
Sign up to save your podcasts
Or


Craig discusses Ballot Question 1 coming up in Massachusetts in the next two weeks and a take you may not have been expecting. Tune in.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring’s latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
So with our fancy electronic cars driving around and our electric cars driving around, how do you repair them? Should you have the right to repair those vehicles? That's the question they're asking in Massachusetts next month.
Hi guys. You are listening to Craig Peterson.
These cars, the Tesla has been on the market now for quite a few years, back in 2013, Massachusetts voted here on this right to repair legislation.
The idea was that these car manufacturers should not keep you out of your vehicle while working on it. Having just a regular car guy, car shop, whoever it is, you got a gal that does it? You could not have them mess with your car and still retain the warranty, in many cases. So they changed that law.
Now we have these cars that thankfully are 90% software. What do we do now? The reason I said 90% software is, of course, you've got the chassis, right? You've got the suspension. You've got a steering wheel. You have a gas pedal. You have a brake pedal. You have a motor or motors depending on the vehicle that's all mechanical.
That's all parts and pieces. Some of them move. Some of them don't move. Don't forget about the brakes, but every last one of those things is controlled by computer, even in a standard car, nowadays. I've ranted and raved about how I'll never drive a Volvo because they make assumptions about when the car should take over. It's kind of true for every vehicle. That steering wheel probably does not have a mechanical linkage to those front wheels on your car. Did you know that? Turning that steering wheel, all that's really doing is setting off a sensor in the steering column. That brake pedal almost certainly is not connected to the brakes on your car. Right?
 It used to be, you push it down. There's a diaphragm created pressure. They use that to amplify through hydraulic pressure to the brakes, and then the brakes would grab whatever type of brakes you had. Right? Sometimes it was strictly mechanical as well, without that hydraulic assist in there. Same thing with the steering wheel, that gas pedal is guaranteed to not be hooked up directly to the engine. Used to be you'd push down the gas pedal and what would it do? It would change some valves in the carburetor or a little bit later on in the fuel injector and feed the fuel into the car nowadays. All it is is a rheostat or potentiometer.
Just a little dial like you might have on your television that is being manipulated. Buy that gas pedal, go, and have a look. Next time. You're there down there, cleaning out the car, getting rid of all of that salt from the wintertime, looking down at that car. And when you're down on the floor, the driver's side. Look at where the gas pedal is, but you can see this more, obviously in most cars on the gas pedal and the brake pedal look up, you'll see the linkage just goes to a little dial. Well, most of the time now, That's all well and good, but what it means is our cars no longer have that mechanical linkage.
If you go to my Mercedes, my 1980 Mercedes diesel, you will see mechanical linkages to everything. When I push on that accelerator, there is a steel rod that goes up under the hood of the vehicle that tilts forward control on the fuel injectors that inject the diesel into the cylinders. It is absolutely something that you can look at.
If it's jammed, you can look and see why you can replace a bearing. You maybe add a little grease here or there, you can straighten out a bent rod. But when it's software, what can you do? How much can you tinker with it? And if you tinker with it, what's going to happen?
Now with motor vehicles, it's become pretty obvious over the years, whoever touched it, whoever broke it, whoever caused an accident to occur, is the person or company, liable for the accident. So for repairs, damages, whatever might be involved.
How about an electric car? That's self-driving who carries the insurance, who has the liability. I think you know. I personally would carry insurance just in general, right? Some broad-based insurance, but is Tesla responsible for this? When that Tesla car hits someone who's responsible?
We know what just happened in Phoenix within the last month where charges were brought against a driver that was sitting there in one of these autonomous vehicles. It was driving down the road and hit a lady on a bicycle. As I recall, as she was crossing the road. Now the car didn't properly detect what was happening, so it did not stop in time.
The driver apparently wasn't paying attention, right? Drivers in quotes, air quotes, because obviously, they weren't paying attention. So that driver got charged and it's not going to be fun for that driver.
When that vehicle truly is represented to be autonomous, what happens when there is no more steering wheel in the vehicle, or whose responsible? You probably can say the manufacturer's responsible for it.
If you have the right to repair your vehicle, what does that mean? How far does that go? If you tinker with your vehicle and the software in it? You might burn out the electric motor, just like changing the chip and your engine might damage the engine, my damage to the valves, or whatever might get damaged. At that point you take it in, they look at it, the dealer manufacturer says, hey, you broke it. It's yours. We're not fixing it or at least we're not going to pay to fix it. You can pay.
So what happens now with an electric vehicle? And what happens when you trace that liability down and say, okay, who's responsible here. What happens if that person who's responsible is you because you had the right to repair and you went a little further than might be prudent.
This is an example of the law outpacing technology. Usually, the law is behind the technology. It's usually years behind technology. And that makes sense.
That gives the technology a bit of a chance to get established and then once its established then the technology can be rolled out and we know what the laws should be because you never know what's going to happen until it happens.
Now, personally, I think we have far too many laws and some basic rules or laws about liability are probably all we need.
We don't need laws about every little bit of liability, but there are a lot of questions that would need to be answered. That's where the judiciary can come in, not to make laws certainly, but to interpret the law, and say that law means you cannot kill someone negligently and therefore it's your problem and can get that all resolved. So that has years to come.
So you can see I think, how this all relates to this 2020 Massachusetts question one ballot initiative. This is the sort of thing we're starting to see all over the country here. How can traditional independent automotive repair shops, aftermarket parts, suppliers, home, tinkerers, and mechanics? How are they going to function as part of the automotive ecosystem? This ballot initiative aims to enact a law that makes vehicle-specific data for opening connectivity available to anyone. For the purposes in this case of quotes, maintaining, diagnosing, and repairing the motor vehicle. So interesting problems in trust and repurposing it. Personally, I think it's a safety threat.
I think it's a little too ahead of the game.
Hey, when we get back, we've got a lot more to talk about.
We are going to talk about Ring a little bit here and there. Latest security cameras. I don't know if you've been following this market much lately, but this is pretty cool.
You'll find out more about this by going online.
Craig Peterson dot com
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses a new home security device from Ring. The always-on home cam -- get this... it is a drone. Then he talks about Elon Musk and his 25,000 Completely Autonomous Tesla he will have in 3 years. Plus, you better think twice, or three times before paying that ransom to get your data back.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring's latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
You've been looking for a home security system. We've talked about a few of them on the show before. Right now we're going to be talking about a completely different approach to home security and what Ring's latest camera is all about.
Hi everybody. Craig Peterson here. Thanks for joining me.
Okay. Ring has been around for a while. As I recall Ring was purchased, two, three years ago by our friends over at Amazon. They have some interesting security stuff and they've certainly had their fair share or share of computer problems, security problems here over the years who hasn't, right?
This is what's being called a true ambitious new home security device. This thing is really cool. It sits there. It just, it says Ring on the front. it's just a little square almost. The device has got rounded corners, so looks very nice. And it's got a little light button on it.
One of those little Rings, which is always cool, but it's called the always home cam. And this thing reminds me a little bit of a movie that I've enjoyed many times called Tron from way back when. You might even remember these flying T things, although they had two legs on them and they flew around, that's what this Ring looks like.
It is an autonomous and manual little Quadrocopter, and it is designed where all of the blades are completely hidden if you will. So they're not going to run into anything. They're not going to hurt anything or anyone and hanging beneath these four enclosed blades is a thing like a pack of gum. You remember the old packs of gum, the long thin ones. That's it looks like underneath these four blades. So the idea is you pay them 250 bucks and you plug this thing in, you're going to have to configure it obviously, but it is this little, I guess a Quadrocopters, how I describe it that sits in its charging base.
Now, when it's in the charging base, it's the tail, the long downward part of the T that sits completely immersed in the charging base.
So this charging Base goes all the way up around the base of the Quadrocopter. And it's just the blades that are exposed on top. What it has on that is a camera. I imagine it probably also has a microphone. It doesn't say, but it has a little camera. So when it's in the dark it's charging and that camera is not active.
Even if it was it wouldn't be able to see anything. But what's really cool about this thing is that it can provide you with viewpoints throughout your house. You don't need multiple cameras anymore. The Rings founder's name is Jamie Siminoff. And he's also the chief inventor said that Ring has spent the last two years called focused on the development of the device.
And that it is an obvious product that is very hard to build. And thanks to advancements in drone technology. Ring pulled it off. They're not available yet. It's called the "always home cam." So I'm keeping an eye out for this thing. It is quite cool. It, you can program it what path to take, where it can go.
When you first get it, you build a little map of your home for it to follow. And it asks you for specific viewpoints, such as the kitchen or the bedroom, and the drone can be commanded to fly on-demand or programmed to fly when a disturbance is detected. So you might have a Ring alarm system you in that might include a window opening sensor door, opening sensor. So this little drone can fly up in the air. When it detects someone trying to break in and off it goes, isn't that cool? The drum makes an audible noise when it's flying. Of course, it's small and it's got all these little blades for little blades. So it's obvious when footage is being recorded.
I'm looking at a picture of her right now. It's very cool. Indoor only it's got high Def Ten-Eighty P video. It only records when it's in flight, the propellors are enclosed and integrates with the Ring alarm. So if you are a Ring fan, Check it out. If you're looking for home security, it is not a bad thing.
If you are a business, do not buy Ring. Okay. Because there are real security problems with some of these devices. They are not certified for use in any business that has any federal contacts. In the near future, it's all being disallowed. So just keep that in mind as well. If you're looking to buy security stuff. Also the cheap security stuff we have found backdoors in. Chinese spies that they're just getting in and they are messing around. So be careful of the Panda out there that is the bottom line.
Now we were talking about Teslas earlier, autonomous cars, electric cars. I got to add this. I was thinking about it as we were talking, but Elon Musk announced just about two weeks ago some amazingly aggressive plans. He has built a big battery plant. You probably know about that. I think that was in New Mexico or Nevada. I can't remember. Might be in Nevada. His whole goal behind all of this is to just slash the costs of producing batteries. And he says, Elon Musk, that is that within three years, he's going to have a fully autonomous electric vehicle for $25,000. Isn't that absolutely amazing?
Now they were expecting that he would be announcing a million-mile battery, which would be, wow! If he had a million-mile battery and a $25,000 Tesla, I would buy it. I would sell some of the other cars and buy them. They also announced a car that has over a 500-mile range. You're going to have to use one of their supercharge to get that thing charged back up again. But it's absolutely amazing.
Could you imagine that a $25,000 electric vehicle battery operated to the market within three years now, the other giveaway from this, because he said it would be autonomous that means, by the way, he has a goal of an autonomous vehicle within three years? So that's another thing to consider.
So the model asks the three, my daughter just bought a Tesla Model three, and she's barely used it yet, but she's absolutely loved with it. It is cool. There's no doubt. It is very cool, technology here.
I got to hit this before the hour runs out and that is that paying ransomware could land you in jail. This is a fascinating article, came out in about a week ago in ARS Technica, and Dan Golden wrote this thing, but I agree with him.
I have many times had to advise people not to pay ransoms for their data and most of the time I have to admit they went and they paid the ransom.
Even these companies that say that they can get your data back by scripting it, breaking the encryption, et cetera. Even those companies, well, a large percent of them, not all of them, the percentage of them are actually paying the ransom behind the scenes.
So you pay them 50 grand and they pay the 20 grand 40 grand ransom and they make a cool 10 grand right off the bat.
Right now. I've got to also mention that there are a couple of websites out there that are dedicated to helping you break the encryption on ransomware. If you do have your data ransomed, now I'm talking about its encrypted and they say, if you want to ever see it again, you pay us. That's different than having ransomware to actually extortion saying, we stole all of your data. Then we encrypted it. And unless you pay this extortion money, not only are you not going to get your data recovered on your computers, but we are going to release everything that we stole, which is your client lists, on and on. We're going to release that to the worldwide internet.
Most companies say, Oh no, don't do that. we'll pay, we'll pay. I can understand that. Statistics I've seen right now, I think it's a little less than 50% of companies are paying the ransoms.
Now, part of the reason when I say not to pay the ransoms is you, don't want to encourage these guys. They are stealing your data. You have your intellectual property that you have spent a lifetime building, right? Or a career building it's not something that really they should be having access to and you don't want to encourage them. One of the things that these bad guys have found. Is, if they can get you to pay a ransom today, they can get you to pay a ransom in a couple of weeks. So they'll try and hit you again because it takes most companies a while. And to bring in security managed security company like mine takes a while to get everything locked down.
Usually what we'll do in that case, is we'll come in, just lock the heck down then try and restore them from backup. Hopefully, their backups are good. I got to say 80% of the time, the companies that think they have backups do not have good backups and it can't all be restored. Plus the time it takes to restore them, you got to factor all of this in. Treasury Department officials said in an official advisory published last Thursday that these bad guys are part of as designated sanctioned nexus, which means you are paying a ransom to an organized criminal or to a blocked person list. There prohibited lists, Cuba, Iran, North Korea, other countries that it is forbidden for you to do business with. So guess what ends up happening then if you pay ransoms law enforcement officials can now charge you. The treasury department, says they're going to. So keep an eye out for that.
Make sure you stick around because we'll be back here after the top of the hour.
Check out my website, Craig peterson.com. There's a whole lot of information there as well for you.
And we're going to talk about the future of computers and it has nothing to do with Intel, nothing to do with AMD, at least the way it looks right now.
So stick around and we'll tell you about upgrading your Windows machine or your Mac because it's all changing.
You're listening to Craig Peterson.
Stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses a new home security device from Ring. The always-on home cam -- get this... it is a drone. Then he talks about Elon Musk and his 25,000 Completely Autonomous Tesla he will have in 3 years. Plus, you better think twice, or three times before paying that ransom to get your data back.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring’s latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
You've been looking for a home security system. We've talked about a few of them on the show before. Right now we're going to be talking about a completely different approach to home security and what Ring's latest camera is all about.
Hi everybody. Craig Peterson here. Thanks for joining me.
Okay. Ring has been around for a while. As I recall Ring was purchased, two, three years ago by our friends over at Amazon. They have some interesting security stuff and they've certainly had their fair share or share of computer problems, security problems here over the years who hasn't, right?
This is what's being called a true ambitious new home security device. This thing is really cool. It sits there. It just, it says Ring on the front. it's just a little square almost. The device has got rounded corners, so looks very nice. And it's got a little light button on it.
One of those little Rings, which is always cool, but it's called the always home cam. And this thing reminds me a little bit of a movie that I've enjoyed many times called Tron from way back when. You might even remember these flying T things, although they had two legs on them and they flew around, that's what this Ring looks like.
It is an autonomous and manual little Quadrocopter, and it is designed where all of the blades are completely hidden if you will. So they're not going to run into anything. They're not going to hurt anything or anyone and hanging beneath these four enclosed blades is a thing like a pack of gum. You remember the old packs of gum, the long thin ones. That's it looks like underneath these four blades. So the idea is you pay them 250 bucks and you plug this thing in, you're going to have to configure it obviously, but it is this little, I guess a Quadrocopters, how I describe it that sits in its charging base.
Now, when it's in the charging base, it's the tail, the long downward part of the T that sits completely immersed in the charging base.
So this charging Base goes all the way up around the base of the Quadrocopter. And it's just the blades that are exposed on top. What it has on that is a camera. I imagine it probably also has a microphone. It doesn't say, but it has a little camera. So when it's in the dark it's charging and that camera is not active.
Even if it was it wouldn't be able to see anything. But what's really cool about this thing is that it can provide you with viewpoints throughout your house. You don't need multiple cameras anymore. The Rings founder's name is Jamie Siminoff. And he's also the chief inventor said that Ring has spent the last two years called focused on the development of the device.
And that it is an obvious product that is very hard to build. And thanks to advancements in drone technology. Ring pulled it off. They're not available yet. It's called the "always home cam." So I'm keeping an eye out for this thing. It is quite cool. It, you can program it what path to take, where it can go.
When you first get it, you build a little map of your home for it to follow. And it asks you for specific viewpoints, such as the kitchen or the bedroom, and the drone can be commanded to fly on-demand or programmed to fly when a disturbance is detected. So you might have a Ring alarm system you in that might include a window opening sensor door, opening sensor. So this little drone can fly up in the air. When it detects someone trying to break in and off it goes, isn't that cool? The drum makes an audible noise when it's flying. Of course, it's small and it's got all these little blades for little blades. So it's obvious when footage is being recorded.
I'm looking at a picture of her right now. It's very cool. Indoor only it's got high Def Ten-Eighty P video. It only records when it's in flight, the propellors are enclosed and integrates with the Ring alarm. So if you are a Ring fan, Check it out. If you're looking for home security, it is not a bad thing.
If you are a business, do not buy Ring. Okay. Because there are real security problems with some of these devices. They are not certified for use in any business that has any federal contacts. In the near future, it's all being disallowed. So just keep that in mind as well. If you're looking to buy security stuff. Also the cheap security stuff we have found backdoors in. Chinese spies that they're just getting in and they are messing around. So be careful of the Panda out there that is the bottom line.
Now we were talking about Teslas earlier, autonomous cars, electric cars. I got to add this. I was thinking about it as we were talking, but Elon Musk announced just about two weeks ago some amazingly aggressive plans. He has built a big battery plant. You probably know about that. I think that was in New Mexico or Nevada. I can't remember. Might be in Nevada. His whole goal behind all of this is to just slash the costs of producing batteries. And he says, Elon Musk, that is that within three years, he's going to have a fully autonomous electric vehicle for $25,000. Isn't that absolutely amazing?
Now they were expecting that he would be announcing a million-mile battery, which would be, wow! If he had a million-mile battery and a $25,000 Tesla, I would buy it. I would sell some of the other cars and buy them. They also announced a car that has over a 500-mile range. You're going to have to use one of their supercharge to get that thing charged back up again. But it's absolutely amazing.
Could you imagine that a $25,000 electric vehicle battery operated to the market within three years now, the other giveaway from this, because he said it would be autonomous that means, by the way, he has a goal of an autonomous vehicle within three years? So that's another thing to consider.
So the model asks the three, my daughter just bought a Tesla Model three, and she's barely used it yet, but she's absolutely loved with it. It is cool. There's no doubt. It is very cool, technology here.
I got to hit this before the hour runs out and that is that paying ransomware could land you in jail. This is a fascinating article, came out in about a week ago in ARS Technica, and Dan Golden wrote this thing, but I agree with him.
I have many times had to advise people not to pay ransoms for their data and most of the time I have to admit they went and they paid the ransom.
Even these companies that say that they can get your data back by scripting it, breaking the encryption, et cetera. Even those companies, well, a large percent of them, not all of them, the percentage of them are actually paying the ransom behind the scenes.
So you pay them 50 grand and they pay the 20 grand 40 grand ransom and they make a cool 10 grand right off the bat.
Right now. I've got to also mention that there are a couple of websites out there that are dedicated to helping you break the encryption on ransomware. If you do have your data ransomed, now I'm talking about its encrypted and they say, if you want to ever see it again, you pay us. That's different than having ransomware to actually extortion saying, we stole all of your data. Then we encrypted it. And unless you pay this extortion money, not only are you not going to get your data recovered on your computers, but we are going to release everything that we stole, which is your client lists, on and on. We're going to release that to the worldwide internet.
Most companies say, Oh no, don't do that. we'll pay, we'll pay. I can understand that. Statistics I've seen right now, I think it's a little less than 50% of companies are paying the ransoms.
Now, part of the reason when I say not to pay the ransoms is you, don't want to encourage these guys. They are stealing your data. You have your intellectual property that you have spent a lifetime building, right? Or a career building it's not something that really they should be having access to and you don't want to encourage them. One of the things that these bad guys have found. Is, if they can get you to pay a ransom today, they can get you to pay a ransom in a couple of weeks. So they'll try and hit you again because it takes most companies a while. And to bring in security managed security company like mine takes a while to get everything locked down.
Usually what we'll do in that case, is we'll come in, just lock the heck down then try and restore them from backup. Hopefully, their backups are good. I got to say 80% of the time, the companies that think they have backups do not have good backups and it can't all be restored. Plus the time it takes to restore them, you got to factor all of this in. Treasury Department officials said in an official advisory published last Thursday that these bad guys are part of as designated sanctioned nexus, which means you are paying a ransom to an organized criminal or to a blocked person list. There prohibited lists, Cuba, Iran, North Korea, other countries that it is forbidden for you to do business with. So guess what ends up happening then if you pay ransoms law enforcement officials can now charge you. The treasury department, says they're going to. So keep an eye out for that.
Make sure you stick around because we'll be back here after the top of the hour.
Check out my website, Craig peterson.com. There's a whole lot of information there as well for you.
And we're going to talk about the future of computers and it has nothing to do with Intel, nothing to do with AMD, at least the way it looks right now.
So stick around and we'll tell you about upgrading your Windows machine or your Mac because it's all changing.
You're listening to Craig Peterson.
Stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses the new firmware architecture being used in the newer computers and laptops and why this architecture is preferred.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring's latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
Hey, we've been talking about how computers are everywhere. What can we expect from our computerized cars? What can we expect from computers? Intel has had a monopoly with Microsoft called the Wintel monopoly.
Hi everybody. You're listening to Craig Peterson.
So if you missed part of today's show. Make sure you double-check and also make sure you are on my newsletter list. I'm surprised here how every week I get questions from people and it's great. That's it. I love to help.
I was asked when I was about 19 to read this little book and to also to fill out a form that said what I wanted on my headstone. That's it heady question to ask somebody at 19 years of age, but I said that this was pretty short and sweet. I said, "he helped others." Just those three words, because that's what I always wanted to do. That's what I always enjoyed doing. You can probably tell that's why I'm doing what I'm doing right now is to help people stop the bad guys and to make their lives a little bit better in the process, right? That's the whole goal. That's the hope anyway.
If you need a little help, all you have to do is reach out. Be glad to help you out. Just email me M E at Craig Peterson dot com. Or if you're on my email list, you'll get all of my weekly articles, everything I talked about here on the show, as well as my during the week little emails that I send out with videos that I've been doing.
I've been putting more together. Didn't get any out this week I had planned to, but I probably will get them out next week. I was able to make a couple of this week and we'll queue them up for the coming week, but you'll get all of that. So just go to. Craig peterson.com/subscribe. You'll find everything there. As part of all of that of course, you will also be getting information about the training that I do. I do all kinds of free training and webinars, and I've got all kinds of reports. One of the most popular ones lately has been my self-audit kit. It's a little tool kit that you can use to audit it, your business and see if you are compliant. It's just a PDF that you can take from the email that I send you. If you ask for it, all you have to do is ask for an audit kit, put that in the subject line, and email [email protected] and we'll get you going.
So I've had a few people who have this week said, Hey, can you help me out? What do I do? I help them out. It turns out when I'm helping them out, they're not even on my email list. So I'll start there. If you're wondering where to start, how to get up to speed a little bit, right?
You don't have to know all of this stuff like the back of your hand, but you do have to have the basic understanding. Just go online. And a sign-up Craig peterson.com/subscribe would love to have you there. Even when we get into the ice station zebra weather here coming up in not so long, unfortunately, in the Northeast.
When you're thinking about your computer and what to buy. There are a lot of choices. Of course, the big ones nowadays are a little different than they were just a few years ago. Or a couple of years ago, you used to say, am I going to get a Windows computer, or am I going to get a Mac now?
I think there's a third choice that's really useful for most people, depends on what you're doing. If what you do is some web browsing, some email, and also might do a couple of things with some video and pictures and organizing you really should look at the third option. Which is a tablet of some sort and that is your iPad.
Of course, the number one in the market, these things last a long time. They retain their value. So their higher introductory price isn't really a bad thing. And they're also not that much more expensive when you get right down to it and consider the resale value of them. So have a look at the tablet, but that's really one of the three major choices also today when you're deciding that you might not be aware of it, but you are also deciding what kind of processor you're going to be using.
There is a lot of work that's been done going on arm processors. What they are called A R M. I started working with this class of processor, also known as RISC, which is reduced instruction set processors, many years ago, back in the nineties. I think it was when I first started working with RISC machines.
But the big difference here is that these are not Intel chips that are in the iPads that are in or our iPhones, they aren't Intel or AMD processors that are in your Android phones or Android tablet. They're all using something that's called ARM architecture.
This used to be called advanced risc machine acorn risk machine. They've been around a while, but ARM is a different type of processor entirely then Intel. the basic Intel design is to try and get as much done with one instruction as possible.
So for instance, if you and I decided to meet up at a Dunkin donuts, I might say, okay, so we're going to go to the Duncan's on Elm Street, but the one that's South of Main Street, and I'll meet you there at about 11 o'clock.
And then I gave you some of the directions on how to get to the town, et cetera. And so we meet at dunks and to have a good old time. That would be a RISC architecture, which has reduced instructions. So you can tell it, okay, you get to take a right turn here, take a left turn there. In the computing world, it would be, you have to add this and divide that and then add these and divide those and subtract this.
Now to compare my little dunk story. What you end up doing with an Intel processor or what's called a CISC processor, which is a complex instruction set, is we've already been to dunks before that dunks in fact, so all I have to say is I'll meet you at dunks. Usual time. There's nothing else I have to say. So behind all of that is the process of getting into your car, driving down to dunks the right town, the right street, the right dunks, and maybe even ordering.
So in a CISC processor, it would try and do all of those things with one instruction. The idea is, let's make it simple for the programmer. So all of the programmers have to do if the programmer wants to multiply two double-precision floating-point numbers, the programmer that if he's just dealing with machine-level only has to have one instruction.
Now those instructions take up multiple cycles. We can. Get into all the details, but I think I've already got some people glazing over. But these new ARM processors are designed to be blindingly fast is what matters. We can teach a processor how to add, and if we spend our time figuring out how to get that processor to add faster.
We end up with ultimately faster chip and that's the theory behind risk or reduced instruction set computers, and it has taken off like wildfire.
So you have things like the iPad pro now with an arm chip that's in there designed by Apple. Now they took the basic license with the basic ARM architecture and they've advanced it quite a bit. In fact, but that Ipad processor now is faster than most laptop processors made by Intel or AMD. That is an impressive feat.
So when we're looking a little bit forward, we're no longer looking at machines that are just running an Intel instruction set. We're not just going to see, in other words, the Intel and AMD inside stickers on the outside of the computer. Windows 10 machines running on ARM processors are out already.
Apple has announced arm based laptops that will be available very soon. In fact, there is a scheduled press conference. I think it's next week by Apple, the 15th. Give or take. Don't hold me to that one, but they're going to have a, probably an announcement of the iPhone 12 and maybe some delivery dates for these new ARM-based laptops.
So these laptops are expected to last all day. Really all day. 12 hours worth of working with them, using them. They're expected to be just as fast or faster in some cases as the Intel chips are. So ARM is where things are going.
We already have the Microsoft updated surface pro X. That was just announced about two weeks ago, which is ARM-based. We've gotten macs now coming out with their ARM-based versions. In fact, I think they're going to have two of them before the end of the year. Both Apple and Microsoft are providing support for x86 apps. So what that means is the programs that you have bought that are designed to run on an Intel architecture will run on these ARM chips.
Now, as a rule, it's only the 64-bit processes that are going to work. The 32-bit processes, if you haven't upgraded your software to 64 bits yet you're gonna have to upgrade it before you can do the ARM migration. We're going to see less expensive computers. Arm chips are much cheaper as a whole than Intel. Intel chips are insanely high priced.
They are also going to be way more battery efficient. So if you're looking for a new computer. Visual studio code has been updated optimized for windows 10 on ARM. We're going to see more and more of the applications coming out.
And it won't be long, a couple of years now, you will have a hard time finding some of the Intel-based software that's out there.
Hey, you're listening to Craig Peterson.
Stick around. Cause we'll be right back and "it won't happen to me." That's our next topic.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses the new firmware architecture being used in the newer computers and laptops and why this architecture is preferred.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring’s latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
Hey, we've been talking about how computers are everywhere. What can we expect from our computerized cars? What can we expect from computers? Intel has had a monopoly with Microsoft called the Wintel monopoly.
Hi everybody. You're listening to Craig Peterson.
So if you missed part of today's show. Make sure you double-check and also make sure you are on my newsletter list. I'm surprised here how every week I get questions from people and it's great. That's it. I love to help.
 I was asked when I was about 19 to read this little book and to also to fill out a form that said what I wanted on my headstone. That's it heady question to ask somebody at 19 years of age, but I said that this was pretty short and sweet. I said, "he helped others." Just those three words, because that's what I always wanted to do. That's what I always enjoyed doing. You can probably tell that's why I'm doing what I'm doing right now is to help people stop the bad guys and to make their lives a little bit better in the process, right? That's the whole goal. That's the hope anyway.
If you need a little help, all you have to do is reach out. Be glad to help you out. Just email me M E at Craig Peterson dot com. Or if you're on my email list, you'll get all of my weekly articles, everything I talked about here on the show, as well as my during the week little emails that I send out with videos that I've been doing.
 I've been putting more together. Didn't get any out this week I had planned to, but I probably will get them out next week. I was able to make a couple of this week and we'll queue them up for the coming week, but you'll get all of that. So just go to. Craig peterson.com/subscribe. You'll find everything there. As part of all of that of course, you will also be getting information about the training that I do. I do all kinds of free training and webinars, and I've got all kinds of reports. One of the most popular ones lately has been my self-audit kit. It's a little tool kit that you can use to audit it, your business and see if you are compliant. It's just a PDF that you can take from the email that I send you. If you ask for it, all you have to do is ask for an audit kit, put that in the subject line, and email [email protected] and we'll get you going.
So I've had a few people who have this week said, Hey, can you help me out? What do I do? I help them out. It turns out when I'm helping them out, they're not even on my email list. So I'll start there. If you're wondering where to start, how to get up to speed a little bit, right?
You don't have to know all of this stuff like the back of your hand, but you do have to have the basic understanding. Just go online. And a sign-up Craig peterson.com/subscribe would love to have you there. Even when we get into the ice station zebra weather here coming up in not so long, unfortunately, in the Northeast.
When you're thinking about your computer and what to buy. There are a lot of choices. Of course, the big ones nowadays are a little different than they were just a few years ago. Or a couple of years ago, you used to say, am I going to get a Windows computer, or am I going to get a Mac now?
I think there's a third choice that's really useful for most people, depends on what you're doing. If what you do is some web browsing, some email, and also might do a couple of things with some video and pictures and organizing you really should look at the third option. Which is a tablet of some sort and that is your iPad.
Of course, the number one in the market, these things last a long time. They retain their value. So their higher introductory price isn't really a bad thing. And they're also not that much more expensive when you get right down to it and consider the resale value of them. So have a look at the tablet, but that's really one of the three major choices also today when you're deciding that you might not be aware of it, but you are also deciding what kind of processor you're going to be using.
There is a lot of work that's been done going on arm processors. What they are called A R M. I started working with this class of processor, also known as RISC, which is reduced instruction set processors, many years ago, back in the nineties. I think it was when I first started working with RISC machines.
But the big difference here is that these are not Intel chips that are in the iPads that are in or our iPhones, they aren't Intel or AMD processors that are in your Android phones or Android tablet. They're all using something that's called ARM architecture.
This used to be called advanced risc machine acorn risk machine. They've been around a while, but ARM is a different type of processor entirely then Intel. the basic Intel design is to try and get as much done with one instruction as possible.
So for instance, if you and I decided to meet up at a Dunkin donuts, I might say, okay, so we're going to go to the Duncan's on Elm Street, but the one that's South of Main Street, and I'll meet you there at about 11 o'clock.
And then I gave you some of the directions on how to get to the town, et cetera. And so we meet at dunks and to have a good old time. That would be a RISC architecture, which has reduced instructions. So you can tell it, okay, you get to take a right turn here, take a left turn there. In the computing world, it would be, you have to add this and divide that and then add these and divide those and subtract this.
Now to compare my little dunk story. What you end up doing with an Intel processor or what's called a CISC processor, which is a complex instruction set, is we've already been to dunks before that dunks in fact, so all I have to say is I'll meet you at dunks. Usual time. There's nothing else I have to say. So behind all of that is the process of getting into your car, driving down to dunks the right town, the right street, the right dunks, and maybe even ordering.
So in a CISC processor, it would try and do all of those things with one instruction. The idea is, let's make it simple for the programmer. So all of the programmers have to do if the programmer wants to multiply two double-precision floating-point numbers, the programmer that if he's just dealing with machine-level only has to have one instruction.
Now those instructions take up multiple cycles. We can. Get into all the details, but I think I've already got some people glazing over. But these new ARM processors are designed to be blindingly fast is what matters. We can teach a processor how to add, and if we spend our time figuring out how to get that processor to add faster.
We end up with ultimately faster chip and that's the theory behind risk or reduced instruction set computers, and it has taken off like wildfire.
So you have things like the iPad pro now with an arm chip that's in there designed by Apple. Now they took the basic license with the basic ARM architecture and they've advanced it quite a bit. In fact, but that Ipad processor now is faster than most laptop processors made by Intel or AMD. That is an impressive feat.
So when we're looking a little bit forward, we're no longer looking at machines that are just running an Intel instruction set. We're not just going to see, in other words, the Intel and AMD inside stickers on the outside of the computer. Windows 10 machines running on ARM processors are out already.
Apple has announced arm based laptops that will be available very soon. In fact, there is a scheduled press conference. I think it's next week by Apple, the 15th. Give or take. Don't hold me to that one, but they're going to have a, probably an announcement of the iPhone 12 and maybe some delivery dates for these new ARM-based laptops.
So these laptops are expected to last all day. Really all day. 12 hours worth of working with them, using them. They're expected to be just as fast or faster in some cases as the Intel chips are. So ARM is where things are going.
We already have the Microsoft updated surface pro X. That was just announced about two weeks ago, which is ARM-based. We've gotten macs now coming out with their ARM-based versions. In fact, I think they're going to have two of them before the end of the year. Both Apple and Microsoft are providing support for x86 apps. So what that means is the programs that you have bought that are designed to run on an Intel architecture will run on these ARM chips.
Now, as a rule, it's only the 64-bit processes that are going to work. The 32-bit processes, if you haven't upgraded your software to 64 bits yet you're gonna have to upgrade it before you can do the ARM migration. We're going to see less expensive computers. Arm chips are much cheaper as a whole than Intel. Intel chips are insanely high priced.
They are also going to be way more battery efficient. So if you're looking for a new computer. Visual studio code has been updated optimized for windows 10 on ARM. We're going to see more and more of the applications coming out.
And it won't be long, a couple of years now, you will have a hard time finding some of the Intel-based software that's out there.
Hey, you're listening to Craig Peterson.
Stick around. Cause we'll be right back and "it won't happen to me." That's our next topic.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses the problem that many businesses face -- employee apathy and lack of security awareness.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring's latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
We've got companies who are investing a lot of money to upgrade the technology, to develop security processes, boost it. Staff yet studies are showing that they're overlooking the biggest piece of the puzzle. What is the problem?
Hey everybody. You're listening to Craig Peterson.
Employee apathy has been a problem for many businesses for a very long time. Nowadays, employee apathy is causing problems on the cybersecurity front. As we've talked about so many times, cybersecurity is absolutely critical. For any business or businesses are being attacked sometimes hundreds of times, a minute, a second, even believe it or not.
Some of these websites come under attack and if we're not paying close attention, we're in trouble. So a lot of companies have decided while they need to boost their IT staff. They've got to get some spending on some of the hardware that's going to make life. Better. And I am cheering them on.
I think both of those are great ideas, but the bottom line problem is there is million-plus open cybersecurity it jobs. So as a business, odds are excellent that you won't be able to find the type of person that you need. Isn't that a shame?
But I've got some good news for you here. You can upgrade the technology that's going to help. But if you upgrade the technology, make sure you're moving towards, what's called a single pane of glass. You don't want a whole bunch of point solutions. You want something that monitors everything. Pulls all of that knowledge together uses some machine learning and some artificial intelligence and from all of that automatically shuts down attacks, whether they're internal or external, that's what you're looking for.
There are some vendors that have various things out there. If you sell to the federal government within three years, you're going to have to meet these new requirements, the CMMC requirements, level three, four, level five, which are substantial.
You cannot do it yourself, you have to bring in a cybersecurity expert. Who's going to work with your team and help you develop a plan. I think that's really great, really important, but here's where the good news comes in.
You spent an astronomical amount of money to upgrade this technology and get all of these processes in place and you brought in this consultant, who's going to help you out. You boosted your IT staff. But studies are starting to indicate that a lot of these businesses are overlooking the biggest piece of the puzzle, which is their employees.
Most of these successful attacks nowadays are better than 60%, it depends on how you're scoring this, but most of the attacks these days come in through your employees.
That means that you clicked on a link. One of your employees clicked on a link. If you are a home user, it's exactly the same thing. The bad guys are getting you because you did something that you should not have done. Just go have a look online. If you haven't already make sure you go to have I been poned.com. Poned is spelled PWNED
Have a look at it there online and try and see if your email address and passwords that you've been using have already been compromised. Have already been stolen. I bet they have, almost everybody has.
Do you know what to do from that? This is part of the audit kit that I'll send to you. If you ask for that. Kind of goes through this and a whole lot of other stuff. But checking to see if your data has been stolen, because now is they use that to trick people.
So they know that you go to a particular website that you use a particular email address or password. They might've been able to get into one of these social networks and figure out who your friends are. They go and take that information. Now a computer can do this. They just mine it from a website like LinkedIn, find out who the managers in the company are.
And then they send off some emails that look very convincing, and those convincing emails get them to click. That could be the end of it. Because you are going somewhere, you shouldn't go and they're going to trick you into doing something. Knowledge really is the best weapon when it comes to cybersecurity.
A lot of companies have started raising awareness among employees. I have some training that we can provide as well. That is very good. It's all video training and it's all tracked. We buy these licenses in big bundles. If you are a small company contact me and I'll see if I can't just sneak you into one of these bundles.
Just email me @craigpeterson.com in the subject line, put something like training, bundle, or something. You need to find training for your employees and their training programs need to explain the risk of phishing scams. Those they're the big ones. That's how most the ransomware it gets into businesses is phishing scams. That's how ransomware gets down to your computers.
You also need to have simulations that clarify the steps you need to take when faced with a suspicious email. Again, if you want, I can point you to a free site that Google has on some phishing training and it's really quite good.
It walks you through and shows you what the emails might look like and if you want to click or not. But there's a lot of different types of training programs. You've got to make sure that everybody inside your organization or in your, the family is educated about cybersecurity.
What do you do when you get an email that you suspect might be a phishing email? They need to know that this needs to be forwarded to IT, or perhaps they just tell IT, Hey, it's in my mailbox, if IT has access to their mailbox, so IT can look at it and verify it.
You need to have really good email filters, not the type that comes by default with a Microsoft Windows 365 subscription, but something that flags all of this looks for phishing scams and blocks them.
There's been a ton of studies now that are showing that there is a greater awareness of cybersecurity dangers, but the bottom-line problem is that employees are still showing a lax attitude when it comes to practicing even the most basic of the cybersecurity prevention methods. TrendMicro, who is a cybersecurity company.
We tend to not use their stuff because it's just not as good. But TrendMicro is reporting that despite 72% of employees claim to have gained better cybersecurity awareness during the pandemic 56% still admitted to using a non-work application on a company device. Now that can be extremely dangerous. 66% admitted uploading corporate data to that application. This includes, by the way, things like using just regular versions of Dropbox. Do you share files from the office and home? Dropbox does have versions that are all that have all kinds of compliance considerations that do give you security. But by default, the stuff a home user does not get the security you need. They're doing all of this even knowing that their behavior represents a security risk. And I think it boils right down to, it's not going to happen to me. Just apathy and denial. So same thing I've seen, being a security guy for the last 30 years, I've seen over and over, apathy and denial. Don't let it happen to them.
By the way, about 50% believe that they could be hacked no matter what protective measures are taken. 43% took the polar opposite. They didn't take the threat seriously at all. 43% didn't believe they could be hacked.
Some interesting numbers stick around. When we get back, we're going to talk about Mac OS is driving cybersecurity rethink.
We'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses the problem that many businesses face -- employee apathy and lack of security awareness.Â
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring’s latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
We've got companies who are investing a lot of money to upgrade the technology, to develop security processes, boost it. Staff yet studies are showing that they're overlooking the biggest piece of the puzzle. What is the problem?
Hey everybody. You're listening to Craig Peterson.
 Employee apathy has been a problem for many businesses for a very long time. Nowadays, employee apathy is causing problems on the cybersecurity front. As we've talked about so many times, cybersecurity is absolutely critical. For any business or businesses are being attacked sometimes hundreds of times, a minute, a second, even believe it or not.
Some of these websites come under attack and if we're not paying close attention, we're in trouble. So a lot of companies have decided while they need to boost their IT staff. They've got to get some spending on some of the hardware that's going to make life. Better. And I am cheering them on.
I think both of those are great ideas, but the bottom line problem is there is million-plus open cybersecurity it jobs. So as a business, odds are excellent that you won't be able to find the type of person that you need. Isn't that a shame?
But I've got some good news for you here. You can upgrade the technology that's going to help. But if you upgrade the technology, make sure you're moving towards, what's called a single pane of glass. You don't want a whole bunch of point solutions. You want something that monitors everything. Pulls all of that knowledge together uses some machine learning and some artificial intelligence and from all of that automatically shuts down attacks, whether they're internal or external, that's what you're looking for.
There are some vendors that have various things out there. If you sell to the federal government within three years, you're going to have to meet these new requirements, the CMMC requirements, level three, four, level five, which are substantial.
You cannot do it yourself, you have to bring in a cybersecurity expert. Who's going to work with your team and help you develop a plan. I think that's really great, really important, but here's where the good news comes in.
You spent an astronomical amount of money to upgrade this technology and get all of these processes in place and you brought in this consultant, who's going to help you out. You boosted your IT staff. But studies are starting to indicate that a lot of these businesses are overlooking the biggest piece of the puzzle, which is their employees.
Most of these successful attacks nowadays are better than 60%, it depends on how you're scoring this, but most of the attacks these days come in through your employees.
That means that you clicked on a link. One of your employees clicked on a link. If you are a home user, it's exactly the same thing. The bad guys are getting you because you did something that you should not have done. Just go have a look online. If you haven't already make sure you go to have I been poned.com. Poned is spelled PWNED
 Have a look at it there online and try and see if your email address and passwords that you've been using have already been compromised. Have already been stolen. I bet they have, almost everybody has.
 Do you know what to do from that? This is part of the audit kit that I'll send to you. If you ask for that. Kind of goes through this and a whole lot of other stuff. But checking to see if your data has been stolen, because now is they use that to trick people.
So they know that you go to a particular website that you use a particular email address or password. They might've been able to get into one of these social networks and figure out who your friends are. They go and take that information. Now a computer can do this. They just mine it from a website like LinkedIn, find out who the managers in the company are.
And then they send off some emails that look very convincing, and those convincing emails get them to click. That could be the end of it. Because you are going somewhere, you shouldn't go and they're going to trick you into doing something. Knowledge really is the best weapon when it comes to cybersecurity.
A lot of companies have started raising awareness among employees. I have some training that we can provide as well. That is very good. It's all video training and it's all tracked. We buy these licenses in big bundles. If you are a small company contact me and I'll see if I can't just sneak you into one of these bundles.
Just email me @craigpeterson.com in the subject line, put something like training, bundle, or something. You need to find training for your employees and their training programs need to explain the risk of phishing scams. Those they're the big ones. That's how most the ransomware it gets into businesses is phishing scams. That's how ransomware gets down to your computers.
You also need to have simulations that clarify the steps you need to take when faced with a suspicious email. Again, if you want, I can point you to a free site that Google has on some phishing training and it's really quite good.
 It walks you through and shows you what the emails might look like and if you want to click or not. But there's a lot of different types of training programs. You've got to make sure that everybody inside your organization or in your, the family is educated about cybersecurity.
What do you do when you get an email that you suspect might be a phishing email? They need to know that this needs to be forwarded to IT, or perhaps they just tell IT, Hey, it's in my mailbox, if IT has access to their mailbox, so IT can look at it and verify it.
You need to have really good email filters, not the type that comes by default with a Microsoft Windows 365 subscription, but something that flags all of this looks for phishing scams and blocks them.
There's been a ton of studies now that are showing that there is a greater awareness of cybersecurity dangers, but the bottom-line problem is that employees are still showing a lax attitude when it comes to practicing even the most basic of the cybersecurity prevention methods. TrendMicro, who is a cybersecurity company.
We tend to not use their stuff because it's just not as good. But TrendMicro is reporting that despite 72% of employees claim to have gained better cybersecurity awareness during the pandemic 56% still admitted to using a non-work application on a company device. Now that can be extremely dangerous. 66% admitted uploading corporate data to that application. This includes, by the way, things like using just regular versions of Dropbox. Do you share files from the office and home? Dropbox does have versions that are all that have all kinds of compliance considerations that do give you security. But by default, the stuff a home user does not get the security you need. They're doing all of this even knowing that their behavior represents a security risk. And I think it boils right down to, it's not going to happen to me. Just apathy and denial. So same thing I've seen, being a security guy for the last 30 years, I've seen over and over, apathy and denial. Don't let it happen to them.
By the way, about 50% believe that they could be hacked no matter what protective measures are taken. 43% took the polar opposite. They didn't take the threat seriously at all. 43% didn't believe they could be hacked.
Some interesting numbers stick around. When we get back, we're going to talk about Mac OS is driving cybersecurity rethink.
We'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses the oversharing attitudes of Millennials and Generation Z, and the importance of paying attention to our networks, how it can lead to malware in businesses, and what can be done to stop it.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring's latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
By the way, to follow up on that last segment. So Millennials and Generation Z are terrible with security. They keep reusing passwords. They accept connections with strangers. Most of the time. If that's not believable, I don't know what it is. They've grown up in this world of share everything with everyone. What does it matter? Don't worry about it. Yeah. I guess that's the way it goes. Right? Kids these days. Which generation hasn't said that in the past?
You're listening to Craig Peterson. Thanks for joining me today.
We were just talking about millennials, generation Z, and the whole, it won't happen to me, employee apathy, and we've got to stop that.
Even within ourselves, right? We're all employees in some way or another. What does that mean? It means we've got to pay attention. We've' got to pay a lot of attention, and that isn't just true in the windows world.
Remember, we've got to pay attention to our network. It would be best if you were upgrading the firmware on your switches, definitely upgrading the software and firmware in your firewalls and your routers, et cetera. Keep that all up to date.
Even as a home user, you've got a switch or more than one. You've got a router. You've got a firewall in many cases, that your ISP internet service provider provides equipment. If you've got a Comcast line or a FairPoint, whatever, it might be coming into your home, they're providing you with some of that equipment, and you know what their top priority is not your security. I know. Shocker.
Their top priority is something else. I don't know, but it sure isn't security. What I advise most people to do is basically remove their equipment or have them turn off what's called network address translation. Turn off the firewall and put your own firewall in place. I was on the phone with a lady that had been listening to me for years, and I was helping her out. In fact, we were doing a little security audit because she ran a small business there in her home. I think she was an accountant if I remember right. She had her computer hooked up directly to the internet. She misunderstood what I was saying. I want to make this clear what I'm saying here. People should still have a firewall. It would be best if you still had a router, but you're almost always better off getting a semi-professional piece of hardware. If you will, the prosumer side, something like the Cisco GO hardware, put that in place instead of having the equipment that your ISP is giving you.
We've got to keep all of this stuff up to date. Many of us think that Macs are invulnerable, Apple Macintoshes, or Apple iOS devices, like our iPhones and iPads. In many ways, they are. They have not been hit as hard as the Windows devices out there.
One of the main reasons is they're not as popular. That's what so many people that use Windows say you don't get hit because you're just not as popular. There is some truth to that. However, the main reason is that they are designed from the beginning with security in mind; unlike Windows, security was an absolute afterthought for the whole thing.
Don't tell me that it's because of age. Okay. I can hear it right now. People say, well, Mac is much, much newer than Microsoft Windows. Microsoft didn't have to deal with all of this way back when. How I respond to that is, yeah. Microsoft didn't have to deal with it way back when it wasn't connected to a network and your viruses coming in via floppy desk. Right? They really were. In fact, the first one came in by researchers. Apple's operating system is much, much older than windows and goes back to the late 1960s, early 1970s. So you can't give me that it is just that they didn't care.
They didn't care to consider security at all, which is still one of my soapbox subjects if you will. Security matters. When we are talking about your Macs, you still have to consider security on a Mac. It's a little different on a Mac. You're probably want to turn on some things.
The windows come with the firewall turned on; however, it has all of its services wide open. They're all available for anybody to attach to. That's why we have our windows hardening course that goes through, what do you turn off? How do you turn it off? What should you have in the windows firewall?
Now the Mac side, all of these services turned off by default, which is way more secure. If they're not there to attack, they're not going to be compromised. Right. They can't even be attacked in the first place. So I like that strategy, but you might want to turn on your firewall on your Mac anyways.
There are some elegant little features and functions in it. But the amount of malware that's attacking Apple Macintoshes, nowadays, is twice as much as it used to be.
We've got these work from home people. We've got IT professionals within the companies, just scrambling to make it so that these people working from home can keep working from home. It's likely a permanent thing. It's going to be happening for a long time. But these incidents of malware on the Mac is pretty limited in reality.
The malware on a Mac is unlikely to be any ransomware or software that particularly steals things like your Excel files or your Word docs on a Mac, and I should say it is much more likely to be outerwear. It's much more likely to be. Adware or some other unwanted programs, and that's what's rising pretty fast on Macs.
Mac-based companies are being concerned here about cybersecurity issues. They are paying more attention to them. They're windows based counterparts have had to deal with a lot of this stuff for a long time because they were targets. So we've got to divide the Mac really into two pieces, just like any other computer. You've got the operating system with its control over things like the network, et cetera. Then you have the programs or applications. That is running on that device. So you want to keep both of them secure. The applications running on your device, Apple's done a much, much better job of sandboxing them. Making them so that they're less dangerous. The latest release, in fact, Catalina had a lot of security stuff built into that. Microsoft and Windows 10 added a lot more security. So that's all really, really good.
Now, if you have to maintain a network of Macs, we like IBM software. They have some great software for managing Macs, but if you want something inexpensive and very usable to configure Macs and control the software on them. Have a look at JAMF, J A M F. They just had their user's conference this last weekend. They were talking about how the landscape has changed over on the Mac side.
All right. We've got one more segment left today, and I'm going to talk about these cybersecurity frameworks. What should you be using?
If you are a business or a home user, what are those checkboxes that you absolutely have to have to use?
You're listening to Craig Peterson.
Stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses the oversharing attitudes of Millennials and Generation Z, and the importance of paying attention to our networks, how it can lead to malware in businesses, and what can be done to stop it.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring’s latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
By the way, to follow up on that last segment. So Millennials and Generation Z are terrible with security. They keep reusing passwords. They accept connections with strangers. Most of the time. If that's not believable, I don't know what it is. They've grown up in this world of share everything with everyone. What does it matter? Don't worry about it. Yeah. I guess that's the way it goes. Right? Kids these days. Which generation hasn't said that in the past?
You're listening to Craig Peterson. Thanks for joining me today.
We were just talking about millennials, generation Z, and the whole, it won't happen to me, employee apathy, and we've got to stop that.
Even within ourselves, right? We're all employees in some way or another. What does that mean? It means we've got to pay attention. We've' got to pay a lot of attention, and that isn't just true in the windows world.
Remember, we've got to pay attention to our network. It would be best if you were upgrading the firmware on your switches, definitely upgrading the software and firmware in your firewalls and your routers, et cetera. Keep that all up to date.
Even as a home user, you've got a switch or more than one. You've got a router. You've got a firewall in many cases, that your ISP internet service provider provides equipment. If you've got a Comcast line or a FairPoint, whatever, it might be coming into your home, they're providing you with some of that equipment, and you know what their top priority is not your security. I know. Shocker.
Their top priority is something else. I don't know, but it sure isn't security. What I advise most people to do is basically remove their equipment or have them turn off what's called network address translation. Turn off the firewall and put your own firewall in place. I was on the phone with a lady that had been listening to me for years, and I was helping her out. In fact, we were doing a little security audit because she ran a small business there in her home. I think she was an accountant if I remember right. She had her computer hooked up directly to the internet. She misunderstood what I was saying. I want to make this clear what I'm saying here. People should still have a firewall. It would be best if you still had a router, but you're almost always better off getting a semi-professional piece of hardware. If you will, the prosumer side, something like the Cisco GO hardware, put that in place instead of having the equipment that your ISP is giving you.
 We've got to keep all of this stuff up to date. Many of us think that Macs are invulnerable, Apple Macintoshes, or Apple iOS devices, like our iPhones and iPads. In many ways, they are. They have not been hit as hard as the Windows devices out there.
One of the main reasons is they're not as popular. That's what so many people that use Windows say you don't get hit because you're just not as popular. There is some truth to that. However, the main reason is that they are designed from the beginning with security in mind; unlike Windows, security was an absolute afterthought for the whole thing.
Don't tell me that it's because of age. Okay. I can hear it right now. People say, well, Mac is much, much newer than Microsoft Windows. Microsoft didn't have to deal with all of this way back when. How I respond to that is, yeah. Microsoft didn't have to deal with it way back when it wasn't connected to a network and your viruses coming in via floppy desk. Right? They really were. In fact, the first one came in by researchers. Apple's operating system is much, much older than windows and goes back to the late 1960s, early 1970s. So you can't give me that it is just that they didn't care.
They didn't care to consider security at all, which is still one of my soapbox subjects if you will. Security matters. When we are talking about your Macs, you still have to consider security on a Mac. It's a little different on a Mac. You're probably want to turn on some things.
The windows come with the firewall turned on; however, it has all of its services wide open. They're all available for anybody to attach to. That's why we have our windows hardening course that goes through, what do you turn off? How do you turn it off? What should you have in the windows firewall?
Now the Mac side, all of these services turned off by default, which is way more secure. If they're not there to attack, they're not going to be compromised. Right. They can't even be attacked in the first place. So I like that strategy, but you might want to turn on your firewall on your Mac anyways.
There are some elegant little features and functions in it. But the amount of malware that's attacking Apple Macintoshes, nowadays, is twice as much as it used to be.
We've got these work from home people. We've got IT professionals within the companies, just scrambling to make it so that these people working from home can keep working from home. It's likely a permanent thing. It's going to be happening for a long time. But these incidents of malware on the Mac is pretty limited in reality.
The malware on a Mac is unlikely to be any ransomware or software that particularly steals things like your Excel files or your Word docs on a Mac, and I should say it is much more likely to be outerwear. It's much more likely to be. Adware or some other unwanted programs, and that's what's rising pretty fast on Macs.
Mac-based companies are being concerned here about cybersecurity issues. They are paying more attention to them. They're windows based counterparts have had to deal with a lot of this stuff for a long time because they were targets. So we've got to divide the Mac really into two pieces, just like any other computer. You've got the operating system with its control over things like the network, et cetera. Then you have the programs or applications. That is running on that device. So you want to keep both of them secure. The applications running on your device, Apple's done a much, much better job of sandboxing them. Making them so that they're less dangerous. The latest release, in fact, Catalina had a lot of security stuff built into that. Microsoft and Windows 10 added a lot more security. So that's all really, really good.
Now, if you have to maintain a network of Macs, we like IBM software. They have some great software for managing Macs, but if you want something inexpensive and very usable to configure Macs and control the software on them. Have a look at JAMF, J A M F. They just had their user's conference this last weekend. They were talking about how the landscape has changed over on the Mac side.
All right. We've got one more segment left today, and I'm going to talk about these cybersecurity frameworks. What should you be using?
If you are a business or a home user, what are those checkboxes that you absolutely have to have to use?
You're listening to Craig Peterson.
Stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses Cybersecurity Audits, Compliance, NIST Standards, CMMC, and what is expected of the Department of Defense Contractors and Sub-contractors in this segment.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Right To Repair Or A Fight For Survival?
Ring's latest security camera is a drone that flies around inside your house
Malware Attacks Declined But Became More Evasive in Q2
Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla
Paying ransomware demands could land you in hot water with the feds
Windows 10 machines running on ARM will be able to emulate x64 apps soon
'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness
Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'
A Guide to the NIST Cybersecurity Framework
---
Automated Machine-Generated Transcript:
You might've heard about cybersecurity frameworks? Well, the one that's most in use right now is the NIST cybersecurity framework that helps guide you through the process of securing your business or even securing your home. That's our topic.
Hi everybody. Craig Peterson here.
It's a great time to be out on the road and kind of checking in. Of course, you can find me online at craigpeterson.com. We've got security threats that have been growing quite literally. Exponentially. They are really making a lot of money by extorting it from us, stealing it from us. It's nothing but frustration to us.
It's never been more important to put together an effective cybersecurity risk management policy. That's true if you're a home user and you've got your yourself and your spouse and a kid or two in the home. Have a policy and put it together.
That's where NIST comes in handy. NIST is the National Institute of standards and technology they've been around for a long time. They've been involved in cryptography. These are the guys and gals that give us accurate clocks. In fact, we run two clocks here that we have for our clients, which are hyper-accurate. It's crazy it down to the millionth of a second. It's just amazing. That's who NIST is.
They've put all these standards together for a very, very long time, but just before March, this year, It was reported that about 46 percent of businesses had suffered cyber attacks in 2019. That was up 10% from the year before. Of course, we've all been worried about the Wuhan virus, people getting COVID-19, it is a problem.
The biggest part of the problem is everybody's worried about it. Nobody wants to go to work. They don't want to go out to a restaurant. They don't want to do any of these things. You as a business owner are worried about how do you keep your business doors open? How do you provide services to the customers you have when your employees won't come in or cooperate or were paid more to stay at home than they would be to come back to work. I get it right. I know I'm in the same boat.
Well, because of that we just have not been paying attention to some of the things we should be doing. One of the main ways that business people can measure their preparedness and their progress in managing cyber security-related risks, is to use the cybersecurity framework that is developed by NIST. It is a great framework.
It provides you with different levels. The higher-end, the framework that is used by military contractors. Nowadays, we've been helping businesses conform to what's called NIST 800-171 and 800-53 High, which are both important and cybersecurity standards.
So if you really, really, really need to be secure, are those are the ones you're going to be going with. Right now, no matter how much security you need I really would recommend you checking it out. I can send you information on the NIST framework. I have a little flow chart. I can send you to help to figure out what part of the framework should you be complying with.
It also helps you figure out if you by law need to be complying with parts of the framework. It will really help you. It's well thought out. It's going to make you way more efficient as you try and put together and execute your cyber risk management policy. Remember cyber risk, isn't just for the software that you're running, or the systems you're running. It's the people, it includes some physical security as well.
Now President Trump has been very concerned about it. I'm sure you've heard about it in the news. As he's talked about problems with TicTok and with Huawei and some of these other manufacturers out there. Huawei is a huge problem. Just absolutely huge.
One of these days I can give you the backstory on that, but how they completely destroyed one of the world leaders in telecommunications technology by stealing everything they had. Yeah. It's a very sad story company you may have heard of, founded over a hundred years ago.
They're non-regulatory but they do publish guides that are used in regulations. So have a look at them, keep an eye on them. They have to help federal agencies as well. Meet the requirements is something called the federal information security management act called FISMA and that relates to the protection of government information and assets.
So if you are a contractor to the federal government, pretty much any agency, you have physical requirements.
So think about that. Who do you sell things to? When you're also dealing with the federal government they look at everything that you're doing and say, are you making something special for us? If you are, there are more and higher standards that you have to meet as well. It just goes on and on, but this framework was created by NIST ratified by Congress in 2014. It's used by over 30% of businesses in the US and will probably be used by 50% of businesses in the US this year.
So if you're not using them you might want to have a look at them. It's big companies like JP Morgan, Chase, Microsoft, Boeing, and Intel who meet a much higher standard than most businesses need to meet.
A lot of businesses all you need to meet is what's called the CMMC one standard. You'll find that at NIST as well. And there are much higher levels than that up to level five, which is just, wow. All of the stuff that you have to keep secured looks like military level or better, frankly security.
There are other overseas companies that are using it too, by the way in England, in Japan, Canada, many of them.
I'm looking at the framework right now. The basic framework is to identify, protect, detect, respond, and recover. Those are the main parts of it. That's you have to do as a business in order to stay in business in this day and age, they get into it in a lot more detail.
They also have different tiers for different tiers that you can get involved in. Then subcategories. I have all of this framework as part of our audit kit that I'll send out to anybody that asks for it that's a listener. All you have to do is send an email to me, M E @craigpeterson.com, and then the subject line, just say audit kit and I'll get back to you. I'll email that off to it's a big PDF.
You can also go to NIST in the online world and find what they have for you. Just go to NIST, N I S T.gov, The National Institute of Standards and Technology, and you'll see right there, cybersecurity framework, it's got all of the stuff there. You can learn more here if you want. If you're new to the framework they've got online learning. They are really working hard to try and secure businesses and other organizations here in the US and as I said used worldwide. It's hyper, hyper important. It's the same framework that we rely on in order to protect our information and protect our customer's information. So NIST, N I S T.gov, check it out.
If you missed it today, you're going to want to check out the podcast. Now you can find the podcast on any of your favorite podcasting platforms.
It is such a different world. Isn't it? We started out today talking about our cars. Our cars now are basically big mechanical devices ever so complex with computers, controlling them. But the cars of tomorrow that are being built by Tesla and other companies, those cars are absolutely amazing as well, but they're frankly, more computer than they are mechanical car.
So what should we expect from these cars? I'm talking about longevity here. We expect a quarter-million miles from our cars today. Some of these electric vehicles may go a half a million or even a million miles in the future. When they do that, can we expect that? Our computers get operating system updates and upgrades, for what five years give or take?
If you have an Android phone, you're lucky if you get two years' worth of updates. Don't use Android, people. It's just not secure. How about our cars? How long should we expect updates for the firmware in our cars? So that's what we talked about first, today.
Ring has a new security camera that is absolutely cool. It's called the always home cam. I talked about it earlier. It is a drone that flies around inside your house and ties into other Ring equipment. I think it's absolutely phenomenal and it's not quite out yet, but I'll let you know more about that.
If you get ransomware and you pay the ransom, the feds are saying now that you are supporting terrorist organizations. You might want to be careful because they are starting to knock on doors, and there's jail time behind some of these things. So watch it when it comes to ransomware and a whole lot more as well.
So make sure you visit me online. Go to Craig peterson.com/subscribe. It's very important that you do that and do that now.
So you'll get my weekly newsletter. I've got some special gifts, including security, reboot stuff that I'll send to you right away. Craig peterson.com/subscribe.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed