Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • VPN's are dying -- Love live Zero-Trust plus more on this Tech Talk with Craig Peterson Podcast

    Welcome!

    Craig discusses problems that businesses can face when using VPNs and why you should be looking to a Zero-trust network if you are running a business today.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Traders set to don virtual reality headsets in their home offices

    What's on Your Enterprise Network? You Might Be Surprised

    Malware Attacks Declined But Became More Evasive in Q2

    One of this year’s most severe Windows bugs is now under active exploit

    The VPN is dying, long live zero trust

    Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

    Microsoft boots apps out of Azure used by China-sponsored hackers

    WannaCry Has IoT in Its Crosshairs

    Love in the time of Zoom: Why we’re in the midst of a dating revolution

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] So we know a little bit about VPNs and what they are. So what's zero-trust and how's a zero-trust network run. What are we looking for here in the near future? More than half of businesses will be zero-trust.

    Hi everybody. Craig Peterson here. Thanks for being with us today. Of course, you'll find me online as well. You can just go to Craig peterson.com.  I've started to do some three-minute training.

    So the first one went out on Wednesday and I was really surprised just how much work it takes to make a three-minute training. But we did it, we got it accomplished. We're going to try and have a couple of those a week, plus the weekend newsletter, which is, of course, a fair amount of work, but we're doing it for you. Hopefully, you got a lot out of it.

    I got a crazy number of responses to the first video. So thank you. Thank you. Thank you for your responses. Hopefully, I got back to you in a reasonable amount of time here, and we're able to help you out a little bit. Anyhow, if you missed it, go look back on Wednesday this week that's when I put out the first one. So it should have been in your email box Wednesday. As usual, it's from [email protected]. So if you're not getting them and you think you should be double-checking to make sure I am in your contact list or whitelist me somehow so that you get those. They're important. I'm going to be doing more of those a week just to kind of a light touch. Let you guys know what's up.

    So VPNs have been around now for more than a couple of decades, they've been fantastic. They've saved a lot of businesses a lot of money. Now course, they tend to be kind of dangerous, particularly these free VPNs and the commercial ones that you're using, to somehow try and make yourself more secure. I just shake my head every time I hear these ads that are misleading. They are lying to you it's really not going to protect you that much, frankly, if at all. It gives a little bit of privacy in certain situations, but not in others. I had a great call with Doug in fact, this week. And he was having some problems. He is a small business guy been in business for a long time, sold his business and now he's almost 80. I think he said he was 78. He's kind of back in business, again, keeping himself busy and occupied. He was wondering and worried about trying to keep some of this stuff secure. So we went through it a little bit with him.

    He uses macs, so it is definitely easier to keep secure. When he's on the road, he has one of these little devices he takes with him that allows him to connect to the internet from Verizon. One that directs you directly connects you to the internet, which is dangerous.  Another one that provides you with what's called Nat or network address translation that's a little bit safer. So he's going to send me a model number in particulars of what he's using so that I can help him out a little bit.

    By doing that, he's no longer tying into the wifi at the airport or on the airplane or at the coffee shop, wherever he's going. He's got his daughter doing that too, which I think is a very good idea. I know a lot of people, as well that do that. I do it as well. I have one of those little devices. I just replaced the battery in mine because it started swelling. The lithium-ion battery starts to swell, you've got to replace them.  What can happen is when they swell they will short out and can start a fire. So be very careful about that.

    So he's smart enough to know that you don't want to use public wi-fi. He effectively brings his own little wifi device with him, which is again, a great idea.

    Some people try and use VPNs when they are out there on the road and connecting back into the main office or into their homes. I have that as well, and that lets me get directly in.

    Most of the time now, what we've been doing for our office and for our customers is putting together zero trust networks. These are far more secure than anything else we have out there right now, as far as firewalls and everything else goes.  The idea is, just like its name implies, that we're looking at everything. We're no longer just trying to do what's called a perimeter security approach where we have a firewall at the perimeter.

    Now we are trying to protect ourselves and our businesses from any kind of attack, including insider attacks, including the lateral movement that I've talked about so many times before. Where a bad guy gets a foothold inside of a network and that bad guy immediately tries to start spreading things. Very dangerous. Very, very dangerous. There's a number of other flaws too. Perimeter security just doesn't do a good job of counting for any third parties any vendors you might be working with contractors, all of your supply chain partners. If attackers steal somebody's VPN credentials, now the attacker can get into the network and roam freely. Like I've talked about many times.

    Many of us use the same username and password on pretty much every device out there.  That's a problem because when it gets onto the dark web, now the bad guys have it. Plus the VPNs over time have become a lot more complex and very difficult to manage.

    It's rare. I say rare but I've never seen an exception. In other words, it seems that these businesses have misconfigured VPNs. It seems to be a pandemic out there, frankly. A lot of pain around VPNs.

    So this is going to change it all. You are. We're going to have different equipment internally. Your devices are not gonna be able to connect to each other directly.

    So the way we have it set up all of the devices on a network, instead of speaking directly with each other, have to go through at least a firewall. The firewall watches what they're trying to do even inside the network. So it's no longer just out there at the perimeter. Frankly, what we've been doing with VPNs, it's just clunky. It's outdated. Frankly, kind of dangerous. So keep all of that in mind.

    All right if you need a little help, if you have some questions, I am more than glad to get on the phone with you guys and chat a little bit and help steer you in the right direction. You can just email me M E @craigpeterson.com and I'd be more than glad to get back with you. So keep all of that in mind. VPN is dying. Zero-Trust is what's coming down the road.

    Now, I just mentioned the problems of potential internal threats, and that can include bad guys that are in your network, spreading laterally, as I just mentioned, but it can also mean that your employees are the problem.

    I've seen that before I had it happen to me, where I had an employee who took all of my customer records and took my customers with him. I could not believe it. I still can't believe it to this day. What he did I don't understand it. What does he think he's doing? He may have built up a relationship with my customers. I don't think he brought a single customer in. In fact, he built up a relationship with my customers, and then he figured, they're his customers now because he has a relationship with them.

    So forget it, Craig. They're his customers. It is just absolutely amazing.

    Shopify, which many of you have heard of before and many people are using. Has found that two of their support team employees were involved in a scheme to steal customer transaction records from specific merchants. It affected apparently fewer than 200 merchants, but there's an example of where zero-trust can really come into play. Do your sales guys have access to information they shouldn't have?

    How about some of your support people? We have to make sure we're monitoring where they're going and what people are doing within our networks. Okay.

    When we come back, we've got a couple more things to talk about Microsoft, Wanna Cry is coming back up again.

     We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    9 min
  • Issues at Microsoft Azure Store and WannaCry is Back plus more on this Tech Talk with Craig Peterson Podcast

    Welcome!

    Craig discusses big problems found with the Microsoft Azure Store and provisioned servers that were part of this massive command and control network run out of China.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Read More:

    Traders set to don virtual reality headsets in their home offices

    What's on Your Enterprise Network? You Might Be Surprised

    Malware Attacks Declined But Became More Evasive in Q2

    One of this year's most severe Windows bugs is now under active exploit

    The VPN is dying, long live zero trust

    Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

    Microsoft boots apps out of Azure used by China-sponsored hackers

    WannaCry Has IoT in Its Crosshairs

    Love in the time of Zoom: Why we're in the midst of a dating revolution

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to talk about Microsoft and the Azure store and President Trump and WannaCry. Do you remember that terrible piece of malware? It's back.

    Hey, you're listening to Craig Peterson, make sure you follow me online as well. Craig peterson.com. It is a pleasure to be with here with you here today. I had just so many great discussions with people this week.

    I sent out a three-minute training, the first three-minute training. I'm going to be doing more and more of these here as time goes on. This training got just a plethora of responses from people. I'm so happy I could help out many people this week, including a bunch of tiny businesses, and that's what I love to do.

    That's why I do this, right. Help you guys out a little bit here. Now. I have customers, big paying customers, usually companies that are regulated and need cybersecurity. But for the rest of you, I still will help you just as much as I can. There are some things you need to do, and that's what this is all about.

    Well, you know already about the Apple app store. I've talked about it many times. Do you know about the Google play store? Both of those are stores that you go to to buy or download little applications that you can use on your smart devices. They're both tremendous small stores. Apple tends to do a better job when it comes to watching for security problems than Google does.

    Both of them tend to take about a 30% chunk of any money that you pay. Then of 75% or 70%, I should say to the developer. Well, Microsoft has a store, as well. You might have heard of Azure. That's a service that Microsoft has, and it is an online service. It's a cloud service. It lets you run Microsoft Windows in the cloud, in a data center.

    That's managed by Microsoft, run by Microsoft in most cases. Also, by the way, it'll let you run various types of Linux, and that was a bit of a surprise, but anyhow. That's the Microsoft Azure story. Then we also have over on Amazon, and that's called AWS Amazon web services. There is a lot of others too.

    We tend to use some of the IBM stores, including the IBM mainframe stuff, which has just been unique to us, just how good those things are. The IBM mainframes, how fast they are, and how inexpensive they are for computing stuff. It's just amazing. Anyhow. Microsoft and IBM and Amazon and anybody that has one of these cloud services also have a store.

    And it's much like the stores that you would expect to find for your smartphone. But in the stores where we're talking about here, Azure, or these cloud services, they are selling and leasing or renting fully configured machines. So you can go on, you can say, Hey, I want a new Ubuntu version, blah, blah, blah, or red hat enterprise Linux, which is what we tend to use, version this and such, and maybe you want also to use containerized stuff. And so they have all of these things pre-configured you can say, Hey, I want a database engine and Tada, poof, there is a database engine for you. It can be either poorly maintained by them. And you have no idea what it is. It acts like MySQL or whatever other databases you might want it to appear to be. Perhaps it's your version of that. Those types of apps are available in these cloud services to use those terms loosely.

    Well, earlier this year, it turns out, according to Dan Goodman, who wrote an article over at ARS Technica up on my site. Still, members of the Microsoft threat intelligence center suspended 18 Azure active directory applications because they determined they're part of this massive command and control network run out of China.

    Now we can also talk here about commanding control because your computer might even be part of this. So, if you have a computer and that computer gets hacked, one of the reasons they hack it is to use it as part of a command and control network.

    Now here's the idea behind the command and control hackers. They're not going to ransom your data. They're not going to try and do something nasty with it. These command and control guys don't care that your computer can do anything other than connect to the internet.

    So one of the things they'll do with command and control is to do what's called a denial of service attack against somebody. So there's some company they don't like, or maybe they're ransoming. This company says, Hey, listen, we'll shut down your website unless you pay us a million dollars.

    What they'll do is he'll use a thousand, 10,000, however many computers they have in their command and control network. They'll use them now to send off fake website requests to that company. Then that company's servers just get hammered, and nowadays, we see in the order of tens or even hundreds of thousands of requests per second coming into some of these data centers and that there are services out there to protect against it. Those types of denial of service attacks. Okay. But here's where things start getting interesting. They all also use command and control systems to send out emails, do phishing, and even research them. So command and control just as it sounds is they have control of your computer. They send commands to execute.

    So, in this case, what we're finding is that Microsoft had these apps that were in there as your active directory, their cloud service, that were part of this commanding control network. 18 different applications. Again, we're not just we're not talking about an app, like an app that would be in the windows phone. Suppose you are sad enough to have bought one and no longer getting support. So it is a difference. It's a pretty big difference. These are the types of applications that are used by businesses, database applications, web server applications. All right. It's not just the fortune 500 companies that are doing this anymore.

    We're talking about the smaller guys who don't have the resources to be able to check.

    You know, between the two of us, most of these fortune 500 companies aren't doing what they should be doing either. Hence all of the hacks that we've been seeing. So this hacking group that Microsoft is calling gadolinium had the cloud hook, hosted applications, and had also been storing stolen data in a Microsoft one drive account and used that account to execute various parts of their campaign. Now, Microsoft, Amazon, all these other cloud providers have been touting how secure it is, how fast these cloud services are. They're just so much cheaper. Oh, this scale that comes from renting computer resources. I remember describing what they were hoping for a way back when with cloud services, that it would be like the power company who cares where the electricity comes from as long as you flick the switch and the light comes on.

    It is no longer like that. The hackers have realized now the benefits of hacking the cloud surfaces and, in this case, using them to share their stolen data to store it, et cetera, et cetera. And now, there's so many free trial services and one-time payment accounts. Hackers have been able to get these different things up and running quickly.

    As I mentioned before, they can even buy their materials, their software to do the hacking, do the phishing, do the ransomware, and sell the decryption stuff. They even have banks that'll handle the transactions to convert Bitcoin into the US or whatever dollars they want to. Very very big deal.

    Earlier in the show, I've talked about this before some of these tools are in use right now, particularly in Windows PowerShell, that are not well secured and legitimately used by the system. Administrators have become a huge, huge tool for the bad guys to use. They're so widely used for legitimate tasks. It's tough to detect the reuse of these illegal tasks.

    This group, this gadolinium group, has recently started using a modified version of the PowerShell empire post-exploitation framework. It's open-source. Can you believe this stuff that's going on? So it's terrifying. Agility and scale, frankly, are working both ways here against us, and for us, I am very concerned about some of the stuff that's going to be happening.

    If we've got some of these bad guys that are out there, right? Some of these terrorist groups, domestic terrorist groups, are burning our cities right now and shooting people, shooting cops, et cetera, that these terrorists will be using these same techniques shortly here in the US. You probably already are. We already know it is using them to finance and fund their operations. Very, very scary stuff.

    So, one more thing real quick before we go. That is WannaCry. Very, very big deal. SonicWall is reporting a 109% increase in ransomware in the US during the first half of 2020. Keep your eyes out. It is very, very inexpensive for the bad guys to do. Get ransomware on your systems. They have high rates of return on it with hardly any risk for them and even outsourced it. We've talked about that before. It is a preferred method of attack for cybercriminals. So be very, very careful out there.

    Get the right kind of security. I was talking with a couple of companies this week. We're going to be putting some of the prosumer Cisco stuff in place to help out a small company and some of the commercial hardware you need to have if you are a regulated industry. So we'll be doing some of that this week, too. So I'm going to be kind of busy, but I plan to release two videos this week, two training videos, and knock on wood. One will be on Tuesday, and one will be on Thursday, but we'll see how it goes. I only got one out this week.

    You've been listening to Craig Peterson. Have a great week, and make sure you visit me online. [email protected].

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Issues at Microsoft Azure Store and WannaCry is Back plus more on this Tech Talk with Craig Peterson Podcast

    Welcome!

    Craig discusses big problems found with the Microsoft Azure Store and provisioned servers that were part of this massive command and control network run out of China. 

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Read More:

    Traders set to don virtual reality headsets in their home offices

    What's on Your Enterprise Network? You Might Be Surprised

    Malware Attacks Declined But Became More Evasive in Q2

    One of this year’s most severe Windows bugs is now under active exploit

    The VPN is dying, long live zero trust

    Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

    Microsoft boots apps out of Azure used by China-sponsored hackers

    WannaCry Has IoT in Its Crosshairs

    Love in the time of Zoom: Why we’re in the midst of a dating revolution

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to talk about Microsoft and the Azure store and President Trump and WannaCry. Do you remember that terrible piece of malware? It's back.


    Hey, you're listening to Craig Peterson, make sure you follow me online as well. Craig peterson.com. It is a pleasure to be with here with you here today. I had just so many great discussions with people this week.


    I sent out a three-minute training, the first three-minute training. I'm going to be doing more and more of these here as time goes on. This training got just a plethora of responses from people. I'm so happy I could help out many people this week, including a bunch of tiny businesses, and that's what I love to do.


    That's why I do this, right. Help you guys out a little bit here. Now. I have customers, big paying customers, usually companies that are regulated and need cybersecurity. But for the rest of you, I still will help you just as much as I can. There are some things you need to do, and that's what this is all about.

    Well, you know already about the Apple app store. I've talked about it many times. Do you know about the Google play store? Both of those are stores that you go to to buy or download little applications that you can use on your smart devices. They're both tremendous small stores. Apple tends to do a better job when it comes to watching for security problems than Google does.

    Both of them tend to take about a 30% chunk of any money that you pay. Then of 75% or 70%, I should say to the developer. Well, Microsoft has a store, as well. You might have heard of Azure. That's a service that Microsoft has, and it is an online service. It's a cloud service. It lets you run Microsoft Windows in the cloud, in a data center.

    That's managed by Microsoft, run by Microsoft in most cases. Also, by the way, it'll let you run various types of Linux, and that was a bit of a surprise, but anyhow. That's the Microsoft Azure story. Then we also have over on Amazon, and that's called AWS Amazon web services. There is a lot of others too.

    We tend to use some of the IBM stores, including the IBM mainframe stuff, which has just been unique to us, just how good those things are. The IBM mainframes, how fast they are, and how inexpensive they are for computing stuff. It's just amazing. Anyhow. Microsoft and IBM and Amazon and anybody that has one of these cloud services also have a store.

    And it's much like the stores that you would expect to find for your smartphone. But in the stores where we're talking about here, Azure, or these cloud services, they are selling and leasing or renting fully configured machines. So you can go on, you can say, Hey, I want a new Ubuntu version, blah, blah, blah, or red hat enterprise Linux, which is what we tend to use, version this and such, and maybe you want also to use containerized stuff. And so they have all of these things pre-configured you can say, Hey, I want a database engine and Tada, poof, there is a database engine for you. It can be either poorly maintained by them. And you have no idea what it is. It acts like MySQL or whatever other databases you might want it to appear to be. Perhaps it's your version of that. Those types of apps are available in these cloud services to use those terms loosely.

    Well, earlier this year, it turns out, according to Dan Goodman, who wrote an article over at ARS Technica up on my site. Still, members of the Microsoft threat intelligence center suspended 18 Azure active directory applications because they determined they're part of this massive command and control network run out of China.

    Now we can also talk here about commanding control because your computer might even be part of this. So, if you have a computer and that computer gets hacked, one of the reasons they hack it is to use it as part of a command and control network.

    Now here's the idea behind the command and control hackers. They're not going to ransom your data. They're not going to try and do something nasty with it. These command and control guys don't care that your computer can do anything other than connect to the internet.

    So one of the things they'll do with command and control is to do what's called a denial of service attack against somebody. So there's some company they don't like, or maybe they're ransoming. This company says, Hey, listen, we'll shut down your website unless you pay us a million dollars.

    What they'll do is he'll use a thousand, 10,000, however many computers they have in their command and control network. They'll use them now to send off fake website requests to that company. Then that company's servers just get hammered, and nowadays, we see in the order of tens or even hundreds of thousands of requests per second coming into some of these data centers and that there are services out there to protect against it. Those types of denial of service attacks. Okay.
    But here's where things start getting interesting. They all also use command and control systems to send out emails, do phishing, and even research them. So command and control just as it sounds is they have control of your computer. They send commands to execute.

    So, in this case, what we're finding is that Microsoft had these apps that were in there as your active directory, their cloud service, that were part of this commanding control network. 18 different applications. Again, we're not just we're not talking about an app, like an app that would be in the windows phone. Suppose you are sad enough to have bought one and no longer getting support. So it is a difference. It's a pretty big difference.
    These are the types of applications that are used by businesses, database applications, web server applications. All right. It's not just the fortune 500 companies that are doing this anymore.

    We're talking about the smaller guys who don't have the resources to be able to check.

    You know, between the two of us, most of these fortune 500 companies aren't doing what they should be doing either. Hence all of the hacks that we've been seeing. So this hacking group that Microsoft is calling gadolinium had the cloud hook, hosted applications, and had also been storing stolen data in a Microsoft one drive account and used that account to execute various parts of their campaign. Now, Microsoft, Amazon, all these other cloud providers have been touting how secure it is, how fast these cloud services are. They're just so much cheaper. Oh, this scale that comes from renting computer resources. I remember describing what they were hoping for a way back when with cloud services, that it would be like the power company who cares where the electricity comes from as long as you flick the switch and the light comes on.

    It is no longer like that. The hackers have realized now the benefits of hacking the cloud surfaces and, in this case, using them to share their stolen data to store it, et cetera, et cetera. And now, there's so many free trial services and one-time payment accounts. Hackers have been able to get these different things up and running quickly.

    As I mentioned before, they can even buy their materials, their software to do the hacking, do the phishing, do the ransomware, and sell the decryption stuff. They even have banks that'll handle the transactions to convert Bitcoin into the US or whatever dollars they want to. Very very big deal.

    Earlier in the show, I've talked about this before some of these tools are in use right now, particularly in Windows PowerShell, that are not well secured and legitimately used by the system. Administrators have become a huge, huge tool for the bad guys to use. They're so widely used for legitimate tasks. It's tough to detect the reuse of these illegal tasks.

    This group, this gadolinium group, has recently started using a modified version of the PowerShell empire post-exploitation framework. It's open-source. Can you believe this stuff that's going on? So it's terrifying. Agility and scale, frankly, are working both ways here against us, and for us, I am very concerned about some of the stuff that's going to be happening.

    If we've got some of these bad guys that are out there, right? Some of these terrorist groups, domestic terrorist groups, are burning our cities right now and shooting people, shooting cops, et cetera, that these terrorists will be using these same techniques shortly here in the US. You probably already are. We already know it is using them to finance and fund their operations. Very, very scary stuff.

    So, one more thing real quick before we go. That is WannaCry. Very, very big deal. SonicWall is reporting a 109% increase in ransomware in the US during the first half of 2020. Keep your eyes out. It is very, very inexpensive for the bad guys to do. Get ransomware on your systems. They have high rates of return on it with hardly any risk for them and even outsourced it. We've talked about that before. It is a preferred method of attack for cybercriminals. So be very, very careful out there.

    Get the right kind of security. I was talking with a couple of companies this week. We're going to be putting some of the prosumer Cisco stuff in place to help out a small company and some of the commercial hardware you need to have if you are a regulated industry. So we'll be doing some of that this week, too.
    So I'm going to be kind of busy, but I plan to release two videos this week, two training videos, and knock on wood. One will be on Tuesday, and one will be on Thursday, but we'll see how it goes. I only got one out this week.

    You've been listening to Craig Peterson. Have a great week, and make sure you visit me online. [email protected].

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: VPN's are a Problem for businesses, Federal Register Changes for DOD Contractors and Love in the age of Zoom

    Welcome!

    Good morning, everybody. I was on WTAG this morning with Jim Polito. He had a few questions about VPNs, seems like it is a little confusing for people to understand that they were designed for something completely different than what people are using them for today and that is where the problems are coming from. Then I broke some big news about the Federal Register changes and DOD contractors and sub-contractors that went into effect last night at 5 pm. Then we got a little light-hearted with a brief discussion about Love and Zoom. Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] We're giving you an emergency regulation, right now you have 48 hours notice and you have to actually secure your systems by December 1st. We now have people who can audit you, who have secret clearances or better and they're going to start that audit December 1st.

    Hey, good morning everybody. Craig Peterson here. Mr. Jim Polito was in his studio for the first time in many months. He sounds much better there in the studio. We got into VPNs. What is the problem? What is this whole thing called zero-trust, and how's that going to be affecting us here in days, weeks, months ahead. Also huge, huge, huge, huge announcement. Federal register. If you do anything for anybody that does anything for the Department of Defense, including mowing their lawns. A big change in the federal register. You are now in serious trouble. If you don't meet these guidelines, that has been published for a couple of years. This NIST 800-171, but anyhow, I mentioned that is Whoa!

    So here we go with Mr. Polito

    Jim Polito: [00:01:16] A great Tuesday segment, it would be a great segment any day of the week. He is our good friend and tech talk guru. Craig Peterson. Good morning, sir.

    Craig Peterson: [00:01:28] Hey, good morning, Jim. How are you?

    Jim Polito: [00:01:31] I'm good. I'm good. I'm actually, I never thought the day would come and this will be the second topic, but I never thought the day would come that Craig Peterson and I would be talking about dating. We're going to talk about dating. We're going to talk about dating in the age of COVID, but before we get to that, you have some really big news you provided me with. Okay. So I understand the concept of a VPN. A VPN so that you can work securely from home or another remote location, and yet still have access to everything.

    Every computer, every little bit of hardware you have in software and drives that you have to say your business now. Thank God Danny has this, uh, my former producer now. Program director, because Danny can, uh, if I need something VPN in from home and do it or fix it or whatever, uh, now you're saying that VPN, what? Isn't the. Gold standard anymore. What's going on?

    Craig Peterson: [00:02:46] We have to remember where VPN came from in the first place. You know, it's been over 20 years ago, but I had three megabits worth of internet here at the house and it was costing me, 20 years ago, about $6,000 a month to have three megabits worth of internet. Yeah, exactly. So I had internet here at the house so I could work at home and that network was then routed through, of course, the phone company had all of those lines and that they went to the office and then the whole VPN concept came along. What we could do now is run a virtual network link.

    So rather than paying the six grand a month, for me to be able to connect to the office or my house. I could now connect the two networks together, just over the internet. So my cost went from about 6,000 a month to about 150 to $200 a month back then. It was a huge win. Yeah. That's what they're designed for is for the networks to connect together. And that is the problem. If you connect your home network to the office network, you now have a huge problem because all of the attack surfaces, all of the computers in your home, that really cool internet coffee pot that you bought that is really a computer that happens to make coffee is now gained access to your network at the office. That's where the problem is.

    This is the internet of things that you often talk to me about, right?

    Yeah. It's the internet of things, plus if you've got teenage boys, where are they going online? Right. What are some of the worst, the worst places you can think of? And so now all of these computers that are infected can now spread laterally out there and, and that's just a huge problem.

    So, yeah, VPN, as you said is no longer the gold standard. In fact, I've got to make a quick announcement here in just a second about their defense the national register just had an emergency update as of 5:00 PM yesterday, but this all ties in.

    Because what we're moving towards now is what is called a zero-trust network.

    It's a way different concept than most people are used to than businesses are using, But the idea is why should you connect your home network to the office network? Because that's dangerous as heck. Okay. A zero-trust network as any device that wants to speak to another specific device has to be approved to not only does that device have to be approved to talk to the other device, but the protocol it is using has to be approved.

    So it has gotten very very different in this world today because of all the hacks going on and the zero-trust is what you're going to start seeing a right, left and center here over the next year or two. Moving away from just the concept of an open VPN.

    Jim Polito: [00:06:05] Wow. We're talking with our good friend, Craig Peterson, tech talk guru, and all about all things technical.

    Now. The VPN in terms of security as you were talking, I mean, it was the gold standard. Isn't this just a race every time we turn around. So this new system that you're talking about, won't it have a shelf life, won't it at some point be useless against the bad guys.

    Craig Peterson: [00:06:38] You can have a great point.

    It's always been a game of oneupmanship between the defenders and the attackers. That's why zero-trust comes into play. Yeah. There are going to be problems with the implementation. The biggest problem we see is stuff being misconfigured. Businesses are completely misconfiguring the VPNs. Heaven forbid they have to try and figure out zero-trust. That's where we're going to see the biggest problems is with misconfiguration. But the whole concept behind zero trust says basically, no, there is no one that's going to shift because everything has to be approved and what we're trying to do with this is stop the lateral movement.

    So if your business gets infected with something, Nowadays, it ultimately ends up being ransomware much of the time, but it gets infected. The bad guys if they've got ransomware in your machine, don't do what they used to do a few years ago. What they do right now, Jim and these guys are smart. Right? What does that make money doing? The good stuff.

    Jim Polito: [00:07:44] Yeah,

    Craig Peterson: [00:07:44] But what they're doing is, they've got ahold of Jim Pollito's son's computer. Yeah. And so they don't immediately encrypt it. They don't immediately pop up a notice saying, Hey, you've got ransomware. Like they used to do.

    What they're doing now is they spread laterally inside your network. So their software looks for files that have interesting names, it uploads them to the bad guys. So they can have a look at that. The bad guys might hop onto your computer now and poke around saying, Hey, wait a minute.

    Your Jim Polito's son works for this health management company and it looks like they might have some assets. So now the bad guys are looking at your computer. I mean the bad guy's actual intelligence, not programming. So these people are looking at it saying, Oh, wait a minute. Here, we've got medical records, we've got all of this stuff and now they evaluate, okay.

    So what do we think this is worth. We're into the town of Worcester's computer network. What should we do now? Well, let's infect some more machines because we're in now. So they start spreading to other desktops here. You know, Jim Polito's his son's girlfriend's computer, who also works there in the town.

    Now they have visibility into everything, but they've also copied many of these files out of your network. So this might go on for weeks and businesses aren't even noticing this because they don't track any exfiltration of data. Most businesses. So they're pulling all of this data out and now what they do is they encrypt everything on your computers and they pop up a notice saying you have one of two choices.

    You can either pay us X dollars. And if it's a town it's probably more along the lines of $10 million dollars

    Jim Polito: [00:09:38] Yeah.

    Craig Peterson: [00:09:38] You can either pay us that and we'll give you the decryption keys. By the way, they have a help desk now where you can contact the help desk and they'll help you out. Or what will happen is we'll just release all of the tax records of everybody in the town, or all of the medical records of everybody in your medical office or all of the records of all of your customers? Yeah, it's crazy.

    Jim Polito: [00:10:01] Yeah.

    Craig Peterson: [00:10:01] You know, I've been saying businesses aren't doing this, and this is where the federal register thing comes in. There was an emergency order. If you will, last night here.

    On the defense acquisition regulation system from the department of defense. Finally, finally. They basically said all of you contractors out there, the DOD subcontractors, we know you've been lying to us about your compliance with these rules that have been out for two years and so we're giving you an emergency regulation right now.

    You have 48 hours' notice. You have to actually secure your systems by December 1st. We now have people who can audit you, who have secret clearances or better. They're going to start that audit on December 1st.

    Jim Polito: [00:10:54] Wow.

    Craig Peterson: [00:10:54] So just we're talking about, um, you know, company X that make power supplies for DOD contractors, right? This is the power supply. There are no smarts in there. They now have to comply with these new, which are called CMMC rules that are out there. These are just the set of compliance stuff. And they said you have to do it now. Quit. pencil whipping the forms because we're going to be taking a close look.

    Oh, and by the way, It's only federal prison time as much as 10 years and millions of dollars worth of fines. Okay. So finally, the feds are getting upset about all of this and, and you've asked me before, what are we going to do about it? How can we make happen? Well, let me tell ya when we get some CEOs going to prison, Jim.

    Ears are going to get a little bigger. I think as people listen with these auditors coming in with their sharp pencils, having a good look at the security. So again, here I am on a soapbox. Sorry.

    Jim Polito: [00:12:01] No, it's okay. It's okay. It was, it was a complete story. Yeah, it's gotta be done now quickly before we leave, on the lighter side, Zoom. Is the new singles bar. Is that what you're trying to tell me? Because, by the way, I know you have concerns is about Zoom and the security associated with Zoom for businesses to lose proprietary information over Zoom. But Zoom is new, Hey, what's your sign, you know, is the new singles bar.

    Craig Peterson: [00:12:36] Yeah, I love this. If this is absolutely amazing here. People are getting married later in life, or not getting married at all. Our fertility rates have plummeted to 1.7. Now, this is going to make it even worse. But businesses and now roof dating groups, you know, we used to have the fast dating. You remember George doing that on Seinfeld? Like 30 seconds eight? Yup. It's. So now. Yeah, speed dating. So now all of this is happening on Zoom businesses or having happy hour. Some of them are sending out little bottles of wine and all of the employees do Zoom. You have to see each other getting drunk and it's spreading into dating more and more and more. It's a fascinating thing. Really changed South here, Jim.

    Jim Polito: [00:13:33] Wow. Well, you know, I mean, come on. It's the age of COVID and, maybe that's more effective. You get a look at the person, you can hear them talk, you know, you don't have to give them your personal number. It's just a Zoom thing. If the man or woman is a loser, while you're all set, it's like, yo, I gotta go. I gotta go. I'm all set. I gotta, I ain't gotta go, you know, uh, That's a good thing that you and I aren't out there anymore.

    That's a good thing. Yeah. Craig Peterson folks now, uh, Craig, I think I got a correction from Danny. It's 11 o'clock on Sundays. On WHYN, WTAG. That's what he's telling me now. Craig Peterson show. That's what he's telling me.

    So we'll have to, we'll have to make sure about that, but in the meantime, how can folks more information from the tech talk guru?

    Well, you can always go to my [email protected]. But if you have specific questions, especially now, I can send you guys, if you drop me in a line the information here on the changes to the federal register.

    If you make anything that is bought by any DOD, contractors, your business just changed at 5:00 PM last night. Just email me M E @craigpeterson.com. I'll send you some of these articles that are out there. The changes by the DOD. Just email me and with any question, I answered dozens a week, just

    [email protected].

    All right, Craig, we'll talk to you next week. Always a pleasure, always some great surprises.

    Craig Peterson: [00:15:18] Thanks, Jim. Take care.

    Jim Polito: [00:15:20] Bye-bye.

    Craig Peterson: [00:15:21] Hey, I got to get busy right now because there are a lot of companies that need some help and I gotta make sure everybody knows, and I am finishing up right now our first little three- minute videos.

    It's taking me a long time, first time around, right. It always does, but things will go a lot swifter here in the future.

    We're planning on doing this every Tuesday and Thursday. So keep an eye on your emails for that.

    Take care, everybody. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    16 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: VPN's are a Problem for businesses, Federal Register Changes for DOD Contractors and Love in the age of Zoom

    Welcome!

    Good morning, everybody. I was on WTAG this morning with Jim Polito.  He had a few questions about VPNs, seems like it is a little confusing for people to understand that they were designed for something completely different than what people are using them for today and that is where the problems are coming from. Then I broke some big news about the Federal Register changes and DOD contractors and sub-contractors that went into effect last night at 5 pm. Then we got a little light-hearted with a brief discussion about Love and Zoom. Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] We're giving you an emergency regulation, right now you have 48 hours notice and you have to actually secure your systems by December 1st. We now have people who can audit you, who have secret clearances or better and they're going to start that audit December 1st.

    Hey, good morning everybody. Craig Peterson here. Mr. Jim Polito was in his studio for the first time in many months. He sounds much better there in the studio. We got into VPNs. What is the problem? What is this whole thing called zero-trust, and how's that going to be affecting us here in days, weeks, months ahead. Also huge, huge, huge, huge announcement. Federal register. If you do anything for anybody that does anything for the Department of Defense, including mowing their lawns. A big change in the federal register. You are now in serious trouble. If you don't meet these guidelines, that has been published for a couple of years. This NIST 800-171, but anyhow, I mentioned that is Whoa!

    So here we go with Mr. Polito

    Jim Polito: [00:01:16] A great Tuesday segment, it would be a great segment any day of the week. He is our good friend and tech talk guru. Craig Peterson. Good morning, sir.

    Craig Peterson: [00:01:28] Hey, good morning, Jim. How are you?

    Jim Polito: [00:01:31] I'm good. I'm good. I'm actually, I never thought the day would come and this will be the second topic, but I never thought the day would come that Craig Peterson and I would be talking about dating. We're going to talk about dating. We're going to talk about dating in the age of COVID, but before we get to that, you have some really big news you provided me with. Okay. So I understand the concept of a VPN. A VPN so that you can work securely from home or another remote location, and yet still have access to everything.

    Every computer, every little bit of hardware you have in software and drives that you have to say your business now. Thank God Danny has this, uh, my former producer now. Program director, because Danny can, uh, if I need something VPN in from home and do it or fix it or whatever, uh, now you're saying that VPN, what? Isn't the. Gold standard anymore. What's going on?

    Craig Peterson: [00:02:46] We have to remember where VPN came from in the first place. You know, it's been over 20 years ago, but I had three megabits worth of internet here at the house and it was costing me, 20 years ago, about $6,000 a month to have three megabits worth of internet. Yeah, exactly. So I had internet here at the house so I could work at home and that network was then routed through, of course, the phone company had all of those lines and that they went to the office and then the whole VPN concept came along. What we could do now is run a virtual network link.

    So rather than paying the six grand a month, for me to be able to connect to the office or my house. I could now connect the two networks together, just over the internet. So my cost went from about 6,000 a month to about 150 to $200 a month back then. It was a huge win. Yeah. That's what they're designed for is for the networks to connect together. And that is the problem. If you connect your home network to the office network, you now have a huge problem because all of the attack surfaces, all of the computers in your home, that really cool internet coffee pot that you bought that is really a computer that happens to make coffee is now gained access to your network at the office. That's where the problem is.

    This is the internet of things that you often talk to me about, right?

    Yeah. It's the internet of things, plus if you've got teenage boys, where are they going online? Right. What are some of the worst, the worst places you can think of? And so now all of these computers that are infected can now spread laterally out there and, and that's just a huge problem.

    So, yeah, VPN, as you said is no longer the gold standard. In fact, I've got to make a quick announcement here in just a second about their defense the national register just had an emergency update as of 5:00 PM yesterday, but this all ties in.

    Because what we're moving towards now is what is called a zero-trust network.

    It's a way different concept than most people are used to than businesses are using, But the idea is why should you connect your home network to the office network? Because that's dangerous as heck. Okay. A zero-trust network as any device that wants to speak to another specific device has to be approved to not only does that device have to be approved to talk to the other device, but the protocol it is using has to be approved.

    So it has gotten very very different in this world today because of all the hacks going on and the zero-trust is what you're going to start seeing a right, left and center here over the next year or two. Moving away from just the concept of an open VPN.

    Jim Polito: [00:06:05] Wow. We're talking with our good friend, Craig Peterson, tech talk guru, and all about all things technical.

    Now. The VPN in terms of security as you were talking, I mean, it was the gold standard. Isn't this just a race every time we turn around. So this new system that you're talking about, won't it have a shelf life, won't it at some point be useless against the bad guys.

    Craig Peterson: [00:06:38] You can have a great point.

    It's always been a game of oneupmanship between the defenders and the attackers. That's why zero-trust comes into play. Yeah. There are going to be problems with the implementation. The biggest problem we see is stuff being misconfigured. Businesses are completely misconfiguring the VPNs. Heaven forbid they have to try and figure out zero-trust. That's where we're going to see the biggest problems is with misconfiguration. But the whole concept behind zero trust says basically, no, there is no one that's going to shift because everything has to be approved and what we're trying to do with this is stop the lateral movement.

    So if your business gets infected with something, Nowadays, it ultimately ends up being ransomware much of the time, but it gets infected. The bad guys if they've got ransomware in your machine, don't do what they used to do a few years ago. What they do right now, Jim and these guys are smart. Right? What does that make money doing? The good stuff.

    Jim Polito: [00:07:44] Yeah,

    Craig Peterson: [00:07:44] But what they're doing is, they've got ahold of Jim Pollito's son's computer. Yeah. And so they don't immediately encrypt it. They don't immediately pop up a notice saying, Hey, you've got ransomware. Like they used to do.

     What they're doing now is they spread laterally inside your network. So their software looks for files that have interesting names, it uploads them to the bad guys. So they can have a look at that. The bad guys might hop onto your computer now and poke around saying, Hey, wait a minute.

    Your Jim Polito's son works for this health management company and it looks like they might have some assets. So now the bad guys are looking at your computer. I mean the bad guy's actual intelligence, not programming. So these people are looking at it saying, Oh, wait a minute. Here, we've got medical records, we've got all of this stuff and now they evaluate, okay.

    So what do we think this is worth. We're into the town of Worcester's computer network. What should we do now? Well, let's infect some more machines because we're in now. So they start spreading to other desktops here. You know, Jim Polito's his son's girlfriend's computer, who also works there in the town.

    Now they have visibility into everything, but they've also copied many of these files out of your network. So this might go on for weeks and businesses aren't even noticing this because they don't track any exfiltration of data. Most businesses. So they're pulling all of this data out and now what they do is they encrypt everything on your computers and they pop up a notice saying you have one of two choices.

    You can either pay us X dollars. And if it's a town it's probably more along the lines of  $10 million dollars

    Jim Polito: [00:09:38] Yeah.

    Craig Peterson: [00:09:38] You can either pay us that and we'll give you the decryption keys. By the way, they have a help desk now where you can contact the help desk and they'll help you out. Or what will happen is we'll just release all of the tax records of everybody in the town, or all of the medical records of everybody in your medical office or all of the records of all of your customers? Yeah, it's crazy.

    Jim Polito: [00:10:01] Yeah.

    Craig Peterson: [00:10:01] You know, I've been saying businesses aren't doing this, and this is where the federal register thing comes in. There was an emergency order. If you will, last night here.

    On the defense acquisition regulation system from the department of defense. Finally, finally. They basically said all of you contractors out there, the DOD subcontractors, we know you've been lying to us about your compliance with these rules that have been out for two years and so we're giving you an emergency regulation right now.

    You have 48 hours' notice. You have to actually secure your systems by December 1st. We now have people who can audit you, who have secret clearances or better. They're going to start that audit on December 1st.

    Jim Polito: [00:10:54] Wow.

    Craig Peterson: [00:10:54] So just we're talking about, um, you know, company X that make power supplies for DOD contractors, right? This is the power supply. There are no smarts in there. They now have to comply with these new, which are called CMMC rules that are out there. These are just the set of compliance stuff. And they said you have to do it now. Quit. pencil whipping the forms because we're going to be taking a close look.

    Oh, and by the way, It's only federal prison time as much as 10 years and millions of dollars worth of fines. Okay. So finally, the feds are getting upset about all of this and, and you've asked me before, what are we going to do about it? How can we make happen? Well, let me tell ya when we get some CEOs going to prison, Jim.

    Ears are going to get a little bigger. I think as people listen with these auditors coming in with their sharp pencils, having a good look at the security. So again, here I am on a soapbox. Sorry.

    Jim Polito: [00:12:01] No, it's okay. It's okay. It was, it was a complete story. Yeah, it's gotta be done now quickly before we leave, on the lighter side, Zoom. Is the new singles bar. Is that what you're trying to tell me? Because, by the way, I know you have concerns is about Zoom and the security associated with Zoom for businesses to lose proprietary information over Zoom. But Zoom is new, Hey, what's your sign, you know, is the new singles bar.

    Craig Peterson: [00:12:36] Yeah, I love this. If this is absolutely amazing here. People are getting married later in life, or not getting married at all. Our fertility rates have plummeted to 1.7. Now, this is going to make it even worse. But businesses and now roof dating groups, you know, we used to have the fast dating. You remember George doing that on Seinfeld? Like 30 seconds eight? Yup. It's. So now. Yeah, speed dating. So now all of this is happening on Zoom businesses or having happy hour. Some of them are sending out little bottles of wine and all of the employees do Zoom. You have to see each other getting drunk and it's spreading into dating more and more and more. It's a fascinating thing. Really changed South here, Jim.

    Jim Polito: [00:13:33] Wow. Well, you know, I mean, come on. It's the age of COVID and, maybe that's more effective. You get a look at the person, you can hear them talk, you know, you don't have to give them your personal number. It's just a Zoom thing. If the man or woman is a loser, while you're all set, it's like, yo, I gotta go. I gotta go. I'm all set. I gotta, I ain't gotta go, you know, uh, That's a good thing that you and I aren't out there anymore.

    That's a good thing. Yeah. Craig Peterson folks now, uh, Craig, I think I got a correction from Danny. It's 11 o'clock on Sundays. On WHYN, WTAG. That's what he's telling me now. Craig Peterson show. That's what he's telling me.

    So we'll have to, we'll have to make sure about that, but in the meantime, how can folks more information from the tech talk guru?

    Well, you can always go to my [email protected]. But if you have specific questions, especially now, I can send you guys, if you drop me in a line the information here on the changes to the federal register.

    If you make anything that is bought by any DOD, contractors, your business just changed at 5:00 PM last night. Just email me M E @craigpeterson.com. I'll send you some of these articles that are out there. The changes by the DOD. Just email me and with any question, I answered dozens a week, just

    [email protected].

    All right, Craig, we'll talk to you next week. Always a pleasure, always some great surprises.

    Craig Peterson: [00:15:18] Thanks, Jim. Take care.

    Jim Polito: [00:15:20] Bye-bye.

    Craig Peterson: [00:15:21] Hey, I got to get busy right now because there are a lot of companies that need some help and I gotta make sure everybody knows, and I am finishing up right now our first little three- minute videos.

    It's taking me a long time, first time around, right. It always does, but things will go a lot swifter here in the future.

    We're planning on doing this every Tuesday and Thursday. So keep an eye on your emails for that.

    Take care, everybody. Bye-bye.

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    16 min
  • AS HEARD ON NH Today with Jack Heath WGIR-AM 610: Social Media and Public Perception of Politics today

    Welcome,

    Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed the political perceptions of the electorate in the age of Social Media and how it is affecting our decisions. Here we go with Jack.

    These and more tech tips, news, and updates visit

    - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Hey, good morning, everybody. Craig Peterson here. I think election season is in full force and I was on with Mr. Jack Heath this morning, chatting a little bit about this and social media and the high hopes I had for the internet back in the early eighties, 81 82, and how things have just gone? Well, downhill.

    Politicization did I say that right? Politicalization of the internet and how really things have gotten a whole lot worse. There's something I'm going to have to think about. Maybe find a guest or two to talk about it. Anyhow, here we go with Mr. Heath.

    Jack Heath: [00:00:42] All right. They may not seem like a tech talk point, but Craig Peterson joining us a little bit later on in the show, we were packed in the seven o'clock hour. The host of tech talk and Craig, good morning. I wonder what the debate tomorrow night and social media, perhaps you could comment on. It seems every year or two, we have more social media platforms. People are different ages using different mediums. You have all the different social media apps.

    Yet this will be tomorrow night on the radio. We'll be having the debate live television, but people are getting information. Look at the number of people that may watch 90 minutes of that debate. He may be surprised and may not be as many people as you think. How important is social media with something like a presidential debate after the debate?

    You know, who won? Who said what? What's in store, What part of its sticks?

    Craig Peterson: [00:01:24] Hey, good morning, Jack. We were hoping that really social media, the online world would mean a revolution for us. That we would be able to see both sides of all the debate. Get closer together. I had high hopes. I remember back in the back to 81, 82 when I first got on the internet and it was a wonderful place way back.

    Jack Heath: [00:01:45] Right. That was when Al Gore invented it right.

    Craig Peterson: [00:01:48] Yeah. Yeah, my maybe a couple of years before. In fact, the whole thing that's interesting to me about it is that in fact, what we've ended up with is ways to segment ourselves even further than we had before all of these social media sites. Right?

    Feeding us stuff they think we want to see, and they're highly addictive. Now leads to another problem rather than watching them a whole hour and a half of this debate or some of the debates that you have hosted in the past, Jack or on the radio. What people are tending to do now is just wait for the highlights. We've gotten where our attention span on average is less than that of a goldfish.

    Jack Heath: [00:02:33] Yeah.

    Craig Peterson: [00:02:33] So we just want to know what are the highlights? Give me a quick point. Then you're only going to get the point that their social media site thinks that you want to see.

    Jack Heath: [00:02:46] Then you see how divided people are in social media. There's no middle road on anything.

    Craig Peterson: [00:02:50] It makes it worse. It's like so many new stations and others now online that just feed one side, and be as inflammatory as possible.

    Jack Heath: [00:03:00] Right.

    Craig Peterson: [00:03:01] In order to get people to pay attention to and to listen. So, Jack, I think that's just what's going to end up happening here. Most people won't see the whole debate, not even close to it.

    They'll just be sitting there scrolling through their social media feeds. Then when something comes across about the terrible thing that Trump said or the horrible thing the Biden did, that's what they'll see in their feeds.

    Yeah, I think you're right. All right, Craig Peterson, thank you very much for the tech talk update.

    Jack Heath: [00:03:27] Thank you, Craig.

    Take care. Okay. My fingers are crossed and if everything goes well, you'll be getting an email here, midweek with a little training in it. I am calling it three-minute training. It might be three to five minutes if I can keep it short. I'm really going to try and help everybody out here.

    There's no squeezing. There's no beating you over the head and shoulders to buy stuff from me. These are real training and I'm going to try and do most of them by video. Some of them will be just audio as well as we introduce these concepts that business owners need to understand along with the rest of us and what they can do about it in their business.

    One of the big articles I had this last week and I was disappointed that I didn't get more feedback on it, but it was about how CEOs really, really need to pull up their socks. But anyhow, be that as it may.

    Have a great week and we will be back tomorrow I expect to be on with Jim. I think Jim Polito is back from his little vacay and I am going to be working today and tomorrow on getting together that very first training.

    Take care, Everybody.

    Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    5 min
  • AS HEARD ON NH Today with Jack Heath WGIR-AM 610: Social Media and Public Perception of Politics today

    Welcome,

    Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed the political perceptions of the electorate in the age of Social Media and how it is affecting our decisions. Here we go with Jack. 

    These and more tech tips, news, and updates visit

    - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    Craig Peterson: [00:00:00] Hey, good morning, everybody. Craig Peterson here. I think election season is in full force and I was on with Mr. Jack Heath this morning, chatting a little bit about this and social media and the high hopes I had for the internet back in the early eighties, 81 82, and how things have just gone? Well, downhill.

    Politicization did I say that right? Politicalization of the internet and how really things have gotten a whole lot worse. There's something I'm going to have to think about. Maybe find a guest or two to talk about it. Anyhow, here we go with Mr. Heath.

    Jack Heath: [00:00:42] All right. They may not seem like a tech talk point, but Craig Peterson joining us a little bit later on in the show, we were packed in the seven o'clock hour. The host of tech talk and Craig, good morning. I wonder what the debate tomorrow night and social media, perhaps you could comment on. It seems every year or two, we have more social media platforms. People are different ages using different mediums. You have all the different social media apps.

    Yet this will be tomorrow night on the radio. We'll be having the debate live television, but people are getting information. Look at the number of people that may watch 90 minutes of that debate. He may be surprised and may not be as many people as you think. How important is social media with something like a presidential debate after the debate?

    You know, who won? Who said what? What's in store, What part of its sticks?

    Craig Peterson: [00:01:24] Hey, good morning, Jack. We were hoping that really social media, the online world would mean a revolution for us. That we would be able to see both sides of all the debate. Get closer together. I had high hopes. I remember back in the back to 81, 82 when I first got on the internet and it was a wonderful place way back.

    Jack Heath: [00:01:45] Right. That was when Al Gore invented it right.

    Craig Peterson: [00:01:48] Yeah. Yeah, my maybe a couple of years before. In fact, the whole thing that's interesting to me about it is that in fact, what we've ended up with is ways to segment ourselves even further than we had before all of these social media sites. Right?

    Feeding us stuff they think we want to see, and they're highly addictive. Now leads to another problem rather than watching them a whole hour and a half of this debate or some of the debates that you have hosted in the past, Jack or on the radio. What people are tending to do now is just wait for the highlights. We've gotten where our attention span on average is less than that of a goldfish.

    Jack Heath: [00:02:33] Yeah.

    Craig Peterson: [00:02:33] So we just want to know what are the highlights? Give me a quick point. Then you're only going to get the point that their social media site thinks that you want to see.

    Jack Heath: [00:02:46] Then you see how divided people are in social media. There's no middle road on anything.

    Craig Peterson: [00:02:50] It makes it worse. It's like so many new stations and others now online that just feed one side, and be as inflammatory as possible.

    Jack Heath: [00:03:00] Right.

    Craig Peterson: [00:03:01] In order to get people to pay attention to and to listen. So, Jack, I think that's just what's going to end up happening here. Most people won't see the whole debate, not even close to it.

    They'll just be sitting there scrolling through their social media feeds. Then when something comes across about the terrible thing that Trump said or the horrible thing the Biden did, that's what they'll see in their feeds.

    Yeah, I think you're right. All right, Craig Peterson, thank you very much for the tech talk update.

    Jack Heath: [00:03:27] Thank you, Craig.

    Take care. Okay. My fingers are crossed and if everything goes well, you'll be getting an email here, midweek with a little training in it. I am calling it three-minute training. It might be three to five minutes if I can keep it short.  I'm really going to try and help everybody out here.

    There's no squeezing. There's no beating you over the head and shoulders to buy stuff from me. These are real training and I'm going to try and do most of them by video. Some of them will be just audio as well as we introduce these concepts that business owners need to understand along with the rest of us and what they can do about it in their business.

    One of the big articles I had this last week and I was disappointed that I didn't get more feedback on it, but it was about how CEOs really, really need to pull up their socks. But anyhow, be that as it may.

     Have a great week and we will be back tomorrow I expect to be on with Jim. I think Jim Polito is back from his little vacay and I am going to be working today and tomorrow on getting together that very first training.

    Take care, Everybody.

    Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    5 min
  • Welcome! Remote Work and Security of Home IoT devices on network plus more on Tech Talk with Craig Peterson on WGAN

    Craig discusses problems that businesses can face when remote workers have IoT devices on the network they use to connect to work.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Read More:

    Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

    Ransomware accounted for 41% of all cyber insurance claims in H1 2020

    A bevy of new features make iOS 14 the most secure mobile OS ever

    Don't Fall for It! Defending Against Deepfakes

    Patient dies after a ransomware attack reroutes her to a remote hospital

    Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

    Time for CEOs to Stop Enabling China's Blatant IP Theft

    Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

    74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, we got a new red flag for home workers when it comes to those smart digital assistants that we have in our homes. Yeah, indeed. Not only can it cause problems for us in our homes, but that problem can go right through to the business.

    Craig Peterson here. Thanks for joining me today, and thanks for all of your messages. I've gotten some great comments. This week had one that I'm going to do another followup on, but it had to do with what kind of router to use at home. I did a whole webinar on this back in March. I'm going to add that back to my list again because obviously, there's still a lot of questions.

    Many people can't attend these webinars, but I really would suggest when I do come out with them. That you consider attending if you possibly can. I get it. You can't always attend these things that you'd like to attend, but I responded directly anyways, and I've gotten to the point now where I look at it and say, these crappy, sorry for that term, pieces of hardware that you buy from the big box retailers that are given to you by your friends, at the phone company, the cable company, they are not worth it. It is not worth it. You've got to at least go to the prosumer stuff. And that's what I said to him. The prosumers stuff means that you really got to get something like a Cisco Go hardware.

    Really? You do. Yeah. There's a lot of alternatives out there. Juniper has some stuff. HP has some stuff, but there's only one that has a beautifully integrated ecosystem. The low end of the consumer world nowadays really has to be prosumer and me. I'll let you know if there's something that comes out that I think is as good or better.

    But, also that Cisco is what I do. My company mainstream has been the number one, installing reseller of Cisco gear in the Northeast US, quarters into quarters. So it's something I like. So just to let you know. Okay. But bottom line, my advice to him was trying to get the Cisco GO stuff.

    Now you can buy it on Amazon, but there are things that you need that you cannot buy from Amazon. You've got to go to a licensed reseller in order to get the more advanced protection that you get from some of this Cisco software that is available for the go. Of course, as you move up the line, there's better and better software, but at least start there.

    Let's start the show off here with our first article. You'll see this, of course, in your newsletter that came out this week, and this is something I've talked about a long time in general. And in general, what we're talking about is. The whole internet of things concept, and how many years have we talked about that? It's been at least a decade. In fact, I was going through some of the articles on our website.

    We're just shutting some of them down because they are so old. But back in 2007, I was already talking about this. So we are 13 years later. And we still have these same problems. People still aren't taking care of them, and they're still doing things the same way, and they are getting nailed. And nowadays, particularly when we're thinking about workers working from home, and I am going to be in a couple of weeks doing a little sip series about working from home and what are the top things you can do to protect your business. If you have people connecting from home now, I don't mean like they're just connecting from home an hour a week, nor do we're only gonna talk about the people who are working from home pretty much full time, Doesn't matter. There are some things you have to do, things you can't do.

    And so we'll be going into those with some of the training coming up in a couple of weeks and make sure. You are on my newsletter list. If you want to find out about that stuff, that's just Craig peterson.com/subscribe.

    So we're working from home. I think we've established that we're starting to see office space deserts now. I went to see my chiropractor this week and massage therapist. I'm standing outside her office, and she's in this cluster of offices with other people having a little business, and of course, it's a type of business where she can't really do it from home now, can she. She has to actually have her hands on you in order to do some of this stuff. And boy, was it. Oh, a wonderful thing. Cause my neck and my back just it's been really bad after that whole kind of COVID, in bed for a couple of weeks, thing. And. I looked around the parking lot. It was shocking to me. I was there, and this was after lunch. Usually, there are a lot of people who are there in the parking lot, not just for her business. There's gotta be a hundred different office spaces that are in there. There has to be that in this case, when I was, there were three cars in the parking lot, and that was it.

    So you are talking about these office space deserts. Where the people just aren't going in there anymore. It's just astounding. Some of these big cities like New York City, the whole city is shut down. They're losing all of these restaurants and all of these places where people used to go shopping because people aren't going there.

    Where are they? They're at home. In some cases, you have to be at home. Think about all of the families or the young kids, where the kids are no longer going into school. They're sitting at home, they're on their computers, hopefully, following the teacher and doing their schoolwork. Now I got to put a side note here.

    This is the perfect opportunity for you as a parent. To see what your kids are being taught, to look over the shoulder. Now it's amazing to me. I have read quotes from teachers who said they don't want parents looking in because they don't want parents to know what's being taught. Then there are some unions in some of the local school districts that are saying, and it has to do with the privacy of the other children in the class.

    You use to be able to, as a parent, go and basically audit your school's classroom that your kid was in. So you could go there and sit in the back and just see what's being taught and how it's being taught. And then the teachers didn't like that because heaven forbid a parent question the professional.

    Now we found out, some of these teachers, in fact, a very large number of them are blatant Marxists, just teaching the Marxists dogma. You can see that now, when you look at all of these fascists marching in the street, it's just incredible. So take that opportunity and watch what your kids are doing.

    Watch what the teachers are saying and help your kids out. But in many cases, obviously, we can't and get people to watch kids. We can't get babysitters because there's such a high demand for that. So we are forced to work from home. For that very reason, just to make sure that the place doesn't burn down and maybe you can get a few minutes to watch what the teacher's saying. What's really going on there in that classroom.

    So if you're working from home, what are you doing? We are sitting there on very frequently, our own computers connected again, quite frequently to the network at the office. Now, if you've attended any of my VPN training, that VPN we're designed for businesses to connect to. Networks at different locations, and that's what they're good at. They're not really designed to protect anything other than the data while it's being transported. That actually becomes a problem, and if you use one of these VPN services, it makes you less secure. I go into the reasons why in my VPN course, and we'll be teaching that one again. So keep an eye out.

    But we're now looking at having people at home using their home computers, which don't have all of the protections in place that hopefully, your business computers had, the medium and large businesses have some pretty decent protections in place, but the small businesses, those businesses under 500 employees, very rarely have the right kind of protection in place.

    So now you have a personal home computer to the network at the business. What's on that home computer? We've talked about that before. That's a real problem, but now we're asking them the question of what else is on your home network that's connecting to that business network. One of the things is probably your Amazon, Alexa, or your Google home or who knows what other things. We got light bulbs hooked up. We've got all kinds of things hooked up to our home networks. They found a trio of vulnerabilities recently in Amazon Alexa devices, just as they found them in all of these others, a Google home, everything else.

    Apparently, these vulnerabilities could have led to broader attacks on the home networks because of the way most of us are misconfiguring VPNs. Those attacks can now easily spread over the network to our business computers. So these are vulnerabilities that were made public last week by researchers at Checkpoint.

    Checkpoint has been in the security business for a long time. They made firewalls. I think they're based out of Israel. They've had some very cool stuff, but we're looking at more than 200 million Alexa smart home devices. I have them in my home, but what I've done is, I actually have five different networks in my home.

    One of them is for the internet of things devices, so if they are compromised, they cannot get out, and they cannot get to any of the other devices inside my network.

    Then, of course, I'm using professional gear for my network, not just prosumer gear. I would advise people to look at that very seriously.

    So next we have a study coming out about the presidential election and how both parties, both sides, are very concerned about some security concerns.

    So we'll get into that when we get back.

    Stick around, you're listening to Craig Peterson, and I'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Remote Work and Security of Home IoT devices on network plus more on Tech Talk with Craig Peterson on WGAN

    Craig discusses problems that businesses can face when remote workers have IoT devices on the network they use to connect to work.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Read More:

    Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

    Ransomware accounted for 41% of all cyber insurance claims in H1 2020

    A bevy of new features make iOS 14 the most secure mobile OS ever

    Don't Fall for It! Defending Against Deepfakes

    Patient dies after a ransomware attack reroutes her to a remote hospital

    Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

    Time for CEOs to Stop Enabling China's Blatant IP Theft

    Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

    74 Days From the Presidential Election, Security Worries Mount   Respawn point: The inevitable reincarnation of the corporate office
      Smart-Lock Hacks Point to Larger IoT Problems
      Cops in Miami, NYC arrest protesters from facial recognition matches
      7 Ways to Keep Your Remote Workforce Safe   Using Zoom Can Get You Arrested!   Former Chief Security Officer For Uber Charged With Obstruction of Justice

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, we got a new red flag for home workers when it comes to those smart digital assistants that we have in our homes. Yeah, indeed. Not only can it cause problems for us in our homes, but that problem can go right through to the business.

    Craig Peterson here. Thanks for joining me today, and thanks for all of your messages. I've gotten some great comments. This week had one that I'm going to do another followup on, but it had to do with what kind of router to use at home. I did a whole webinar on this back in March. I'm going to add that back to my list again because obviously, there's still a lot of questions.

    Many people can't attend these webinars, but I really would suggest when I do come out with them. That you consider attending if you possibly can. I get it. You can't always attend these things that you'd like to attend, but I responded directly anyways, and I've gotten to the point now where I look at it and say, these crappy, sorry for that term, pieces of hardware that you buy from the big box retailers that are given to you by your friends, at the phone company, the cable company, they are not worth it. It is not worth it. You've got to at least go to the prosumer stuff. And that's what I said to him. The prosumers stuff means that you really got to get something like a Cisco Go hardware.

    Really? You do. Yeah. There's a lot of alternatives out there. Juniper has some stuff. HP has some stuff, but there's only one that has a beautifully integrated ecosystem. The low end of the consumer world nowadays really has to be prosumer and me. I'll let you know if there's something that comes out that I think is as good or better.

    But, also that Cisco is what I do. My company mainstream has been the number one, installing reseller of Cisco gear in the Northeast US, quarters into quarters. So it's something I like. So just to let you know. Okay. But bottom line, my advice to him was trying to get the Cisco GO stuff.

    Now you can buy it on Amazon, but there are things that you need that you cannot buy from Amazon. You've got to go to a licensed reseller in order to get the more advanced protection that you get from some of this Cisco software that is available for the go. Of course, as you move up the line, there's better and better software, but at least start there.

    Let's start the show off here with our first article. You'll see this, of course, in your newsletter that came out this week, and this is something I've talked about a long time in general. And in general, what we're talking about is. The whole internet of things concept, and how many years have we talked about that? It's been at least a decade. In fact, I was going through some of the articles on our website.

    We're just shutting some of them down because they are so old. But back in 2007, I was already talking about this. So we are 13 years later. And we still have these same problems.  People still aren't taking care of them, and they're still doing things the same way, and they are getting nailed. And nowadays, particularly when we're thinking about workers working from home, and I am going to be in a couple of weeks doing a little sip series about working from home and what are the top things you can do to protect your business. If you have people connecting from home now, I don't mean like they're just connecting from home an hour a week, nor do we're only gonna talk about the people who are working from home pretty much full time, Doesn't matter. There are some things you have to do, things you can't do.

    And so we'll be going into those with some of the training coming up in a couple of weeks and make sure. You are on my newsletter list. If you want to find out about that stuff, that's just Craig peterson.com/subscribe.

    So we're working from home. I think we've established that we're starting to see office space deserts now. I went to see my chiropractor this week and massage therapist.  I'm standing outside her office, and she's in this cluster of offices with other people having a little business, and of course, it's a type of business where she can't really do it from home now, can she. She has to actually have her hands on you in order to do some of this stuff. And boy, was it. Oh, a wonderful thing. Cause my neck and my back just it's been really bad after that whole kind of COVID, in bed for a couple of weeks, thing. And. I looked around the parking lot. It was shocking to me. I was there, and this was after lunch. Usually, there are a lot of people who are there in the parking lot, not just for her business. There's gotta be a hundred different office spaces that are in there. There has to be that in this case, when I was, there were three cars in the parking lot, and that was it.

    So you are talking about these office space deserts. Where the people just aren't going in there anymore. It's just astounding. Some of these big cities like New York City, the whole city is shut down. They're losing all of these restaurants and all of these places where people used to go shopping because people aren't going there.

    Where are they? They're at home. In some cases, you have to be at home. Think about all of the families or the young kids, where the kids are no longer going into school. They're sitting at home, they're on their computers, hopefully, following the teacher and doing their schoolwork. Now I got to put a side note here.

    This is the perfect opportunity for you as a parent. To see what your kids are being taught, to look over the shoulder. Now it's amazing to me. I have read quotes from teachers who said they don't want parents looking in because they don't want parents to know what's being taught. Then there are some unions in some of the local school districts that are saying, and it has to do with the privacy of the other children in the class.

    You use to be able to, as a parent, go and basically audit your school's classroom that your kid was in. So you could go there and sit in the back and just see what's being taught and how it's being taught. And then the teachers didn't like that because heaven forbid a parent question the professional.

    Now we found out, some of these teachers, in fact, a very large number of them are blatant Marxists, just teaching the Marxists dogma. You can see that now, when you look at all of these fascists marching in the street, it's just incredible. So take that opportunity and watch what your kids are doing.

    Watch what the teachers are saying and help your kids out. But in many cases, obviously, we can't and get people to watch kids. We can't get babysitters because there's such a high demand for that. So we are forced to work from home. For that very reason, just to make sure that the place doesn't burn down and maybe you can get a few minutes to watch what the teacher's saying. What's really going on there in that classroom.

    So if you're working from home, what are you doing? We are sitting there on very frequently, our own computers connected again, quite frequently to the network at the office. Now, if you've attended any of my VPN training, that VPN we're designed for businesses to connect to. Networks at different locations, and that's what they're good at. They're not really designed to protect anything other than the data while it's being transported. That actually becomes a problem, and if you use one of these VPN services, it makes you less secure. I go into the reasons why in my VPN course, and we'll be teaching that one again. So keep an eye out.

    But we're now looking at having people at home using their home computers, which don't have all of the protections in place that hopefully, your business computers had, the medium and large businesses have some pretty decent protections in place, but the small businesses, those businesses under 500 employees, very rarely have the right kind of protection in place.

    So now you have a personal home computer to the network at the business. What's on that home computer? We've talked about that before. That's a real problem, but now we're asking them the question of what else is on your home network that's connecting to that business network. One of the things is probably your Amazon, Alexa, or your Google home or who knows what other things. We got light bulbs hooked up. We've got all kinds of things hooked up to our home networks. They found a trio of vulnerabilities recently in Amazon Alexa devices, just as they found them in all of these others, a Google home, everything else.

    Apparently, these vulnerabilities could have led to broader attacks on the home networks because of the way most of us are misconfiguring VPNs. Those attacks can now easily spread over the network to our business computers. So these are vulnerabilities that were made public last week by researchers at Checkpoint.

    Checkpoint has been in the security business for a long time. They made firewalls. I think they're based out of Israel. They've had some very cool stuff, but we're looking at more than 200 million Alexa smart home devices. I have them in my home, but what I've done is, I actually have five different networks in my home.

    One of them is for the internet of things devices, so if they are compromised, they cannot get out, and they cannot get to any of the other devices inside my network.

    Then, of course, I'm using professional gear for my network, not just prosumer gear. I would advise people to look at that very seriously.

    So next we have a study coming out about the presidential election and how both parties, both sides, are very concerned about some security concerns.

    So we'll get into that when we get back.

    Stick around, you're listening to Craig Peterson, and I'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Security Concerns on Voting Technology plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses problems related to Mail-in Voting and Voting technology.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

    Ransomware accounted for 41% of all cyber insurance claims in H1 2020

    A bevy of new features make iOS 14 the most secure mobile OS ever

    Don't Fall for It! Defending Against Deepfakes

    Patient dies after a ransomware attack reroutes her to a remote hospital

    Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

    Time for CEOs to Stop Enabling China's Blatant IP Theft

    Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

    74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Red team-blue team. This is a very interesting problem that is now being confirmed. Through a study. A bipartisan study. We are in trouble with our election this year.

    Hey everybody. Craig Peterson here. Thanks for joining us.

    Man alive! can anything be more political than a presidential election cycle? It is as. Downloading what has been happening when what's being said right now. There are a number of studies that have looked into the efficacy, the ability to have a fair election where we really know the results. There've been all kinds of suggestions.

    We've talked on the show before. About well, we could have, an app that we use to vote. We saw what happened with the Democrat primary in Iowa, right? Total mess. We saw what happened with this app called Vote. I don't know if you heard about this, but this is another voting company. There were some security assessments done and votes criticize the researchers and their methods.

    The security issues that were uncovered with the votes application, we've actually confirmed a security company called Trail of Bits in March this year. Some serious problems. At the USENIX security conference that just occurred here, about a week ago. Okay. They had a panel of voting experts and they got together and they talked about election security.

    They in fact had a couple of sessions at the Usenix security conference that was covering the voting systems and technology. We've talked before about the black hat. Conference and how they set up these voting machines and just see if they could be he hacked. There was like a 12-year old hacked a voting machine that just so simple for so many of these machines out there.

    The biggest problem with the voting machines is you don't have a physical audit trail in many cases. What did they do? They added some audit trails to some of them. They have a thermal printer. have you ever taken the receipt from the grocery store, stuck it in your pocket, and left it there for a couple of weeks and it becomes illegible or heaven forbid, it gets too warm? Maybe it is stuck in a hot room or a storage room or a car. It turns completely black.

    What good is that sort of thing going to do? All you have is a whole bunch of lines, one at a time about what the votes were. Very hard to tabulate. It's not like the cards that you can use to vote on which many States in new England Jews and frankly, our country right wide right now.

    But those cards. You can sit there and analyze them. You might've seen a video of what happened in the Florida election and holding these punch cards up to try and figure out. Is this a hanging Chad and pregnant? Chad was a punched. Was it not Punched? Was this intentional? Did they mean to do that instead?

    All of this craziness with the cards. Let's say the question is about the president and who was voted for, was it Joe Biden or was it, Donald Trump, and all they have to do is look at the card. Okay. there's partisan left, a partisan right, maybe a neutral observer standing there. They say this is clearly Joe Biden. So they put it in the Joe Biden pile next. Who is this? that's clearly President Trump, so we'll put it in the Donald Trump pile. Then when you're done, you just count them in the pile versus these audit trails. Yeah. They're audit trails. But how do you do that when it's a paper tape?

    How do you do that? If it's been written into a database? How do you know that database wasn't altered? Yeah. Yeah. Okay. there's, there are ways to track things in databases and databases having different types of integrity protection, but overall, you can't really trust it.

    And these researchers reverse-engineered this votes Android application, and they did a static analysis on this back end server software that was actually tallying the vote and without having access to the source code without having them a massive number of people who are trying to analyze the system as Russia does.

    Russia has its hands on some of our voting equipment. It's easy enough to buy online and pretends you're someone you aren't. So they were doing this blind, the security researchers, and they found five high severity vulnerabilities and a serious privacy issue.

    That's using one of these apps from a company that does voting. And we've talked about some of the different voting systems out there from Diebold and many others that have various types of problems. Really. The only way to know if a vote is valid. Is to have a, I like the card ID where you fill in the little circle and then that gets run through a voting machine and it's all overseen by, hopefully, independent people, but I don't care if they're partisan one way or the other and that machine tallies it and keeps the card.

    So you can now go back and do a spot analysis on it, or you can do deep analysis on it. I think all of that sort of thing makes sense.

    But that's not what we're talking about this year. We're talking about having a presidential election where people are mailing in ballots. It just blows my mind. People comparing it somehow to absentee ballots and absentee voting.

    It is not the same thing. And here's why. If you want an absentee ballot, you go to the town clerk or the election official. And you swear out in front of them that you need an absentee ballot. Now in most places that have now been removed that requirement to say, yeah, I'm going to be out of town out of the country. Eh, whatever the reason is, I'm not going to be able to vote on that day to this year. I think it's November 3rd and therefore needed an absentee ballot. Okay. So that's step one. And that's been removed in almost all cases.

    I don't have a particular problem with that. Although I would much rather see someone showing up to vote on voting day, which by the way is required by the constitution. I have no idea how this early voting stuff has happened, how it could possibly be constitutional. The vote is November 3rd. It doesn't start on September 1st. It's November 3rd, and that allows the campaigns to get their messaging straight.

    It allows the little guys to actually compete with these people who are already serving in office. Anyhow, that's a separate issue.

    You have now been standing in front of that clerk's office. And that clerk now brings out the paperwork. what ballot do you want? You might have a partisan ballot, but for the general election, you don't, you have all of the final candidates and now they verify you are who you say you are.

    In most cases, that means you present a valid ID. They check the voter rolls and make sure you are eligible to vote and once that's all taken care of, they will hand you the paperwork. Then you can go home. You can vote on that. You sealed it in an envelope, you sign the outside of the envelope across the seal. You follow the instructions. They are not that complicated. And you either drop that back at the clerk's office, which is the safest way to do it, or you mail it and it goes to the clerk's office and it has to be there before the election. And there's some argument that it just has to be stamped by the post office before the end of November 3rd. That's the absentee voting process.

    What's happening in many States is they're saying, Oh, all you have to do now is look in your mailbox because we're sending ballots to everybody that we have a name and address for and then you just fill it out. You send it in. TaDa all done. No verification of who you are.

    In some cases like the way Florida has been doing that, there is a verification that they did receive your ballot, but that's kind of it.

    And there are more problems. And these are what I'm going to talk about when we get back, what are the real problems? The deep problems when we're talking about these ballots.

    We'll get into that. Here are the problems that hackers could use. Very inexpensively, very easy for us to have zero confidence that the vote tally is right.

    So stick around. I'll be right back. You listening to Craig Peterson right here on the radio, on podcasts, and [email protected].

    Stick around.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…