Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Continuation of The Considerations Surrounding Privacy and Computer repair plus more on this Tech Talk with Craig Peterson Podcast

    Craig continues his explanation of what you need to do if you have to take your computer to a shop to be repaired. This segment covers encryption.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries’ virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to talk right now a little bit more about removing that personal data before you send it in for repair and a couple of other things that you need to know about your rights when it comes to repairs.

    Hey, you're listening to Craig Peterson. Thanks for joining us today.

    Next up is probably pretty obvious to everybody make sure you're very selective about who you trust. What's the reputation of your work with them before? If you're dealing with a managed services provider, They have a fair deal, in fact, of responsibility for your data.  If they are a federal compliant managed security services provider, then there are federal laws to help protect some of your data.

    But if you leave that data on that computer, it's like not paying for the guy that did all of the yard work outside who brought in the bulldozers and the trucks full of soil, et cetera. They have a mechanics lien on your home. They can take that right out of you and even force the sale of the home in order to get paid.

    Kind of similar in the computer world. They did put in the time to fix a computer, they might've added parts, et cetera. So when you sign that contract, when you're dropping that thing off, remember that you kinda are signing your computer away. That is not a good thing for you if you don't come back in the 90 days, because that computer and all of the data on it becomes not yours.  It becomes the repair shop's data and computer. They can do with it, whatever it is they want to do with it. That's, what's gotten Hunter Biden into some serious trouble here and Joe Biden as well. Remember this, isn't a Hunter Biden problem.

    It's now showing some major corruption on the part of Joe Biden. So if it's true, Where did this all start? Well, he's kept his head down pretty well for 47 years in the US Senate, et cetera. But, this one thing just dropping the computer off for repairs could be a problem.

    Encryption is important. Remember most of us are just using what's called encryption at rest. In other words, the data is encrypted while it's on the disk. That does not meet some of the higher standards of various regulations, but it's okay. It's a start.  So you use encryption on the disk, you use the builtin windows encryption or the built-in Apple encryption as well. Now there are some very good tips here as well. That has to do with your keys. I keep all of my keys, my software keys, my log-in keys, license keys in a vault. An encrypted vault.

    There is another level of that. It's something that we are trying to convince our clients that they need to do because some regulations are requiring it now. Although most companies are not doing it. That is, it has to not just be kept in an encrypted vault, but half has to be kept in an encrypted vault that will self-destruct if someone tries to get into it.

    So keep your software keys, separate, keep them off of your main computer. Nowadays put them in your smartphone in an encrypted vault. I use one password there. You can use LastPass, which is another good one. There are many others, but keep them on a separate device. This again is the next step ultimate insecurity. We get into this in our cybersecurity mastery program. When we're talking about some of these different levels that you have to comply with, but you can have a unique key for each disk, that's stored on a separate machine so that when your computer boots up, it has to go to the separate machine in order to get the keys in order to decrypt and use your hard disks. Okay.

    That's way above and beyond what home users are going to do. It's way above and beyond what a SOHO, a small office home office business is going to do. It is absolutely required for government contracts here in the next three years, it's already required today for some vendors. 

    There's one more step here we've got to remember. That the repair guys have to be able to repair your computer. You're going to want to make it easy for them to access your device.

    A word of caution. We've had stories, and I have personal knowledge of people working at some of these big companies. Many of us look at it and say, I'm not going to take it to Joe's repair shop, because who knows if they're going to repair properly or what's going to happen to my data, et cetera, et cetera.

     There was a great article we talked about when it came out a couple of years back from one of the bigger companies out there that have a squad of people that go around and install equipment, fix equipment, et cetera. Where some of their stores were being paid a bounty. What would happen is you'd bring your computer in and they would look at the data on the computer. They would check to see if they could find kiddie porn or anything else illegal, such as well pictures of you smoking crack cocaine, which is what's alleged here on Hunter Biden's computer. They would get paid a few hundred dollars, that technician, for finding it. How's that for scary? They would work with the police. The police had a bounty program. It was just absolutely nuts.

    So how easy do you need to make it for these people? Don't go crazy with making it easy for them. In fact, in many cases, before I would possibly take a computer in for repair,  of course, I don't, right? We repair them ourselves. Or we have a repair company come out and we watch them repair every step of the way.

     What I would do is remove that drive, no matter what kind of computer it is, and then take it in for repairs. The company that's doing the repairs, they've got bootable USB drives that they can just plug right in, boot it up, it's up, it's running. Life is good and they give it back to you.

    Hopefully, the problem isn't that, that hard drive was bad. But again, hard drives are easy enough to replace. But what you going to do to make it easy for them to repair, if you're going to ship it to them or give it to them with the hard disk intact, is to remove the password.

    Now I've done that before with my Apple computers, taking them into Apple for repairs. I also make sure that there's nothing on the machines. We'll make sure the backups good, which you should be doing anyway. Then we wipe the computer by destroying the key, the encryption key for that computer. Then we reinstall the operating system and we test the machine again because sometimes it's just the operating system got messed up. Particularly if you're dealing with a windows computer. So that's always a good thing to do anyway. Then when we give the computer to the repair guy. She's going to be able to just run it and it's not going to require a password and life is good, right? She's often running.

    That's what I would recommend as opposed to just removing the password on the computer. Remove the password, destroy the address by simply deleting the key and you can do that with these disk and full disk encryption programs, and then reinstall windows or Mac iOS, whatever it is. Check your machine again, make sure it's still not working the way you want it to, and then take it in for repairs.

    Things do break. It doesn't matter what kind of computer it is. It doesn't matter if it's a smartphone or a laptop or a server, they are going to break. There's your basic tip. Make sure you got the backups. Make sure everything is as it should be. So that you're not going to get nailed and your data's not gonna get stolen if the bad guys did hack into your computer and use it as a store and forward for illegal materials, they will no longer be on that computer.

    Stick around. We'll be right back and make sure you get my newsletter. Craig peterson.com/subscribe.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    9 min
  • DHS and FBI Warning about Election Hacking plus more on this Tech Talk with Craig Peterson Podcast

    Craig explains why DHS and the FBI are warning us about Election Hacking and why it individual State Website Security is the culprit.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries' virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We've talked about the potential here of hackers getting into our election systems and what are they going to be able to do? No, I've never been really big on this, but now FBI and DHS, well they're both disagreeing with me.

    Hey everybody. Welcome back. You're listening to Craig Peterson.

    I've talked about the likelihood of hackers being able to influence, I mean, in a very big way, our election here in the US and I've kind of poo-pooed it, because as a general rule with 50 state elections, it would be very difficult for a foreign adversary of some sort or somebody that just wants to mess with us to really cause havoc with our election.

    Of course, it looks like we're going to cause enough havoc ourselves falls because of this lockdown that we did. All of the crazy things we're trying to change at the very last minute with our voting this time around. This is going to be one heck of an election season. Ah, I'm not looking forward to it.

    I have been warning about some of the problems that have existed with Secretary of State office websites. Some of these Secretaries of State are putting up websites that allow the local County chairs, city, et cetera, to upload the vote tallies via the web. To the Secretary of State now, on the whole, that sounds pretty good. It seems pretty reasonable.

    You might remember what happened in Iowa early 20 20. Yeah. Where the Democrats decided they were going to use this app for tallying all of the votes. It wasn't being used for voting, but it was being used for the tally who won. We actually don't know who won the Iowa Democrat caucuses. Isn't that right? Just amazing, because of the technology and the problems behind it.

    Well, when we're talking now about state hackers, countries that have massive hacking campaigns, ongoing. Yeah. How much could they mess up our election by getting into the Secretaries of State websites? Because not only are the 50 States responsible for running the elections. Tallying the votes, but they're also responsible to give that data, hopefully, good data, the federal government. So how does the federal government get that data?

    Well, they tend to get it by going to the 50 Secretaries of State websites nowadays. And that's where my big concern comes from. Obviously, I do not like these touch screen voting machines.

    I know I am a good old fashioned writing on a piece of paper or the kind of the heavier paper, a hundred-plus pound stuff. You fill in an oval for who you want and then that card you put it in the machine. The machine counts it. I love those because the bottom line it's completely auditable.

    I talk a lot about audits because so many of my customers are getting audited because of federal regulations, but this is different.

    Let's say the machine tallied, a hundred votes for Trump, and 120 votes for Biden. A spot audit could be conducted. So you take all of the cards that were fed into that machine and you manually count them.

    Okay. This is obviously a Trump vote. Okay. That's obviously a Biden vote. So you're going through, you're seeing what the votes were for each person and you can now say, okay, it came up the counts the same, and you know, that machines counter right for what you were looking for was correct. Those cards can then be taken later on and you can have a Republican and a Democrat and a libertarian or whatever the parties are in your state watch as those individual ballots are counted because a physical ballot exists. That's just incredibly important. They can't hack a pencil. I love that saying. Right? I think it was our Secretary of State that said that you can't hack a pencil. I'm not sure that's not all entirely true, but it's mostly true.

    But you can hack some of the systems that are behind the reporting, according to the FBI and the Department of Homeland security right now. An article by Brooke Crothers is pointing out that hackers and they're saying possibly nation-state actors, which means who China, Russia, Cuba, North Korea, Venezuela, Brazil, not so much in Venezuela, not so much nowadays, either because their economy is in shatters because they are a blank country, a socialist country. Exactly. So their economies in shatters.

    Brazil's in shatters looks like we might get a trade agreement by the way, with Brazil kind of interesting, but.

    They are saying now that there is no evidence so far, this is a Homeland security, that the integrity of the elections data was compromised. And they're saying that it does not appear these targets are being selected because they are part of our election apparatus. In other words, wait a minute, guys. Our secretaries of state's website, other systems are being hacked just as a part of a random hack. What happens if they get ransomware? And what happens if a nation-state really does want to go after them this week.

    We saw six spies arrested, Chinese spies who were stealing information critical to the United States of America. They lie on their visa applications. You know, that's why right now the State department's saying you might not want to go to China because China's threatening to kidnap Americans over there and hold them hostage in exchange for these spies. It's not like the old days where we would catch some Russian spies. They would catch some American spies and then we trade them. Right?

    No, China is right now threatening to, and they already have with Canada and two other countries, they are threatening to kidnap regular old, innocent Americans off the street of China and hold them hostage until we give back there are six spies. Can you imagine that? Yeah, China is not an enemy. China is a friend, right? Well, it's a friend. If they give you one and a half-billion dollars. That's another story for a new section here.

    What I have been concerned about it looks like it's happening, that these were not attacked because they're part of the election apparatus. These were attacked because they were vulnerable systems. So what vulnerabilities were used, I think everyone needs to pay attention to this cause this is a very, very big deal. This is Seesaw. This is the cybersecurity and infrastructure security agency Seesaw. They are saying that they got in through what's called vulnerability chaining.

    That is a big deal and that is on my list of things as part of what we cover in my cybersecurity mastery course. This is a technique that's commonly used and it's used against businesses. It's used against federal state agencies, government critical infrastructure, elections organizations.

    In this case, it targeted something that I've been talking about forever. VPN vulnerability. Don't use virtual private networks unless you really, really, really, really know what you're doing. Okay. This was a target against a VPN vulnerability and a flaw in that log on, which is a windows protocol that used to authenticate people who are connecting over the VPN.

    Now what makes us even worse is that not only did the Secretary of State offices and other government offices not have adequate security to prevent this, not only did they not have properly configured VPNs, which is like 98% of them out there. So pull up your socks, people.

    Patches were already available for all of the vulnerabilities. They were already out there. This is what came straight from the FBI and CISA the patches were already there and they had been disclosed and the systems were not updated. So. How safe then is, is our election infrastructure?

    I go back to what I've been warning about for many, many years, our over reliance on the accuracy and security of the technology. These guys that did it are known as advanced persistent threat actors. Which usually means nation-states. They did not identify who it was most of the time lately. It's been China, no matter what these so-called news organizations have been saying, it hasn't been Russia. Russia really hasn't done much lately. It's mostly China and apparently, it looks like it's a financially motivated nation-state actor that can mean Russia. They are more financially motivated, but so is China. That's why they're stealing our business secrets as well. Okay. Very, very bad.

    Microsoft. You might remember, we talked about it here in September, said it detected Russian, Chinese, and Iranian actors targeting the 2020 US elections. So this is stepped up activity. They are targeting the 2020 election, according to Microsoft and the national counterintelligence and security center director, William Evanina. It's a very big, very big deal. So something else to worry about for our elections in 2020.

    It's also something you need to worry about if you are working from home. If you are a business owner or if you're an IT person, and that's why I'm here, I'm trying to help you guys understand this. That's why I have my cybersecurity mastery program. So you can ask me any questions you want to, and we can get things solved. Get them rolling.

    Be sure you are on my email list so you get my newsletters. You get the training and you know, what's going on.

    Hey, you're listening to Craig Peterson.

    We're going to talk about the IRS being investigated this time. You've seen those CLEAR things in airports, let you pass through quickly. We're going to talk about what they're trying to do nationwide.

    Stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • DHS and FBI Warning about Election Hacking plus more on this Tech Talk with Craig Peterson Podcast

    Craig explains why DHS and the FBI are warning us about Election Hacking and why it individual State Website Security is the culprit.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries’ virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We've talked about the potential here of hackers getting into our election systems and what are they going to be able to do?  No, I've never been really big on this, but now FBI and DHS, well they're both disagreeing with me.

    Hey everybody. Welcome back. You're listening to Craig Peterson.

    I've talked about the likelihood of hackers being able to influence, I mean, in a very big way, our election here in the US and I've kind of poo-pooed it, because as a general rule with 50 state elections, it would be very difficult for a foreign adversary of some sort or somebody that just wants to mess with us to really cause havoc with our election.

    Of course, it looks like we're going to cause enough havoc ourselves falls because of this lockdown that we did. All of the crazy things we're trying to change at the very last minute with our voting this time around. This is going to be one heck of an election season. Ah, I'm not looking forward to it.

    I have been warning about some of the problems that have existed with  Secretary of State office websites. Some of these Secretaries of State are putting up websites that allow the local County chairs, city, et cetera, to upload the vote tallies via the web. To the Secretary of State now, on the whole, that sounds pretty good. It seems pretty reasonable.

    You might remember what happened in Iowa early 20 20. Yeah. Where the Democrats decided they were going to use this app for tallying all of the votes. It wasn't being used for voting, but it was being used for the tally who won. We actually don't know who won the Iowa Democrat caucuses. Isn't that right? Just amazing, because of the technology and the problems behind it.

    Well, when we're talking now about state hackers, countries that have massive hacking campaigns, ongoing. Yeah. How much could they mess up our election by getting into the Secretaries of State websites? Because not only are the 50 States responsible for running the elections. Tallying the votes, but they're also responsible to give that data, hopefully, good data, the federal government. So how does the federal government get that data?

    Well, they tend to get it by going to the 50 Secretaries of State websites nowadays. And that's where my big concern comes from. Obviously, I do not like these touch screen voting machines.

    I know I am a good old fashioned writing on a piece of paper or the kind of the heavier paper, a hundred-plus pound stuff. You fill in an oval for who you want and then that card you put it in the machine. The machine counts it. I love those because the bottom line it's completely auditable.

     I talk a lot about audits because so many of my customers are getting audited because of federal regulations, but this is different.

     Let's say the machine tallied, a hundred votes for Trump, and 120 votes for Biden. A spot audit could be conducted. So you take all of the cards that were fed into that machine and you manually count them.

    Okay. This is obviously a Trump vote. Okay. That's obviously a Biden vote. So you're going through, you're seeing what the votes were for each person and you can now say, okay, it came up the counts the same, and you know, that machines counter right for what you were looking for was correct. Those cards can then be taken later on and you can have a Republican and a Democrat and a libertarian or whatever the parties are in your state watch as those individual ballots are counted because a physical ballot exists. That's just incredibly important. They can't hack a pencil. I love that saying. Right? I think it was our Secretary of State that said that you can't hack a pencil. I'm not sure that's not all entirely true, but it's mostly true.

    But you can hack some of the systems that are behind the reporting, according to the FBI and the Department of Homeland security right now. An article by Brooke Crothers is pointing out that hackers and they're saying possibly nation-state actors, which means who China, Russia, Cuba, North Korea, Venezuela, Brazil, not so much in Venezuela, not so much nowadays, either because their economy is in shatters because they are a blank country, a socialist country. Exactly. So their economies in shatters.

    Brazil's in shatters looks like we might get a trade agreement by the way, with Brazil kind of interesting, but.

    They are saying now that there is no evidence so far, this is a Homeland security, that the integrity of the elections data was compromised. And they're saying that it does not appear these targets are being selected because they are part of our election apparatus. In other words, wait a minute, guys. Our secretaries of state's website, other systems are being hacked just as a part of a random hack. What happens if they get ransomware? And what happens if a nation-state really does want to go after them this week.

    We saw six spies arrested, Chinese spies who were stealing information critical to the United States of America. They lie on their visa applications. You know, that's why right now the State department's saying you might not want to go to China because China's threatening to kidnap Americans over there and hold them hostage in exchange for these spies. It's not like the old days where we would catch some Russian spies. They would catch some American spies and then we trade them. Right?

    No, China is right now threatening to, and they already have with Canada and two other countries, they are threatening to kidnap regular old, innocent Americans off the street of China and hold them hostage until we give back there are six spies. Can you imagine that? Yeah, China is not an enemy. China is a friend, right? Well, it's a friend. If they give you one and a half-billion dollars. That's another story for a new section here.

    What I have been concerned about it looks like it's happening, that these were not attacked because they're part of the election apparatus. These were attacked because they were vulnerable systems. So what vulnerabilities were used, I think everyone needs to pay attention to this cause this is a very, very big deal. This is Seesaw. This is the cybersecurity and infrastructure security agency Seesaw. They are saying that they got in through what's called vulnerability chaining.

    That is a big deal and that is on my list of things as part of what we cover in my cybersecurity mastery course. This is a technique that's commonly used and it's used against businesses. It's used against federal state agencies, government critical infrastructure, elections organizations.

    In this case, it targeted something that I've been talking about forever. VPN vulnerability. Don't use virtual private networks unless you really, really, really, really know what you're doing. Okay. This was a target against a VPN vulnerability and a flaw in that log on, which is a windows protocol that used to authenticate people who are connecting over the VPN.

    Now what makes us even worse is that not only did the Secretary of State offices and other government offices not have adequate security to prevent this, not only did they not have properly configured VPNs, which is like 98% of them out there. So pull up your socks, people.

    Patches were already available for all of the vulnerabilities. They were already out there. This is what came straight from the FBI and CISA the patches were already there and they had been disclosed and the systems were not updated. So. How safe then is, is our election infrastructure?

    I go back to what I've been warning about for many, many years, our over reliance on the accuracy and security of the technology. These guys that did it are known as advanced persistent threat actors. Which usually means nation-states. They did not identify who it was most of the time lately. It's been China, no matter what these so-called news organizations have been saying, it hasn't been Russia. Russia really hasn't done much lately. It's mostly China and apparently, it looks like it's a financially motivated nation-state actor that can mean Russia. They are more financially motivated, but so is China. That's why they're stealing our business secrets as well. Okay. Very, very bad.

    Microsoft. You might remember, we talked about it here in September, said it detected Russian, Chinese, and Iranian actors targeting the 2020 US elections. So this is stepped up activity. They are targeting the  2020 election, according to Microsoft and the national counterintelligence and security center director, William Evanina. It's a very big, very big deal. So something else to worry about for our elections in 2020.

    It's also something you need to worry about if you are working from home. If you are a business owner or if you're an IT person, and that's why I'm here, I'm trying to help you guys understand this. That's why I have my cybersecurity mastery program. So you can ask me any questions you want to, and we can get things solved. Get them rolling.

    Be sure you are on my email list so you get my newsletters. You get the training and you know, what's going on.

    Hey, you're listening to Craig Peterson.

    We're going to talk about the IRS being investigated this time. You've seen those CLEAR things in airports, let you pass through quickly. We're going to talk about what they're trying to do nationwide.

    Stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • IRS and Data Aggregators plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses how the IRS gets around collecting data on US Citizens. They buy the information from these private Data Aggregators like our friends at Equifax - who by the way collect tons of information on you without your permission (you have no say in what information they collect) and then sell it!

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries' virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson (2): [00:00:00] Coming up in this hour, we're going to talk about the IRS. Yes. Investigated for using location data without a warrant. We're going to talk about us airports and the company that clears you going through that little test that they have at the very beginning.

    Hi everybody. Craig Peterson here. Yeah. If you've ever had a run-in with our friends at Homeland security with blue shirts, transportation security, many people have decided to do something that.

    I haven't done and I don't know what I would do. I think it's kind of dangerous and we'll explain why here in just a couple of minutes. Of course, at my website at craigpeterson.com, make sure you're on my email list. So you get all of my newsletters and all of that great information that comes with them. And right now, if you sign up, we are including some bootstrap stuff, getting your cybersecurity for your home altogether, as well as for small businesses.

    So all of that. Craig peterson.com/subscribe.

    We were talking in the last hour a lot about taking your computer to a computer repair shop and what to do. Well, how about you shouldn't do and how Hunter Biden apparently got himself into a whole lot of trouble by this little eighty dollar repair that apparently needed to be done to his Mac computer. Yeah. Not so much fun.

    We're going to start out this hour by talking about the I R S. Yes, the internal revenue service, right. We have a system here in the United States. It's different than most socialist countries, certainly different than the fascist and communist countries of old, where you got your check from the government and that was your paycheck.

    There's no withholdings or anything because of course everything is free and you get money to spend as long as you've cut those little ration coupons in order to spend it. Even then, right, the stuff's not on the shelves. The joys of socialism.

    Here in the United States, we don't have capitalism in its purest form. There are a lot of limits on what can be done and what should be done. The federal government bets a lot of your money on technologies that never pan out. We could give up hundreds of millions, actually, billions of dollars worth of wasted tax money that went to various friends of various government officials, frankly, when you start tracking down the money, it's very, very frustrating to me and I'm sure to many of you out there.

    So we have something called the Internal Revenue Service here in the United States. Its job is to collect the revenue, the taxes from the people. We voluntarily disclose all of the money that we make. We are paying taxes with withholdings. If we have, I have a regular salary income, right?

    That W2 income and the in the cases of some of the other ways we make money, we're supposed to disclose it, right? Like I do some farming. So I had this little form that gets filled out along with my taxes. Cause I got chickens and bees that I raise and. It's just a really complicated system and it frustrates me to no end how complicated it is.

    That's because we've got our wonderful legislators and rule-makers just constantly changing everything, right? It's kind of crazy.

    Well, one of the things the IRS has been concerned about is I think a very concerning thing, frankly, and it should be concerning for all of us. This is also part of our cybersecurity control number 16 here, which is account monitoring and control. What the IRS has done, they said, Hey, listen, we got to find these people who are out there who are using these electronic devices and are potentially not paying taxes that are due.

    Again, this is something I warned about years ago, not just because it's part of control 16, but because. It's just inevitable, right? The government wants to get its hands on all of the data it possibly can.

    It's like marketing firms, right? As a marketer, you want to know your customer and you want to give them the right message at the right time. What good is it to have an ad for a Ford truck when you're never, ever going to buy a truck? It doesn't do you any good? It doesn't do the advertiser any good.

    So how does the government do this and what did the IRS do? We've got a couple of Senators right now, Ron Wyden and Elizabeth Warren, who is now demanding a formal investigation into, how the IRS used location data that they got from a third party.

    We've known for a long time that the Federal Government is not allowed to collect data on US persons. What does that mean? Bottom line, they're not supposed to be out there and looking at what we're doing. I think that kind of makes sense because we're supposed to have privacy. We're supposed to be secure, right? In our papers, our documents, it is part of the Constitution, which is being ignored more and more, nowadays. But anyway, so they're not supposed to be coming after our data. So they go to data aggregators. Data aggregators and I had some on my show years ago when it was first in my mind becoming a real problem. It might've been even a decade ago now, but these are companies that buy data. Some of the data is a matter of public record and you would be surprised I'm sure to find out all of the public records that are out there on you. Some of the data is private that they buy from some of these agencies that track your credit. They give you a credit score. Some of it is a property that you own. It's the state secretary of state's office. That has all of the liens filed under that uniform commercial code. So UCC one filings, all of these things. They get pushed to put together and take driver's information - driver's license information, car registration, and now they have a picture of you.

    One of the things that they've added to this recently, and this wasn't true way back when I was first interviewing these guys, is the information from your cell phone. Now you might say, well, I have my location tracking turned off on my cell phone. So what are they doing? Have you played a free game lately?

    To do know what a free game actually costs too, because some of these games that you download, some of the software that you put onto your mobile devices are tracking you in some places sometimes you know about it. These Fitbit watches, for instance, remember a few years ago, there was a big controversy because military members were wearing Fitbit and we're going out and running in the morning and tracking their runs and having competitions with each other, which is a wonderful thing. Then we found that it was being tracked and put onto a public website. So you could see all the Fitbit users all over the world. And you could zoom in on military bases, including apparently secret military bases where people were running around in this big oval, that was about the size you might expect from a landing strip.

    So this information can be used and can be misused. Frankly, there was a real big thing too. A few years ago, they found some monitors down in Central Park in New York, and then some of the other parks, and they listened for the broadcast that comes from smartphones.

    Smartphones, for instance, are they're out there trying to find wifi networks. What you can do is you can send out a wifi network ID and then talk to a phone and apparently what was going on is some bad guys were using them to track women who are jogging through central park and potentially attack those women. Again, information that you're not really thinking about, that's being leaked.

    So what's happened now is the IRS and other federal agencies and state and local agencies have done this as well. The IRS apparently went to one of these data aggregators and they wanted to find where certain people were, where their homes were. So how do you do that? How the IRS wants to find phones, they want to know where you live. All you have to do is figure out where does this phone spends the night, because the phone is at your home at night, typically, right? It's turned on in case the kids need to reach you.

    This week we got a phone call at like four 30 in the morning. One of our daughters was in pain on the floor in the bathroom and it was a phenomenal thing. So we don't turn off the phone. It's great having that and it was great that you could call us from her bathroom, right?

    That could never have happened before, but it happened now. Her phone was at her house at night. Ours is our house at night. it is common, certainly not just talking to these cell towers. Right.

    But apps that are on them could potentially be targeting us, keeping our data, keeping our information.

    So when we come back, I want to talk a little bit more about this.

    Because two things I want to talk about that haven't been done to help protect our information, but I also want to tie this back to the IRS again.

    How far should the federal government be able to go to track people who have no criminal convictions, no history? They're just regular ordinary citizens that are out there.

    Hey, you're listening to Craig Peterson. Stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min
  • IRS and Data Aggregators plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses how the IRS gets around collecting data on US Citizens.  They buy the information from these private Data Aggregators like our friends at Equifax - who by the way collect tons of information on you without your permission (you have no say in what information they collect) and then sell it!

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries’ virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson (2): [00:00:00] Coming up in this hour, we're going to talk about the IRS. Yes. Investigated for using location data without a warrant. We're going to talk about us airports and the company that clears you going through that little test that they have at the very beginning.

    Hi everybody. Craig Peterson here. Yeah. If you've ever had a run-in with our friends at Homeland security with blue shirts, transportation security, many people have decided to do something that.

    I haven't done and I don't know what I would do. I think it's kind of dangerous and we'll explain why here in just a couple of minutes.  Of course, at my website at craigpeterson.com, make sure you're on my email list. So you get all of my newsletters and all of that great information that comes with them. And right now, if you sign up, we are including some bootstrap stuff, getting your cybersecurity for your home altogether, as well as for small businesses.

    So all of that. Craig peterson.com/subscribe.

    We were talking in the last hour a lot about taking your computer to a computer repair shop and what to do. Well, how about you shouldn't do and how Hunter Biden apparently got himself into a whole lot of trouble by this little eighty dollar repair that apparently needed to be done to his Mac computer. Yeah. Not so much fun.

     We're going to start out this hour by talking about the I R S. Yes, the internal revenue service, right. We have a system here in the United States. It's different than most socialist countries, certainly different than the fascist and communist countries of old, where you got your check from the government and that was your paycheck.

     There's no withholdings or anything because of course everything is free and you get money to spend as long as you've cut those little ration coupons in order to spend it. Even then, right, the stuff's not on the shelves. The joys of socialism.

    Here in the United States, we don't have capitalism in its purest form. There are a lot of limits on what can be done and what should be done. The federal government bets a lot of your money on technologies that never pan out. We could give up hundreds of millions, actually, billions of dollars worth of wasted tax money that went to various friends of various government officials, frankly, when you start tracking down the money, it's very, very frustrating to me and I'm sure to many of you out there.

    So we have something called the Internal Revenue Service here in the United States. Its job is to collect the revenue, the taxes from the people. We voluntarily disclose all of the money that we make. We are paying taxes with withholdings. If we have, I have a regular salary income, right?

    That W2 income and the in the cases of some of the other ways we make money, we're supposed to disclose it, right? Like I do some farming. So I had this little form that gets filled out along with my taxes. Cause I got chickens and bees that I raise and. It's just a really complicated system and it frustrates me to no end how complicated it is.

    That's because we've got our wonderful legislators and rule-makers just constantly changing everything, right? It's kind of crazy.

    Well, one of the things the IRS has been concerned about is I think a very concerning thing, frankly, and it should be concerning for all of us. This is also part of our cybersecurity control number 16 here, which is account monitoring and control. What the IRS has done, they said, Hey, listen, we got to find these people who are out there who are using these electronic devices and are potentially not paying taxes that are due.

    Again, this is something I warned about years ago, not just because it's part of control 16, but because. It's just inevitable, right? The government wants to get its hands on all of the data it possibly can.

    It's like marketing firms, right? As a marketer, you want to know your customer and you want to give them the right message at the right time. What good is it to have an ad for a Ford truck when you're never, ever going to buy a truck? It doesn't do you any good? It doesn't do the advertiser any good.

    So how does the government do this and what did the IRS do? We've got a couple of Senators right now, Ron Wyden and Elizabeth Warren, who is now demanding a formal investigation into, how the IRS used location data that they got from a third party.

    We've known for a long time that the Federal Government is not allowed to collect data on US persons. What does that mean? Bottom line, they're not supposed to be out there and looking at what we're doing. I think that kind of makes sense because we're supposed to have privacy. We're supposed to be secure, right? In our papers, our documents, it is part of the Constitution, which is being ignored more and more, nowadays. But anyway, so they're not supposed to be coming after our data. So they go to data aggregators. Data aggregators and I had some on my show years ago when it was first in my mind becoming a real problem. It might've been even a decade ago now, but these are companies that buy data. Some of the data is a matter of public record and you would be surprised I'm sure to find out all of the public records that are out there on you. Some of the data is private that they buy from some of these agencies that track your credit. They give you a credit score. Some of it is a property that you own. It's the state secretary of state's office. That has all of the liens filed under that uniform commercial code. So UCC one filings, all of these things. They get pushed to put together and take driver's information - driver's license information, car registration, and now they have a picture of you.

     One of the things that they've added to this recently, and this wasn't true way back when I was first interviewing these guys, is the information from your cell phone. Now you might say, well,  I have my location tracking turned off on my cell phone. So what are they doing? Have you played a free game lately?

    To do know what a free game actually costs too, because some of these games that you download, some of the software that you put onto your mobile devices are tracking you in some places sometimes you know about it.  These Fitbit watches, for instance, remember a few years ago, there was a big controversy because military members were wearing Fitbit and we're going out and running in the morning and tracking their runs and having competitions with each other, which is a wonderful thing.  Then we found that it was being tracked and put onto a public website. So you could see all the Fitbit users all over the world. And you could zoom in on military bases, including apparently secret military bases where people were running around in this big oval, that was about the size you might expect from a landing strip.

    So this information can be used and can be misused. Frankly, there was a real big thing too. A few years ago, they found some monitors down in Central Park in New York, and then some of the other parks, and they listened for the broadcast that comes from smartphones.

    Smartphones, for instance, are they're out there trying to find wifi networks.  What you can do is you can send out a wifi network ID and then talk to a phone and apparently what was going on is some bad guys were using them to track women who are jogging through central park and potentially attack those women. Again, information that you're not really thinking about, that's being leaked.

    So what's happened now is the IRS and other federal agencies and state and local agencies have done this as well. The IRS apparently went to one of these data aggregators and they wanted to find where certain people were, where their homes were. So how do you do that? How the IRS wants to find phones, they want to know where you live. All you have to do is figure out where does this phone spends the night, because the phone is at your home at night, typically, right? It's turned on in case the kids need to reach you.

    This week we got a phone call at like four 30 in the morning. One of our daughters was in pain on the floor in the bathroom and it was a phenomenal thing. So we don't turn off the phone. It's great having that and it was great that you could call us from her bathroom, right?

    That could never have happened before, but it happened now. Her phone was at her house at night. Ours is our house at night. it is common, certainly not just talking to these cell towers. Right.

    But apps that are on them could potentially be targeting us, keeping our data, keeping our information.

    So when we come back, I want to talk a little bit more about this.

     Because two things I want to talk about that haven't been done to help protect our information, but I also want to tie this back to the IRS again.

     How far should the federal government be able to go to track people who have no criminal convictions, no history? They're just regular ordinary citizens that are out there.

    Hey, you're listening to Craig Peterson. Stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min
  • Data Aggregators and Biometric Databases plus more on this Tech Talk with Craig Peterson Podcast

    In this very busy segment, Craig addresses a number of tech issues that are in the news right now. First off BEC scams. Business Email Compromises are also commonly known as Spear Phishing scams and target executives. In the past, many came from outside the US but this has changed. Next, he discusses what happened with Excel and the loss of some Covid data. Then he explains why the IRS is looking at Cryptocurrency on people's tax returns. So let's get into it!

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries' virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson (2): [00:00:00] We're talking about the misuse of our data by these data aggregators. What's it being used for? What can you do in order to maybe not stop it, at least slow some of it down? What government's doing to us, frankly.

    Hey, welcome back everybody. Craig Peterson here.

    So we were talking about these data aggregators and what they're collecting on us. Well, the most recent stuff that they started collecting is information from the apps we're using. Typically we're talking about apps that are free apps as opposed to paid apps. While we're using them we're giving away information about our location. This became such a problem that really came to the attention of Apple and Google both now.

    Google has had very kind of fine-tuned stuff for many years in Android that tells you the app wants this, wants that, wants the other thing, and frankly, that's pretty darn handy. Isn't it?

    What Apple has done is, Apple has tried to make it very, very simple for you. Far fewer options. When it comes to the granularity of what an app is asking for. Apple forces these app developers to only get or ask for the absolute minimum that they need. The more recent versions of Apple's iOS and Android have built into them now, a request so that when an app is asking for access to, for instance, your location, this GPS data, it will pop up a little warning.

    Apple in the latest release of its operating system it did a really nice thing. In fact, I think it was late in iOS 13, they added this, but it started reminding you every once in a while that this app is using your GPS. For instance, in the background, you want it to still be able to use it. They added it a while ago. Hey, by the way, You can just restrict it to having access while you're using the app.

    So when you're looking at those little popups, come up on your Android device or your iOS device, keep in mind. Okay. What is this app for? Why do I have this app? Oh, because I want to Tetris. Why would an app that is playing Tetris need access to your contacts? Why would it need access to your location? Why would it need access to any of these things? I like the way that Microsoft has gone with Windows and Apple with its operating systems and Android, where it is giving you definitive have warnings now about what apps want.

    Many of these apps still sell the information. Remember Google is in the business of selling information about you and selling your information as well. So if you have Google maps on your phone, even if it's an iOS phone, you may well be leaking your personal information to Google, and then it goes to the data aggregators.

    Apparently what the Senators are worried about here is that the IRS had gone out and got data that we didn't receive under a warrant. A letter here from the Inspector General says we are going to conduct a review of this matter, and we are in the process of contacting the criminal investigation division about this review signed by Jay Russell George, who is the Inspector General. That was his response back to the Senators Warren and Wyden. So I like this, right. I like what she's trying to do here. I don't think that they should be able to get this data without a warrant of some sort. But it's happening every day and it isn't just the IRS.

    It is many other agencies out there that are getting this data and that's what kind of concerns me.

    So let's move on to another real problem here and this is our personal identities. Remember I mentioned at the top of the hour. This whole airport thing, right. Where we've got TSA out there and they are chartered with, let me put it that way, trying to keep us safe. I think that's a wonderful thing. We used to have airlines and airports that are paying for security. They can still do that. And in some cases they do, but most airports have TSA agents there now.

    Have you noticed that there are two programs that are being actively used? You've got one, which is the prescreening. So you go, they take your fingerprints, they take all of your identity and they look you up. Okay. And they are checking public records by the way. They're checking to make sure that you buy oil for your home to heat it. If you're in the Northeast or you have an electric bill in your name and that all of the address rest all add up to gather. They check, of course, criminal records as well, but again goes back to the data aggregators and then they say this person no criminal record. And they are pretty much who they say they are. It looks like they're a decent, upstanding citizen. So we are going to l, have them this little pass.

    Now that lets them be pre-screened. It's a little easier at the airport it's a little faster get through. Although now so many people are pre-screened that line is slowed down a lot.

    So now there's another program that you might've noticed?

    Well, there's a couple of others as NexUS and things, but another one you might have noticed, which is called CLEAR. I have a friend who swears by CLEAR because he just goes into the airport Bam he's through TSA. What clear does is it is taking your biometric information and is doing the background check that we talked about before. A real problem for getting through TSA. Right? Is it a real problem? Has it been a real problem for you? Because what CLEAR is doing is making it so that it just takes seconds to pass through TSA.

    But here's what you're doing. They've got all of your personal information. They've got your driver's license. They now have your biometrics. They have your Iris information from your eye. So they know who you are. They can recognize that eye.

    Think about biometric information here for a minute. If you are on locking a door, using your fingerprint, that fingerprint scanner has to have that biometric information. Many businesses, many buildings now will unlock doors based on your face. Again, biometric information. There are more advanced systems that listen to your voice. There are systems that watch your cadence as you're walking because those are all unique to individuals. That's what they're doing in China right now, too. You're wearing a face mask, but they can still identify you.

    There is a problem with having this type of biometric information. I think it's a very big problem. Hey, if you go to "Have I Been pwned.com" and you find that your password and your username were leaked in a hack of a website, let's say. What do you do? Well, of course, first thing, first, you change your password and you make sure you're not using it anywhere else.

    What do you do if your biometric information is stolen?

    We'll be talking more about that when we get back, you are listening to Craig Peterson right here.

    Stick around. Cause we'll be right back.

    Of course, we're always online, Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    9 min
  • Data Aggregators and Biometric Databases plus more on this Tech Talk with Craig Peterson Podcast

    In this very busy segment, Craig addresses a number of tech issues that are in the news right now. First off BEC scams.  Business Email Compromises are also commonly known as Spear Phishing scams and target executives.  In the past, many came from outside the US but this has changed.  Next, he discusses what happened with Excel and the loss of some Covid data.  Then he explains why the IRS is looking at Cryptocurrency on people's tax returns. So let's get into it!

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries’ virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson (2): [00:00:00] We're talking about the misuse of our data by these data aggregators. What's it being used for? What can you do in order to maybe not stop it, at least slow some of it down? What government's doing to us, frankly.

    Hey, welcome back everybody. Craig Peterson here.

    So we were talking about these data aggregators and what they're collecting on us. Well, the most recent stuff that they started collecting is information from the apps we're using. Typically we're talking about apps that are free apps as opposed to paid apps. While we're using them we're giving away information about our location. This became such a problem that really came to the attention of Apple and Google both now.

     Google has had very kind of fine-tuned stuff for many years in Android that tells you the app wants this, wants that, wants the other thing, and frankly, that's pretty darn handy. Isn't it?

    What Apple has done is, Apple has tried to make it very, very simple for you. Far fewer options.  When it comes to the granularity of what an app is asking for. Apple forces these app developers to only get or ask for the absolute minimum that they need. The more recent versions of Apple's iOS and Android have built into them now, a request so that when an app is asking for access to, for instance, your location, this GPS data, it will pop up a little warning.

    Apple in the latest release of its operating system it did a really nice thing. In fact, I think it was late in iOS 13, they added this, but it started reminding you every once in a while that this app is using your GPS. For instance, in the background, you want it to still be able to use it. They added it a while ago. Hey, by the way, You can just restrict it to having access while you're using the app.

    So when you're looking at those little popups, come up on your Android device or your iOS device, keep in mind. Okay. What is this app for? Why do I have this app? Oh, because I want to Tetris. Why would an app that is playing Tetris need access to your contacts? Why would it need access to your location? Why would it need access to any of these things?  I like the way that Microsoft has gone with Windows and Apple with its operating systems and Android, where it is giving you definitive have warnings now about what apps want.

    Many of these apps still sell the information. Remember Google is in the business of selling information about you and selling your information as well. So if you have Google maps on your phone, even if it's an iOS phone, you may well be leaking your personal information to Google, and then it goes to the data aggregators.

    Apparently what the Senators are worried about here is that the IRS had gone out and got data that we didn't receive under a warrant. A letter here from the Inspector General says we are going to conduct a review of this matter, and we are in the process of contacting the criminal investigation division about this review signed by Jay Russell George, who is the Inspector General. That was his response back to the Senators Warren and Wyden. So I like this, right. I like what she's trying to do here. I don't think that they should be able to get this data without a warrant of some sort. But it's happening every day and it isn't just the IRS.

    It is many other agencies out there that are getting this data and that's what kind of concerns me.

    So let's move on to another real problem here and this is our personal identities. Remember I mentioned at the top of the hour. This whole airport thing, right. Where we've got TSA out there and they are chartered with, let me put it that way, trying to keep us safe. I think that's a wonderful thing. We used to have airlines and airports that are paying for security. They can still do that. And in some cases they do, but most airports have TSA agents there now.

    Have you noticed that there are two programs that are being actively used? You've got one, which is the prescreening. So you go, they take your fingerprints, they take all of your identity and they look you up. Okay. And they are checking public records by the way. They're checking to make sure that you buy oil for your home to heat it. If you're in the Northeast or you have an electric bill in your name and that all of the address rest all add up to gather. They check, of course, criminal records as well, but again goes back to the data aggregators and then they say this person no criminal record. And they are pretty much who they say they are. It looks like they're a decent, upstanding citizen. So we are going to l, have them this little pass.

    Now that lets them be pre-screened. It's a little easier at the airport it's a little faster get through. Although now so many people are pre-screened that line is slowed down a lot.

    So now there's another program that you might've noticed?

    Well, there's a couple of others as NexUS and things, but another one you might have noticed, which is called CLEAR. I have a friend who swears by CLEAR because he just goes into the airport Bam he's through TSA. What clear does is it is taking your biometric information and is doing the background check that we talked about before. A real problem for getting through TSA. Right? Is it a real problem? Has it been a real problem for you? Because what CLEAR is doing is making it so that it just takes seconds to pass through TSA.

     But here's what you're doing. They've got all of your personal information. They've got your driver's license. They now have your biometrics. They have your Iris information from your eye. So they know who you are. They can recognize that eye.

    Think about biometric information here for a minute. If you are on locking a door, using your fingerprint, that fingerprint scanner has to have that biometric information. Many businesses, many buildings now will unlock doors based on your face. Again, biometric information. There are more advanced systems that listen to your voice. There are systems that watch your cadence as you're walking because those are all unique to individuals. That's what they're doing in China right now, too. You're wearing a face mask, but they can still identify you.

    There is a problem with having this type of biometric information.  I think it's a very big problem. Hey, if you go to "Have I Been pwned.com" and you find that your password and your username were leaked in a hack of a website, let's say. What do you do? Well, of course, first thing, first, you change your password and you make sure you're not using it anywhere else.

    What do you do if your biometric information is stolen?

     We'll be talking more about that when we get back, you are listening to Craig Peterson right here.

     Stick around. Cause we'll be right back.

    Of course, we're always online, Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    9 min
  • Dangers of Biometric Databases and CLEAR's new focus plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses CLEAR and why what they are doing now is NOT a good idea. These biometric databases can be hacked just like any other database. The Danger is - there is no way to guarantee 100% security of your data and if it gets hacked -- You can't change your biometrics!

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries' virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson (2): [00:00:00] Hey, who has your biometric information? Is it really a problem? You've got your phone, you unlock with your face or your, maybe your fingerprint, your thumbprint. Where's that information all going? What is CLEAR doing now? In case you're not aware of it CLEAR is a company that has been taking biometric information and using it at airports has got about 5 million members.

    You're listening to Craig Peterson. Thanks for joining us today.

    Clear who are they? If you've seen the signs, you've seen the people that walk through CLEAR, either use an eye scan called an Iris scan or a fingerprint scan they're used in airports, also used in stadiums.

    Well, April this year came as quite a wake-up call for our CLEAR, because the air travel industry just completely fell off a cliff, didn't it. You had the Coronavirus scare spreading worldwide airline passengers just stopped flying. It's just crazy.

    Some airplanes were turned around and mid to air and sent back to where they came from. Because borders were closed at the very last minute. Then there was the grave reality that hit in April of this year because basically, nobody was flying. Revenue was plummeting, empty airports and airlines are reporting a 95% drop in travelers. Absolutely. Huge. It's crazy. Crazy to think about just how devastating it was. Not just for the airline industry, but for related industries.

    Well, people hadn't been using CLEAR to travel. My friend, Dean he's sworn by CLEAR because he could just walk right in and walk onto the plane. It was that simple for him.

    He also uses one of these luggage transportation services, you pay like a hundred bucks a pop and they pick up his luggage from his house they ship it to the hotel he's going to be at and he never has to touch it. He literally just walks on board with the book or whatever it is he wants. Man, am I envious. Okay.

    So there are about 5 million people who paid past tense for CLEAR's service. It costs them about 180 bucks a year and they would go to these kiosks, that TSA, about 60 airports and sports arenas had these things and it verified their identity. They were able to then skip these long lines at the airport security and off they went. Absolutely phenomenal.

    Well, it looks like based on a report that came out here from a company called one zero, who looked at some public records that CLEAR's income was about halved. This surprises me that it wasn't 90, 95% drop in revenue knew, but some people just kept going at $190.

    One zero says that they've had a look at more than 3,500 documents and emails and they have found the CLEAR is now using the pandemic scare to pivot. What it's doing now is instead of just being at the airlines in the stadiums, they want to be the clearinghouse for biometric information everywhere. Absolutely everywhere. It wants to be the identity verification platform. Covering every moment of our lives, every day in our lives. They've already got tons of information from these public sources, from these companies that sell our information. They've also got information on people, customers who used CLEAR to buy at concessions, enter the sports stadiums, and they are now starting to explore if not already selling that data for marketing purposes. Isn't that something?

    By the way, you can get a free CLEAR identity for stadiums. So you don't have to pay if you're just using it to go into some stadium. So this is very, very concerning.

    I got a great article on this from one zero.medium.com. Up on my website @craigpetersohn.com. If you want to get into a little bit more.

    CLEAR considers itself a platform company. They've got something, they call a health pass they introduced in May this year. It's using CLEAR's identity verification service and attaches your personal health information to the profile. This gets really scary.

    Remember I said here before the break that you should be going to "Have I been pwned", I've said that many times, and if you need a link to that, just email [email protected]. I'll be glad to send it to you. Just the subject line, just say radio show. If you go there to "Have I been pwned" and you find that your password has been breached, so you just change your password.

    What do we do now, if we're registered with CLEAR? If we're a registered traveler? If CLEAR has our facial recognition biometrics? If CLEAR has our fingerprint biometrics? And on and on, and it gets hacked. You cannot change your biometrics. At least that's the whole idea, right?

    I am extremely concerned about it, which is why I don't use CLEAR.

    Now let's take that same question and let's apply it to our devices because we are using our biometrics to unlock the devices. Right now the Apple iPhones are the best when it comes to facial recognition, there are a number of Samsung models that have been quite easily fooled.

    The fingerprint recognition on the older I-phones is quite good. Frankly, some of the Samsung models have been easily defeated for fingerprint recognition.

    First off do go search on your phone model, find out how good it is? How good is the facial recognition? Because you're giving your facial biometrics to the phone. You're giving your fingerprints to the phone. What Apple has done is they put it into something they call the secure enclave. Now, last week I spent a lot of time talking about the T2 chip about TPM, these different types of encryption, and security controls that are on our laptops and on our smartphones.

    If you want more about that go to last week's show, you'll find it on Craig peterson.com because I discussed that in-depth. But I'm very concerned about this.

    My wife and I both have more than 10 digit passcodes on all of our devices. We use 20 plus character codes, login passwords on our Mac books, and on our desktops as well, just to try and keep it safe. Neither one of us actually trust the type of security you get from fingerprints or elsewhere.

    Now, one of my sons, what he does, is he doesn't use this thumbprint. He uses a knuckle. A print on a knuckle. I know some other people that use various private parts, women, and men to identify themselves. Maybe that's a good idea. Maybe it's not. But I would be very cautious here. Be careful with CLEAR. It might be nice to be able to just zoom through the airport. It's one thing if the government has the information, but governments are losing the stuff all the time, they're getting hacked all the time.

    That's bad enough but giving it purposely to these companies like CLEAR that really bothers me again, search for your phone online, and in the Apple world, the secure enclave on the phone, that's where your biometric information is kept. It is never ever sent to Apple. Can't say the same about all of these Android devices.

    Stick around. You're listening to Craig Peterson and we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Dangers of Biometric Databases and CLEAR's new focus plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses CLEAR and why what they are doing now is NOT a good idea. These biometric databases can be hacked just like any other database.  The Danger is - there is no way to guarantee 100% security of your data and if it gets hacked -- You can't change your biometrics!

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries’ virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson (2): [00:00:00] Hey, who has your biometric information? Is it really a problem? You've got your phone, you unlock with your face or your, maybe your fingerprint, your thumbprint. Where's that information all going? What is CLEAR doing now?  In case you're not aware of it CLEAR is a company that has been taking biometric information and using it at airports has got about 5 million members.

    You're listening to Craig Peterson. Thanks for joining us today.

    Clear who are they? If you've seen the signs, you've seen the people that walk through CLEAR, either use an eye scan called an Iris scan or a fingerprint scan they're used in airports, also used in stadiums.

    Well, April this year came as quite a wake-up call for our CLEAR, because the air travel industry just completely fell off a cliff, didn't it. You had the Coronavirus scare spreading worldwide airline passengers just stopped flying. It's just crazy.

    Some airplanes were turned around and mid to air and sent back to where they came from. Because borders were closed at the very last minute. Then there was the grave reality that hit in April of this year because basically, nobody was flying. Revenue was plummeting, empty airports and airlines are reporting a 95% drop in travelers. Absolutely. Huge. It's crazy. Crazy to think about just how devastating it was. Not just for the airline industry, but for related industries.

    Well, people hadn't been using CLEAR to travel. My friend, Dean he's sworn by CLEAR because he could just walk right in and walk onto the plane. It was that simple for him.

    He also uses one of these luggage transportation services, you pay like a hundred bucks a pop and they pick up his luggage from his house they ship it to the hotel he's going to be at and he never has to touch it.  He literally just walks on board with the book or whatever it is he wants. Man, am I envious. Okay.

    So there are about 5 million people who paid past tense for CLEAR's service. It costs them about 180 bucks a year and they would go to these kiosks, that TSA, about 60 airports and sports arenas had these things and it verified their identity. They were able to then skip these long lines at the airport security and off they went. Absolutely phenomenal.

    Well, it looks like based on a report that came out here from a company called one zero, who looked at some public records that CLEAR's income was about halved. This surprises me that it wasn't 90, 95% drop in revenue knew, but some people just kept going at $190.

    One zero says that they've had a look at more than 3,500 documents and emails and they have found the CLEAR is now using the pandemic scare to pivot. What it's doing now is instead of just being at the airlines in the stadiums, they want to be the clearinghouse for biometric information everywhere. Absolutely everywhere. It wants to be the identity verification platform. Covering every moment of our lives, every day in our lives. They've already got tons of information from these public sources, from these companies that sell our information. They've also got information on people, customers who used CLEAR to buy at concessions, enter the sports stadiums, and they are now starting to explore if not already selling that data for marketing purposes. Isn't that something?

     By the way, you can get a free CLEAR identity for stadiums. So you don't have to pay if you're just using it to go into some stadium. So this is very, very concerning.

    I got a great article on this from one zero.medium.com. Up on my website @craigpetersohn.com. If you want to get into a little bit more.

     CLEAR considers itself a platform company. They've got something, they call a health pass they introduced in May this year. It's using CLEAR's identity verification service and attaches your personal health information to the profile. This gets really scary.

    Remember I said here before the break that you should be going to "Have I been pwned", I've said that many times, and if you need a link to that, just email [email protected]. I'll be glad to send it to you. Just the subject line, just say radio show. If you go there to "Have I been pwned" and you find that your password has been breached, so you just change your password.

    What do we do now, if we're registered with CLEAR? If we're a registered traveler? If CLEAR has our facial recognition biometrics? If CLEAR has our fingerprint biometrics? And on and on, and it gets hacked. You cannot change your biometrics. At least that's the whole idea, right?

    I am extremely concerned about it, which is why I don't use CLEAR.

    Now let's take that same question and let's apply it to our devices because we are using our biometrics to unlock the devices. Right now the Apple iPhones are the best when it comes to facial recognition, there are a number of Samsung models that have been quite easily fooled.

    The fingerprint recognition on the older I-phones is quite good. Frankly, some of the Samsung models have been easily defeated for fingerprint recognition.

     First off do go search on your phone model, find out how good it is? How good is the facial recognition? Because you're giving your facial biometrics to the phone. You're giving your fingerprints to the phone. What Apple has done is they put it into something they call the secure enclave. Now, last week I spent a lot of time talking about the T2 chip about TPM, these different types of encryption, and security controls that are on our laptops and on our smartphones.

    If you want more about that go to last week's show, you'll find it on Craig peterson.com because I discussed that in-depth. But I'm very concerned about this.

    My wife and I both have more than 10 digit passcodes on all of our devices. We use 20 plus character codes, login passwords on our Mac books, and on our desktops as well, just to try and keep it safe. Neither one of us actually trust the type of security you get from fingerprints or elsewhere.

    Now, one of my sons, what he does, is he doesn't use this thumbprint. He uses a knuckle. A print on a knuckle. I know some other people that use various private parts, women, and men to identify themselves. Maybe that's a good idea. Maybe it's not. But I would be very cautious here. Be careful with CLEAR. It might be nice to be able to just zoom through the airport. It's one thing if the government has the information, but governments are losing the stuff all the time, they're getting hacked all the time.

    That's bad enough but giving it purposely to these companies like CLEAR that really bothers me again, search for your phone online, and in the Apple world, the secure enclave on the phone, that's where your biometric information is kept. It is never ever sent to Apple. Can't say the same about all of these Android devices.

    Stick around. You're listening to Craig Peterson and we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • IRS investigating Cryptocurrency Cheaters, BEC on the Rise, Covid Contact tracing issues plus more on this Tech Talk with Craig Peterson Podcast

    In this very busy segment, Craig addresses a number of tech issues that are in the news right now. First off BEC scams. Business Email Compromises are also commonly known as Spear Phishing scams and target executives. In the past, many came from outside the US but this has changed. Next, he discusses what happened with Excel and the loss of some Covid data. Then he explains why the IRS is looking at Cryptocurrency on people's tax returns. So let's get into it!

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    FBI, DHS says hackers have gained access to election systems

    The IRS Is Being Investigated for Using Location Data Without a Warrant

    Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    IRS may put cryptocurrency question at the top of 1040 to catch cheaters

    Publishers worry as ebooks fly off libraries' virtual shelves

    25% of BEC Cybercriminals Based in the US

    What's Really Happening in Infosec Hiring Now?

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson (2): [00:00:00] Well, we've got a story here about how Excel may have lost some 16,000 potential COVID cases. A little story about the IRS and really happening in info security right now. Great career.

    Hi, everybody listening to Craig Peterson.

    Oh, cybersecurity. IT cybersecurity, I think is a great profession. It is a difficult profession. Don't get me wrong. I talk with people in IT all the time about how it is just kind of overwhelming. How they just got this major inferiority complex in Infosecurity understandably so. There's so much going on, it's a very high-stress job.

    There is a great article that was out in Dark Reading earlier this year, talking about what was predicted for security roles going forward. Due to the pandemic scare, what matters.

    Six months later, Dark Reading went back and had a look at it. What they've found is it's just as tough to fill open cybersecurity positions as it was pre-pandemic. In fact, there are new problems now that I, I hadn't really even thought about, frankly. 30% of businesses that responded to the survey said that their security teams are hiring now. 45% said that they need additional staff, but are restricted by hiring freezes or spending limits. So add those two together where it's 75% of companies are looking to get more cybersecurity people. 12% said that they were recently forced to cut security staff. Which is obviously in my view, more than a little short-sighted, right?

    So they went in and started looking at it a little more deeply. It's a years-old story now, and it typically takes about eight months to replace a security analyst and about four months to train a replacement. There is right now a huge shortage of appropriately skilled workers. Others are claiming it's an unreasonable set of expectations amongst employers, and that job listings that are put out there are difficult to decipher.

    I think that's funny considering its cybersecurity, right? Get it - decipher. I have thought long and hard about maybe offering some sort of cybersecurity training course. That's what the cybersecurity mastery thing is all about. Getting you the basics of cybersecurity and then have a couple of phone calls a month to answer questions that people have that are in the program.

    That's the whole thing behind understanding cybersecurity or mastering cybersecurity program because employers want the right skill set. There just aren't enough people out there.

    The pay is very good depends on what you consider good, I suppose. Right now for a not particularly well-skilled person, the salaries are in the hundred thousand dollars a year range, Which is why statistically looking at this whole thing a business that has fewer than 500 employees with standard revenue based on how much revenue per employee cannot afford a cybersecurity team. You just can't afford it because it's so darn expensive.

    You're much better to find an outsource team. That'll do it for you. It'll save you a whole lot of money. So keep that in mind.

    A business email compromise is a very, very big problem. We've talked about it before. FBI is talking about all of the hacks that have occurred via BEC. I've had firsthand experience with it that is how we picked up a couple of clients. We do a cyber health assessment for one company and this company had a few different servers and some desktop machines. We did a whole, what we call an NSAAP, which is a network security assessment and action plan.

    So we gave them this action plan. These machines need to be upgraded. These machines this software needed to be upgraded. These machines were not properly protected. These ports were open. They shouldn't have been right. So it was a really good network plan for them. I think it was like 300 pages long of stuff they needed to do.

    Again, this was a very small company. I think they've only got maybe three or four dozen employees and gave it to them. Thanks. Appreciate it. Bye-bye. Then we got a call from them. I don't know what was it? Eight months later because they had become, I'm a victim of a business, email compromise attack.

    This happens all the time now. This is where someone sends an email pretending to be someone they're not usually within the organization, but sometimes they pretend to be a vendor. One of the attacks that I know of here, that's pretty common, comes out of Eastern Europe.

    Hey, Mr. CFO. They send this while the owner, CEO, the president is out of town and unreachable, and they know that because the owner posted it on Facebook and the bad guys have been tracking the company for a little while and said, Oh, he's going to be down in Bermuda. This period of time in February.

    So they send an email to the CFO and supposedly from the business owner, and there are methods they use so that they can use a legitimate email address, or it looks really like it is from the business owner. The email says something like, Hey, we started using this new vendor. We haven't paid their invoices. We're three months behind unless you wire this $120,000 that is going to go away and can really hurt the company. Can't deal with this right now. Please just go ahead and wire the money and then the CFO does it.

    We saw this happen to Shark Tank's Barbara Cochran. You know her from Shark Tank. She's one of the sharks, big real estate investors. Her assistant got tricked into wiring out - Was it 300,000? I can't remember. It was a fair amount of money. She got tricked into wiring it overseas.

    Now the FBI tells us that once that happens, 90 seconds later that money can no longer be recovered. It just disappeared. We have clients that have had the money disappear. Of course, we picked them up after it's disappeared, right? Just like this customer that did not do what we told him he should do. Right.

    Even if they did it themselves, they would have been ahead of the game. They didn't have to hire us to do it. We gave them an action plan as part of our NSAAP evaluation. Right? They lost, last I heard, actually, it has gone up, a $180,000. So they lost money right out of their operating account. It got emptied and they also ended up incurring all kinds of fees and then they couldn't deliver some things. So they had problems with customers, right.? It just goes on and on and on.

    This stat is something that was a bit of a surprise for me. There's a study that was just done looking at business email compromises and found that the attacks are coming one-quarter of them from the United States. One-quarter of all of the business emails is coming from the US. Of course, many times these people are caught by the FBI and end up in prison. But of these attackers located in the US, nearly half of them are in these five States, California, Georgia, Florida, Texas, and New York. So be very, very careful.

    Interesting reports got information from more than 9,000 defense engagements from this year between May and July, right? 2200 of them, by the way, they could identify the likely location of the attackers. So interesting stuff. That's a problem.

    IRS is saying that they may have a question and on the top of the new form, 1040 asking filers if they dealt in virtual currency in 2020, we talked about the IRS earlier in the show today. The IRS is concerned that people are making money off of these blockchain things, like Bitcoin, and are not reporting the capital gains that they had from these cryptocurrencies. So be careful with that. IRS is starting to take that very seriously.

    Then COVID, we put all kinds of systems in place because of the panics around the Wuhan virus and worry about people having the COVID-19 symptoms. Apparently in the UK, more than 50,000 potentially infectious people may have been missed by the contract tracers. How?

    Well, Microsoft has a million row limit on the Excel spreadsheet. Now, if you have a spreadsheet with a million rows in it, you are misusing spreadsheet software that really needs to be in a database somewhere. Okay. That's not something to do in a spreadsheet. Apparently what they were doing in the UK is hospitals, et cetera, or we're sending in spreadsheets. We're probably doing the same thing here in the US and then those spreadsheets are being pulled into one master spreadsheet and almost 16,000 positive tests were left off the official daily figures which translate to more than 50,000 potentially infectious people running around. A great little story from the guardian.

    Again, all of this stuff is up on my website. I have a great newsletter people love, and I'd love to have you on it. Where I talk about these things. We do a little bit of training. I answer people's questions. You'll find it all @craigpetersohn.com slash subscribe. Make sure you're on that list so you can stay on top of these things.

    Take care, everybody we'll be back next Saturday at one.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…