preferred method of attack for cybercriminals. So be very, very careful out there.

    Get the right kind of security. I was talking with a couple of companies this week. We're going to be putting in place some of the prosumer Cisco stuff to help out a very small company and some of the commercial stuff that you need to have if you are a regulated industry. So we'll be doing some of that this week, too.

    You've been listening to Craig Peterson. Have a great week, and make sure you visit me online. [email protected].

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 19 min
  • AS HEARD ON NH Today WGIR-AM 610: Printer Technology, Identifying Fraudulent Ballots and Social Engineering

    Welcome,

    It's Friday, everybody. Craig Peterson here. I was on with Jeff Chidester on NH Today. We discussed the Fraudulent Ballots and Printing Technology and how they can tell not only that it was printed. Then we got into social media and social engineering. Here we go with Jeff.

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] That it prints on everything. And that grid has all that information. The idea is we don't want people using color copiers or printers to print money, which is why the secret service got involved with this. But it's gotten even more intense now with these new printers and new printer technology.

    Good morning, everybody.

    This is a kind of an unusual appearance, but this is an unusual week, right? I was on this morning on the New Hampshire today with Mr. Jeff Chidester. He was sitting in this morning. He and I go way back. He's just a great guy. I love him, but we got into some, I think, great topics here on how we can detect certain types of fraud when it comes to voting and also a deep dive into social engineering.

    These sites are showing us stuff they think that we want to see and, uh, even search engine. So how do you get around those problems? This was a great little hit this morning. I'll be back, of course, tomorrow. But it is going to be a repeat show, but I think you're going to enjoy it anyway. It's one that I picked personally,

    Jeff Chidester: [00:01:11] Welcome back eight 38 in the morning. Of course, we've moved this gentleman around throughout the week because of the election, but we also want to make sure we get to hear from him. Of course, we're talking about Craig Peterson. You can find out more about Craig by going to Craig peterson.com.

    Craigpeterson.com.

    Craig, I haven't talked to you in a long time. How you been, bud.

    It has been awhile. Hey, I'm doing really great. It's great to hear you on the radio again,

    It's fun. We had a really fun show today. It's always a pleasure when I get to join you. I think keeping with the theme when we think about the tech aspect of voting, one of the other things that have come out to light, is something that you've been talking about is the ability to go ahead and now print out these ballots.

    I mean, some States actually allowed it, but the continuation of being able to do that also leads to potentially more fraud.

    Craig Peterson: [00:01:54] Absolutely true. We have rumors out there. I know, for instance, in one of the polling places here in New Hampshire, they actually ran in and made copies of some of the same-day voter registrations because they ran out of the cards. There were so many people voting the same day. There are rumors that there's been some ballot stuffing going on. Apparently, in some areas, they have taken the real ballot they got their hands on. They ran it through a copier, printed them out and filled them in, and showing up with briefcases full of these things.

    And many people might not be aware of it. But, you probably are, though, Jeff. Our color printers for, well, more than a decade. Now, when you print a page, any page at all that printer embeds on it, the serial number of the printer that made that print, as well as the date and time of that print. Were you aware of

    Jeff Chidester: [00:02:54] that?

    No, it wasn't.

    Is it how, where is it? Where do you see that? How would you see that?

    Craig Peterson: [00:03:01] The secret service apparently has some kind of secret agreements with all of these printer manufacturers, but it's not just in the US, it's worldwide, but if you have a slightly older printer, what you can look for is a series of little yellow dots, and they are scattered all over the page. And you can take a page that you print out and go ahead and take a picture of a zoom into the upper left-hand corner and take a picture, then put it on your computer and zoom in even more because these things are just one pixel and it has a grid that it prints on everything.

    And that grid has all that information. The idea is we don't want people using color copiers or printers to print money, which is why the secret service got involved with this. But it's gotten even more intense now with these new printers and new printer technology, and you'll probably familiar as well—Jeff, with the technology where you can embed a message in something else.

    So, for instance, you might send a picture of something to supposedly your friend, and it's intercepted by the Russians, and the Russians look out and say, Oh, it's just a picture. But embedded inside of that is a secret message. That sort of thing could happen pretty commonly. That is exactly what our printers are doing right now. They're using dithering now to create moderate watermarks. And it isn't just color printers anymore. It's even black and white printers.

    So if they really want to get into this, they can tell that a ballot has been faked and which printer printed it, and the date and time of the printing itself.

    Jeff Chidester: [00:04:49] Once again, we're talking to Craig Peterson.

    Of course, you can find out more by going toCraigpeterson.com. Craigpeterson.com. I'll throw it up on the Facebook page as well. And tech talk show as well. It can be heard on many stations, actually. And his podcast. You just over the place.

    You know, Craig, I never knew that. That's actually fascinating.

    It would be interesting to see how people looked into that as they went through that process, of being able to deduce that number and that code. That's just once again, I just did not know that.

    One of the things I wanted to talk to you about, Craig too, is when we think about, I haven't had a chance to talk to you in so long, you look at all these tech issues, and you look at how the tech giants have really been so much focused.

    We found out yesterday that the tech giants have once again basically shut down President Trump's accounts, and they're not letting those posts up. Where's that going to go? I mean, I understand that the balance they want to have, but once again, they are, they're not supposed to be technically, journalists.

    it's up to the people to decide whether they believe the information or not. I know that's a little bit difficult. We have to trust people. Where's this going to go, as far as a tech understanding, as far as the federal government addressing this issue.

    Craig Peterson: [00:05:53] I remember way back in 83 when I first got really involved in the internet, and I was so excited because we had democratization of information, unfiltered and of course now what you're referring to today is the fact that these major social media platforms are filtering what we see.

    That started those five, maybe it was eight years ago, where on Facebook you could follow somebody, and you would see on your feed everything that person posted. Facebook decided, no, we're not going to do that. We are going to decide what Jeff Chidester might be most interested in seeing.

    Some major celebrities dropped right off. Basically, what was happening is Facebook said, "Hey, you company X or Mr. Celebrity B" If you want people to see the posts, you know, the people that said they liked your page and they want to follow you. Do you want those people to see your posts? You have to pay us extra.

    That's when this whole controversy started, right? And where you're going, is, are they a publisher or are they more like a public forum? They're acting a lot like a publisher where I see this going. People are very upset about this on multiple levels right now because the left and the right have had this type of censorship applied to them. I am a free and open. Internet. It's difficult from a technology standpoint to do the type of censoring that they're doing. So they've got more people involved now they've got 200% more people censoring than computers. Ultimately I think this has been a terrible thing for democracy mean I'm gonna boil it right down to that.

    It's a feedback loop, right? So anything you're interested in, you'll see. And anything that disagrees with what the computer thinks you might be interested in. You'll never see it.

    Jeff Chidester: [00:07:44] Well, absolutely. Once again, we're talking to Craig Peterson. Of course, you can find out more about Craig by going to craigpeterson.com craigpeterson.com.

    I happen to think that their algorithms actually suck in a little way because I keep getting dancing cat videos. I hate cats. So maybe that's why they're going after me.

    Craig Peterson: [00:07:59] There is good news here, though. And here's what it is. There are some suggestions that that algorithm, that program, that computer, that decides what it's going to show you, that they open up, what's called an API or an application programming interface to it.

    So that third parties could put out, Hey, listen, you don't like the way Facebook monitors and controls your feed. We are the Republican party, and you can use ours, and we'll show you Republican stuff you're interested in or the Democrat party or whatever it might be. That might be even worse to a degree, but I'm sure there will be organizations that if that does happen and it looks like it might, where they open up that computer engine, there will be organizations that say, Hey, we're going to try and be fair and balanced, and we'll give you a little bit of both.

    Jeff Chidester: [00:08:52] It's a good point too when people have to be very mindful that what they're getting back for data is not the complete picture. So you have to be pretty aggressive, especially if you're going to use these tools to inform yourself, be aggressive with your search patterns, and your mindset to make sure you're getting the stories from every particular angle.

    That means that my searching has to be searched differently on several different machines because I found out eventually one gets polluted. Even though I'm trying to get pushed past and looking at both sides,

    Craig, before I let you go once again, Craig Peterson, you can find out more by going to craigpeterson.com. You can catch him on tech talk as well. Any last thoughts?

    Craig Peterson: [00:09:25] Well, of course, that is every Saturday, 1130.

    Yes, use two other search engines. Don't use Google for almost anything anymore, unless it's a really tough, difficult search. I have found much better results lately with duckduckgo.com.

    I love that. It's so much better, or maybe even quant Q W A N T, which is out of France. And that'll give you much better results when you're doing the searching.

    if you're like me and you really have to dig down deep, because remember I do the cybersecurity, then I use something called Devonthink, and it's paid software, but it can crawl sites, and it uses multiple search engines and Boolean algebra, even to allow me to really dig into a topic.

    So there you go. I think that's the way for most people to go.

    Jeff Chidester: [00:10:16] Perfect. 1130 tech talk Saturday, of course, Craig Peterson online Craig peterson.com. Craig has a great weekend.

    Justin McIssac: [00:10:21] I don't know if you're wearing shorts, but if you are keep it clean, man.

    Jeff Chidester: [00:10:25] Alright,

    Have a good weekend

    Craig Peterson: [00:10:27] I had a really fun little appearance this week.

    I did a presentation for Ingram micro. They are like the largest distributor, I think, in the world. They're just massive. We provide master managed security services for some of their managed services providers, break-fix shops, VARs, et cetera. If you're interested in how you can sell cybersecurity and make some bucks off of it but not have to spend quite literally up to $5 million just to get launched. Check out Sellcybersecurity dot com sellcybersecurity.com.

    I have a little form there and a video of the session. All it is going to do is give me your email, address, and name, and then I'll email you. Not any sort of a funnel or anything else. So check it out, sellcybersecurity.com.

    Have a great weekend, everybody.

    We'll be back next week. Take care. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • AS HEARD ON NH Today WGIR-AM 610: Printer Technology, Identifying Fraudulent Ballots and Social Engineering

    Welcome,

    It's Friday, everybody. Craig Peterson here. I was on with Jeff Chidester on NH Today. We discussed the Fraudulent Ballots and Printing Technology and how they can tell not only that it was printed. Then we got into social media and social engineering.   Here we go with Jeff. 

    These and more tech tips, news, and updates visit.

    - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] That it prints on everything. And that grid has all that information. The idea is we don't want people using color copiers or printers to print money, which is why the secret service got involved with this. But it's gotten even more intense now with these new printers and new printer technology. 

    Good morning, everybody.

    This is a kind of an unusual appearance, but this is an unusual week, right? I was on this morning on the New Hampshire today with Mr. Jeff Chidester. He was sitting in this morning. He and I go way back. He's just a great guy. I love him, but we got into some, I think, great topics here on how we can detect certain types of fraud when it comes to voting and also a deep dive into social engineering.

     These sites are showing us stuff they think that we want to see and, uh, even search engine. So how do you get around those problems? This was a great little hit this morning. I'll be back, of course, tomorrow. But it is going to be a repeat show, but I think you're going to enjoy it anyway. It's one that I picked personally, 

    Jeff Chidester: [00:01:11] Welcome back eight 38 in the morning. Of course, we've moved this gentleman around throughout the week because of the election, but we also want to make sure we get to hear from him. Of course, we're talking about Craig Peterson. You can find out more about Craig by going to Craig peterson.com.

    Craigpeterson.com. 

    Craig, I haven't talked to you in a long time. How you been, bud.

    It has been awhile. Hey, I'm doing really great. It's great to hear you on the radio again, 

    It's fun. We had a really fun show today. It's always a pleasure when I get to join you. I think keeping with the theme when we think about the tech aspect of voting, one of the other things that have come out to light, is something that you've been talking about is the ability to go ahead and now print out these ballots.

    I mean, some States actually allowed it, but the continuation of being able to do that also leads to potentially more fraud. 

    Craig Peterson: [00:01:54] Absolutely true. We have rumors out there. I know, for instance, in one of the polling places here in New Hampshire, they actually ran in and made copies of some of the same-day voter registrations because they ran out of the cards. There were so many people voting the same day. There are rumors that there's been some ballot stuffing going on. Apparently, in some areas, they have taken the real ballot they got their hands on. They ran it through a copier, printed them out and filled them in, and showing up with briefcases full of these things.

    And many people might not be aware of it. But, you probably are, though, Jeff. Our color printers for, well, more than a decade. Now, when you print a page, any page at all that printer embeds on it, the serial number of the printer that made that print, as well as the date and time of that print. Were you aware of 

    Jeff Chidester: [00:02:54] that?

    No, it wasn't.

    Is it how, where is it? Where do you see that? How would you see that? 

    Craig Peterson: [00:03:01] The secret service apparently has some kind of secret agreements with all of these printer manufacturers, but it's not just in the US, it's worldwide, but if you have a slightly older printer, what you can look for is a series of little yellow dots, and they are scattered all over the page. And you can take a page that you print out and go ahead and take a picture of a zoom into the upper left-hand corner and take a picture, then put it on your computer and zoom in even more because these things are just one pixel and it has a grid that it prints on everything.

    And that grid has all that information. The idea is we don't want people using color copiers or printers to print money, which is why the secret service got involved with this. But it's gotten even more intense now with these new printers and new printer technology, and you'll probably familiar as well—Jeff, with the technology where you can embed a message in something else. 

    So, for instance, you might send a picture of something to supposedly your friend, and it's intercepted by the Russians, and the Russians look out and say, Oh, it's just a picture. But embedded inside of that is a secret message. That sort of thing could happen pretty commonly. That is exactly what our printers are doing right now. They're using dithering now to create moderate watermarks. And it isn't just color printers anymore. It's even black and white printers. 

    So if they really want to get into this, they can tell that a ballot has been faked and which printer printed it, and the date and time of the printing itself. 

    Jeff Chidester: [00:04:49] Once again, we're talking to Craig Peterson.

    Of course, you can find out more by going toCraigpeterson.com. Craigpeterson.com. I'll throw it up on the Facebook page as well. And tech talk show as well. It can be heard on many stations, actually. And his podcast. You just over the place. 

    You know, Craig, I never knew that. That's actually fascinating.

    It would be interesting to see how people looked into that as they went through that process, of being able to deduce that number and that code. That's just once again, I just did not know that. 

    One of the things I wanted to talk to you about, Craig too, is when we think about, I haven't had a chance to talk to you in so long, you look at all these tech issues, and you look at how the tech giants have really been so much focused.

    We found out yesterday that the tech giants have once again basically shut down President Trump's accounts, and they're not letting those posts up. Where's that going to go? I mean, I understand that the balance they want to have, but once again, they are, they're not supposed to be technically, journalists.

    it's up to the people to decide whether they believe the information or not. I know that's a little bit difficult. We have to trust people. Where's this going to go, as far as a tech understanding, as far as the federal government addressing this issue. 

    Craig Peterson: [00:05:53] I remember way back in 83 when I first got really involved in the internet, and I was so excited because we had democratization of information, unfiltered and of course now what you're referring to today is the fact that these major social media platforms are filtering what we see. 

    That started those five, maybe it was eight years ago, where on Facebook you could follow somebody, and you would see on  your feed everything that person posted. Facebook decided, no, we're not going to do that. We are going to decide what Jeff Chidester might be most interested in seeing.

    Some major celebrities dropped right off.  Basically, what was happening is Facebook said, "Hey, you company X or Mr. Celebrity B" If you want people to see the posts, you know, the people that said they liked your page and they want to follow you. Do you want those people to see your posts? You have to pay us extra. 

    That's when this whole controversy started, right? And where you're going, is, are they a publisher or are they more like a public forum? They're acting a lot like a publisher where I see this going. People are very upset about this on multiple levels right now because the left and the right have had this type of censorship applied to them. I am a free and open. Internet. It's difficult from a technology standpoint to do the type of censoring that they're doing. So they've got more people involved now they've got 200% more people censoring than computers. Ultimately I think this has been a terrible thing for democracy mean I'm gonna boil it right down to that.

    It's a feedback loop, right? So anything you're interested in, you'll see. And anything that disagrees with what the computer thinks you might be interested in. You'll never see it. 

    Jeff Chidester: [00:07:44] Well, absolutely. Once again, we're talking to Craig Peterson. Of course, you can find out more about Craig by going to craigpeterson.com craigpeterson.com.

    I happen to think that their algorithms actually suck in a little way because I keep getting dancing cat videos. I hate cats. So maybe that's why they're going after me. 

    Craig Peterson: [00:07:59] There is good news here, though. And here's what it is. There are some suggestions that that algorithm, that program, that computer, that decides what it's going to show you, that they open up, what's called an API or an application programming interface to it.

    So that third parties could put out, Hey, listen, you don't like the way Facebook monitors and controls your feed. We are the Republican party, and you can use ours, and we'll show you Republican stuff you're interested in or the Democrat party or whatever it might be. That might be even worse to a degree, but I'm sure there will be organizations that if that does happen and it looks like it might, where they open up that computer engine, there will be organizations that say, Hey, we're going to try and be fair and balanced, and we'll give you a little bit of both.

    Jeff Chidester: [00:08:52] It's a good point too when people have to be very mindful that what they're getting back for data is not the complete picture. So you have to be pretty aggressive, especially if you're going to use these tools to inform yourself, be aggressive with your search patterns, and your mindset to make sure you're getting the stories from every particular angle.

    That means that my searching has to be searched differently on several different machines because I found out eventually one gets polluted. Even though I'm trying to get pushed past and looking at both sides, 

    Craig, before I let you go once again, Craig Peterson, you can find out more by going to craigpeterson.com. You can catch him on tech talk as well. Any last thoughts? 

    Craig Peterson: [00:09:25] Well, of course, that is every Saturday, 1130.

     Yes, use two other search engines. Don't use Google for almost anything anymore, unless it's a really tough, difficult search. I have found much better results lately with duckduckgo.com. 

    I love that. It's so much better, or maybe even quant Q W A N T, which is out of France. And that'll give you much better results when you're doing the searching. 

    if you're like me and you really have to dig down deep, because remember I do the cybersecurity,  then I use something called Devonthink, and it's paid software, but it can crawl sites, and it uses multiple search engines and Boolean algebra, even to allow me to really dig into a topic.

    So there you go. I think that's the way for most people to go. 

    Jeff Chidester: [00:10:16] Perfect. 1130 tech talk Saturday, of course, Craig Peterson online Craig peterson.com. Craig has a great weekend.  

    Justin McIssac: [00:10:21] I don't know if you're wearing shorts, but if you are  keep it clean, man. 

    Jeff Chidester: [00:10:25] Alright, 

    Have a good weekend 

    Craig Peterson: [00:10:27] I had a really fun little appearance this week.

    I did a presentation for Ingram micro. They are like the largest distributor, I think, in the world. They're just massive. We provide master managed security services for some of their managed services providers, break-fix shops, VARs, et cetera. If you're interested in how you can sell cybersecurity and make some bucks off of it but not have to spend quite literally up to $5 million just to get launched. Check out  Sellcybersecurity dot com sellcybersecurity.com. 

    I have a little form there and a video of the session. All it is going to do is give me your email, address, and name, and then I'll email you. Not any sort of a funnel or anything else. So check it out, sellcybersecurity.com.

     Have a great weekend, everybody.

    We'll be back next week. Take care. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Voting and Tesla Driver Assist.

    Welcome!

    Good morning, everybody. I was on WTAG this morning with Jim Polito. Since it was Voting day, of course, we had to talk about that but then we got into a discussion about Tesla, Alpha and Beta tests, how they are perfecting their software, and what we can really expect. Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] There's been a lot of speculation about what that second computer is being used for and without getting into the nitty-gritty too much, the Teslas are connecting, calling home on a daily basis, typically.

    Hi everybody. Yeah, I was on with Mr. Polito this morning. We had a great time talking about a couple of things, but, he was a little surprised about Tesla. In fact, he's a little afraid, but, I'll let him tell that too. All right. So here we go with Mr. Jim Polito.

    Jim Polito: [00:00:33] Here he is the man, the myth, the legend. I am talking of course about our very good friend and tech talk guru, Craig Peterson. Good morning, sir.

    Craig Peterson: [00:00:48] Good morning, Jim. Happy voting day.

    Jim Polito: [00:00:51] Yeah. listen. I'm good. I vote. As they say vote early and often, Yeah. Hey, I wanted to ask you if there's anything in particular, in voting, that you wanted to talk about. Any kind of a tech talk angle, but then I have questions about Tesla.

    So let's start with the vote. Yeah. Let's start with voting.

    Craig Peterson: [00:01:13] Unfortunately, we've got reports, major warnings out, and I got a flash alert from the FBI about that this week. The bad guys are into our voting systems very deeply, in some cases.

    That's really concerning to me and obviously the FBI and Homeland security. They're saying that it looks like it's probably Russian hackers. They are getting in. Yeah and are affiliated, at least in the past, they have been affiliated with the Kremlin. Just throw another monkey wrench into this whole mess.

    There's not much we could do. It's too late. You got to show up and as bring in your ballot or vote right there. In the future. I don't know, Jim, if we're going to be able to have a really secure system. There are so many great types of technology using public keys and things. The thing that scares me about every one of those is that they're tracking your vote, which means it could easily get to the point where it's no longer secret ballot.

    Jim Polito: [00:02:21] I do worry about that. Joel had mentioned earlier, like people saying, wait a minute, it's not public information who you vote for, but it is public information if you vote.

    Sounds like a threat. Yeah. it's all out there. I just wonder, because in the future what's going to happen. Is it going to stay that type of activity where you walk into a building and you vote, or is this mail thing going to continue? And then eventually they're going to want to make the leap to, okay. You can do it online in a secure way. And I just worry about that.

    Craig Peterson: [00:03:00] We're looking at places like Facebook, right? These online sites, Facebook, particularly where they really want to be the center of your life. you couldn't go on Facebook without seeing a hundred thousand different reminders to vote today.

    I strongly suspect that Facebook's going to come out before the election and say, Hey, we've got a secure voting platform. What could possibly go wrong? There's really a lot of companies in that boat.

    Jim Polito: [00:03:34] I don't think so, Facebook. By the way, Facebook and Twitter have said today, if anybody calls the election for themselves unless two major media organizations have done it, they're going to block it or suppress it. I don't know.

    Who makes that decision? What are the two major news organizations?

    Craig Peterson: [00:03:52] Huffington post and Fox, right? Those two.

    Jim Polito: [00:03:57] Huffington Post and Fox. Right? Good thinking.

    All right, let's get off this and get on the road. That one of my greatest fears is that one day people will be able to sit in their car and watch a video.

    They'll be watching TV in their car and they won't feel the need to hear old Jim's take on the day's news. I feel like that's still a long way off because, for the most part, self-driving cars are not there yet, buddy. They may want to tell you that they are, but they're not there yet.

    Can you tell me about Tesla's latest, self-driving beta release?

    Craig Peterson: [00:04:41] Here's what's going on with Tesla. Of course, they've got these electric cars and it's all controlled via the computer. Tesla has two different computer systems onboard and we know that one of those computer systems is being used for staying in the lane and the automatic control of distance, so like cruise control. There's been a lot of speculation about what that second computer is being used for. Without getting into the nitty-gritty too much, the Teslas are connecting, calling home, on a daily basis, typically. Tesla's trying to make a self-driving car.

    If I was trying to make a self-driving car, the best way to do this is with "I've got a hundred thousand cars on the street" is have the cars run the normal software and on that second computer run tests, software, and any time there's an exception, like the driver hits the brakes or grabs the steering wheel to turn or something. I analyze it.

    Analyzes what happened and then sends out to Tesla's home office. Hey, we just had a condition 63 and let me know if you want more details and then the car could potentially upload it. There was no way you could upload all of the data these cars are collecting. We're talking about terabytes a day for these Teslas driving long distances.

    The thinking is that Elon Musk and Tesla have tons of data and analyses done by the computer in your car. That way they don't have to build as big a data center or anything else. So Tesla has probably been running alpha self-driving code. In other words, code that's not ready for release at all on your Tesla for years, frankly.

    Now we've got what you just pointed out is that beta release. Tesla has been raising the price all of the time, Hey, do you want self-driving, no problem. So I think it's an $8,000, maybe $10,000 add on. There is no self-driving Tesla right now. Remember it's an assist. Okay.

    Jim Polito: [00:06:57] Yeah. It's called driver assist. Means, I passed it to, Craig Peterson and then he does the layup, you know what I mean? I'm not shooting the shot.

    Craig Peterson: [00:07:08] Yeah. exactly right. So that's what it is today. So there's not this self-driving beta release that they released to just a few people.

    There's a great article in Ars Technica, this week, where a YouTuber called Brandon M. Captured drone footage of his Tesla self-parking. Now there are four parking spots here. One of the spots had a red car parked in it and the other three are empty. And yet Brandon's Tesla is heading right for a rear-end collision with this red car. Exactly.

    It's not ready yet. Some other people are saying, Brandon, again, saying it's crazy. It's scary. And it's unbelievably good. That means it's getting close to that time where the software performances may be there. We'll see. But you know what, Jim, I think Tesla is already won the self-driving car business, but it's not there yet.

    You can't trust it yet. It's still making major mistakes.

    Jim Polito: [00:08:11] We're talking with Craig Peterson, our tech guru. So, Craig, your assessment looks they're way out ahead of everyone else. But they haven't arrived at the, not to make a pun. They haven't arrived at the destination yet, but they're leaps and bounds.

    Yeah. You know what, by the way, with the assist, I should have used a hockey metaphor, not a basketball one, with UI. I apologize, my Canadian friend. That I didn't use a hockey metaphor.

    No, but you're saying Tesla. Has it'd be tough for somebody to catch up with them. Unless of course, all of a sudden the Chinese company has a self-driving system, and coincidentally, it's going to look just like a Teslas.

    Craig Peterson: [00:08:51] This is a hat trick now. They've got it out there. It's working. It's working pretty darn well. It's known to be beta. We've got Elon Musk saying that by the end of this year, full self-driving with the exception of maybe the last hundred yards is going to be available to the average Tesla owner.

    He says buy it now. This is the only car it is going to appreciate in value over time because the value and the cost of the self-driving add-ons are going to continue to increase. So that Tesla you bought the self-driving at $4,000 while selling at 10 means there's a $6,000 increase in the value of that car.

    Now, of course, he's wrong because, in reality, there is wear particularly on the batteries, and the hundred thousand dish miles, it's you've got to put another $20,000 into your car. This is interesting and I think he's gonna win. I think Waymo is just too far behind as is everybody else

    Jim Polito: [00:09:55] Interesting.

    Alright, so there you have it. All from Craig Peterson. I have job security. They're not there yet. I feel good about that. Craig has a great show every Sunday at 11 o'clock on W T A G and W H Y N, where you can get more and more from him.

    But, Craig, if folks want to reach out to you now,

    Craig Peterson: [00:10:17] Well, the best way is just to go to Craig peterson.com/subscribe.

    And if you subscribe right now, I'm going to be sending you a security reboot. because as you know that's what I pay a lot of attention to. This weekend on the show, we're going to talk about the new ransomware demands are doubling every six months, teaching your employees about spotting, smashing, and vishing.

    If you're a home user, what does that even mean? And what should you do? And, that's really what we're focusing on Sunday at 11.

    Jim Polito: [00:10:49] And John Bay back. My, Intrepid newsman reminded me that it was okay to use the basketball metaphor because Naismith the inventor of basketball was Canadian.

    Craig Peterson: [00:10:58] That's right, I forgot about that.

    Jim Polito: [00:11:02] There you go. I use the right one, John. Thank you for having my back. Craig, always thank you for being here with us. You're a great asset to the show and we'll catch up with you next week. Unless of course something big happens between now and then.

    Craig Peterson: [00:11:16] Absolutely. From what I heard, Kamala was also not born, but raised in Montreal and was at least a Canadian. If she's not still.

    Jim Polito: [00:11:26] She would claim everything, you know what I mean? If it meant a vote. She would claim just about everything. If it meant a vote. Craig Peterson, everyone. Thank you, sir.

    Craig Peterson: [00:11:36] Take Care.

    Jim Polito: [00:11:37] All right. Bye-bye

    Craig Peterson: [00:11:38] So there's Mr. Jim Pollito.

    I hope everybody took the chance to vote. At least those of you that are voting the right way. And man, I don't know what's going to happen here in another four years with technology and voting and where it's all going to go. It's going to be an interesting time and you can be sure I'll keep you up on all of it.

    By the way, I have had a lot of feedback about the one-hour radio show, as opposed to the. No, what is it? Eight different segments. And, people love it. So expect that in the future, if you are subscribed, you're going to get my show as one big chunk. It is a podcast as opposed to just a copy of the radio show. So we've been changing that up. Karen has been busy doing all of that stuff for us.

    So if you're not subscribed, go to your favorite podcast app and subscribe there. You can use the iHeart radio app, but one of the easiest ways to find out how to subscribe, just go to Craig peterson.com/iheart, for instance, and it will automatically redirect you right to that I heart page, or you can go Craig peterson.com/itunes if you're using an iPhone and subscribe.

    I'd really appreciate it. It helps with the numbers and that helps to get the people out and listening.

    Take care, everybody. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    14 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Voting and Tesla Driver Assist.

    Welcome!

    Good morning, everybody. I was on WTAG this morning with Jim Polito.  Since it was Voting day, of course, we had to talk about that but then we got into a discussion about Tesla, Alpha and Beta tests, how they are perfecting their software, and what we can really expect.  Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] There's been a lot of speculation about what that second computer is being used for and without getting into the nitty-gritty too much, the Teslas are connecting, calling home on a daily basis, typically.

    Hi everybody. Yeah, I was on with Mr. Polito this morning. We had a great time talking about a couple of things, but, he was a little surprised about Tesla. In fact, he's a little afraid, but, I'll let him tell that too. All right. So here we go with Mr. Jim Polito.

    Jim Polito: [00:00:33] Here he is the man, the myth, the legend. I am talking of course about our very good friend and tech talk guru, Craig Peterson. Good morning, sir.

    Craig Peterson: [00:00:48] Good morning, Jim. Happy voting day.

    Jim Polito: [00:00:51] Yeah. listen. I'm good. I vote. As they say vote early and often, Yeah. Hey,  I wanted to ask you if there's anything in particular, in voting, that you wanted to talk about. Any kind of a tech talk angle, but then I have questions about Tesla.

    So let's start with the vote. Yeah. Let's start with voting.

    Craig Peterson: [00:01:13] Unfortunately, we've got reports, major warnings out, and I got a flash alert from the FBI about that this week. The bad guys are into our voting systems very deeply, in some cases.

    That's really concerning to me and obviously the FBI and Homeland security. They're saying that it looks like it's probably Russian hackers. They are getting in. Yeah and are affiliated, at least in the past, they have been affiliated with the Kremlin.  Just throw another monkey wrench into this whole mess.

    There's not much we could do. It's too late. You got to show up and as bring in your ballot or vote right there. In the future. I don't know, Jim, if we're going to be able to have a really secure system. There are so many great types of technology using public keys and things. The thing that scares me about every one of those is that they're tracking your vote, which means it could easily get to the point where it's no longer secret ballot.

    Jim Polito: [00:02:21] I do worry about that. Joel had mentioned earlier, like people saying, wait a minute, it's not public information who you vote for, but it is public information if you vote.

    Sounds like a threat. Yeah. it's all out there. I just wonder, because in the future what's going to happen. Is it going to stay that type of activity where you walk into a building and you vote, or is this mail thing going to continue? And then eventually they're going to want to make the leap to, okay. You can do it online in a secure way. And I just worry about that.

    Craig Peterson: [00:03:00] We're looking at places like Facebook, right? These online sites, Facebook, particularly where they really want to be the center of your life. you couldn't go on Facebook without seeing a hundred thousand different reminders to vote today.

     I strongly suspect that Facebook's going to come out before the election and say, Hey, we've got a secure voting platform. What could possibly go wrong? There's really a lot of companies in that boat.

    Jim Polito: [00:03:34] I don't think so, Facebook. By the way, Facebook and Twitter have said today, if anybody calls the election for themselves unless two major media organizations have done it, they're going to block it or suppress it. I don't know.

    Who makes that decision? What are the two major news organizations?

    Craig Peterson: [00:03:52] Huffington post and Fox, right? Those two.

    Jim Polito: [00:03:57] Huffington Post and Fox. Right? Good thinking.

    All right, let's get off this and get on the road. That one of my greatest fears is that one day people will be able to sit in their car and watch a video.

    They'll be watching TV in their car and they won't feel the need to hear old Jim's take on the day's news. I feel like that's still a long way off because, for the most part, self-driving cars are not there yet, buddy. They may want to tell you that they are, but they're not there yet.

    Can you tell me about Tesla's latest, self-driving beta release?

    Craig Peterson: [00:04:41] Here's what's going on with Tesla. Of course, they've got these electric cars and it's all controlled via the computer. Tesla has two different computer systems onboard and we know that one of those computer systems is being used for staying in the lane and the automatic control of distance, so like cruise control. There's been a lot of speculation about what that second computer is being used for. Without getting into the nitty-gritty too much, the Teslas are connecting, calling home, on a daily basis, typically. Tesla's trying to make a self-driving car.

    If I was trying to make a self-driving car, the best way to do this is with "I've got a hundred thousand cars on the street" is have the cars run the normal software and on that second computer run tests, software, and any time there's an exception, like the driver hits the brakes or grabs the steering wheel to turn or something. I analyze it.

    Analyzes what happened and then sends out to Tesla's home office. Hey, we just had a condition 63 and let me know if you want more details and then the car could potentially upload it.  There was no way you could upload all of the data these cars are collecting. We're talking about terabytes a day for these Teslas driving long distances.

    The thinking is that Elon Musk and Tesla have tons of data and analyses done by the computer in your car. That way they don't have to build as big a data center or anything else. So Tesla has probably been running alpha self-driving code. In other words, code that's not ready for release at all on your Tesla for years, frankly.

    Now we've got what you just pointed out is that beta release. Tesla has been raising the price all of the time, Hey, do you want self-driving, no problem. So I think it's an $8,000, maybe $10,000 add on. There is no self-driving Tesla right now. Remember it's an assist. Okay.

    Jim Polito: [00:06:57] Yeah. It's called driver assist. Means, I passed it to, Craig Peterson and then he does the layup, you know what I mean? I'm not shooting the shot.

    Craig Peterson: [00:07:08] Yeah. exactly right. So that's what it is today. So there's not this self-driving beta release that they released to just a few people.

    There's a great article in Ars Technica, this week, where a YouTuber called Brandon M. Captured drone footage of his Tesla self-parking. Now there are four parking spots here. One of the spots had a red car parked in it and the other three are empty. And yet Brandon's Tesla is heading right for a rear-end collision with this red car. Exactly.

    It's not ready yet. Some other people are saying, Brandon, again, saying it's crazy. It's scary. And it's unbelievably good. That means it's getting close to that time where the software performances may be there. We'll see. But you know what, Jim, I think Tesla is already won the self-driving car business, but it's not there yet.

    You can't trust it yet. It's still making major mistakes.

    Jim Polito: [00:08:11] We're talking with Craig Peterson, our tech guru. So, Craig, your assessment looks they're way out ahead of everyone else. But they haven't arrived at the, not to make a pun. They haven't arrived at the destination yet, but they're leaps and bounds.

    Yeah. You know what, by the way, with the assist, I should have used a hockey metaphor, not a basketball one, with UI. I apologize, my Canadian friend. That I didn't use a hockey metaphor.

    No, but you're saying Tesla. Has it'd be tough for somebody to catch up with them. Unless of course, all of a sudden the Chinese company has a self-driving system, and coincidentally, it's going to look just like a Teslas.

    Craig Peterson: [00:08:51] This is a hat trick now. They've got it out there. It's working. It's working pretty darn well. It's known to be beta. We've got Elon Musk saying that by the end of this year, full self-driving with the exception of maybe the last hundred yards is going to be available to the average Tesla owner.

    He says buy it now. This is the only car it is going to appreciate in value over time because the value and the cost of the self-driving add-ons are going to continue to increase. So that Tesla you bought the self-driving at $4,000 while selling at 10 means there's a $6,000 increase in the value of that car.

    Now, of course, he's wrong because, in reality, there is wear particularly on the batteries, and the hundred thousand dish miles, it's you've got to put another $20,000 into your car. This is interesting and I think he's gonna win. I think Waymo is just too far behind as is everybody else

    Jim Polito: [00:09:55] Interesting.

    Alright, so there you have it. All from Craig Peterson. I have job security. They're not there yet. I feel good about that. Craig has a great show every Sunday at 11 o'clock on W T A G and W H Y N, where you can get more and more from him.

    But, Craig, if folks want to reach out to you now,

    Craig Peterson: [00:10:17] Well, the best way is just to go to Craig peterson.com/subscribe.

    And if you subscribe right now, I'm going to be sending you a security reboot. because as you know that's what I pay a lot of attention to. This weekend on the show, we're going to talk about the new ransomware demands are doubling every six months, teaching your employees about spotting, smashing, and vishing.

    If you're a home user, what does that even mean? And what should you do? And, that's really what we're focusing on  Sunday at 11.

    Jim Polito: [00:10:49] And John Bay back. My, Intrepid newsman reminded me that it was okay to use the basketball metaphor because Naismith the inventor of basketball was Canadian.

    Craig Peterson: [00:10:58] That's right, I forgot about that.

    Jim Polito: [00:11:02] There you go. I use the right one, John. Thank you for having my back. Craig, always thank you for being here with us. You're a great asset to the show and we'll catch up with you next week. Unless of course something big happens between now and then.

    Craig Peterson: [00:11:16] Absolutely. From what I heard, Kamala was also not born, but raised in Montreal and was at least a Canadian. If she's not still.

    Jim Polito: [00:11:26] She would claim everything, you know what I mean? If it meant a vote. She would claim just about everything. If it meant a vote. Craig Peterson, everyone. Thank you, sir.

    Craig Peterson: [00:11:36] Take Care.

    Jim Polito: [00:11:37] All right. Bye-bye

    Craig Peterson: [00:11:38] So there's Mr. Jim Pollito.

    I hope everybody took the chance to vote. At least those of you that are voting the right way. And man, I don't know what's going to happen here in another four years with technology and voting and where it's all going to go. It's going to be an interesting time and you can be sure I'll keep you up on all of it.

    By the way, I have had a lot of feedback about the one-hour radio show, as opposed to the. No, what is it? Eight different segments. And, people love it. So expect that in the future, if you are subscribed, you're going to get my show as one big chunk. It is a podcast as opposed to just a copy of the radio show. So we've been changing that up. Karen has been busy doing all of that stuff for us.

    So if you're not subscribed, go to your favorite podcast app and subscribe there. You can use the iHeart radio app, but one of the easiest ways to find out how to subscribe, just go to Craig peterson.com/iheart, for instance, and it will automatically redirect you right to that I heart page, or you can go Craig peterson.com/itunes if you're using an iPhone and subscribe.

     I'd really appreciate it. It helps with the numbers and that helps to get the people out and listening.

    Take care, everybody. Bye-bye.

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    14 min
  • IT Wages are down, Big Tech and HIB Visas, Ransomware and the National Guard plus more on this Tech Talk with Craig Peterson Podcast

    Welcome! Craig has an exciting podcast that covers quite a few interesting topics this week including USB safety, Properly disposing of your smartphone before getting a new one, Why the National Guard is being used to investigate Cybersecurity incidents in Louisiana, Iran, and threatening mail sent to democrat voters, Phishing is back in the news and why you must train your employees to watch for it. Then he talks about IT Wages and problems with the H1B Visa program.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    How safe is your USB drive? How to protect your privacy when selling your phone Louisiana Calls Out National Guard to Fight Ransomware Surge U.S. government concludes Iran was behind threatening emails sent to Democrats How AI Will Supercharge Spear-Phishing IT Job Wages Are No Longer 'Exceptional' Need for 'Guardrails' in Cloud-Native Applications Intensifies GIRDUSKY: Corporations Use The 'STEM Shortage' Myth To Abuse Guest Worker Programs

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We've even seen where USB thumb drives come pre-infected with viruses and other pieces of nastiness. So, just how safe is your USB drive in this day and age of us taking them home and to work?

    Hi, everybody, Craig Peterson here. Welcome. We're going to be talking not only about USB drives, but how to protect your privacy when you're selling your phone. Okay. We've got a national guard call out in Louisiana over the election. We've got the government concluding that Iran was behind some email sent to Democrats and we've got artificial intelligence that's going to just supercharge, spear phishing. We'll be talking about that. Defining both of what they are.

    IT wages are no longer considered exceptional. That's a study from Harvard business school. Guardrails in cloud-native applications are needed. That's a great call. I love that.

    Corporations using this STEM shortage myth to abuse the H1B programs. H1B visa programs that President Trump has been trying to clamp down on.

    What do you call these little devices that we have these a USB drives, thumb drives? what do you call them personally? Probably about 10 years ago, I grabbed the domain. I registered thumbdrive.com and I never did anything with it. I was thinking, Oh man. I could have a whole bunch of different thumb drives up there. I ended up letting it go when I was really low on cash one time. I just went to it today. Thumb drive.com and it's somebody selling Toshiba thumb drive type stuff. It's still the disappointments in life that you tend to remember much more than the successes. So it's a bit of a shame. But thumb drives have become way more useful in this day and age. We're going from work to home. Our kids are taking their work for school. They've got to bring it to the teacher. Many of the times, of course now it's electronic, right? We upload it. We don't even use FTP anymore, but we upload it. We download it and we might email it. We use Box or Dropbox or Google drive in order to share files. That's really the most common way to do it nowadays.

    But thumb drives are still out there. They're still in wide use and I still have a supply of them and somehow they all seem to keep disappearing and that's where the problems start, really?

    If you own at least one thumb drive, you've transferred a file. You might've used it as a method of backing up some of your documents or your photos or other things you might like to carry your work with you. So you can dive into it at a moment's notice and you keep it in your pocket. I have one that is waterproof. It's a light fireproof, and it sitting there on my key chain. So that I have it if I ever need it in order to do something and you know what, I've used it a few times, but not so much. I've even got thumb drives in my wallet. Just really thin ones in case ever need them. I have used them from time to time.

    If you're like most people. You might be using thumb drives that aren't necessarily trustworthy. So let's talk about that for a minute. Students tend to use flash drives to print out study materials at a Kinko's store, or maybe they go to a library to grab something. Maybe you are using it to move documents back and forth to your work, to your family events, soccer church, or whatever it might be.

    Now, when we're talking about kids, they also tend to lend their classmates these drives, and they might have their notes from their class on them. They might've made their notes on a Google Chromebook, and now somebody plugged it into a windows laptop or Mac. Think about spreading diseases, right? It's the same sort of thing as they're passing them around and sharing them.

    It's not just kids in school, in college. It's also friends at the office. It's friends that you have at home and you really can't be sure of these things and how protected they're going to be. If any of those thumb drives have been infested with malware, it's really very possible that your computer, if you've used one of these infected thumb drives, that your computer is now infected as well.

    Some devices like your Macs, for instance, you've got a Mac laptop are immune to all windows viruses that are windows based. So it can spread them. It's like a little super spreader. So that if there is a virus for windows, that's on your Mac in a file, your Mac, will be just fine. It doesn't care. But when you now transfer it to somebody else, or you put it onto a drive you're in big trouble. here are some options that you can take.

    Microsoft has made a big change a couple of releases ago, major releases in the windows operating system. There used to be an autorun file that was there, on, for instance, a CD drive or a thumb drive. So when Windows opened it up and said, okay, I'm going to run this file. And that file would do something like cool, play a movie for you. Or it might run a video game or whatever it's supposed to be doing on there, but the bad guys started taking advantage of that pretty early on. They started using this crass cross-contamination route using these autorun files as a way to send all of their malware to other people. Okay, so you have to be careful.

    We're going to get into some solutions here in just a minute. What really do you have on your thumb drives? I want everybody to think about it for a minute. What are you using them for? How can they be misused? What happens if they're lost? I mentioned that this week on the radio, what happens if you lose the thumb drive and it has some intellectual property on it? has personal information on it?

    I know a couple of listeners who are using external drives, which are more common now than they used to be. They plug into the USB port. It's the same sort of problem. You can't put these into your pocket like you can a thumb drive, but you can certainly share them. You can move them around and they're using these USB drives now spinning media, or sometimes even SSD, they're using them to move stuff back and forth.

    So how do you deal with it? One of the ways is what we tend to do for our customers that need high security. We remove the mechanisms for people to be able to use them in the first place. We'll disconnect it from the motherboard if that's possible and we'll fill the port with epoxy. So people can't just put it in there. Now most of the time, they're not being malicious. They just want to plug it in and grab this file.

    But there are people who are malicious who are trying to steal data. Which is why, again, in high security, We remove those USB ports. So that the thumb drives just can't be put in there. Companies like IBM have opted to completely ban removable storage devices, period. It's a real big deal. They were talking about all of this at WeLiveSecurity.com Amer Owaida is his name who was talking about some of this stuff. But when he looked around, he found that IBM was banning it, many other major companies were.

    Let's start with what can be done. First of all. When we're transferring sensitive information from one place to another. So for instance, we might be tightening up security in a doctor's office or helping a doctor's office upgrade their systems, and we need to send all of their patient data.

    To the third party who now has this new system that they're going to be starting to use in the doctor's office and we want it to be secure. So we have a disk drive cabinet that is encrypted the whole thing is, it's just a little thing. It's not much bigger than a disc drive and it has a drive inside of it. You have to enter the key when it powers on, and then it uses that key for the encryption on the disk So even if somebody breaks into the case, it doesn't matter because the disk that's inside is encrypted using this key. So you could consider doing that. There are thumb drives that have built into them. Thumb print readers. Most of them that I've seen are pretty easily defeated, but let me tell you that's harder to do than, having to defeat one of these things than just plugging in a drive that's not encrypted okay.

    So step number one. You need to have, if you can use them, drives that you can trust for confidential information. That means they need to look different. They need to be different than the drives that you are using for home for your personal data, for your personal backups. So first of all, they need to look different. So maybe just having that thumbprint reader on the drive is enough to remind you. Sensitive data should be on that drive with a thumb print reader.

    The next thing you probably want to do is encrypt all of the sensitive data that you want to load onto the drive. Now there's a number of ways to do it. You've got built right into windows, full disk encryption. Same thing's true for your Mac. So you could encrypt it that way. You can also use something that's free. I think it's pretty easy called PGP, which uses public keys. You encrypt the files before you put them on the disks.

    I do like the hardware security solutions for the thumb drive that uses a pin code. That's probably best, as I said, I don't really trust the biometric scanners, but there's some really great articles out there about these thumb drives, and what could possibly go wrong.

    Now there are thumb drives that are designed to burn up your computer, literally melt it down. Don't pick them up. Oh yeah, we've used that trick against Iranians before.

    Our smartphones have our lives on them. There are some very quick ways to make sure all of your data on them are destroyed, because we're upgrading these things left right and center. It isn't just about e-waste as they call it. It's about your personal information.

    Let's start getting into our security here on your phones. People are getting rid of their phones on really record rates. In fact, in market for new customers, their smartphones has dropped dramatically. We've reached saturation in most markets, worldwide, where people who want a smartphone have a smart phone, people who want an iPhone or maybe an Android, heaven forbid, have got those devices and they're pretty happy with them.

    Now, the Android is going to be cheaper initially. If you ask me, it's way cheaper in the longer run to have an iPhone. What do we do with these things? We're talking about 50 million metric tons of e-waste every year and a large part of that is our smartphone devices.

    Most of it isn't recycled. However. Your smart phone can be. So instead of tossing it into the trash, I think you need to look at a few different options. You can recycle it. You can donate it. You can sell it. There are a number of different places that you can go in order to get rid of these things and really make back a few bucks in the long run here.

    Best Buy, Whole Foods, Home Depot, Lowe's and Staples typically have free drop off spots to take dead batteries. So that's step one. If you have a removable battery. You can remove it and drop it off on one of those. You can also check out a website that's called earth nine one one, and it's simple or nine one one.com and it will tell you where you can recycle these things because they've got all kinds of nastiness in them. The button cells, the older ones had mercury. You've got lithium, you've got zinc in these things. So that's always a good place to go to start recycling them.

    There's also cell phones for soldiers where you can donate. That's their website, cell phones for soldiers dot com they will take your cell phones and they'll provide them to soldiers overseas. This is really cool too. Cell phones for soldiers also provides about 2,500 calling cards every week as well for the soldiers to use. Man, I'm choking up a little bit here.

    In case you didn't know it, by the way, we're planning on building a 4g cell phone network on the moon and a 5g cell phone network on Mars, like real soon now with the next couple of years. So maybe you can donate them to NASA for them to take while they go up there. Now, there are a few places that you can go to. Recycle specifically, and I've used Gazelle before.

    Let me just check. Make sure they are online still. Yeah, there they are. Gazelle, G a Z E L e.com. They'll let you buy refurbed pre-owned phones. You can sell them as well. They'll trade them in for cash. So let me just see, I'm poking around on their website as I'm here.

    I'll tell you how to clean up your phone securely here a little bit, but let's say like me, I've got an iPhone eight plus, right? That's my phone. It's probably about time to upgrade it. I'm going to say it's factory unlocked and it's saying, I think mine's a two 56. So I'm going to say two 56 because I want money. Does the device power on? Yes. If I slowly functional all parts work. Yes. Front and back. Free of cracks. Yes. Cosmetic looks like new, which is true. So for excellent condition worth 181 bucks, light signs of use it's worth 173, normal signs 160 bucks. Then you can send it in. I've even seen gazelle having kiosks, where you can go ahead and just put your phone in. They have cameras in them and somebody remotely will look at the phone that you just stuck into it and will give you an offer. So there's buy-back services, flip C and all kinds of others.

    So before you get rid of it, make sure you have a good hard look. Declutter gadget gone. That's a cool name, right? Oh, Apple, by the way, they've got store credits. I got $300. Last time I turned in my iPhone at the store. right now my iPhone eight is worth 170 bucks at the Apple store. So it's worth about the same as it is worth over on gazelle. Best buy let's you trade it in. Some will take them to Craigslist, Facebook marketplace, E-bay and others. So there you go. There are some things to do with that phone. Eco ATM, by the way, that's the name of the ATM that's owned by Gazelle trade. Amazon has a trade- in store, but just look, if you do a search for gazelle, you're going to see ads for others as well.

    Before you do that, let's talk about your privacy here. Before you just throw it away into one of these recycled bins. So this is some suggestions from Tech Republic and I'm of course, going to add my own little tips into this as well. Veronica Combs wrote this original article. she says that you should unpair all devices. I don't think that matters really. I don't think you have to unpair anything because of what gonna do next is sign out of all services.

    Now that can be important. If you have an iPhone, what all you really need to do on your iPhone is go to the settings. Once you're there in settings, you're going to go to general and then reset and then select a erase all content. Before you do that, you're going to have to turn off, Find my iPhone because if find my iPhone is turned on not only does it let you find your iPhone, if it's lost or stolen. but What find model iPhone it is Also it makes the phone, so it cannot be erased and then used by a third party. You have to be able to log into the phone using your Apple ID if it has been reset. So turn that off first. Find my iPhone. Then go to settings general, reset, erase all contents. Now it's not really erasing the content on the iPhone and also un-encrypted Android devices. What it does is it destroys the decryption key. That only takes a second or two. Once that's destroyed that phone is now completely reset. It's like a factory reset. There is nothing left on the machine. So on Android phones turn off the factory reset protection.

    This started a couple of releases to go with Android. You can go to settings, privacy, factory data, reset, and then choose reset phone. once you've done that with your phone, either one of them. You are safe to send it off to a recycler.

    Now, if you're like the campaign staff for Hillary Clinton or her phones themselves, they just took ball-peen hammers to them. Once the investigation had started and it was illegal to destroy evidence. So remember that, if you use a ball-peen hammer, apparently it's legal to destroy it that way. By the way, it'll make it pretty much unrecoverable if you really bash the living daylights out of How could our elections be attacked? Well, they already are according to a report right now in Louisiana. It may not have been directed at our election infrastructure, but it sure is affecting it. Here we go.

    We have some serious problems being reported down in Louisiana. According to threat post the Louisiana National Guard, has been called out. Now that's a very big deal. You might ask yourself, why would they call out the National Guard to battle a cyber security problem?

    That would be a good question, if you were to ask, so let's ask it. The answer to that would be. That the national guard, as well as our military, have been trained. Not all of them, obviously. They have teams that have been trained to do cybersecurity work, and we've done some. I've done some training on that for the FBI InfraGard program, so I have some intimate awareness of how this stuff works. Here's the bottom line, according to the article that was in Reuters. They're saying that there's evidence suggesting a sophisticated hacking group was involved.

    So what happened now? This is something that happens to businesses. It happens to government agencies. It happens to almost everybody out there. They were attacked. Most of the time these attacks are coming, the more successful ones, in the form of phishing and phishing campaigns.

    I've got some training that if your company really wants to do some, phishing training, let me know. I have some excellent training materials and we buy licenses for these from our third party. It just isn't worth it for me to do custom training for all of my companies and we buy these things in blocks and I have extra licenses. We buy them a thousand at a time. So if you'd like to offer some security training for your employees, that's primarily focused in on the whole concept of fishing and what they should be doing, what they shouldn't be doing. Social engineering even goes so far as to inbound phone calls. Let me know, just drop me a line. [email protected] and I'll be glad to get back to you. We can make some arrangements to help you out there.

    Cause I know a lot of companies just don't know where to go and you can't afford these expensive trainings. We have some extra licenses, so we can definitely help you with some of that stuff. So just email [email protected]. If you'd like to get a little bit of that training and I can probably do it too for a home users, if you're interested, let me know. I'll see if I can't just drop you into one of these classes with one of my business clients, that, again, it's a nice little series of training. I think they do a really good job. I should be able to squeeze some people in here and there. So let me know.

    That's how most of the time bad guys are getting into our networks. They send an email, it looks like it's legitimate. It looks like not only is it legitimate, but it's something you need to open and you need to open it right now. These guys have gotten really good at that sort of a thing. Then you click on it and they have your information or they have you running a program for them.

    Now, many times these programs are called RATS, which is a remote access Trojan. If they can get a RAT onto your network, it's over for you if you don't know it's there. That's why we always suggest and there's a few companies that have these, I like Cisco, but there are some other good ones out there that we work with, that have the ability to detect these Trojans. They're watching them calling home. Where are they going?

    A remote access Trojan on your network means they can remotely get onto your network right through your firewall. Right through it and then start doing whatever they want to on their network, anytime they want. That's part of the reason I really strongly urge everyone to use umbrella and you can find it, just umbrella.com. We sell the professional version of this for enterprises, but they have free versions as well. That are simple as just changing your DNS server IP addresses. They've got them right there on the homepage. Two, two Oh (860) 722-2222. It explains it all. If you just go to umbrella.com.

    The idea is you use the Cisco umbrella software for your DNS server and if there is a Remote Access Trojan, when it tries to call home to give the bad guys access to your network, it is foiled in its attempt.

    It doesn't block it per se, but it's like hopping in an UBER and saying take me to one, two, three main street and the Uber driver says, I don't know where that is. That's kind of the equivalent here, you ain't getting to one, two, three main street if the car or the driver doesn't know where that is or how to get you there. That's what umbrella does for you. There's free versions of it.

    If you're a business you should use one of the higher level ones. What we sell the enterprise version is tastic for businesses because it allows it all to be customized as well. Umbrella has family stuff too, that you can use and the family stuff is great too. You can keep the kids from stumbling on websites that they probably shouldn't be stumbling on bottom line.

    This paper that was released, showed that they had done a forensic investigation. I'm looking at this Reuters story, that goes into it and they found something called the Kim Jong rat. Which is a back door. It is a remote access Trojan and it had a source code leaked.

    I haven't checked lately on the dark web, but it used to be a little buy tools like this for 20 bucks. They're not expensive.

    So problem number one, the bad guys got into Louisiana's government networks. Problem. Number two, they installed a remote access Trojan in the network. Very common. Usually within a week to two weeks after that been installed, they will have examined your network and they are going to be digging in even deeper.

    What did they do here? Wow. They installed the Trojan. Now I've talked about this before. We've seen attacks involving EmoTet, it was found also in the networks of these government victims, according to Reuters. The EmoTet Trojan can also load other malware and it's like a worm. It propagates all by itself through the networks, onto the file servers and onto the desktops and laptops.

    It also, by the way, is just as happy to spread through a VPN connection. Do you know what I think about VPNs? They have their place. I use them, but as a rule, VPN's not a good idea. For most very small businesses, not at all. Okay. So this is a problem.

    We now have the national guard in Louisiana called in according to Reuters to protect the systems, when we're in the middle of election season. Isn't that fun?

    Before we get to that, I want to talk about this email. That concludes that Iran was behind sending these very threatening emails out to Democrats. How could that have happened? What should you be looking for? We got answers.

    There have been some emails that are very scary out there. There were supposedly from this pro-Trump group called the Proud Boys and they have a very scary message. The messages say that they are in possession of all your information. By the way, that if you really want it and you're willing to pay a few bucks on the dark web you can probably get anybody's information on almost anything, okay.

    But in there in possession of all your information and they've instructed voters to change their party registration and cast their ballots for Trump and I quote here from the emails, and this is an article from the Washington post. Yes. It says you will vote for Trump on election day, or we will come after you. So pretty, scary stuff.

    Some of these were in a hotly contested swing States in the upcoming presidential election. It's going to be one heck of a season here. Let me tell you. But the U S official said privately that through the post that the operation was not terribly sophisticated and they said it was disclosed before it could have any major impact.

    The cybersecurity researchers that they spoke with said little about the operation. They're thinking there wasn't a large scale deception. We'll see what happens. It was first divulged Tuesday by local law enforcement and election officials in Florida and Alaska, and people rightly reported them. For FBI reporting, it is IC three.gov online. If you get an email like this, or you get another threatening email or something that you think the FBI might. Want to know about because they do investigate these things.

    I am involved in a couple of their investigations, that revolve around China and Chinese espionage. Anything like this, you can report, just go to IC three.gov. I C three as in internet crime complaint center. I C three.gov. Okay.

    This is a real problem. In 2016, it took months for the Obama administration to publicly point the finger Moscow for the hacks and leaks of democratic e-mails despite the intelligence community, having determined Russian culpability early on. So there you go. The Russia story continues at the Washington post, but this came up from a disclosure by the Director of National Intelligence, the DNI, John Ratcliffe.

    I like the fact that president Trump has, I'm not going to say strong armed, but he certainly has convinced our intelligence agencies to be more open with the public. Be more open with business, this FBI InfraGard thing that I'm involved with and did a lot of training, meaning over the years for, it's been around for a very long time. Let me see. 1996 it's been around. So it's a partnership for protection. It's a nonprofit, they have a lot of volunteers like myself that are involved with it. So the cooperation between the fed and business is nothing new. 96 was a long time ago. That would have been what President Clinton, that did that, but it actually started in Ohio and one of the field offices, as I recall.

    President Trump here has taken this to the next level and we have had disclosures from the NSA. Remember NSA, we used to joke is true for no such agency because it was just so secretive. The NSA has even released information about vulnerabilities in our systems. So it's a huge deal.

    On Thursday, by the way, Iran, some in the Swiss Envoy in Tehran, and Switzerland is who handles affairs for the US there, because the U S doesn't have an embassy or anything really there in Iran. Other than probably the CIA. They were condemning the baseless accusations of meddling in the U S election. They said the Iran has no interest into freeing interfering in the US election. It's the old habit and there's a new name for it, but the old habit of keeping information from people. You might remember in World War Two, right? If you tell a big lie often enough and you tell it with absolute rigor, people will believe you nowadays, they call it gaslighting and it's been very effective. So that's the Iran is trying to do. So be careful with those emails.

    So that kind of leads us into this whole thing on spear phishing.

    If you miss it today, I'm going to have that up on my website, along with IT job wages and pretty much everything else. I try and get it all up on Craig Peterson.com. I send out my weekly newsletter and we've also sent out some that people are really interested in. If you didn't get it this last week, you might just drop me a note.

    We don't automatically send it to people who sign up new. So if you are going to go to Craig peterson.com/subscribe right now, you'd only get future newsletters. You wouldn't get the past ones. This past weekend I put together a really great newsletter. And it talked about taking your computer in for repairs.

    I used this fictitious character called Hunter. Who took his Mac book into a computer store to have it repaired for water damage. I came up with all of the main things you should do step-by-step before you take a computer in for water damage. I think if our fictitious character Hunter had done all of this, he wouldn't be in all of this big trouble with this daddy, but I can send that to you, if you're interested. We talked about it a little earlier this week as well, but just email me at Craig Peterson dot com. And let me know you want the Hunter email. I'll be glad to send that to you.

    Also, if you sign up, I am going to be sending you some of my most popular special report. The stuff you need to know, because everybody needs to understand how to do a security reboot.

    I've got some very in-depth courses, but let's just start you with a simple checklist. I don't want to confuse anybody. So it's easy enough for me to just reply to you when you sign up and send you this stuff I have at this point about 60 different six zero different special reports.

    So when you ask a question, oftentimes I can just send you a special report on it. Oftentimes if I don't have a special report, I will write one. because if you're interested, other people are entrusted too.

    So make sure you sign up and you can just do that by going to Craig Peterson.com/subscribe. I'd be glad to do that for you.

    We also have a couple of things, that I really want to cover quickly here when it comes to the election and election technology. I think as a whole, our election is pretty safe from a technology standpoint, right? I'm not saying anything about people printing their own ballots and sending them the in. About gathering ballots about bribing people to vote a certain way. That's not what I'm talking about. Obviously, all of that's easy enough to manipulate. We've seen post carriers who are dropping ballots into gullies and ditches and trash cans. That's one thing.

    On the other side, there's the technology. I am pretty confident that in most of our States here where we are using these paper ballots and they're more like a light cardboard, right? What a hundred pound stock give or take 80 pound where we fill in that oval. Then we take it up to the machine. We put it into the machine, which reads it, optically and tallies. It I'm pretty confident those machines are in good shape.

    One of my sons, who works with me and he's a Cisco fire jumper certified guy. He is also one of these election overseers. He had a look at machines that were shipped off from the Secretary of State's office, and even though some of the seals were broken, The seals that really counted, which are the seals over that little memory card inside that optical reader. Those seals were all intact. So that does my heart. Good. I'm also pretty confident that the people who are working the local polls and tabulating are being supervised and there tend to be Republicans and Democrats and independently minded people who are overseeing the process. So those tallied numbers that are then sent off to the Secretary of State's office, I think are likely to be correct.

    Then the Secretary of State's office, puts them up on their website and then the Feds are going to look at them. That's where I'm the most worried about it. Emails sent to the Feds with tallies. The feds visiting a hacked website.

    We just went through the major ransomware and remote access Trojan problem that they're having down in Louisiana. That is a very big problem because that could be a weak point that would be exploited by people who wanted to change our votes.

    If you are involved in oversight in this stuff, make sure everything is double checked with the human. Get on the phone, call somebody, call the Secretary of State's office to verify. If you're working at a local polling place, verify that the Secretary of State's office has the right numbers. Then make sure the right numbers are on the Secretary of State sites website.

    The rest of this is going to be an absolute disaster. What can I say.

    Craig Peterson (2): [00:38:49] You've probably heard about spear phishing. I did a little phishing myself online and looked at some of these companies, like Barracuda that are saying that they stopped spear phishing attacks using AI. Hey, I've never been a fan of Barracuda.

    Now spear phishing is by definition and this is from CSO online.com, is the act of sending an email to specific and well-researched targets while purporting it to be a trusted sender.

    Now you've seen phishing. If you've been on the internet for the last 10 or 20 years, you've probably seen what's called the Nigerian Prince scam. That's an idea that has really perpetrated into every bad guy's mind over the years. The idea is, Hey, if we can send an email out to people and find the gullible people, maybe we can make some money.

    It's fishing just like you might be out in a boat and you're casting a net to catch a certain type of fish. You hope that the gill size is right on that net and you're always catch some other things, right? Dolphin, tuna, and some of these other things, but, you don't really care.

    What we're talking about here with regular phishing, which is spelled P H I S H I N G. We are talking about bad guys casting a huge net. This net is out there to try and catch anybody, anything there will go ahead and get caught in that net.

    So the Nigerian Prince scam is, Hey, I am a Prince in Nigeria and I need to move my family's $1 million worth of wealth and the only way I can do that and get it out of US banks is if I have a US bank account. So if I could go ahead and I'll transfer in this $10,000 that I need to move. I'll let you keep 2000. So I'm going to transfer 10,000 into your account, and then you're going to wire me $8,000 of that money and you can keep the $2,000.

    Now, there are many forms of this scam. The Nigerian Prince scam is one of them. Of course what's happened here is they say they wired the money in, and that money may show as pending in your account coming from an overseas account. So you look at, and you say, Oh yeah the $10,000 is there. The Nigerian Prince contacts you and says, Hey, I sent you that $10,000. I really need that 8,000 now, or I'm not going to be able to get my mother out of jail or something along those lines, kidney for my best friend on and on. People look at the account, look at that, there's that $10,000. Now they go to the bank and they wire the $8,000 to this account overseas and off goes your $8,000. When you wire that money out, it is gone.

    What happens is a few days later, it can take a anywhere up to basically two weeks for the bank to clear the money. I know about the check 22 laws, that's all down the tubes. It's eight days to two weeks usually, especially for international transactions and they can take three weeks or longer sometimes. That transaction where he wired the money in is canceled on his side because he's got an inside thing going on with the bank. So you thought you had 10,000 that he had put into your account. You wired out 8,000. Net 2000, that's not so bad.

    But then a week or two, or maybe even three weeks later, your bank contacts you for insufficient funds because that $10,000 transfer that he was putting into your account, actually never finalized and never really happened. So you have now sent him $8,000 of your own money. So that was the Nigerian phishing scam.

    There are a lot of scams that are based on that are still out there today.

    One of the big ones that the FBI just a few months ago arrested a dozen or so people out in California for is a mule scam.

    I don't know if you saw this latest Clint Eastwood movie. I thought it was pretty good. I've liked Clint Eastwood for very long time, but he has a movie out called The Mule, came out in 2018. This is a 90 year old, horticulturalist and Korean war veteran that turned into a drug mule for Mexican cartel. A very interesting movie, rather believable, a lot of movies that just totally rip apart. but I enjoyed this enough to allow it to be believable. He was hauling money for the Mexican cartel.

    What these people in California were doing is they were money laundering and that's typically called a mule, they're moving money around.

    They would get some money from somebody. It much like this scam. I was just talking about with the Nigerian Prince scam. So they say, Hey, we're going to wire some money into your PayPal account, for instance, or we're going to route wired into your bank account. And then we want you to use PayPal to send us the 90% of the money.

    In this case, these mules, we're not getting ripped off. They would actually get the $10,000 in to the bank account and then they would send $9,000 via PayPal and the bad guys were happy cause that money is laundered, it came from a more legitimate looking source.

    I had some really great trainings that I did on this for the FBI InfraGard program with some think it was a secret service guy, and they tracked a lot of this down. There were some arrests here a couple months back.

    We have to be very careful about this and how we're transferring money around and whether or not we do it for one of these people. Because we're getting tricked.

    What's happening is these people who are doing the spear phishing are doing research on us.

    We had a great example of another spear phishing thing. There was a company in the UK that was purchased by a German company. They knew all of the basics about this German company and they got a phone call one day from the CEO of the German company. The CEO told them to wire some funds to this particular bank account, and they did. It sounded like the CEO. They used some technology to impersonate, the guy's voice. They went ahead and wired the money.

    Then we got Barbara Cochran who is one of the sharks on shark tank. Her assistant went ahead and wired, I think it was like $400,000. Another assistant of hers, her executive assistant, caught it, noticed it, because she was CC'd on the response, freaked out. They managed to stop the transfer from happening. So good news on that one.

    These scams are out there and they're out there big time.

    I have another one where a lady was going on line and doing research about business owners. She found a couple of business owners, actually quite a few. She wanted to narrow it down. So she researched them. She found some of these business owners had Facebook pages. She went to the Facebook pages and while on those pages, she found those business owners that said that they were going on vacation. She followed them a little bit and found out about where they were going when they were going. Then she managed to trick the email providers. Into letting them into the actual email account, which she did in this one case, where she got more than $40 million out of the company.

    She finds out who the CFO is and then when the owner is on an airplane or is in Bermuda in cannot be contacted. She then sent off an email to the CFO saying, Hey, we've got this new provider, a supplier we've had for three months and we've never paid any of their invoices. Here's the invoice on the bottom of the invoice or statement the bottom of the statement it says, or to wire the money to, I need you to wire right now, or we're going to be out of business next month because we've never paid this new supplier that, and it's critical. The CFO wired the money because she had done her research and that's what it takes.

    They want to send you an email that is really coded up for you.

    That fake email that you got represents a huge industry and that industry is undergoing some amazing changes. They are using artificial intelligence for evil. So we're going to tell you about it right now.

    Now, these types of phishing, where they are going after a specific person, after doing a bunch of research are called spear phishing attacks.

    It's not like those from the mid nineties where you had the Nigerian Prince out there sending emails and just waiting for anybody to respond to them. These are aimed at someone individual.

    Here's an example that was in Dark Reading this week, where it says:

    Hey, I'll see you at nine for our four hour call. You're going to kill it today. See the dial in details for the call attached. Cheers, Al.

    Now most people would not question the legitimacy of this email. It's kinda laid back. They might've done some research on Al. They might have cracked Al's machine. Somehow gotten a list of all of his contacts and sent this to everybody in his contact list that worked at the same company.

    This is happening all of the time, everybody. So be careful of this.

    So you get it. Looks legit. Everything about it smells legit. You're going to open it up because heck I'm going to kill it today in our nice little conference call, right? Yeah. That's what you're going to do.

    But what could well be happening here is that email attachment that they said, Hey, you need to click on this, could well have a malicious payload. So you have to be careful and it may not have a malicious payroll payload on it. Maybe it went through the email filters looked pretty good, but maybe the website it's pointing to, or even the file on the website it's pointing to is malicious is a malicious pay load.

    So you've got to be very careful and you could lose your job in total embarrassment. You could really the harm the company by opening this. But it's getting worse.

    It's going to get even worse right now. There is something called offensive artificial intelligence. This is ushering in a whole new era of phishing attacks that are going away from these more simple ones, the broad phishing attacks, even the spear phishing attacks, where they do some research about your company.

    I've picked up a few clients, unfortunately, that have had these attacks worked successfully. And then we had to put in some really great software to make it even work better for them.

    Artificial intelligence can go out and start looking around, can figure out what's going on. For instance, blue.ai, found a cluster of pneumonia cases around a market in Wuhan, China, it flagged it and found it nine days before the World Health Organization found it. It's now being used to look at all of this health literature from around the world about COVID 19, the Corona virus, that we have this novel one and figure out what's going on and it's even comparing it to DNA. AI can be absolutely wonderful.

    We use it for monitoring and protecting various types of networks, but inevitably AI now has opened the door for sophisticated cyber attacks.

    It is really crazy what's going on right now. Cause it's not just these phishing attacks, it's going to agument every type of cyber attack. It's using adaptive decision-making capabilities based on what it finds inside your network.

    This is scary as heck because once it gets inside your network, think of Skynet, right? That's really what it's going to ultimately be like, maybe not with Androids out there trying to shoot us, but trying to steal everything we have.

    Our email boxes are just going to be used as a stepping stone to get into the business network.

    The only way to really compete with this is to fight AI with AI. That's what's happening with some bigger companies out there.

    I did a little searching of my own online and I got a little upset because I came across an article.

    At the top an ad for Barracuda. Now, I've known these guys for a long time. They have used open source, freely available firewall software and other software to build their business and, good for them. There's nothing wrong with it. That's our open source software is for.

    But there seem to be some misrepresentation that are out there. That's where it gets scary.

    Right there on their website, Barracuda Sentinel, get AI based protection from phishing and account takeover. You read down a little bit further block threats already in your email, in your inbox. Stay a step ahead of attackers with AI based threat detection. Stop wasting time managing static security rules. I agree with that one. I think the problem that we have is we're putting a lot of trust in these companies.

    This is Barracuda. I have had clients who've used it before, and I've had nightmares trying to fix problems with it, but that's me. I could tell you about them if you wanted.

    On the other side, there are other systems, like from Aruba, Cisco, which is what I use and sell, these are not a panacea. There are all kinds of things that you have to look at and you have to be tying them together.

    We're no longer just dealing with the perimeter. It's no longer just having a good firewall or trying to have a good email filter. Now we really are talking about this Zero Trust model because AI is being used by the bad guys. It is getting into our systems. We have to make sure that none of the data, what we call in the biz, east-west or west-east traffic, east-west traffic, none of that internal data, internal communications is going somewhere it shouldn't, or is being used incorrectly.

    Spear phishing is difficult to detect. It is very difficult for AI detect it. It is much easier for person to detect it. You need to do training on this. Have your people get some training. I think it's just that important.

    This whole business email compromise thing that the FBI has been talking about. That's all tied into spear phishing. So we gotta be very careful.

    Harvard business school has a really interesting article out right now about wages in IT of course, information technology. We used to call it MIS management information systems, way back when.

    Hey, it's bringing back memories of when I was a professor out at Pepperdine university. MIS 422? That class anyways.

    Harvard has been of course helping people in all kinds of aspects of business, which includes things like the law, IT and General business, as well. But they've come out with something that has really surprised a whole bunch of people and it has to do with IT job wages.

    I have talked about getting jobs in cybersecurity and how many open jobs there are. I think the biggest problem people have is getting into cybersecurity and then getting the support they need, once they're in cyber security. Over just the last few weeks, I've had a couple of listeners who have sent me an email and I asked a little bit about it and I pointed them in a couple of different directions and even pulled another listener into one of the conversations who has moved into IT security. Exceptional wages were the norm in computers for a very long time. You got paid good money, if you were good in it whether it's in management or in coding.

    I made good money for a lot of years as a kernel programmer. Writing the operating system itself and device drivers and implementing internet protocols and designing new protocols. I made one of the world's very first centralized security systems for computers and computer networks. Way back when. So it has been around a while and it has paid very well. Their jobs have always been stable, the fast rising within the organization and made a lot of money. Back in the nineties, you had the dotcom boom.

    It really bothered me, all of these people that started hanging up shingles saying, I'm an IT person. I design websites. I do these and they've never really had any real experience with IT.

    To this day still bemoan.Microsoft products. Because it seems like it's a chimpanzees throwing darts at boards, as far as trying to make sure their systems work and inter-operate and don't even conflict with each other. It's so frustrating. Since I've been in the Unix side for so long and the mainframe side as well, the systems that work well and work consistently.

    It turns out the things have changed a bit now when it comes to the wages that are being paid in information technology. In all, but the largest cities, according to Harvard wage growth in IT jobs has become relatively moderate following the dotcom boom.

    They're saying that these wages in IT are a lot more like wage patterns that have been seen in the broader STEM space. STEM being science, technology, engineering, and mathematics. So some of those like mathematics are well known for really having terrible wages, right? You got a PhD in math and wow, you can get a $60,000 a year job. So IT has changed. IT really has leveled out.

    In some geographical regions where there's fierce competition for IT talent, superstar performers do not earn the same high premium they once did over average performing programmers and other IT professionals. So in short, IT wages are still relatively high compared to most other occupations, but they have lost what Harvard says is their exceptional luster.

    The IT wage premiums today, have more to do with where you are working then with rewarding, specific skills that you have for the job. So keep that in mind.

    This paper, if you want to look it up, it's called the digital labor market in equality and decline of IT exceptionalism. It was written in Harvard business school post-doctoral researcher was involved with this at the Martin Marshall professor of business administration. So there's a whole lot to chart the rise and fall of the salaries. They examined 142 of the largest urban areas in the us between 2000 and 2018, and of course we've had crazy change over those 18 years in IT. We've seen the major rise of the internet and apps, which didn't really exist until the last 10 years, these mobile phone smartphone apps. We've also had two pretty darn big recessions over that period of time. In smaller cities and rural areas, which is what we're talking about here for most of my listening area were excluded because of missing data for at least one year. They use the data from the Bureau of labor statistics. They parsed both the broad difference in wages against other lower paying jobs, STEM professionals. Salaries they found in five places, Silicon Valley, San Francisco, Seattle. Washington DC and New York climbed as there was more competition for talent. I will interject there that I think that places like New York city are going to see a continued Exodus of IT professionals since there's so many people working from home. That is going to have an absolutely major impact on all of us IT workers in the rest of the country just didn't get the same bump.

    Let's see. So they're saying there's two distinct and competing forces on the one hand, the advantage of tech hubs and urban metropolises, especially the combination of dense population and vigorous innovation increasingly leads to higher it wages making some regions more attractive to skilled talent.

    On the other hand, this is not Ronald Reagan's, ideally economist, right? On the other hand, wage spread narrowed within advantaged areas, moving the top, 10% of IT wages into convergence with other STEM occupation. So they're saying, yeah. The highest paying IT job category that they examined, which was a research scientist paid between 140 and 170,000 per year in the Bay area. So that's almost a minimum wage out there considering how much it costs for a house, et cetera. 45% more than a typical region such as Indianapolis in contrast, in those with biochemists, they earn about the same wage in the Bay area as they do in Indianapolis on average. Isn't that scary? So it goes on and on. Superstars are not super paid anymore.

    There's major implications for organizations. If you're looking at IT wages. You need to use the same sort of reasoning you would have used for other skilled labor markets. There are HR people who are used to this. When you get into the rare parts of STEM, how rare are they really? How many openings are there?

    This is an interesting time and it's changing more and more at because of people working from home and the lock downs and you saw France just locked down. I think it was Switzerland just locked down. Belgium apparently is about to lock down. We've even got Vermont locking down saying, don't go into these two counties in New Hampshire, which is right across the river because of higher COVID rates. Now I'm not going to get into all of it cOVID rates versus death, right? What morbidities and other things, but it's really tough.

    People are moving out of the big cities, including IT professionals that are moving way out. We've had a lot of people moving into New Hampshire and other areas that are more rural. So I suspect IT jobs as well as other STEM jobs just are going to continue to go down.

    We just talked about AI in the last segment and its effect. I think AI is going to have a huge effect on the whole IT industry, but it's going to take a few years before it really hits.

    We were just talking about wages. We're going to talk right now about another reason those wages have gone down something I've seen personally that has caused harm to my business and that President Trump has been trying to crack down on. We're going to talk about cloud native apps too.

    Hi everybody. Craig Peterson here.

    Let's get into this guest worker program problem that we have. It's very upsetting to me because I have lost business. I have lost contracts because of this program. What's been going on, and I took advantage of this program back in the nineties. I had a company with about 40- 50 employees. They were all IT people and I needed somebody with a very specific skillset.

    I needed a couple of people and so I hired an attorney and what they did is they worked to show the federal government that we had indeed tried to get people to work for us with these skillsets and we couldn't find anybody.

    We needed to bring in a foreign worker and that was under what's called an H1B visa. We brought them into the country and gave them the jobs and the work and off they go. Eventually I ended up having to pay for the airline tickets to send them on back home because we didn't need them anymore after the whole dot com boom thing.

    It was a really, quite a mess back then. This whole H1B visa thing has been a real problem. We have some extremely large consulting companies that have been bringing in thousands of foreign workers in the IT space, tens of thousands of them. They then bid against US American companies.

    Some of these companies, even though they're supposed to pay prevailing wages, with H1Bs, we're not. What we've ended up with now is a clamp down on this.

    We bid on, we had proposals, where there was absolutely no way in heck that we could have matched the price of this other consulting firm using people that were paid about a fifth of what we were paying.

    We found this out, of course, after the fact. We'd dug into it, trying to figure out why, we were the obvious choice, why didn't they use us? President Trump has come to the realization that Americans need the jobs in America, first. He has put a bit of pressure onto this whole H1B program.

    The Daily Caller has an article out this week called Corporations use the STEM shortage myth to abuse tech worker programs that President Trump's announcement really sent shockwaves through the whole tech sector. He suspended most of these guest worker visas through the end of the year.

    The big guys in tech were all condemning this. You've got Google, Amazon, Facebook, Microsoft, all individually condemn the moratorium. It affects these H1B visas, that these big tech firms use to hire the foreign workers that they don't really need. Tim cook who's a head of Apple said he was deeply disappointed. Twitter called it short-sighted. Overall, they may reduce the cost of things that are produced here in the US because they work for much less money. However, The quality isn't there.

    I looked into, when I was bringing some people into the country, I looked into their backgrounds and found these people claiming PhDs and they have their certificates. Yet their background was basically a high school education. It was shocking to me. Shocking. Then what I also found is that some of these companies found somebody they were going to hire from overseas that would work for cheap money. As I said, a fifth of what we had to pay US wages and they crafted the advertisement and they crafted the language in the application to the state department, et cetera, specifically for that person.

    So they took the resume and they said, we need someone with these exact qualifications three and a half years in this technology two years in that technology, a degree in this and degree and that a five years experience in this so that they could then justify it because you post that ad somewhere and Americans are going to look at it and say, no, I don't have that exact qualification. Then they took those applications and they got the foreign workers that got them to come into the US. They were able to pay them a fraction of what they would normally have to pay a US worker. So that's where I'm coming from. Okay.

    I think that's pretty obvious these companies, Google, Amazon, Facebook, Microsoft, as well as these big consulting companies. I mentioned earlier. I didn't give names, but you've probably heard of them. they were all actually worried about their bottom line. That's got to be the sole thing that they were worried about here.

    Congress created this H1B program back in 1990 to help companies recruit skilled foreign workers, where there was a shortage of qualified workers in the US. But the companies have circumvented the H1B programs safeguards. They're weak. It's crazy.

    They've been bringing in cheaper and less qualified foreign workers, even when there's plenty of qualified workers here now. When we've got an unemployment rate above 10 or so, it's ridiculous to be bringing these people in. We have people in the US that can take these jobs that they just don't want to pay because they want to pay foreign workers.

    Now, we had problems before where they were shipping jobs overseas to again unqualified companies. People in the US were forced to train their replacements overseas. You've heard these stories before. I know people that were forced to do this in the tech industry. I's all fake. That's exactly what they're saying right now. Rutgers professor Hal Salzman testified in Congress that this whole idea of a science technology, engineering, mathematics, employee mathematics, employee shortage, this desperate lack of people trained in these fields is a myth.

    Rutgers professor Salzman said that they graduate about twice as many STEM students as there are STEM jobs for them each year. He said, in fact, Minneapolis, Federal reserve bank president Neel Kashkari dismiss the whole concept of STEM shorter worker shortage. Noting that skills gap is just a euphemism for, we want skills at lower wages.

    So if there's no shortage of graduates and Americans are willing to do the work, why are these big tech companies so obsessed with H1B visas? It really comes down to money. Let's see. There's a lot more detail in this article.

    I think Harvard did a great job Harvard business school on this, but man, we've got to be hiring Americans. We've got to.

    I'm great with people coming into the country. I'm an import, right? I've been here for many years. I got my US citizenship and I think it's a wonderful thing because we need new blood. We need talented blood. We need bright people. Bringing in these people for just cheap labor or outsourcing our jobs because it's a lot cheaper is going to hurt these companies in a long run. It's hurting the United States in the short run. There's no doubt about it.

    We are all looking at cloud apps. We probably use them every day. If you've got an iPhone or an Android phone, you're definitely using the cloud. Many businesses have looked at the cloud as a way to save money. Sometimes save a whole lot of money.

    A lot of organizations have decided that the cloud is this panacea that they can use. Because of the pandemic, why not shift the worker's functions to the cloud and get rid of our local computer room, data center closet, wherever it is, you might have your file server, et cetera.

    We have a huge security fallout now because of this sprint to set up employees home offices, because it's not just about vulnerable end points in home networks anymore. We've now rushed into adopting cloud-based technologies that have not been secured. It's absolutely nuts. We've got this hybrid physical cloud-based IT infrastructure and it is altering the landscape. Obviously it's already altered in 2020, but 2021 and beyond it is going to be just changed forever. So how do you manage it? How do you put up guardrails?

    Look at what's happened with Amazon web services, with their S3 data storage and how many security breaches there have been with S3. These buckets being wide open. Salesforce, Slack Service now, and others have all had hacks. We've got major potential for vulnerabilities because we're tying together systems that were never even designed to be working together in the first place. Certainly weren't designed for security in the first place. So this is just a hint of things that are to come. Okay. It's very easy to mess up cloud security. Now there's a number of startups right now that are out there trying to address this. Jupiter One came out of stealth mode here. They had $19 million in series a funding that tells you how much these investors are thinking they're going to make off of this. This service automatically finds and keeps updated online, physical and virtual devices and assets and organization, including cloud native services. That doesn't seem like it's that hard to do, but man, the misconfiguration of all of the Software as a Service, or Cloud Native is common and it's mainly due to human error.

    So if you are using cloud services, I really would suggest that you, if you're a business, you assign someone to look into this or you look into it yourself. You're using Dropbox. You're using Microsoft O three 65. What are they doing to secure their data? A lot of these services don't even guarantee that they'll back it up and just had a huge data loss a because it wasn't being properly backed up,

    Hey, if you have any questions, just email [email protected].

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 17 min
  • IT Wages are down, Big Tech and HIB Visas, Ransomware and the National Guard plus more on this Tech Talk with Craig Peterson Podcast

    Welcome!  Craig has an exciting podcast that covers quite a few interesting topics this week including USB safety, Properly disposing of your smartphone before getting a new one, Why the National Guard is being used to investigate Cybersecurity incidents in Louisiana, Iran, and threatening mail sent to democrat voters, Phishing is back in the news and why you must train your employees to watch for it.  Then he talks about IT Wages and problems with the H1B Visa program.

    For more tech tips, news, and updates, visit - CraigPeterson.com.

    ---

    How safe is your USB drive?   How to protect your privacy when selling your phone
      Louisiana Calls Out National Guard to Fight Ransomware Surge
      U.S. government concludes Iran was behind threatening emails sent to Democrats   How AI Will Supercharge Spear-Phishing
      IT Job Wages Are No Longer 'Exceptional'
      Need for 'Guardrails' in Cloud-Native Applications Intensifies
      GIRDUSKY: Corporations Use The ‘STEM Shortage’ Myth To Abuse Guest Worker Programs

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We've even seen where USB thumb drives come pre-infected with viruses and other pieces of nastiness. So, just how safe is your USB drive in this day and age of us taking them home and to work?

    Hi, everybody, Craig Peterson here. Welcome. We're going to be talking not only about USB drives, but how to protect your privacy when you're selling your phone. Okay. We've got a national guard call out in Louisiana over the election. We've got the government concluding that Iran was behind some email sent to Democrats and we've got artificial intelligence that's going to just supercharge, spear phishing. We'll be talking about that. Defining both of what they are.

    IT wages are no longer considered exceptional. That's a study from Harvard business school. Guardrails in cloud-native applications are needed. That's a great call. I love that.

    Corporations using this STEM shortage myth to abuse the H1B programs. H1B visa programs that President Trump has been trying to clamp down on.

    What do you call these little devices that we have these a USB drives, thumb drives? what do you call them personally? Probably about 10 years ago, I grabbed the domain. I registered thumbdrive.com and I never did anything with it. I was thinking, Oh man.  I could have a whole bunch of different thumb drives up there.  I ended up letting it go when I was really low on cash one time. I just went to it today. Thumb drive.com and it's somebody selling Toshiba thumb drive type stuff.  It's still the disappointments in life that you tend to remember much more than the successes. So it's a bit of a shame. But thumb drives have become way more useful in this day and age. We're going from work to home. Our kids are taking their work for school. They've got to bring it to the teacher. Many of the times, of course now it's electronic, right? We upload it. We don't even use FTP anymore, but we upload it. We download it and we might email it. We use Box or Dropbox or Google drive in order to share files. That's really the most common way to do it nowadays.

    But thumb drives are still out there. They're still in wide use and I still have a supply of them and somehow they all seem to keep disappearing and that's where the problems start, really?

    If you own at least one thumb drive, you've transferred a file. You might've used it as a method of backing up some of your documents or your photos or other things you might like to carry your work with you. So you can dive into it at a moment's notice and you keep it in your pocket. I have one that is waterproof. It's a light fireproof, and it sitting there on my key chain. So that I have it if I ever need it in order to do something and you know what, I've used it a few times, but not so much. I've even got thumb drives in my wallet. Just really thin ones in case ever need them. I have used them from time to time.

    If you're like most people. You might be using thumb drives that aren't necessarily trustworthy. So let's talk about that for a minute. Students tend to use flash drives to print out study materials at a Kinko's store, or maybe they go to a library to grab something. Maybe you are using it to move documents back and forth to your work, to your family events, soccer church, or whatever it might be.

    Now, when we're talking about kids, they also tend to lend their classmates these drives, and they might have their notes from their class on them. They might've made their notes on a Google Chromebook, and now somebody plugged it into a windows laptop or Mac. Think about spreading diseases, right? It's the same sort of thing as they're passing them around and sharing them.

    It's not just kids in school, in college. It's also friends at the office. It's friends that you have at home and you really can't be sure of these things and how protected they're going to be.  If any of those thumb drives have been infested with malware, it's really very possible that your computer, if you've used one of these infected thumb drives, that your computer is now infected as well.

    Some devices like your Macs, for instance, you've got a Mac laptop are immune to all windows viruses that are windows based. So it can spread them. It's like a little super spreader. So that if there is a virus for windows, that's on your Mac in a file, your Mac, will be just fine. It doesn't care. But when you now transfer it to somebody else, or you put it onto a drive you're in big trouble. here are some options that you can take.

    Microsoft has made a big change a couple of releases ago, major releases in the windows operating system. There used to be an autorun file that was there, on, for instance, a CD drive or a thumb drive. So when Windows opened it up and said, okay, I'm going to run this file. And that file would do something like cool, play a movie for you. Or it might run a video game or whatever it's supposed to be doing on there, but the bad guys started taking advantage of that pretty early on. They started using this crass cross-contamination route using these autorun files as a way to send all of their malware to other people. Okay, so you have to be careful.

    We're going to get into some solutions here in just a minute. What really do you have on your thumb drives? I want everybody to think about it for a minute. What are you using them for? How can they be misused?  What happens if they're lost? I mentioned that this week on the radio, what happens if you lose the thumb drive and it has some intellectual property on it?  has personal information on it?

    I know a couple of listeners who are using external drives, which are more common now than they used to be. They plug into the USB port. It's the same sort of problem. You can't put these into your pocket like you can a thumb drive, but you can certainly share them. You can move them around and they're using these USB drives now spinning media, or sometimes even SSD, they're using them to move stuff back and forth.

    So how do you deal with it? One of the ways is what we tend to do for our customers that need high security.  We remove the mechanisms for people to be able to use them in the first place. We'll disconnect it from the motherboard if that's possible and we'll fill the port with epoxy. So people can't just put it in there. Now most of the time, they're not being malicious. They just want to plug it in and grab this file.

    But there are people who are malicious who are trying to steal data. Which is why, again, in high security, We remove those USB ports. So that the thumb drives just can't be put in there. Companies like IBM have opted to completely ban removable storage devices, period. It's a real big deal. They were talking about all of this at WeLiveSecurity.com Amer Owaida is his name who was talking about some of this stuff. But when he looked around, he found that IBM was banning it, many other major companies were.

    Let's start with what can be done. First of all. When we're transferring sensitive information from one place to another. So for instance, we might be tightening up security in a doctor's office or helping a doctor's office upgrade their systems, and we need to send all of their patient data.

    To the third party who now has this new system that they're going to be starting to use in the doctor's office and we want it to be secure. So we have a disk drive cabinet that is encrypted the whole thing is, it's just a little thing. It's not much bigger than a disc drive and it has a drive inside of it. You have to enter the key when it powers on, and then it uses that key for the encryption on the disk So even if somebody breaks into the case, it doesn't matter because the disk that's inside is encrypted using this key. So you could consider doing that. There are thumb drives that have built into them. Thumb print readers. Most of them that I've seen are pretty easily defeated, but let me tell you that's harder to do than, having to defeat one of these things than just plugging in a drive that's not encrypted okay.

    So step number one. You need to have, if you can use them, drives that you can trust for confidential information. That means they need to look different. They need to be different than the drives that you are using for home for your personal data, for your personal backups.  So first of all, they need to look different. So maybe just having that thumbprint reader on the drive is enough to remind you. Sensitive data should be on that drive with a thumb print reader.

    The next thing you probably want to do is encrypt all of the sensitive data that you want to load onto the drive. Now there's a number of ways to do it. You've got built right into windows, full disk encryption. Same thing's true for your Mac. So you could encrypt it that way. You can also use something that's free. I think it's pretty easy called PGP, which uses public keys.  You encrypt the files before you put them on the disks.

    I do like the hardware security solutions for the thumb drive that uses a pin code. That's probably best, as I said, I don't really trust the biometric scanners, but there's some really great articles out there about these thumb drives, and what could possibly go wrong.

    Now there are thumb drives that are designed to burn up your computer, literally melt it down. Don't pick them up. Oh yeah, we've used that trick against Iranians before.

    Our smartphones have our lives on them. There are some very quick ways to make sure all of your data on them are destroyed, because we're upgrading these things left right and center.  It isn't just about e-waste as they call it. It's about your personal information.

    Let's start getting into our security here on your phones. People are getting rid of their phones on really record rates. In fact, in market for new customers, their smartphones has dropped dramatically. We've reached saturation in most markets, worldwide, where people who want a smartphone have a smart phone, people who want an iPhone or maybe an Android, heaven forbid, have got those devices and they're pretty happy with them.

    Now, the Android is going to be cheaper initially. If you ask me, it's way cheaper in the longer run to have an iPhone. What do we do with these things? We're talking about 50 million metric tons of e-waste every year and a large part of that is our smartphone devices.

    Most of it isn't recycled. However. Your smart phone can be. So instead of tossing it into the trash, I think you need to look at a few different options. You can recycle it. You can donate it. You can sell it. There are a number of different places that you can go in order to get rid of these things and really make back a few bucks in the long run here.

    Best Buy, Whole Foods, Home Depot, Lowe's and Staples typically have free drop off spots to take dead batteries. So that's step one. If you have a removable battery. You can remove it and drop it off on one of those. You can also check out a website that's called earth nine one one, and it's simple or nine one one.com and it will tell you where you can recycle these things because they've got all kinds of nastiness in them. The button cells, the older ones had mercury. You've got lithium, you've got zinc in these things. So that's always a good place to go to start recycling them.

    There's also cell phones for soldiers where you can donate. That's their website, cell phones for soldiers dot com they will take your cell phones and they'll provide them to soldiers overseas. This is really cool too. Cell phones for soldiers also provides about 2,500 calling cards every week as well for the soldiers to use. Man, I'm choking up a little bit here. 

    In case you didn't know it, by the way, we're planning on building a 4g cell phone network on the moon and a 5g cell phone network on Mars, like real soon now with the next couple of years. So maybe you can donate them to NASA for them to take while they go up there. Now, there are a few places that you can go to. Recycle specifically, and I've used Gazelle before.

    Let me just check. Make sure they are online still. Yeah, there they are. Gazelle, G a Z E L e.com. They'll let you buy refurbed pre-owned phones. You can sell them as well. They'll trade them in for cash. So let me just see, I'm poking around on their website as I'm here.

    I'll tell you how to clean up your phone securely here a little bit, but let's say like me, I've got an iPhone eight plus, right? That's my phone. It's probably about time to upgrade it.  I'm going to say it's factory unlocked and it's saying, I think mine's a  two 56. So I'm going to say two 56 because I want money. Does the device power on? Yes. If I slowly functional all parts work. Yes. Front and back. Free of cracks. Yes. Cosmetic looks like new, which is true. So for excellent condition worth 181 bucks, light signs of use it's worth 173, normal signs 160 bucks. Then you can send it in. I've even seen gazelle having kiosks, where you can go ahead and just put your phone in. They have cameras in them and somebody remotely will look at the phone that you just stuck into it and will give you an offer. So there's buy-back services, flip C and all kinds of others.

    So before you get rid of it, make sure you have a good hard look. Declutter gadget gone. That's a cool name, right? Oh, Apple, by the way, they've got store credits. I got $300. Last time I turned in my iPhone at the store. right now my iPhone eight is worth 170 bucks at the Apple store. So it's worth about the same as it is worth over on gazelle. Best buy let's you trade it in. Some will take them to Craigslist, Facebook marketplace, E-bay and others. So there you go. There are some things to do with that phone. Eco ATM, by the way, that's the name of the ATM that's owned by Gazelle trade. Amazon has a trade- in store, but just look, if you do a search for gazelle, you're going to see ads for others as well.

    Before you do that, let's talk about your privacy here. Before you just throw it away into one of these recycled bins. So this is some suggestions from Tech Republic and I'm of course, going to add my own little tips into this as well. Veronica Combs wrote this original article. she says that you should unpair all devices. I don't think that matters really. I don't think you have to unpair anything because of what gonna do next is sign out of all services.

    Now that can be important. If you have an iPhone, what all you really need to do on your iPhone is go to the settings. Once you're there in settings, you're going to go to general and then reset and then select a erase all content. Before you do that, you're going to have to turn off, Find my iPhone because if find my iPhone is turned on not only does it let you find your iPhone, if it's lost or stolen. but What find model iPhone it is Also it makes the phone, so it cannot be erased and then used by a third party. You have to be able to log into the phone using your Apple ID if it has been reset. So turn that off first. Find my iPhone. Then go to settings general, reset, erase all contents. Now it's not really erasing the content on the iPhone and also un-encrypted Android devices. What it does is it destroys the decryption key. That only takes a second or two. Once that's destroyed that phone is now completely reset. It's like a factory reset. There is nothing left on the machine. So on Android phones turn off the factory reset protection.

    This started a couple of releases to go with Android. You can go to settings, privacy, factory data, reset, and then choose reset phone. once you've done that with your phone, either one of them. You are safe to send it off to a recycler.

    Now, if you're like the campaign staff for Hillary Clinton or her phones themselves, they just took ball-peen hammers to them. Once the investigation had started and it was illegal to destroy evidence. So remember that, if you use a ball-peen hammer, apparently it's legal to destroy it that way. By the way, it'll make it pretty much unrecoverable if you really bash the living daylights out of How could our elections be attacked? Well, they already are according to a report right now in Louisiana.  It may not have been directed at our election infrastructure, but it sure is affecting it.  Here we go.

    We have some serious problems being reported down in Louisiana. According to threat post the Louisiana National Guard, has been called out. Now that's a very big deal. You might ask yourself, why would they call out the National Guard to battle a cyber security problem?

    That would be a good question, if you were to ask, so let's ask it. The answer to that would be. That the national guard, as well as our military, have been trained. Not all of them, obviously. They have teams that have been trained to do cybersecurity work, and we've done some. I've done some training on that for the FBI InfraGard program, so I have some intimate awareness of how this stuff works. Here's the bottom line, according to the article that was in Reuters. They're saying that there's evidence suggesting a sophisticated hacking group was involved.

    So what happened now? This is something that happens to businesses. It happens to government agencies. It happens to almost everybody out there. They were attacked. Most of the time these attacks are coming, the more successful ones, in the form of phishing and phishing campaigns.

    I've got some training that if your company really wants to do some, phishing training, let me know. I have some excellent training materials and we buy licenses for these from our third party. It just isn't worth it for me  to do custom training for all of my companies and we buy these things in blocks and I have extra licenses. We buy them a thousand at a time. So if you'd like to offer some security training for your employees, that's primarily focused in on the whole concept of fishing and what they should be doing, what they shouldn't be doing. Social engineering even goes so far as to inbound phone calls. Let me know, just drop me a line. [email protected] and I'll be glad to get back to you. We can make some arrangements to help you out there.

    Cause I know a lot of companies just don't know where to go and you can't afford these expensive trainings. We have some extra licenses, so we can definitely help you with some of that stuff. So just email [email protected]. If you'd like to get a little bit of that training and I can probably do it too for a home users, if you're interested, let me know. I'll see if I can't just drop you into one of these classes with one of my business clients, that, again, it's a nice little series of training. I think they do a really good job. I should be able to squeeze some people in here and there. So let me know.

    That's how most of the time bad guys are getting into our networks. They send an email, it looks like it's legitimate. It looks like not only is it legitimate, but it's something you need to open and you need to open it right now. These guys have gotten really good at that sort of a thing. Then you click on it and they have your information or they have you running a program for them.

    Now, many times these programs are called RATS, which is a remote access Trojan. If they can get a RAT onto your network, it's over for you if you don't know it's there. That's why we always suggest and there's a few companies that have these, I like Cisco, but there are some other good ones out there that we work with, that have the ability to detect these Trojans. They're  watching them calling home. Where are they going?

    A remote access Trojan on your network means they can remotely get onto your network right through your firewall. Right through it and then start doing whatever they want to on their network, anytime they want. That's part of the reason I really strongly urge everyone to use umbrella and you can find it,  just umbrella.com. We sell the professional version of this for enterprises, but they have free versions as well. That are simple as just changing your DNS server IP addresses. They've got them right there on the homepage. Two, two Oh (860) 722-2222.  It explains it all. If you just go to umbrella.com.

    The idea is you use the Cisco umbrella software for your DNS server and if there is a Remote Access Trojan, when it tries to call home to give the bad guys access to your network, it is foiled in its attempt.

    It doesn't block it per se, but it's like hopping in an UBER and saying take me to one, two, three main street and the Uber driver says, I don't know where that is. That's kind of the equivalent here, you ain't getting to one, two, three main street if the car or the driver doesn't know where that is or how to get you there. That's what umbrella does for you. There's free versions of it.

    If you're a business you should use one of the higher level ones. What we sell the enterprise version is tastic for businesses because it allows it all to be customized as well. Umbrella has family stuff too, that you can use and the family stuff is great too. You can keep the kids from stumbling on websites that they probably shouldn't be stumbling on bottom line.

    This paper that was released, showed that they had done a forensic investigation.  I'm looking at this Reuters story, that goes into it and they found something called the Kim Jong rat. Which is a back door. It is a remote access Trojan and it had a source code leaked.

    I haven't checked lately on the dark web, but it used to be a little buy tools like this for 20 bucks. They're not expensive.

    So problem number one, the bad guys got into Louisiana's government networks. Problem. Number two, they installed a remote access Trojan in the network. Very common. Usually within a week to two weeks after that  been installed, they will have examined your network and they are going to be digging in even deeper.

    What did they do here? Wow. They installed the Trojan. Now I've talked about this before. We've seen attacks involving EmoTet, it was found also in the networks of these government victims, according to Reuters. The EmoTet Trojan can also load other malware and it's like a worm. It propagates all by itself through the networks, onto the file servers and onto the desktops and laptops.

    It also, by the way, is just as happy to spread through a VPN connection. Do you know what I think about VPNs? They have their place. I use them, but as a rule, VPN's not a good idea.  For most very small businesses, not at all. Okay. So this is a problem. 

    We now have the national guard in Louisiana called in according to Reuters to protect the systems, when we're in the middle of election season. Isn't that fun? 

    Before we get to that, I want to talk about this email. That concludes that Iran was behind sending these very threatening emails out to Democrats. How could that have happened? What should you be looking for? We got answers.

    There have been some emails that are very scary out there. There were supposedly from this pro-Trump group called the Proud Boys and they have a very scary message. The messages say that they are in possession of all your information. By the way, that if you really want it and you're willing to pay a few bucks on the dark web you can probably get anybody's information on almost anything, okay.

    But in there in possession of all your information and they've instructed voters to change their party registration and cast their ballots for Trump and I quote here from the emails, and this is an article from the Washington post. Yes. It says you will vote for Trump on election day, or we will come after you. So pretty, scary stuff.

    Some of these were in a hotly contested swing States in the upcoming presidential election. It's going to be one heck of a season here. Let me tell you. But the U S official said privately that through the post that the operation was not terribly sophisticated and they said it was disclosed before it could have any major impact.

    The cybersecurity researchers that they spoke with said little about the operation.  They're thinking there wasn't a large scale deception. We'll see what happens. It was first divulged Tuesday by local law enforcement and election officials in Florida and Alaska, and people rightly reported them. For FBI reporting, it is IC three.gov online. If you get an email like this, or you get another threatening email or something that you think the FBI might. Want to know about because they do investigate these things.

    I am involved in a couple of their investigations, that revolve around China and Chinese espionage. Anything like this, you can report, just go to IC three.gov. I C three as in internet crime complaint center. I C three.gov. Okay.

    This is a real problem. In 2016, it took months for the Obama administration to publicly point the finger Moscow for the hacks and leaks of democratic e-mails despite the intelligence community, having determined Russian culpability early on. So there you go. The Russia story continues at the Washington post, but this came up from a disclosure by the Director of National Intelligence, the DNI, John Ratcliffe.

    I like the fact that president Trump has, I'm not going to say strong armed, but he certainly has convinced our intelligence agencies to be more open with the public. Be more open with business, this FBI InfraGard thing that I'm involved with and did a lot of training, meaning over the years for, it's been around for a very long time. Let me see. 1996 it's been around. So it's a partnership for protection. It's a nonprofit, they have a lot of volunteers like myself that are involved with it. So the cooperation between the fed and business is nothing new. 96 was a long time ago. That would have been what President Clinton, that did that, but it actually started in Ohio and one of the field offices, as I recall.

    President Trump here has taken this to the next level and we have had disclosures from the NSA. Remember NSA, we used to joke is true for no such agency because it was just so secretive. The NSA has even released information about vulnerabilities in our systems. So it's a huge deal.

    On Thursday, by the way, Iran, some in the Swiss Envoy in Tehran, and Switzerland is who handles affairs for the US there, because the U S doesn't have an embassy or anything really there in Iran. Other than probably the CIA. They were condemning the baseless accusations of meddling in the U S election.  They said the Iran has no interest into freeing interfering in the US election. It's the old habit and there's a new name for it, but the old habit of keeping information from people. You might remember in World War Two, right? If you tell a big lie often enough and you tell it with absolute rigor, people will believe you nowadays, they call it gaslighting and it's been very effective. So that's the Iran is trying to do. So be careful with those emails.

    So that kind of leads us into this whole thing on spear phishing.

    If you miss it today, I'm going to have that up on my website, along with IT job wages and pretty much everything else. I try and get it all up on Craig Peterson.com. I send out my weekly newsletter and we've also sent out some that people are really interested in. If you didn't get it this last week, you might just drop me a note.

    We don't automatically send it to people who sign up new. So if you are going to go to Craig peterson.com/subscribe right now, you'd only get future newsletters. You wouldn't get the past ones. This past weekend I put together a really great newsletter. And it talked about taking your computer in for repairs.

    I used this fictitious character called Hunter. Who took his Mac book into a computer store to have it repaired for water damage.  I came up with all of the main things you should do step-by-step before you take a computer in for water damage.  I think if our fictitious character Hunter had done all of this, he wouldn't be in all of this big trouble with this daddy, but I can send that to you, if you're interested. We talked about it a little earlier this week as well, but just email me at Craig Peterson dot com. And let me know you want the Hunter email. I'll be glad to send that to you.

    Also, if you sign up, I am going to be sending you some of my most popular special report. The stuff you need to know, because everybody needs to understand how to do a security reboot.

    I've got some very in-depth courses, but let's just start you with a simple checklist. I don't want to confuse anybody. So it's easy enough for me to just reply to you when you sign up and send you this stuff I have at this point about 60 different six zero different special reports.

    So when you ask a question, oftentimes I can just send you a special report on it. Oftentimes if I don't have a special report, I will write one. because if you're interested, other people are entrusted too.

    So make sure you sign up and you can just do that by going to Craig Peterson.com/subscribe. I'd be glad to do that for you.

    We also have a couple of things, that I really want to cover quickly here when it comes to the election and election technology. I think as a whole, our election is pretty safe from a technology standpoint, right? I'm not saying anything about people printing their own ballots and sending them the in. About gathering ballots about bribing people to vote a certain way. That's not what I'm talking about. Obviously, all of that's easy enough to manipulate. We've seen post carriers who are dropping ballots into gullies and ditches and trash cans. That's one thing.

    On the other side, there's the technology. I am pretty confident that in most of our States here where we are using these paper ballots and they're more like a light cardboard, right? What a hundred pound stock give or take 80 pound where we fill in that oval. Then we take it up to the machine. We put it into the machine, which reads it, optically and tallies. It I'm pretty confident those machines are in good shape.

    One of my sons, who works with me and he's a Cisco fire jumper certified guy. He is also one of these election overseers. He had a look at machines that were shipped off from the Secretary of State's office, and even though some of the seals were broken, The seals that really counted, which are the seals over that little memory card inside that optical reader. Those seals were all intact. So that does my heart. Good. I'm also pretty confident that the people who are working the local polls and tabulating are being supervised and there tend to be Republicans and Democrats and independently minded people who are overseeing the process. So those tallied numbers that are then sent off to the Secretary of State's office, I think are likely to be correct.

    Then the Secretary of State's office, puts them up on their website and then the Feds are going to look at them. That's where I'm the most worried about it. Emails sent to the Feds with tallies. The feds visiting a hacked website.

    We just went through the major ransomware and remote access Trojan problem that they're having down in Louisiana. That is a very big problem because that could be a weak point that would be exploited by people who wanted to change our votes.

    If you are involved in oversight in this stuff, make sure everything is double checked with the human. Get on the phone, call somebody, call the Secretary of State's office to verify. If you're working at a local polling place, verify that the Secretary of State's office has the right numbers.  Then make sure the right numbers are on the Secretary of State sites website.

    The rest of this is going to be an absolute disaster. What can I say.

    Craig Peterson (2): [00:38:49] You've probably heard about spear phishing. I did a little phishing myself online and looked at some of these companies, like Barracuda that are saying that they stopped spear phishing attacks using AI. Hey, I've never been a fan of Barracuda.

    Now spear phishing is by definition and this is from CSO online.com,  is the act of sending an email to specific and well-researched targets while purporting it to be a trusted sender.

    Now you've seen phishing. If you've been on the internet for the last 10 or 20 years, you've probably seen what's called the Nigerian Prince scam. That's an idea that has really perpetrated into every bad guy's mind over the years. The idea is, Hey, if we can send an email out to people and find the gullible people, maybe we can make some money.

    It's fishing just like you might be out in a boat and you're casting a net to catch a certain type of fish. You hope that the gill size is right on that net and you're always catch some other things, right?  Dolphin, tuna, and some of these other things, but, you don't really care.

    What we're talking about here with regular phishing, which is spelled P H I S H I N G. We are talking about bad guys casting a huge net. This net is out there to try and catch anybody, anything there will go ahead and get caught in that net.

    So the Nigerian Prince scam is, Hey, I am a Prince in Nigeria and I need to move my family's $1 million worth of wealth and the only way I can do that and get it out of US banks is if I have a US bank account. So if I could go ahead and I'll transfer in this $10,000 that I need to move. I'll let you keep 2000. So I'm going to transfer 10,000 into your account, and then you're going to wire me $8,000 of that money and you can keep the $2,000.

    Now, there are many forms of this scam. The Nigerian Prince scam is one of them. Of course what's happened here is they say they wired the money in, and that money may show as pending in your account coming from an overseas account. So you look at, and you say, Oh yeah the $10,000 is there. The Nigerian Prince contacts you and says, Hey, I sent you that $10,000. I really need that 8,000 now, or I'm not going to be able to get my mother out of jail or something along those lines, kidney for my best friend on and on. People look at the account, look at that, there's that $10,000. Now they go to the bank and they wire the $8,000 to this account overseas and off goes your $8,000. When you wire that money out, it is gone.

    What happens is a few days later, it can take a anywhere up to basically two weeks for the bank to clear the money. I know about the check 22 laws, that's all down the tubes. It's eight days to two weeks usually, especially for international transactions and they can take three weeks or longer sometimes. That transaction where he wired the money in is canceled on his side because he's got an inside thing going on with the bank. So you thought you had 10,000 that he had put into your account. You wired out 8,000. Net 2000, that's not so bad.

    But then a week or two, or maybe even three weeks later, your bank contacts you for insufficient funds because that $10,000 transfer that he was putting into your account, actually never finalized and never really happened. So you have now sent him $8,000 of your own money. So that was the Nigerian phishing scam.

    There are a lot of scams that are based on that are still out there today.

    One of the big ones that the FBI just a few months ago arrested a dozen or so people out in California for is a mule scam.

    I don't know if you saw this latest Clint Eastwood movie. I thought it was pretty good. I've liked Clint Eastwood for very long time, but he has a movie out called The Mule, came out in 2018. This is a 90 year old, horticulturalist and Korean war veteran that turned into a drug mule for Mexican cartel. A very interesting movie, rather believable, a lot of movies that just totally rip apart. but I enjoyed this enough to allow it to be believable. He was hauling money for the Mexican cartel.

    What these people in California were doing is they were money laundering and that's typically called a mule, they're moving money around.

    They would get some money from somebody. It much like this scam. I was just talking about with the Nigerian Prince scam. So they say, Hey, we're going to wire some money into your PayPal account, for instance, or we're going to route wired into your bank account. And then we want you to use PayPal to send us the 90% of the money.

    In this case, these mules, we're not getting ripped off. They would actually get the $10,000 in to the bank account and then they would send $9,000 via PayPal and the bad guys were happy cause that money is laundered, it came from a more legitimate looking source.

    I had some really great trainings that I did on this for the FBI InfraGard program with some think it was a secret service guy, and they tracked a lot of this down. There were some arrests here a couple months back.

    We have to be very careful about this and how we're transferring money around and whether or not we do it for one of these people. Because we're getting tricked.

    What's happening is these people who are doing the spear phishing are doing research on us.

    We had a great example of another spear phishing thing. There was a company in the UK that was purchased by a German company. They knew all of the basics about this German company and they got a phone call one day from the CEO of the German company. The CEO told them to wire some funds to this particular bank account, and they did. It sounded like the CEO. They used some technology to impersonate, the guy's voice. They went ahead and wired the money.

    Then we got Barbara Cochran who is one of the sharks on shark tank. Her assistant went ahead and wired, I think it was like $400,000. Another assistant of hers, her executive assistant, caught it, noticed it, because she was CC'd on the response, freaked out. They managed to stop the transfer from happening. So good news on that one.

    These scams are out there and they're out there big time.

    I have another one where a lady was going on line and doing research about business owners. She found a couple of business owners, actually quite a few. She wanted to narrow it down. So she researched them. She found some of these business owners had Facebook pages. She went to the Facebook pages and while on those pages, she found those business owners that said that they were going on vacation. She followed them a little bit and found out about where they were going when they were going. Then she managed to trick the email providers. Into letting them into the actual email account, which she did in this one case, where she got more than $40 million out of the company.

    She finds out who the CFO is and then when the owner is on an airplane or is in Bermuda in cannot be contacted. She then sent off an email to the CFO saying, Hey, we've got this new provider, a supplier we've had for three months and we've never paid any of their invoices. Here's the invoice on the bottom of the invoice or statement the bottom of the statement it says, or to wire the money to, I need you to wire right now, or we're going to be out of business next month because we've never paid this new supplier that, and it's critical. The CFO wired the money because she had done her research and that's what it takes.

    They want to send you an email that is really coded up for you.

    That fake email that you got represents a huge industry and that industry is undergoing some amazing changes. They are using artificial intelligence for evil. So we're going to tell you about it right now.

    Now, these types of phishing, where they are going after a specific person, after doing a bunch of research are called spear phishing attacks.

    It's not like those from the mid nineties where you had the Nigerian Prince out there sending emails and just waiting for anybody to respond to them. These are aimed at someone individual.

    Here's an example that was in Dark Reading this week, where it says:

    Hey, I'll see you at nine for our four hour call. You're going to kill it today. See the dial in details for the call attached. Cheers, Al.

    Now most people would not question the legitimacy of this email. It's kinda laid back. They might've done some research on Al. They might have cracked Al's machine. Somehow gotten a list of all of his contacts and sent this to everybody in his contact list that worked at the same company.

    This is happening all of the time, everybody. So be careful of this.

    So you get it. Looks legit. Everything about it smells legit. You're going to open it up because heck I'm going to kill it today in our nice little conference call, right? Yeah. That's what you're going to do.

    But what could well be happening here is that email attachment that they said, Hey, you need to click on this, could well have a malicious payload. So you have to be careful and it may not have a malicious payroll payload on it. Maybe it went through the email filters looked pretty good, but maybe the website it's pointing to, or even the file on the website it's pointing to is malicious is a malicious pay load.

    So you've got to be very careful and you could lose your job in total embarrassment. You could really the harm the company by opening this. But it's getting worse.

    It's going to get even worse right now. There is something called offensive artificial intelligence. This is ushering in a whole new era of phishing attacks that are going away from these more simple ones, the broad phishing attacks, even the spear phishing attacks, where they do some research about your company.

    I've picked up a few clients, unfortunately, that have had these attacks worked successfully. And then we had to put in some really great software to make it even work better for them.

    Artificial intelligence can go out and start looking around, can figure out what's going on. For instance, blue.ai, found a cluster of pneumonia cases around a market in Wuhan, China, it flagged it and found it nine days before the World Health Organization found it.  It's now being used to look at all of this health literature from around the world about COVID 19, the Corona virus, that we have this novel one and figure out what's going on and it's even comparing it to DNA. AI can be absolutely wonderful.

    We use it for monitoring and protecting various types of networks, but inevitably AI now has opened the door for sophisticated cyber attacks.

    It is really crazy what's going on right now. Cause it's not just these phishing attacks, it's going to agument every type of cyber attack. It's using adaptive decision-making capabilities based on what it finds inside your network.

    This is scary as heck because once it gets inside your network, think of Skynet, right? That's really what it's going to ultimately be like, maybe not with Androids out there trying to shoot us, but trying to steal everything we have.

    Our email boxes are just going to be used as a stepping stone to get into the business network.

    The only way to really compete with this is to fight AI with AI. That's what's happening with some bigger companies out there.

    I did a little searching of my own online and I got a little upset because I came across an article.

    At the top an ad for Barracuda. Now, I've known these guys for a long time. They have used open source, freely available firewall software and other software to build their business and, good for them. There's nothing wrong with it. That's our open source software is for.

    But there seem to be some misrepresentation that are out there. That's where it gets scary.

    Right there on their website, Barracuda Sentinel, get AI based protection from phishing and account takeover. You read down a little bit further block threats already in your email, in your inbox. Stay a step ahead of attackers with AI based threat detection. Stop wasting time managing static security rules. I agree with that one. I think the problem that we have is we're putting a lot of trust in these companies.

    This is Barracuda. I have had clients who've used it before, and I've had nightmares trying to fix problems with it, but that's me.  I could tell you about them if you wanted.

    On the other side, there are other systems, like from Aruba, Cisco, which is what I use and sell,  these are not a panacea. There are all kinds of things that you have to look at and you have to be tying them together.

    We're no longer just dealing with the perimeter. It's no longer just having a good firewall or trying to have a good email filter. Now we really are talking about this Zero Trust model because AI is being used by the bad guys. It is getting into our systems. We have to make sure that none of the data, what we call in the biz, east-west or west-east traffic, east-west traffic, none of that internal data, internal communications is going somewhere it shouldn't, or is being used incorrectly.

    Spear phishing is difficult to detect. It is very difficult for AI detect it. It is much easier for person to detect it. You need to do training on this. Have your people get some training. I think it's just that important.

    This whole business email compromise thing that the FBI has been talking about. That's all tied into spear phishing. So we gotta be very careful.

    Harvard business school has a really interesting article out right now about wages in IT of course, information technology. We used to call it MIS management information systems, way back when.

    Hey,  it's bringing back memories of when I was a professor out at Pepperdine university. MIS 422? That class anyways.

    Harvard has been of course helping people in all kinds of aspects of business, which includes things like the law, IT and General business, as well. But they've come out with something that has really surprised a whole bunch of people and it has to do with IT job wages.

    I have talked about getting jobs in cybersecurity and how many open jobs there are. I think the biggest problem people have is getting into cybersecurity and then getting the support they need, once they're in cyber security. Over just the last few weeks, I've had a couple of listeners who have sent me an email and I asked a little bit about it and I pointed them in a couple of different directions and even pulled another listener into one of the conversations who has moved into IT security. Exceptional wages were the norm in computers for a very long time. You got paid good money, if you were good in it whether it's in management or in coding.

    I made good money for a lot of years as a kernel programmer. Writing the operating system itself and device drivers and implementing internet protocols and designing new protocols. I made one of the world's very first centralized security systems for computers and computer networks. Way back when. So it has been around a while and it has paid very well. Their jobs have always been stable, the fast rising within the organization and made a lot of money. Back in the nineties, you had the dotcom boom.

    It really bothered me, all of these people that started hanging up shingles saying,  I'm an IT person.  I design websites. I do these and they've never really had any real experience with IT.

    To this day still bemoan.Microsoft products. Because it seems like it's a chimpanzees throwing darts at boards, as far as trying to make sure their systems work and inter-operate and don't even conflict with each other. It's so frustrating. Since I've been in the Unix side for so long and the mainframe side as well, the systems that work well and work consistently.

    It turns out the things have changed a bit now when it comes to the wages that are being paid in information technology. In all, but the largest cities, according to Harvard wage growth in IT jobs has become relatively moderate following the dotcom boom.

    They're saying that these wages in IT are a lot more like wage patterns that have been seen in the broader STEM space. STEM being science, technology, engineering, and mathematics. So some of those like mathematics are well known for really having terrible wages, right? You got a PhD in math and wow, you can get a $60,000 a year job. So IT has changed. IT really has leveled out.

    In some geographical regions where there's fierce competition for IT talent, superstar performers do not earn the same high premium they once did over average performing programmers and other IT professionals. So in short, IT wages are still relatively high compared to most other occupations, but they have lost what Harvard says is their exceptional luster.

    The IT wage premiums today, have more to do with where you are working then with rewarding, specific skills that you have for the job. So keep that in mind.

    This paper, if you want to look it up, it's called the digital labor market in equality and decline of IT exceptionalism. It was written in Harvard business school post-doctoral researcher was involved with this at the Martin Marshall professor of business administration. So there's a whole lot to chart the rise and fall of the salaries. They examined 142 of the largest urban areas in the us between 2000 and 2018, and of course we've had crazy change over those 18 years in IT. We've seen  the major rise of the internet and apps, which didn't really exist until the last 10 years, these mobile phone smartphone apps. We've also had two pretty darn big recessions over that period of time. In smaller cities and rural areas, which is what we're talking about here for most of my listening area were excluded because of missing data for at least one year. They use the data from the Bureau of labor statistics. They parsed both the broad difference in wages against other lower paying jobs, STEM professionals. Salaries they found in five places, Silicon Valley, San Francisco, Seattle. Washington DC and New York climbed as there was more competition for talent.  I will interject there that I think that places like New York city are going to see a continued Exodus of IT professionals since there's so many people working from home. That  is going to have an absolutely major impact on all of us IT workers in the rest of the country just didn't get the same bump.

    Let's see. So they're saying there's two distinct and competing forces on the one hand, the advantage of tech hubs and urban metropolises, especially the combination of dense population and vigorous innovation increasingly leads to higher it wages making some regions more attractive to skilled talent.

    On the other hand, this is not Ronald Reagan's, ideally economist, right? On the other hand, wage spread narrowed within advantaged areas, moving the top, 10% of IT wages into convergence with other STEM occupation. So they're saying, yeah. The highest paying IT job category that they examined, which was a research scientist paid between 140 and 170,000 per year in the Bay area. So that's almost a minimum wage out there considering how much it costs for a house, et cetera. 45% more than a typical region such as Indianapolis in contrast, in those with biochemists, they earn about the same wage in the Bay area as they do in Indianapolis on average. Isn't that scary? So it goes on and on. Superstars are not super paid anymore.

    There's major implications for organizations. If you're looking at IT wages. You need to use the same sort of reasoning you would have used for other skilled labor markets. There are HR people who are used to this. When you get into the rare parts of STEM, how rare are they really? How many openings are there?

    This is an interesting time and it's changing more and more at because of people working from home and the lock downs and you saw France just locked down. I think it was Switzerland just locked down. Belgium apparently is about to lock down. We've even got Vermont locking down saying, don't go into these two counties in New Hampshire, which is right across the river because of higher COVID rates. Now I'm not going to get into all of it cOVID rates versus death, right? What morbidities and other things, but it's really tough.

    People are moving out of the big cities, including IT professionals that are moving way out. We've had a lot of people moving into New Hampshire and other areas that are more rural. So I suspect IT jobs as well as other STEM jobs just are going to continue to go down.

    We just talked about AI in the last segment and its effect. I think AI is going to have a huge effect on the whole IT industry, but it's going to take a few years before it really hits.

    We were just talking about wages. We're going to talk right now about another reason those wages have gone down something I've seen personally that has caused harm to my business and that President Trump has been trying to crack down on.  We're going to talk about cloud native apps too.

    Hi everybody. Craig Peterson here.

    Let's get into this guest worker program problem that we have.  It's very upsetting to me because I have lost business. I have lost contracts because of this program. What's been going on, and I took advantage of this program back in the nineties. I had a company with about 40- 50 employees. They were all IT people and I needed somebody with a very specific skillset.

    I needed a couple of people and so I hired an attorney and what they did is they worked to show the federal government that we had indeed tried to get people to work for us with these skillsets and we couldn't find anybody.

    We needed to bring in a foreign worker and that was under what's called an H1B visa. We brought them into the country and gave them the jobs and the work and off they go. Eventually I ended up having to pay for the airline tickets to send them on back home because we didn't need them anymore after the whole dot com boom thing.

    It was a really, quite a mess back then. This whole H1B visa thing has been a real problem. We have some extremely large consulting companies that have been bringing in thousands of foreign workers in the IT space, tens of thousands of them. They then bid against US American companies.

    Some of these companies, even though they're supposed to pay prevailing wages, with H1Bs, we're not. What we've ended up with now is a clamp down on this.

    We bid on, we had proposals, where there was absolutely no way in heck that we could have matched the price of this other consulting firm using people that were paid about a fifth of what we were paying.

    We found this out, of course, after the fact. We'd dug into it, trying to figure out why, we were the obvious choice, why didn't they use us? President Trump has come to the realization that Americans need the jobs in America, first. He has put a bit of pressure onto this whole H1B program.

    The Daily Caller has an article out this week called Corporations use the STEM shortage myth to abuse tech worker programs that President Trump's announcement really sent shockwaves through the whole tech sector. He suspended most of these guest worker visas through the end of the year.

    The big guys in tech were all condemning this. You've got Google, Amazon, Facebook, Microsoft, all individually condemn the moratorium. It affects these H1B visas, that these big tech firms use to hire the foreign workers that they don't really need. Tim cook who's a head of Apple said he was deeply disappointed. Twitter called it short-sighted. Overall, they may reduce the cost of things that are produced here in the US because they work for much less money. However, The quality isn't there.

    I looked into, when I was bringing some people into the country, I looked into their backgrounds and found these people claiming PhDs and they have their certificates. Yet their background was basically a high school education. It was shocking to me. Shocking. Then what I also found is that some of these companies found somebody they were going to hire from overseas that would work for cheap money. As I said, a fifth of what we had to pay US wages and they crafted the advertisement and they crafted the language in the application to the state department, et cetera, specifically for that person.

    So they took the resume and they said, we need someone with these exact qualifications three and a half years in this technology two years in that technology, a degree in this and degree and that a five years experience in this so that they could then justify it because you post that ad somewhere and Americans are going to look at it and say, no, I don't have that exact qualification. Then they took those applications and they got the foreign workers that got them to come into the US. They were able to pay them a fraction of what they would normally have to pay a US worker. So that's where I'm coming from. Okay.

    I think that's pretty obvious these companies, Google, Amazon, Facebook, Microsoft, as well as these big consulting companies. I mentioned earlier. I didn't give names, but you've probably heard of them. they were all actually worried about their bottom line. That's got to be the sole thing that they were worried about here.

    Congress created this H1B program back in 1990 to help companies recruit skilled foreign workers, where there was a shortage of qualified workers in the US. But the companies have circumvented the H1B programs safeguards. They're weak. It's crazy.

    They've been bringing in cheaper and less qualified foreign workers, even when there's plenty of qualified workers here now. When we've got an unemployment rate above 10 or so, it's ridiculous to be bringing these people in. We have people in the US that can take these jobs that they just don't want to pay because they want to pay foreign workers.

    Now, we had problems before where they were shipping jobs overseas to again unqualified companies. People in the US were forced to train their replacements overseas. You've heard these stories before. I know people that were forced to do this in the tech industry. I's all fake. That's exactly what they're saying right now. Rutgers professor Hal Salzman testified in Congress that this whole idea of a science technology, engineering, mathematics, employee mathematics, employee shortage, this desperate lack of people trained in these fields is a myth.

    Rutgers professor Salzman said that they graduate about twice as many STEM students as there are STEM jobs for them each year. He said, in fact, Minneapolis, Federal reserve bank president Neel Kashkari dismiss the whole concept of STEM shorter worker shortage. Noting that skills gap is just a euphemism for, we want skills at lower wages.

    So if there's no shortage of graduates and Americans are willing to do the work, why are these big tech companies so obsessed with H1B visas?  It really comes down to money. Let's see. There's a lot more detail in this article.

    I think Harvard did a great job Harvard business school on this, but man, we've got to be hiring Americans. We've got to.

    I'm great with people coming into the country. I'm an import, right? I've been here for many years. I got my US citizenship and I think it's a wonderful thing because we need new blood. We need talented blood. We need bright people. Bringing in these people for just cheap labor or outsourcing our jobs because it's a lot cheaper is going to hurt these companies in a long run. It's hurting the United States in the short run. There's no doubt about it.

    We are all looking at cloud apps. We probably use them every day. If you've got an iPhone or an Android phone, you're definitely using the cloud. Many businesses have looked at the cloud as a way to save money. Sometimes save a whole lot of money.

    A lot of organizations have decided that the cloud is this panacea that they can use. Because of the pandemic, why not shift the worker's functions to the cloud and get rid of our local computer room, data center closet, wherever it is, you might have your file server, et cetera.

    We have a huge security fallout now because of this sprint to set up employees home offices, because it's not just about vulnerable end points in home networks anymore. We've now rushed into adopting cloud-based technologies that have not been secured. It's absolutely nuts. We've got this hybrid physical cloud-based IT infrastructure and it is altering the landscape. Obviously it's already altered in 2020, but 2021 and beyond it is going to be just changed forever. So how do you manage it? How do you put up guardrails?

    Look at what's happened with Amazon web services, with their S3 data storage and how many security breaches there have been with S3. These buckets being wide open. Salesforce, Slack Service now, and others have all had hacks.  We've got major potential for vulnerabilities because we're tying together systems that were never even designed to be working together in the first place. Certainly weren't designed for security in the first place. So this is just a hint of things that are to come. Okay. It's very easy to mess up cloud security. Now there's a number of startups right now that are out there trying to address this. Jupiter One came out of stealth mode here. They had $19 million in series a funding that tells you how much these investors are thinking they're going to make off of this. This service automatically finds and keeps updated online, physical and virtual devices and assets and organization, including cloud native services. That doesn't seem like it's that hard to do, but man, the misconfiguration of all of the Software as a Service, or Cloud Native is common and it's mainly due to human error.

    So if you are using cloud services, I really would suggest that you, if you're a business, you assign someone to look into this or you look into it yourself. You're using Dropbox. You're using Microsoft O three 65. What are they doing to secure their data? A lot of these services don't even guarantee that they'll back it up and just had a huge data loss a because it wasn't being properly backed up,

    Hey, if you have any questions, just email [email protected].

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    1 hr 17 min
  • AS HEARD ON: WGAN Mornings News with Matt Gagnon: Elections, Hacking, USB Safety

    Good morning everybody!

    I was on WGAN this morning with Matt Gagnon and started off this morning talking about Iran and the letters sent to some of US Voters. They were purported to be from the Proud Boys but were from Iran. We also discussed a bit about Election Hacking and then got into, How safe are our USBs? Here we go with Matt.

    These and more tech tips, news, and updates just visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Typically what's been happening is that the polling places go to the Secretary of State's website, enter in the information. Then the Secretary of State's office now goes through all of that posted on their website. The Feds have been going to the Secretary of State's website and pulling it from there. So there is a risk of hacking.

    Good Morning, everybody. Craig Peterson here. Thanks for joining me. I really appreciate it. And if you could, if you haven't already, make sure you do hit that subscribe button, it really helps get the show numbers up and helps other people find this. This morning I was on with Mr. Matthew and we spoke this morning a little bit about the whole technology and election thing that's going on. Man, it's impossible to not know there's an election going on, isn't it? So here we go with Matt.

    Matt Gagnon: [00:00:59] Seven 36 WGAN morning news on a Wednesday morning. What do we usually do at this time? Oh, I know we talk to Craig Peterson. He's with us right now. Craig. How are you, sir?

    Craig Peterson: [00:01:09] Hey, good morning. I'm doing just fine. Hey, did you hear there's an election going on?

    Matt Gagnon: [00:01:15] There's an election going on? That is brand new information.

    Craig Peterson: [00:01:19] Bad guys are trying to do stuff.

    Matt Gagnon: [00:01:21] I know.

    Craig Peterson: [00:01:22] Somehow the two met its like chocolate and peanut butter.

    Matt Gagnon: [00:01:26] Oh man. Now I'm hungry. Craig, speaking of. Iran and, threatening emails being sent to Democrats, I would say that would fit into the category you were just talking about here.

    Tell me more about this story.

    Craig Peterson: [00:01:37] This is a big deal, frankly, and things have gotten so bad, in fact. Louisiana has called out their national guard, but here's what's going on. there are emails that people have been receiving and they say something that's frankly, a little bit disturbing.

    It says you will vote for Trump on election day or we will come afterward. Yeah, exactly. And supposedly they're from this group that has the, I don't know, people have been hearing a little bit about lately, but it's supposedly the proud boys that are sending this out. People have been pretty upset by this because there have been some legitimate threats to people.

    Is this legitimate? Is it not legitimate? it came out just this last week from the Director of National Intelligence, John Ratcliffe. That in fact of this is election interference and it is coming from Iran. Which is a real big deal. He also said, as well as, some other us officials, that Russia is still the major threat to the election. We know that North Korea has been involved, China's been involved. What it shows is, frankly, you don't have to hack into a computer in order to mess with an election.

    Matt Gagnon: [00:02:58] The other thing that bugs me about this, and I'm sorry I'm gonna have to get on my soapbox here a little bit, Craig. I think you know about this, as well, when you're talking about so many of the things that I've heard about election hacking this year. This is one of the things that I've heard an awful lot about which is that Iran has, or Russia has the voter list. They've got our registered voter list and they're going to use it to mess with us. They must've hacked into computers somewhere, some servers to get it. Maybe at the DNC or the RNC. They got the data and the information about voters from it. Dude, I have that information on my computer. Like seriously.

    Like you can buy voter lists. The voter list is not something that's an ultra-secure thing that needs to be broken into. It's something that is basically public information. If you'd like to get it, you have to pay for it, but you can get it. So if Russia wanted it or if Iran wanted it and they wanted to have a list of people and where they live and what their voter registration status is, their party membership, all that stuff. What they've done in the last four elections, you can just get it.

    It's not hard. The reason I'm bringing it up, Craig, is because I think that it manipulates the news coverage. From people covering politics that don't understand anything about politics, frankly. they're covering it as media outlets and it's disappointing to see that kind of thing.

    Craig Peterson: [00:04:04] Well, ABC News had a report here, so we now know what's really going on. Miryousefi told them, quote, Iran has no interest in interfering in the US election and no preference for the outcome. So we now know what's going on. Obviously a different Iran. Obviously, these people were hallucinating.

    But you're right. The information, if you combine the voter lists now with the information that's been stolen from companies, like Equifax out there, you can now tie all of that together. So you've got their email address. You've got their physical address, who they are. They could interfere in such big ways, right? This is just so minor.

    Matt Gagnon: [00:04:46] You don't need to break into computers. Oh, let's just say, you see your Russia and you actually do want to mess with American elections and target people and stuff like that. There are zero requirements that you have to break into anything to get that information.

    You can literally buy a magazine subscription information and you can basically do what the political parties do, which is layer voter registration data with a bunch of consumer information and data and come up with a model of who the voter is and what their life looks like.

    They can do that themselves. I could do that if I had enough money. It's very simple and easy to do that. It doesn't require some sort of a security violation in order to occur. So if you're worried about them, trying to manipulate the elections by, cleverly marketing to us. The security of computers is not really going to be a part of the equation. In my opinion.

    I think it, is at the endpoint because you've got all the local polling places, reporting it to the Secretaries of State in all of our 50 States and territories, and then the secretaries of state have now brought it to the Feds. But how does that mechanism actually work in the various States?

    And what's your whole works here in Maine, but typically what's been happening is that the polling places go to the secretary of state's website, enter in the information and then the secretary of state's office that's now going through all of that. Posts on their website. So the Fed has been going to the Secretary of State's website and pulling it from there.

    So there is a risk of hacking, but I really hope that people are actually also picking up the phone and checking the polling place and saying, Hey, is it legit?

    But your involvement also. With politics over the years, you know that there are people at every polling place that are double-checking the numbers, double-checking them.

    Craig Peterson: [00:06:37] The secretary of state is publishing. So I agree with you. I think overall we're pretty safe and this just goes right back to phishing. Be careful about the email you get. Cause it's not necessarily legit.

    Matt Gagnon: [00:06:51] Said, Craig. Before we let you go, I do want to ask you how safe your USB drive is? That's the other story that we had here that we wanted to chat about here this morning?

    Craig Peterson: [00:06:58] Yeah, there are quite a few things to be concerned about, particularly in this day where we're working from home. We're taking that USB drive and we're moving it between computers, home, computers, work computers. That is how we put the Iranian nuclear program about five years behind was one little USB thumb drive.

    So be very careful if we're using that as a backup for sensitive documents. We might leave it somewhere, which could be bad. They are also used very commonly for passing viruses around. So if you find a drive at your favorite coffee shop in the morning, be very careful because it may have something nasty on it. Not necessarily because they're trying to, the US and Israel trying to bring down your nuclear program.

    It might've been contaminated before you even got it and now it's there on your computer. So don't use them randomly. Be very careful. There's a lot of reasons why you should not be using regular drives. There are USB thumb drives that are encrypted. So if you accidentally leave it somewhere, it doesn't really matter.

    If you're using a Mac or you're using a Windows PC in both cases, there are options for encrypting them. So they're very careful, only use fresh ones, right out of a package that is probably safe.

    I'm not going to tell you probably, yeah, there have been USB drives that were shipped with malware. Pre-installed accidentally because of the machine they used to format them. Hadn't been infected. Dangerous.

    Matt Gagnon: [00:08:42] These are the very things you're going to hear. Craig Peters on talking about on Saturday. Of course, he has to show there, you can hear it at one o'clock at this very station.

    Appreciate it, Craig, as always. Thanks so much for joining us and we'll talk to you again very soon.

    Craig Peterson: [00:08:52] Hey, take care of Matt. Bye-bye.

    All right. So that's it from my radio hits most likely this week and I will be back this weekend. Thanks, everybody. And thanks to those people who sent me an email yesterday, letting me know what's going on. How they listen? How you consume? If you haven't had a chance or if you wanted a copy of that Hunter Biden email that I put together, talking about what to do with your computer when you take it in for repairs. Just drop me a note. Drop me a line. Me at Craig Peterson. dot com take care. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…