
Sign up to save your podcasts
Or


Welcome!
Craig discusses how a kid on a zoom virtual learning meeting caused his parents to be questioned by Police.Â
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities
Ransomware accounted for 41% of all cyber insurance claims in H1 2020
A bevy of new features make iOS 14 the most secure mobile OS ever
Don't Fall for It! Defending Against Deepfakes
Patient dies after a ransomware attack reroutes her to a remote hospital
Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records
Time for CEOs to Stop Enabling China's Blatant IP Theft
Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] When you think of a violation of somebody violating your privacy, what are you thinking about? Is it people Tom's? Is it somebody sharing a little story about you? That isn't true. with back to school, virtual, um.
Craig Peterson: [00:00:19] Yeah, we've got a story coming out of Joe Biden's country in Maryland. That is very disconcerting. This is from a TV station down in Maryland. Fox Baltimore is the station, and this is very concerning to me. We have many kids that are going to school virtually right now.
 If you know me, I homeschooled along with my wife. In fact, primarily my wife, kids, we had eight kids together. They're all grown. This was back before homeschooling was popular. In fact, back when homeschooling was pretty much illegal and I got hauled into court over it, fought and won by the way.
It gets to be a difficult situation now where. You have a kid that's at home, which means your job is now threatened because can you work at home? Even if you can work at home. Okay. You take the time to monitor the kid to maybe help them out a little bit. There are some out there right now, school districts who are saying, you can't monitor, you can't be in the same room as your child. It might violate other children's privacy.
As though children particularly have a right to privacy. in loco parentis thing, the schools are the parents. You are giving up your child to the school and the school can do amazing bad things with your child without your permission. We're not going into that right now.
But I have seen that again and again, in fact, in our court case, it was eyeopening to me what came up, it was just absolutely shocking. Of course, none of my kids were in school and that was part of the problem. But at that point they said, we went to all of the local schools and, we were going over there cause we wanted to speak to your children.
Cause what they do is they just remove the child from the class. If they want to investigate you. The child has no right to have defense there. They don't have to notify you. They don't even have to record it in most cases. Then they sit there with the child and they do who knows what with that child. I've heard stories about, some of these dolls they use, and it's just scary how perverted some of these people are in government and in our school.
In my case, it was well we could not find your kids in school, therefore, they are not being educated, which if you know my kids if you know any of them, the opposite is true. Most of my kids have gone on to get advanced college degrees, university degrees. Yeah. and the rest of them have far more than a university Ph.D. program equivalent.
It's just shocking. Yeah. What they will do in the whole school system and it has to do with the teachers union. There are some fantastic teachers that really care. I remember two, particularly when I was growing up, cause I went to public schools and I remember their names still.
Mrs. Petri, Mr. Cotes, and the impact they had on me. The very positive impact. I had another one too that I have a few memories of. It is a different world today because the teachers don't want you watching over their shoulders. I have read quotes and I've seen a video where some of these teachers are concerned because the parents are going to find out what's going on in the schools.
What they're being taught. We know, for instance, one of the founders and people that are still running black live matter has come out and she's on video proudly proclaiming that she is a trained Marxist. We see that all of the time, they're trying to convince our kids to do that. Now, there are some amazing teachers that not only help the kids to understand it.
I still remember one of my economics professors and how he really was trying to help us understand what was going on. What was the value of different things and why? And I remember his explanation of how the Dow Jones average worked. Oh man, was he wrong? Be that as it may, we have teachers out there and I know them because you guys have reached out to me who are trying to teach the right things in the schools. Who is pushing back on the agenda that some of these teacher's unions are trying to push in this school?
I would suggest that you be very careful when it comes to your kids being online for school. Hopefully, they're not using something like zoom, which is horrific. It is not controllable by the school and the means it needs to be controlled. It is not secure. It is not safe. Don't use Zoom. But, what are you going to say? You're just a parent, right? What are you going to be able to do about it?
Use by all means WebEx teams or a straight-up WebEx. WebEx teams work great for classrooms and it has the types of controls on it so that you can stay private. You can do the things you need to do to really stay private.
So I see the school districts that are using zoom and saying, Whoa, it all for privacy. We've got to make sure that you are not sitting there watching what's going on. In the meantime, they're using Zoom. It's just Whoa, wait a minute. That's obviously not the reason.
Here's a case again, coming out of Joe Biden's home territory here in Baltimore. Where a child was on one of these virtual classrooms and someone reported her because if you can believe this child had a BB gun mounted on the wall, in his bedroom and that was offensive to other children.
And obviously, the parents who were watching over their kid's shoulders. Yeah. It's fine for those nare-do-wells to be watching and complaining. But it's not fine for you to watch your children make sure things are going, okay.
So apparently this parent reported it to the school administrators. The superintendent and the school board demanded answers. She said the principal initially compared bringing a weapon to a virtual class to bringing a gun to school, she was also told that she could not see the screenshot of her son's bedroom because it's not part of a student record.
Yeah. But it certainly got passed around. Didn't it. Okay, so who's on these calls? Who's viewing this stuff? Of course, the police end up coming to her home and the police have a report that they have to investigate a very big deal, Okay. Is this is very scary!
No one called her first. They just called the police and they had the police go by nothing. So the police knock on her door and say, we need to come in by the way. That's what they do. They say, yeah, we have to come in. We need to come in. Even though they may not have a legal basis, two force entry. That's not just true of the police. That's true of most people working for the government, but, she let them in. she let them look around. I have seen this before in my home state. A butcher block on a kitchen counter makes your home an unsafe environment. They tried to remove the children from that home. So that if the kid's in the kitchen and there's a butcher block behind them on a counter, does that mean there's a weapon?
Did that child bring a weapon to the classroom? Cause there's a butcher block in the kitchen behind him. Or there's a BB gun secured on the wall behind him. This is technology in misuse, frankly, if you ask me, okay. This is very bad. This is very sad. This is Joe Biden's. Baltimore, Maryland. Yes, indeed.
So the police searched it. They were in the home for about 20 minutes. They found no violations of the law. Again, that reminds me, of socialism, show me the man, I'll show you the crime. 20 minutes in the home. What might they have found heaven forbid? Maybe an unclean environment with some kitty litter spilled out of the kitty litter box.
 I've seen worse. I've seen more done for less. Anyways. Keep that in mind with your kids while they're in these virtual classrooms.
When we come back, we're going to talk a little bit about Uber. You have security charges over there.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses a hack at Uber that ended up with its Chief of Security facing Obstruction of Justice charges.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities
Ransomware accounted for 41% of all cyber insurance claims in H1 2020
A bevy of new features make iOS 14 the most secure mobile OS ever
Don't Fall for It! Defending Against Deepfakes
Patient dies after a ransomware attack reroutes her to a remote hospital
Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records
Time for CEOs to Stop Enabling China's Blatant IP Theft
Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers
74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hey, I've got a story right now that should be a word of warning to businesses that have personal information. If you are working for a company and they've got your personal information, you're going to want to hear this too.
Hi everybody Craig Peterson here on WGAN. Thanks for joining me today. I'm on every Saturday from one until 3:00 PM. And if you miss any part of the show, make sure you go online. Craig peterson.com. You can also find me on tune in and any other streaming podcast app that you might care to look for me. I'm pretty much everywhere.
We are going to talk right now about Uber. There are many people who are really not knowledgeable about security that are in security jobs and positions. I would say that the majority of people that are in jobs responsible for security are not fully qualified. They know more than everybody else in the organization, but that doesn't mean they're qualified. So that's one class.
Of course, you have the people who really do know what they're doing. They are few and far between. Then you have Uber's former chief security officer. He just got nailed over a coverup of a hack that had occurred at Uber. This is really fascinating because he played some games.
He played very fast and loose with the truth and a criminal complaint ended up getting filed against him. In federal court this week, the guy's name is Joseph Sullivan. If you look at a picture of him, he's got the kind of beard that almost makes him look like he's one of these gangsters.
I have a thing about facial hair and maybe it's just my generation, my age. I'm not sure what, but he looks creepy to me, that a beard thing that he has Joseph Sullivan, but he was charged with obstruction of justice and misprision of a felony connected with the attempted coverup of a 2016 hack of Uber.
Now isn't that interesting here? And this is a, I'm getting this from justice.gov and it's United States attorney David Anderson, and the FBI were involved in this, Craig de Faire. And this is really an interesting story when you get right down into it. And we'll cover a little bit of that right now.
But according to this complaint that was filed between April of 2015 and November of 2017. This guy, Joseph Sullivan, he's 52 years old lives in Palo Alto, California. Where else he was Uber's chief security officer. Now, he was contacted by two hackers via email that said that they had been able to hack Uber's system and they were able to download a database that had personally identifiable information-on 57 million Uber users and drivers. Now, remember Uber is the company that had this God-mode is what they called it. Uber is a company that had employees, including apparently their CEO. Watching people getting driven and where they started, where they ended up. Now, we'll go, okay. you got to do a little quality control. Hey, I get that.
It turns out they were monitoring celebrities, finding out where the celebrities lived, watching them go, where they were going, that the type of stuff you need. Yeah, in order to twist arms, right? Hold their data a little bit in ransom, little pirate operation going on there. So they got in trouble for that one too.
They have been hacked before. So apparently this Joseph Sullivan guy, when he got the email look to see, did this actually happen? And they found, yeah, indeed. At least this is what the criminal complaint is alleging. They did indeed get them the driver's license numbers for approximately 600,000 people who drove for Uber.
Think about that for a minute. And what are licenses good for? Oh yeah. This year voting, right? Yeah. Yeah, because there's no ID is necessary. It's just mailed in. 57 million users and drivers over half a million driver's license numbers. What he apparently did was he went and used Uber's bug bounty program.
Most companies have that nowadays. It's Hey, you found a bug in our software in our system. We will pay you because we appreciate that. We'd rather you did it and we pay you a bounty than for bad guys to find it. All right. apparently, he was being extorted here because these hackers demanded a six-figure payment in exchange for their silence.
Now that's become very popular nowadays, by the way, this was a few years back. Now, nowadays ransomware works in two ways. One, they say, Hey, if you want your data back, if you want to decrypt it, you got to pay up. The other way it works is that this ransomware downloads your files, first. So the bad guys have it, so they will ransom it one way or the other.
It'll say, Hey, you pay up or I'm going to release all of this data. Or in this case, I'm going to give Uber or black eye. Cause I'm going to tell the media about it and release it. Or Hey, if you want your data decrypted, you gotta pay me. They can get, they're getting clever. These criminals. That's very common nowadays.
So it alleges this criminal complaint. That Sullivan took deliberate steps to conceal deflect and mislead the federal trade commission about the breach. Why? it turns out that a month or so later, their FTC filing was due and part of that needed to be about the security that they were taking because prior settlements with the government and the court required them to report on their security operation.
Yeah. Yeah. interesting Justine and the charges and the statement I've got there. In fact, when I'm reading it from here is the justice.gov, but it actually has the information about the indictment. So this is very one-sided.
There's nothing here from Sullivan's attorneys. It's just what the government is saying. So the complaint also describes how Sullivan. Played a pivotal role in responding to the FCC inquiry about Uber cybersecurity. It's just absolutely amazing. Okay.
So what do we learn from this? I think we learn a few things.
First of all, if you are a business owner and you have any data at all, really nowadays, it's pretty much every business. Even if you don't have driver's licenses, do you know what you got, you might have bank account information, your own bank, account information, not even just customers or businesses that you trade with, where you're just transferring funds back and forth.
You might have all of that stuff on your computers. And we do scans for businesses and we look specifically for bank account numbers, social security, numbers, phone numbers, all kinds of stuff that is illegal to disclose. it's absolutely amazing. Apparently Uber paid the hackers a hundred thousand dollars in Bitcoin in December 2016, and hackers obviously never provided their true names.
Sullivan tried to get the hackers to sign nondisclosure agreements and these agreements that Uber's lawyers put together contained false representations saying that the hackers did not take or store any data, which apparently is not true. So this complaint goes on. It's absolutely amazing.
Again, if you're a business, all 50 States now have laws that require you to disclose when data is stolen. You have to disclose it and you cannot hide it. Particularly if you are a publicly-traded company or if you're a division of a publicly-traded company earlier in the show, I mentioned this whole pencil whipping forms thing where people have a form, it might be for the insurance company and might be for federal or state regulators and they just check the box.
Yup. yup. Yup. Yup. Even though they don't really know. And they don't know enough to know that they don't really know. Okay. So we have to be very careful about that. And so that's why we do these scans. In fact, we do them daily for our customers just to see if the data is out there. So make sure you're not storing any of that data.
I am a bit of a packrat myself, a digital packrat. I have stuff going way back when, but I make sure I don't have any PII. At least I try and make sure of that. You need to do that too. If you're a consumer, remember again, all 50 states have in place laws to help protect you. Now about the only thing that you might be able to do is get a couple of bucks from a settlement.
Look at this. I filed for my settlement offer from Equifax, which is how many years old now, where they lost all of your personal data was all stolen. Maybe four years, five years ago, by hackers it's known to have been stolen. They admitted it was stolen because they didn't keep things patched up and their security people were underfunded work too hard. Which happens every day in this country, unfortunately. And, who knows? the attorneys did, they got their tens of millions of dollars in attorney's fees that happens every year here in this country. I'm still waiting for my supposed check for $25.
They're now saying, it was probably gonna be a lot less than $25. Cause you know, attorney's fees, right? I added that last part, but this is absolutely ridiculous. It's ridiculous.
So if something does happen, if your data shows up on the dark web, you should take action. Cause that's the only way these businesses are going to get their act together.
Craig Peterson: [00:11:08] So I want to encourage you right now to go to a website it's called, have I been pwned dot com. Have I been pwned is like pawned, but with a P w n e d dot com. Okay. Look there, put in your email address and they will search their databases of known hacks. The data existing on the dark web and have been pwned will tell you where your data was stolen.
Craig Peterson: [00:11:35] What was stolen. Might've been just your email address might include your name, your social security number, bank, account numbers. They pretty much have it, but all, and then you can contact these various companies where your data was stored your people, and maybe you should get involved with the criminal complaint.
Against some of these companies be part of a class-action lawsuit, make some bucks, we've got to stop this. We've got to get people smartened up.
All right, everybody makes sure right now you go online Craig peterson.com/subscribe so that you can get in this training. You can get your reboot guide. You can get all of this stuff.
Listen Wednesday mornings at seven 30 while I'm on with Matt Gagnon right here on WGAN.
Take care, everybody.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses a hack at Uber that ended up with its Chief of Security facing Obstruction of Justice charges.Â
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities
Ransomware accounted for 41% of all cyber insurance claims in H1 2020
A bevy of new features make iOS 14 the most secure mobile OS ever
Don't Fall for It! Defending Against Deepfakes
Patient dies after a ransomware attack reroutes her to a remote hospital
Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records
Time for CEOs to Stop Enabling China's Blatant IP Theft
Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hey, I've got a story right now that should be a word of warning to businesses that have personal information. If you are working for a company and they've got your personal information, you're going to want to hear this too.
Hi everybody Craig Peterson here on WGAN. Thanks for joining me today. I'm on every Saturday from one until 3:00 PM. And if you miss any part of the show, make sure you go online. Craig peterson.com. You can also find me on tune in and any other streaming podcast app that you might care to look for me. I'm pretty much everywhere.
We are going to talk right now about Uber. There are many people who are really not knowledgeable about security that are in security jobs and positions. I would say that the majority of people that are in jobs responsible for security are not fully qualified. They know more than everybody else in the organization, but that doesn't mean they're qualified. So that's one class.
Of course, you have the people who really do know what they're doing. They are few and far between. Then you have Uber's former chief security officer. He just got nailed over a coverup of a hack that had occurred at Uber. This is really fascinating because he played some games.
He played very fast and loose with the truth and a criminal complaint ended up getting filed against him. In federal court this week, the guy's name is Joseph Sullivan. If you look at a picture of him, he's got the kind of beard that almost makes him look like he's one of these gangsters.
 I have a thing about facial hair and maybe it's just my generation, my age. I'm not sure what, but he looks creepy to me, that a beard thing that he has Joseph Sullivan, but he was charged with obstruction of justice and misprision of a felony connected with the attempted coverup of a 2016 hack of Uber.
Now isn't that interesting here? And this is a, I'm getting this from justice.gov and it's United States attorney David Anderson, and the FBI were involved in this, Craig de Faire. And this is really an interesting story when you get right down into it. And we'll cover a little bit of that right now.
But according to this complaint that was filed between April of 2015 and November of 2017. This guy, Joseph Sullivan, he's 52 years old lives in Palo Alto, California. Where else he was Uber's chief security officer. Now, he was contacted by two hackers via email that said that they had been able to hack Uber's system and they were able to download a database that had personally identifiable information-on 57 million Uber users and drivers. Now, remember Uber is the company that had this God-mode is what they called it. Uber is a company that had employees, including apparently their CEO. Watching people getting driven and where they started, where they ended up. Now, we'll go, okay. you got to do a little quality control. Hey, I get that.
It turns out they were monitoring celebrities, finding out where the celebrities lived, watching them go, where they were going, that the type of stuff you need. Yeah, in order to twist arms, right? Hold their data a little bit in ransom, little pirate operation going on there. So they got in trouble for that one too.
They have been hacked before. So apparently this Joseph Sullivan guy, when he got the email look to see, did this actually happen? And they found, yeah, indeed. At least this is what the criminal complaint is alleging. They did indeed get them the driver's license numbers for approximately 600,000 people who drove for Uber.
Think about that for a minute. And what are licenses good for? Oh yeah. This year voting, right? Yeah. Yeah, because there's no ID is necessary. It's just mailed in. 57 million users and drivers over half a million driver's license numbers. What he apparently did was he went and used Uber's bug bounty program.
Most companies have that nowadays. It's Hey, you found a bug in our software in our system. We will pay you because we appreciate that. We'd rather you did it and we pay you a bounty than for bad guys to find it. All right. apparently, he was being extorted here because these hackers demanded a six-figure payment in exchange for their silence.
Now that's become very popular nowadays, by the way, this was a few years back. Now, nowadays ransomware works in two ways. One, they say, Hey, if you want your data back, if you want to decrypt it, you got to pay up. The other way it works is that this ransomware downloads your files, first. So the bad guys have it, so they will ransom it one way or the other.
It'll say, Hey, you pay up or I'm going to release all of this data. Or in this case, I'm going to give Uber or black eye. Cause I'm going to tell the media about it and release it. Or Hey, if you want your data decrypted, you gotta pay me. They can get, they're getting clever. These criminals. That's very common nowadays.
So it alleges this criminal complaint. That Sullivan took deliberate steps to conceal deflect and mislead the federal trade commission about the breach. Why? it turns out that a month or so later, their FTC filing was due and part of that needed to be about the security that they were taking because prior settlements with the government and the court required them to report on their security operation.
Yeah. Yeah. interesting Justine and the charges and the statement I've got there. In fact, when I'm reading it from here is the justice.gov, but it actually has the information about the indictment. So this is very one-sided.
There's nothing here from Sullivan's attorneys. It's just what the government is saying. So the complaint also describes how Sullivan. Played a pivotal role in responding to the FCC inquiry about Uber cybersecurity. It's just absolutely amazing. Okay.
So what do we learn from this? I think we learn a few things.
First of all, if you are a business owner and you have any data at all, really nowadays, it's pretty much every business. Even if you don't have driver's licenses, do you know what you got, you might have bank account information, your own bank, account information, not even just customers or businesses that you trade with, where you're just transferring funds back and forth.
You might have all of that stuff on your computers. And we do scans for businesses and we look specifically for bank account numbers, social security, numbers, phone numbers, all kinds of stuff that is illegal to disclose. it's absolutely amazing. Apparently Uber paid the hackers a hundred thousand dollars in Bitcoin in December 2016, and hackers obviously never provided their true names.
Sullivan tried to get the hackers to sign nondisclosure agreements and these agreements that Uber's lawyers put together contained false representations saying that the hackers did not take or store any data, which apparently is not true. So this complaint goes on. It's absolutely amazing.
Again, if you're a business, all 50 States now have laws that require you to disclose when data is stolen. You have to disclose it and you cannot hide it. Particularly if you are a publicly-traded company or if you're a division of a publicly-traded company earlier in the show, I mentioned this whole pencil whipping forms thing where people have a form, it might be for the insurance company and might be for federal or state regulators and they just check the box.
Yup. yup. Yup. Yup. Even though they don't really know. And they don't know enough to know that they don't really know. Okay. So we have to be very careful about that. And so that's why we do these scans. In fact, we do them daily for our customers just to see if the data is out there. So make sure you're not storing any of that data.
I am a bit of a packrat myself, a digital packrat. I have stuff going way back when, but I make sure I don't have any PII. At least I try and make sure of that. You need to do that too. If you're a consumer, remember again, all 50 states have in place laws to help protect you. Now about the only thing that you might be able to do is get a couple of bucks from a settlement.
Look at this. I filed for my settlement offer from Equifax, which is how many years old now, where they lost all of your personal data was all stolen. Maybe four years, five years ago, by hackers it's known to have been stolen. They admitted it was stolen because they didn't keep things patched up and their security people were underfunded work too hard. Which happens every day in this country, unfortunately. And, who knows? the attorneys did, they got their tens of millions of dollars in attorney's fees that happens every year here in this country. I'm still waiting for my supposed check for $25.
They're now saying, it was probably gonna be a lot less than $25. Cause you know, attorney's fees, right? I added that last part, but this is absolutely ridiculous. It's ridiculous.
So if something does happen, if your data shows up on the dark web, you should take action. Cause that's the only way these businesses are going to get their act together.
Craig Peterson: [00:11:08] So I want to encourage you right now to go to a website it's called, have I been pwned dot com. Have I been pwned is like pawned, but with a P w n e d dot com. Okay. Look there, put in your email address and they will search their databases of known hacks. The data existing on the dark web and have been pwned will tell you where your data was stolen.
Craig Peterson: [00:11:35] What was stolen. Might've been just your email address might include your name, your social security number, bank, account numbers. They pretty much have it, but all, and then you can contact these various companies where your data was stored your people, and maybe you should get involved with the criminal complaint.
Against some of these companies be part of a class-action lawsuit, make some bucks, we've got to stop this. We've got to get people smartened up.
All right, everybody makes sure right now you go online Craig peterson.com/subscribe so that you can get in this training. You can get your reboot guide. You can get all of this stuff.
Listen Wednesday mornings at seven 30 while I'm on with Matt Gagnon right here on WGAN.
Take care, everybody.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Good morning everybody!
I was on WGAN this morning with Matt Gagnon, and we began talking about Deep Fakes and then went right into China's theft of US Intellectual Property. Let's get into my conversation with Matt on WGAN.
These and more tech tips, news, and updates just visit - CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Be extra careful, because the best way to defend against these deep fakes is to hold the people accountable that host them.
Good morning, everybody. It was on with Mr. Matt Gangon this morning, and he and I had a couple of conversations about this. It turns out hot topics in which both of us are very interested. Not just curious, frankly, I get on my soapbox.
Matt Gagnon: [00:00:29] It is seven 36 on the WGAN and morning news on Wednesday. It's time to talk to Craig Peterson, and it is a pleasure. Welcome on the program, as usual, Craig, how are you?
Craig Peterson: [00:00:39] Hey, good morning. I am doing well.
Matt Gagnon: [00:00:42] Thank you so much for joining us, sir. Of course, you could hear this voice you hear right now on Saturdays.
Is that correct? Mr. Peterson?
Craig Peterson: [00:00:52] Yes, you can every Saturday from one to three,
Matt Gagnon: [00:00:56] Indeed. All right, let's get right into things here. So I was watching some well done, deep fakes on YouTube the other day. They were taking a, I don't know if you've ever seen these Craig, but they were, they were taking, like impressions, like celebrity impressions of other celebrities.
Then actually. Like deep faking the real face of the real celebrity on to the person. Who's the impressionist and it's creepy. And it's all like Tom cruise. I think a couple of others, like Arnold Schwarzenegger, was one of them. It was creepy. And what I have to say here is.
Very well done. You can almost not tell this technology is getting so good. So anyway, my point in this is to ask you the question of what you can do to defend against this because, as fun, as it might be to see that kind of thing, it does have some, shall we say, nefarious applications?
Craig Peterson: [00:01:42] Yeah, big time. And we're already seen a few of these in this election cycle. I don't know if this is going to be an October surprise for one of the candidates. Defending against them gets very difficult. I do have to say, by the way, But it is more accessible to fake video or not, then it is to phony voice and the way they're doing it, some, someone has to say the words in the phrase and not have it all chopped up, but it does pose a considerable risk to all of us.
There's something called the deep fake detection challenge that's going on right now. They've got AI's artificial intelligence machines if you will. One of which is trying to create a deep fake. The other is trying to detect the deep fake made by the other device, and they go back and forth challenging them.
Then they also have people involved, more than 2200 teams, in trying to detect them. Today, they are pretty easy to detect, but if you know the technology, so I think the bottom line here, Matt, most people is if it is something that you just don't believe to be quite right. That you think this can't be right.
Do a little bit more research into it. Facebook and Twitter, and all of these other guys are working on how do they get rid of deep fakes and detect them. From a machine standpoint right now, it's easy to do, but be extra careful, because the best way to defend against these deep fakes is to hold people accountable that host to them.
So if you find something that you think is a deep phase, there is a report button there on Facebook, and on some of these other social media sites, report it. Then someone will start looking at it. Facebook this week just started having people reviewing some of these. YouTube, I shouldn't say, just had some people start examining videos again.
This year it's been almost entirely artificial intelligence, but we that see them and suspect it needs to report it so that these professionals can get involved.
Matt Gagnon: [00:04:05] I saw another one, I think that was done by maybe Smithsonian or the Nixon library or something too, where somebody had made, when the moon landing happened, Nixon had prepared both a great, it just went well, and I'm so proud of the Americans for landing on the moon. A speech and he also prepared a, and everything just was a disaster, which didn't work speech. And he never delivered the second one cause it worked okay, but they had deep faked that speech, the one he never gave, like onto, onto his, the face onto somebody who was doing it. And I got to tell you, it was, in a couple of spots, it was apparent, but for the most part, it was a creepily accurate. It is a technology that is only going to get more advanced. I would bet you money that voice angled things is probably going to get better as well.
And that's a scary prospect, as cool as this technology is, it's a frightening prospect in the future. It is,
Craig Peterson: [00:04:52] The bottom line is you have to get down to the individual pixels to have a chance of figuring it out.
Matt Gagnon: [00:04:57] Yeah, we're talking to Craig Peterson for our tech guru. He joins us on Wednesdays at this time.
Craig, the Chinese do a lot of really bad things on the internet, IP theft being one of them. and you believe that it's time for CEO's to stop enabling China to do this.
Craig Peterson: [00:05:12] Yeah. this is one of my political season rants.
Matt Gagnon: [00:05:15] That's fine. Hey, listen. It is the season, right?
Oh yeah, exactly. I'll be talking a lot more about this on Saturday at one of course, but it really is.
Craig Peterson: [00:05:27] It's time for CEO's to stop enabling China's theft. I don't know how many times I've said it, but I go into businesses every week and find that they have been hacked by China. Their intellectual property has been stolen in 2018 alone. The US trade representative found that Chinese theft of American intellectual property cost somewhere around four, 500, maybe as much as $600 billion dollars.
The FBI is right now investigating a thousand cases of Chinese intellectual property theft. Two of those are cases I'm involved in. People, we have to protect our IP. That means, an example, and I'll talk more about it this weekend. I've got two or three i'll talk about, but one is a guy I know and this was just two weeks ago.
I found out that he had designed a new system, he's an engineer, for controlling the air conditioning systems within a building and lighting systems and made it way more efficient and effective cut costs, and yet kept it comfortable for everybody. And he had worked on it for two years.
It was hardware and some software integration, and it would integrate with almost any HVAC system out there. the Chinese stole it. What he has now is nothing. They are manufacturing it in China. He is competing against his own while he wouldn't be competing against his own design, being sold for pennies on the dollar.
Because as we know, some of this stuff is made by slave labor. Either of it is made by people who just don't get it stayed much. So he spent two years of his life designing this map and it was stolen from him. Then I'll talk about a few more that I am personally involved with. I'll talk about two of these cases that I'm involved with.
The FBI is investigating, but the bottom line, we cannot sit back and allow them to our IP to be stolen. I'll try not to get a leg up on us and let us entrepreneurs whose businesses are our retirement package. To have our retirement stolen. I have our employees' jobs stolen and have us be in a terrible spot. We have got to wake up.
Matt Gagnon: [00:07:57] The Craig Peterson, our tech guru, joins us on Wednesdays at this time to go over the world of technology. Thank you, Craig. As always. We appreciate it. And we'll talk to you again next week.
Craig Peterson: [00:08:05] Hey, Take Care. Bye-Bye
Hard to believe. It's Wednesday already. Where does the time go here? Every week? Hey, we will be back on Saturday. Of course,
Thursday, we're going to start with one of these little lesson emails it's taken. It's a lot of time to get stuff together, and We're also taking Care of businesses with trouble that needs security help. And frankly, there's a lot of us out there. A lot of our companies that need help.
Anyhow, take care, guys. We'll be back on Saturday. Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Good morning everybody!
I was on WGAN this morning with Matt Gagnon, and we began talking about Deep Fakes and then went right into China's theft of US Intellectual Property. Let's get into my conversation with Matt on WGAN.
These and more tech tips, news, and updates just visit - CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Be extra careful, because the best way to defend against these deep fakes is to hold the people accountable that host them.
Good morning, everybody. It was on with Mr. Matt Gangon this morning, and he and I had a couple of conversations about this. It turns out hot topics in which both of us are very interested. Not just curious, frankly, I get on my soapbox.
Matt Gagnon: [00:00:29] It is seven 36 on the WGAN and morning news on Wednesday. It's time to talk to Craig Peterson, and it is a pleasure. Welcome on the program, as usual, Craig, how are you?
Craig Peterson: [00:00:39] Hey, good morning. I am doing well.
Matt Gagnon: [00:00:42] Thank you so much for joining us, sir. Of course, you could hear this voice you hear right now on Saturdays.
Is that correct? Mr. Peterson?
Craig Peterson: [00:00:52] Yes, you can every Saturday from one to three,
Matt Gagnon: [00:00:56] Indeed. All right, let's get right into things here. So I was watching some well done, deep fakes on YouTube the other day. They were taking a, I don't know if you've ever seen these Craig, but they were, they were taking, like impressions, like celebrity impressions of other celebrities.
Then actually. Like deep faking the real face of the real celebrity on to the person. Who's the impressionist and it's creepy. And it's all like Tom cruise. I think a couple of others, like Arnold Schwarzenegger, was one of them. It was creepy. And what I have to say here is.
Very well done. You can almost not tell this technology is getting so good. So anyway, my point in this is to ask you the question of what you can do to defend against this because, as fun, as it might be to see that kind of thing, it does have some, shall we say, nefarious applications?
Craig Peterson: [00:01:42] Yeah, big time. And we're already seen a few of these in this election cycle. I don't know if this is going to be an October surprise for one of the candidates. Defending against them gets very difficult. I do have to say, by the way, But it is more accessible to fake video or not, then it is to phony voice and the way they're doing it, some, someone has to say the words in the phrase and not have it all chopped up, but it does pose a considerable risk to all of us.
There's something called the deep fake detection challenge that's going on right now. They've got AI's artificial intelligence machines if you will. One of which is trying to create a deep fake. The other is trying to detect the deep fake made by the other device, and they go back and forth challenging them.
Then they also have people involved, more than 2200 teams, in trying to detect them. Today, they are pretty easy to detect, but if you know the technology, so I think the bottom line here, Matt, most people is if it is something that you just don't believe to be quite right. That you think this can't be right.
Do a little bit more research into it. Facebook and Twitter, and all of these other guys are working on how do they get rid of deep fakes and detect them. From a machine standpoint right now, it's easy to do, but be extra careful, because the best way to defend against these deep fakes is to hold people accountable that host to them.
So if you find something that you think is a deep phase, there is a report button there on Facebook, and on some of these other social media sites, report it. Then someone will start looking at it. Facebook this week just started having people reviewing some of these. YouTube, I shouldn't say, just had some people start examining videos again.
This year it's been almost entirely artificial intelligence, but we that see them and suspect it needs to report it so that these professionals can get involved.
Matt Gagnon: [00:04:05] I saw another one, I think that was done by maybe Smithsonian or the Nixon library or something too, where somebody had made, when the moon landing happened, Nixon had prepared both a great, it just went well, and I'm so proud of the Americans for landing on the moon. A speech and he also prepared a, and everything just was a disaster, which didn't work speech. And he never delivered the second one cause it worked okay, but they had deep faked that speech, the one he never gave, like onto, onto his, the face onto somebody who was doing it. And I got to tell you, it was, in a couple of spots, it was apparent, but for the most part, it was a creepily accurate. It is a technology that is only going to get more advanced. I would bet you money that voice angled things is probably going to get better as well.
And that's a scary prospect, as cool as this technology is, it's a frightening prospect in the future. It is,
Craig Peterson: [00:04:52] The bottom line is you have to get down to the individual pixels to have a chance of figuring it out.
Matt Gagnon: [00:04:57] Yeah, we're talking to Craig Peterson for our tech guru. He joins us on Wednesdays at this time.
Craig, the Chinese do a lot of really bad things on the internet, IP theft being one of them. and you believe that it's time for CEO's to stop enabling China to do this.
Craig Peterson: [00:05:12] Yeah. this is one of my political season rants.
Matt Gagnon: [00:05:15] That's fine. Hey, listen. It is the season, right?
Oh yeah, exactly. I'll be talking a lot more about this on Saturday at one of course, but it really is.
Craig Peterson: [00:05:27] It's time for CEO's to stop enabling China's theft. I don't know how many times I've said it, but I go into businesses every week and find that they have been hacked by China. Their intellectual property has been stolen in 2018 alone. The US trade representative found that Chinese theft of American intellectual property cost somewhere around four, 500, maybe as much as $600 billion dollars.
The FBI is right now investigating a thousand cases of Chinese intellectual property theft. Two of those are cases I'm involved in. People, we have to protect our IP. That means, an example, and I'll talk more about it this weekend. I've got two or three i'll talk about, but one is a guy I know and this was just two weeks ago.
I found out that he had designed a new system, he's an engineer, for controlling the air conditioning systems within a building and lighting systems and made it way more efficient and effective cut costs, and yet kept it comfortable for everybody. And he had worked on it for two years.
It was hardware and some software integration, and it would integrate with almost any HVAC system out there. the Chinese stole it. What he has now is nothing. They are manufacturing it in China. He is competing against his own while he wouldn't be competing against his own design, being sold for pennies on the dollar.
Because as we know, some of this stuff is made by slave labor. Either of it is made by people who just don't get it stayed much. So he spent two years of his life designing this map and it was stolen from him. Then I'll talk about a few more that I am personally involved with. I'll talk about two of these cases that I'm involved with.
The FBI is investigating, but the bottom line, we cannot sit back and allow them to our IP to be stolen. I'll try not to get a leg up on us and let us entrepreneurs whose businesses are our retirement package. To have our retirement stolen. I have our employees' jobs stolen and have us be in a terrible spot. We have got to wake up.
Matt Gagnon: [00:07:57] The Craig Peterson, our tech guru, joins us on Wednesdays at this time to go over the world of technology. Thank you, Craig. As always. We appreciate it. And we'll talk to you again next week.
Craig Peterson: [00:08:05] Hey, Take Care. Bye-Bye
Hard to believe. It's Wednesday already. Where does the time go here? Every week? Hey, we will be back on Saturday. Of course,
Thursday, we're going to start with one of these little lesson emails it's taken. It's a lot of time to get stuff together, and We're also taking Care of businesses with trouble that needs security help. And frankly, there's a lot of us out there. A lot of our companies that need help.
Anyhow, take care, guys. We'll be back on Saturday. Bye-bye.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Steve Fourni who was sitting in for the vacationing Jim Polito. He had a few questions about computer security especially in light of the 129 Microsoft Vulnerabilities that were addressed on Patch Tuesday, I did get up on my soapbox for a bit, but Here we go with Steve.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hey, it's political season. I had to get on my soapbox. Okay. Little stump, speech, going on here, Craig Peterson. Of course this morning. I was on in Mass and south-central and Western mass as well as Southern Vermont and also from parts of Connecticut. So yeah, I guess we're expanding.
We're talking about serious computer issues. Steve Fourni was sitting in for Jim Pollito this morning and I like the way he was going with this and what he was thinking about. His train of thought is something that frankly, every business person needs to have. So here we go with Steve, his audio is a little bit low and I reported that over to iHeart because apparently it's going out okay on the terrestrial AM and FM stations, but it definitely not working so great on the iHeart stuff. So somebody turned a pot down. I think it's what happened. But anyway, here we go.
Steve Fourni: [00:01:00] All right. You know that music it's Craig Peterson our tech talk guru always giving us the information that we need. That is important. Now more than ever. We are all on that stinking computer now, and it is more important now than more than ever. Craig. Good morning. How are you, sir?
Hi, I'm doing well. You know If your computer is stinking you can wash it, but be careful.
Not with water while it's on I assume.
So let's start with Microsoft, who I handed in their term paper and he handed it back with 129 vulnerability mistakes and now it appears that they have corrected their work and turned it back in.
Craig Peterson: [00:01:34] Wow. Everybody, Pay attention to this one because this is a very big deal. Yes. We had patch Tuesday, 129 vulnerabilities in 15 Microsoft products is absolutely crazy. But here's the big news, very rarely here does Homeland security issue emergency warnings.
On Friday, the Department of Homeland security gave administrators, system administrators within the federal government until Monday to patch Windows. There is amongst all of these patches, the first patch for this came out last month, and another one's coming out.
Homeland security saying this is so absolutely critical you've got to get it done over the weekend. So that applies to all of us as well. It's called a zero log-on. This presents what they called an unacceptable risk because you don't even have to log on to the windows server in order to take control of the silly thing. Absolutely terrible. This is a flaw in Microsoft Windows net-log- on-remote protocol.
Many of our businesses, and Steve you've heard me talk about this before, we just don't understand how to do this stuff. We've gotten VPNs we are using windows net log on, it is not configured properly. Now it turns out that if you have not applied these most recent patches, you're in serious trouble.
Steve Fourni: [00:03:07] Yikes. So we're talking with Craig Peterson, our tech talk guru. Do you think Craig? It's a generic question, but do you think that most companies, are prepared for where we are in terms of the remote working, because you have, you have like your bosses who have other more important things to. Do you have your IT department who again, probably has more important things to do? Do you think they're in, on the whole, staffed enough to keep tabs on all this stuff?
Craig Peterson: [00:03:35] No, I don't. I really don't. This whole security thing is a very big deal, very hard for business businesses to do. When you get down to the raw number, businesses are concerned obviously about these business expenses. I think it can be looked at also as a plus to be able to tell your client, Hey, a big hug time here. We're keeping your data safe.
But until you have about 500 employees in your business, you are very unlikely to be able to afford the type of security that you need. So you get these businesses out there, small businesses, which is under 500 employees, considered by the SBA to be a small business. These small businesses who are there - I've got myself, somebody who used to be that and such, and now do you know, they really like computers and they are our computer expert and darn it, we've got SonicWall and we've got Norton, antivirus installed. We're all set.
It is not true. They have to, Steve, let go of those reins a little bit, outsource it to a managed security services provider.
I've got another article out there right now. The title is it's time for CEOs to stop enabling China's blatant intellectual property theft. They are absolutely right. We are not doing anywhere near enough. If you're on my email list, I'm starting these three-minute training, If you will, three-minute emails that are going to be going out, ultimately, here a couple of times a week to help CEOs, business owners, senior managers understand a little bit about what these problems are and if you're a home user, you're going to get stuff out of this as well. But this is a huge deal.
Then you get Jeff Bezos. You get the chairman of Microsoft, Sundar Pichai, and Tim Cook, who is the head of Apple. All in front of Congress denying firsthand knowledge of China stealing intellectual property. Mark Zuckerberg admitted that it was well-documented he's right. And I have seen it in the majority. Probably the vast majority. I'm thinking better than 90%. Me personally, 90% of the businesses that have called me and my team in, Steve, to have a look at their systems. Emails weird, something's slow. Can you have a look? They do a scan, do an analysis for us. And we did this for free about two years ago for a bunch of different businesses here, listeners to the radio show subscribers to the email list.
Almost every business out there has likely been penetrated by Chinese or Russian hackers. I have a guy, a friend, I know he's an engineer, hardware engineer, and he designed a business. for businesses, a system that took care of all of the HVAC, all of the heating and air conditioning ventilation in the building, pulled it all together into one piece of glass. One user interfaces and saved them a lot of money.
And turns out, guess what? It was stolen by China. And now he has all of that. It took them a couple of years to put it all together, tested, and make sure it was working all of that now. Is being stolen by China being made in China. And he has no way to make any money off of this because he just can't compete.
It's happening. We've got to pull up our socks, Steve, and it's political time. So I'm up on my soapbox here about this. It's a very big deal. Yeah,
Steve Fourni: [00:07:28] No doubt. We're talking with Craig Peterson, our tech talk guru. I know, Craig, we have other stuff to talk about, but on what you're talking about and those numbers are staggering. We're doing the whole TikTok thing back and forth. And I heard a clip yesterday from a guy who said, every time I mentioned the word fried chicken, I get ads for KFC. So they already have my information. I don't really care about TikTok. We talk about all these businesses that, basically, you're already vulnerable.
Are there actually businesses out there that are sitting there and saying to themselves, you know what, China's already got all our information they have no interest in Jimmy's pizza shop, whatever we'll just roll with it. Are there companies that think of the same way the kid with the fried chicken thinks?
Craig Peterson: [00:08:06] We have a customer right in Worcester, which is a pizza shop and yeah, they do need to be worried about it. Think about your employees. When you're talking about TikTok thinking about your employees coming into your business, using their phones. Yeah. They're on break they're on TikTok on their phones, they're using your Wi-Fi together. Now, all of a sudden, the bad guys have potential access to data that's on your network. Then you were talking earlier, Steve, about ransomware accounting for 41% of all cyber insurance claims. Yeah. That's a lot. How does ransomware work? Most of the time it gets in through phishing attacks.
P H I S H I N G. What does to get you to click on the link? Yeah, one more. There's an old reference. What do they need to get into you and get you to click on that link? It needs information about you. how about do they send an email that looks like it from a friend because they now know who your friends are because they have access to your TikTok friends and an email looks like it's from your friend?
It says, Hey, you got to this great new video that and so cause they know that you like you clicked on the link, that link. Now you've compromised all of the computers in the business by clicking on that link. That's why it matters.
That is absolutely why it matters. You're not wrong in saying that, the bad guys probably have pretty much everything about us. But what they want is really fresh stuff, really new stuff. To get to and trick you into doing something you shouldn't do.
When you're talking about ransomware accounting for 41% of all cyber insurance claims less than half of the claims, I've seen number saying as little as 10% are actually paid out because the insurance company comes in and says, are you following industry-standard practices? Let's have a look. And they do have a look.
That's what happened with the pizza shop right there in Worcester. They had a look and they found out that they weren't, that's why they called us in.
But even if you have insurance, cyber insurance, do you really you think that $10 a month rider is going to cover you for the loss of your business cause it got hacked? No, it will not. This is a big deal that people just aren't paying attention to.
Steve Fourni: [00:10:26] Wolf. When it's not one thing, it's something else. It's unbelievable. We're talking with Craig Peterson, our tech talk guru. Craig if people want to get to more information and again, the helpful tips and advice. I just think it's, important enough and especially again, to give it to us at a level we can actually absorb. Given it to us at a fourth-grade reading level, which we need sometimes. How can they get more information from you, Craig?
Craig Peterson: [00:10:46] Just go to Craig peterson.com/subscribe.
That'll get you on my newsletter list. Comes out once a week. That'll start getting you these little three minute emails. That'll help keep you up to date and help you understand this a little bit better. Just Craig peterson.com/subscribe.
Steve Fourni: [00:11:05] Good stuff. Craig. Thanks so much for the time. Good to catch up again and we'll talk soon.
Craig Peterson: [00:11:11] Bye-bye.
Steve Fourni: [00:11:12] Take care. Appreciate it. There goes Craig Peterson and, yeah, even I was yesterday, my wife and I finally decided where we signed up for one of those, delivery meal things. I mean I do most of the cooking. I just go to the grocery store every day and I get what I needed for dinner that night and I can't do that now.
So we decided to sign up for one of those things. Which I'd love but, as soon as I signed up, the minute I signed up, all my ads were for other meal delivery places, every single one. Even like I said, this happens all the time.
I'll buy concert tickets and then I'll get ad ads, get your tickets. Now, I already did. So there's that kind of stuff that just drives you nuts too. Well, that's enough complaining for today.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Steve Fourni who was sitting in for the vacationing Jim Polito. He had a few questions about computer security especially in light of the 129 Microsoft Vulnerabilities that were addressed on Patch Tuesday, I did get up on my soapbox for a bit, but Here we go with Steve.
For more tech tips, news, and updates visit - CraigPeterson.com
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hey, it's political season. I had to get on my soapbox. Okay. Little stump, speech, going on here, Craig Peterson. Of course this morning. I was on in Mass and south-central and Western mass as well as Southern Vermont and also from parts of Connecticut. So yeah, I guess we're expanding.
We're talking about serious computer issues. Steve Fourni was sitting in for Jim Pollito this morning and I like the way he was going with this and what he was thinking about. His train of thought is something that frankly, every business person needs to have. So here we go with Steve, his audio is a little bit low and I reported that over to iHeart because apparently it's going out okay on the terrestrial AM and FM stations, but it definitely not working so great on the iHeart stuff. So somebody turned a pot down. I think it's what happened. But anyway, here we go.
Steve Fourni: [00:01:00] All right. You know that music it's Craig Peterson our tech talk guru always giving us the information that we need. That is important. Now more than ever. We are all on that stinking computer now, and it is more important now than more than ever. Craig. Good morning. How are you, sir?
Hi, I'm doing well. You know If your computer is stinking you can wash it, but be careful.
Not with water while it's on I assume.
So let's start with Microsoft, who I handed in their term paper and he handed it back with 129 vulnerability mistakes and now it appears that they have corrected their work and turned it back in.
Craig Peterson: [00:01:34] Wow. Everybody, Pay attention to this one because this is a very big deal. Yes. We had patch Tuesday, 129 vulnerabilities in 15 Microsoft products is absolutely crazy. But here's the big news, very rarely here does Homeland security issue emergency warnings.
On Friday, the Department of Homeland security gave administrators, system administrators within the federal government until Monday to patch Windows. There is amongst all of these patches, the first patch for this came out last month, and another one's coming out.
Homeland security saying this is so absolutely critical you've got to get it done over the weekend. So that applies to all of us as well. It's called a zero log-on. This presents what they called an unacceptable risk because you don't even have to log on to the windows server in order to take control of the silly thing. Absolutely terrible. This is a flaw in Microsoft Windows net-log- on-remote protocol.
Many of our businesses, and Steve you've heard me talk about this before, we just don't understand how to do this stuff. We've gotten VPNs we are using windows net log on, it is not configured properly. Now it turns out that if you have not applied these most recent patches, you're in serious trouble.
Steve Fourni: [00:03:07] Yikes. So we're talking with Craig Peterson, our tech talk guru. Do you think Craig? It's a generic question, but do you think that most companies, are prepared for where we are in terms of the remote working, because you have, you have like your bosses who have other more important things to. Do you have your IT department who again, probably has more important things to do? Do you think they're in, on the whole, staffed enough to keep tabs on all this stuff?
Craig Peterson: [00:03:35] No, I don't. I really don't. This whole security thing is a very big deal, very hard for business businesses to do. When you get down to the raw number, businesses are concerned obviously about these business expenses. I think it can be looked at also as a plus to be able to tell your client, Hey, a big hug time here. We're keeping your data safe.
But until you have about 500 employees in your business, you are very unlikely to be able to afford the type of security that you need. So you get these businesses out there, small businesses, which is under 500 employees, considered by the SBA to be a small business. These small businesses who are there -Â I've got myself, somebody who used to be that and such, and now do you know, they really like computers and they are our computer expert and darn it, we've got SonicWall and we've got Norton, antivirus installed. We're all set.
It is not true. They have to, Steve, let go of those reins a little bit, outsource it to a managed security services provider.
I've got another article out there right now. The title is it's time for CEOs to stop enabling China's blatant intellectual property theft. They are absolutely right. We are not doing anywhere near enough. If you're on my email list, I'm starting these three-minute training, If you will, three-minute emails that are going to be going out, ultimately, here a couple of times a week to help CEOs, business owners, senior managers understand a little bit about what these problems are and if you're a home user, you're going to get stuff out of this as well. But this is a huge deal.
Then you get Jeff Bezos. You get the chairman of Microsoft, Sundar Pichai, and Tim Cook, who is the head of Apple. All in front of Congress denying firsthand knowledge of China stealing intellectual property. Mark Zuckerberg admitted that it was well-documented he's right. And I have seen it in the majority. Probably the vast majority. I'm thinking better than 90%. Me personally, 90% of the businesses that have called me and my team in, Steve, to have a look at their systems. Emails weird, something's slow. Can you have a look? They do a scan, do an analysis for us. And we did this for free about two years ago for a bunch of different businesses here, listeners to the radio show subscribers to the email list.
Almost every business out there has likely been penetrated by Chinese or Russian hackers. I have a guy, a friend, I know he's an engineer, hardware engineer, and he designed a business. for businesses, a system that took care of all of the HVAC, all of the heating and air conditioning ventilation in the building, pulled it all together into one piece of glass. One user interfaces and saved them a lot of money.
And turns out, guess what? It was stolen by China. And now he has all of that. It took them a couple of years to put it all together, tested, and make sure it was working all of that now. Is being stolen by China being made in China. And he has no way to make any money off of this because he just can't compete.
It's happening. We've got to pull up our socks, Steve, and it's political time. So I'm up on my soapbox here about this. It's a very big deal. Yeah,
Steve Fourni: [00:07:28] No doubt. We're talking with Craig Peterson, our tech talk guru. I know, Craig, we have other stuff to talk about, but on what you're talking about and those numbers are staggering. We're doing the whole TikTok thing back and forth. And I heard a clip yesterday from a guy who said, every time I mentioned the word fried chicken, I get ads for KFC. So they already have my information. I don't really care about TikTok. We talk about all these businesses that, basically, you're already vulnerable.
Are there actually businesses out there that are sitting there and saying to themselves, you know what, China's already got all our information they have no interest in Jimmy's pizza shop, whatever we'll just roll with it. Are there companies that think of the same way the kid with the fried chicken thinks?
Craig Peterson: [00:08:06] We have a customer right in Worcester, which is a pizza shop and yeah, they do need to be worried about it. Think about your employees. When you're talking about TikTok thinking about your employees coming into your business, using their phones. Yeah. They're on break they're on TikTok on their phones, they're using your Wi-Fi together. Now, all of a sudden, the bad guys have potential access to data that's on your network. Then you were talking earlier, Steve, about ransomware accounting for 41% of all cyber insurance claims. Yeah. That's a lot. How does ransomware work? Most of the time it gets in through phishing attacks.
P H I S H I N G. What does to get you to click on the link? Yeah, one more. There's an old reference. What do they need to get into you and get you to click on that link? It needs information about you. how about do they send an email that looks like it from a friend because they now know who your friends are because they have access to your TikTok friends and an email looks like it's from your friend?
It says, Hey, you got to this great new video that and so cause they know that you like you clicked on the link, that link. Now you've compromised all of the computers in the business by clicking on that link. That's why it matters.
That is absolutely why it matters. You're not wrong in saying that, the bad guys probably have pretty much everything about us. But what they want is really fresh stuff, really new stuff. To get to and trick you into doing something you shouldn't do.
When you're talking about ransomware accounting for 41% of all cyber insurance claims less than half of the claims, I've seen number saying as little as 10% are actually paid out because the insurance company comes in and says, are you following industry-standard practices? Let's have a look. And they do have a look.
That's what happened with the pizza shop right there in Worcester. They had a look and they found out that they weren't, that's why they called us in.
But even if you have insurance, cyber insurance, do you really you think that $10 a month rider is going to cover you for the loss of your business cause it got hacked? No, it will not. This is a big deal that people just aren't paying attention to.
Steve Fourni: [00:10:26] Wolf. When it's not one thing, it's something else. It's unbelievable. We're talking with Craig Peterson, our tech talk guru. Craig if people want to get to more information and again, the helpful tips and advice. I just think it's, important enough and especially again, to give it to us at a level we can actually absorb. Given it to us at a fourth-grade reading level, which we need sometimes. How can they get more information from you, Craig?
Craig Peterson: [00:10:46] Just go to Craig peterson.com/subscribe.
That'll get you on my newsletter list. Comes out once a week. That'll start getting you these little three minute emails. That'll help keep you up to date and help you understand this a little bit better. Just Craig peterson.com/subscribe.
Steve Fourni: [00:11:05] Good stuff. Craig. Thanks so much for the time. Good to catch up again and we'll talk soon.
Craig Peterson: [00:11:11] Bye-bye.
Steve Fourni: [00:11:12] Take care. Appreciate it. There goes Craig Peterson and, yeah, even I was yesterday, my wife and I finally decided where we signed up for one of those, delivery meal things. I mean I do most of the cooking. I just go to the grocery store every day and I get what I needed for dinner that night and I can't do that now.
So we decided to sign up for one of those things. Which I'd love but, as soon as I signed up, the minute I signed up, all my ads were for other meal delivery places, every single one. Even like I said, this happens all the time.
I'll buy concert tickets and then I'll get ad ads, get your tickets. Now, I already did. So there's that kind of stuff that just drives you nuts too. Well, that's enough complaining for today.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed a critical patch that was announced on Friday and is so dangerous that the Fed's gave their system administrators until today to get their servers patched up. Also, Microsoft announced 129 Critical patches on Tuesday -- Patch, Patch, Patch! Then we talked about some good economic news. Here we go with Jack.
These and more tech tips, news, and updates visit
- CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hey, had a quick hit with Jack this morning up on New Hampshire today. We did talk a little bit about well, politics, really. What is going on with e-commerce and why did the federal government only give its own administrators 24 hours, basically to get this done? Zero log-on. Man, what a problem?
Jack Heath: [00:00:23] We appreciate it earlier. He yielded because of all the talk of the Supreme court, Craig Peterson, our tech talk guy with a quick moment or two on a tech talk point, or maybe tell us what his thoughts are when it comes to tech. Good morning.
Craig Peterson: [00:00:36] Hey, good morning, Jack. There is a huge warning that just came out.
It's unprecedented. This is from Homeland security. I've got to make sure that our listeners understand this. This came out Friday and they gave the federal government system administrators until today to patch windows, there is what's called a zero log-in vulnerability in windows servers. You can ask your tech people what that means, but bottom line check with them today. Make sure they know about this.
Microsoft released a hundred patches for 129 vulnerabilities, last Tuesday. This particular patch has been out now for about a month. Jack, we've got to make sure that people are patching and patching quickly. Get it done.
Some good news on the eCommerce retail front. They are expecting a thirty percent year over year increase in shopping online this year.
Black Friday might end up being truly a great day to go into the black for retailers again this year. Even with all of the people sitting at home, but maybe that's what spurred it in the first place.
Jack Heath: [00:01:48] Yeah. Who knows what that's going to look like? Right? From a retail online, you'd have to think the scales are online.
Craig Peterson: [00:01:55] Yes, they absolutely are. And they are seeing right now I'm looking at numbers showing some really big deals out there, but this is going to continue. The trend is expected to hit six and a half-trillion dollars here in about two more years, online sales. It's just growing dramatically and I think this whole COVID thing, shopping from home, really gave it a big kick in the pants.
We've got Walmart out there now just really going head to head with Amazon.
Jack Heath: [00:02:24] Oh, it's huge. I mean, you know, it used to be, you only heard about this during the holiday season, multiple packages on the porch. Take a walk in your neighborhood, the driving, the delivery people have been some of the busiest people of all time. Between Amazon, the post office, private deliverers. I mean, people will deliver packages to one resident sometimes it's like six times a day. That porch has packages. All right, Craig. Thank you.
Craig Peterson: [00:02:46] Take care.
This is an exciting week, but we are trying something new. We're going to be providing you with some training here, just real quick. I'm calling these our three-minute read and these there'll be emails. That'll be coming in your email box. If you already get my newsletter, you'll get my three-minute reads. It is going to help you out. So let me know what you think of these.
I had a lot of responses to over the weekend to our newsletter because we've got this new, Ask Craig column and people are asking. So that's really helping out with businesses and in a few people with some home issues. In fact, there was a big question. I am going to try and answer this week about home routers and some of the problems he's having.
So anyway, I'll keep an eye out, a big week this week, and Craig peterson.com/subscribe.
Take care, everybody. Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed a critical patch that was announced on Friday and is so dangerous that the Fed's gave their system administrators until today to get their servers patched up. Also, Microsoft announced 129 Critical patches on Tuesday -- Patch, Patch, Patch! Then we talked about some good economic news. Here we go with Jack.Â
These and more tech tips, news, and updates visit
-Â CraigPeterson.com
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] Hey, had a quick hit with Jack this morning up on New Hampshire today. We did talk a little bit about well, politics, really. What is going on with e-commerce and why did the federal government only give its own administrators 24 hours, basically to get this done? Zero log-on. Man, what a problem?
Jack Heath: [00:00:23] We appreciate it earlier. He yielded because of all the talk of the Supreme court, Craig Peterson, our tech talk guy with a quick moment or two on a tech talk point, or maybe tell us what his thoughts are when it comes to tech. Good morning.
Craig Peterson: [00:00:36] Hey, good morning, Jack. There is a huge warning that just came out.
It's unprecedented. This is from Homeland security. I've got to make sure that our listeners understand this. This came out Friday and they gave the federal government system administrators until today to patch windows, there is what's called a zero log-in vulnerability in windows servers. You can ask your tech people what that means, but bottom line check with them today. Make sure they know about this.
Microsoft released a hundred patches for 129 vulnerabilities, last Tuesday. This particular patch has been out now for about a month. Jack, we've got to make sure that people are patching and patching quickly. Get it done.
Some good news on the eCommerce retail front. They are expecting a thirty percent year over year increase in shopping online this year.
Black Friday might end up being truly a great day to go into the black for retailers again this year. Even with all of the people sitting at home, but maybe that's what spurred it in the first place.
Jack Heath: [00:01:48] Yeah. Who knows what that's going to look like? Right? From a retail online, you'd have to think the scales are online.
Craig Peterson: [00:01:55] Yes, they absolutely are. And they are seeing right now I'm looking at numbers showing some really big deals out there, but this is going to continue. The trend is expected to hit six and a half-trillion dollars here in about two more years, online sales. It's just growing dramatically and I think this whole COVID thing, shopping from home, really gave it a big kick in the pants.
We've got Walmart out there now just really going head to head with Amazon.
Jack Heath: [00:02:24] Oh, it's huge. I mean, you know, it used to be, you only heard about this during the holiday season, multiple packages on the porch. Take a walk in your neighborhood, the driving, the delivery people have been some of the busiest people of all time. Between Amazon, the post office, private deliverers. I mean, people will deliver packages to one resident sometimes it's like six times a day. That porch has packages. All right, Craig. Thank you.
Craig Peterson: [00:02:46] Take care.
This is an exciting week, but we are trying something new. We're going to be providing you with some training here, just real quick. I'm calling these our three-minute read and these there'll be emails. That'll be coming in your email box. If you already get my newsletter, you'll get my three-minute reads. It is going to help you out. So let me know what you think of these.
I had a lot of responses to over the weekend to our newsletter because we've got this new, Ask Craig column and people are asking. So that's really helping out with businesses and in a few people with some home issues. In fact, there was a big question. I am going to try and answer this week about home routers and some of the problems he's having.
So anyway, I'll keep an eye out, a big week this week, and Craig peterson.com/subscribe.
Take care, everybody. Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig explains why Hackers have found a new target that they love and why it might put you in jeopardy.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs
Think You're Spending Enough on Security?
DHS Braces For 'Potential EMP Attack' As Presidential Election Nears
US Sanctions Russian Attackers for 2020 Election Interference
Cyber-Risks Explode With Move to Telehealth Services
Why online voting is harder than online banking
Price gouging and defective products rampant on Amazon, reports find
Ransomware Has Gone Corporate—and Gotten More Cruel
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Welcome everybody. Hey, if you think that your IT being outsourced is going to somehow protect you from the bad guys. Unless they are a security service provider, I've got some news for you.
Hello everybody. Craig Peterson here. A welcome and glad you joined us here on news radio 98.5 And AM 560. I also want to remind everybody that you can find me online. You can listen to this as you are a hold of radio range, even just go ahead and. Ask your favorite platform, whether it's Google or Alexa to play, WGAN we'll give you some more or details a little bit later on in the show today, but let's start with our top story of the day today.
That has to do with managed IT providers. Now, a lot of businesses are trying to do the whole information technology thing themselves. You've probably heard different ads. In fact, there's one group that advertises frequently here on WGAN, and this is kind of a big deal when you get right down to it. Are you better off taking care of your IT yourself? Or are you better off having someone else do it?
Then when you really dig into it, the bigger question I think is, does it make sense to just use a regular IT company to outsource everything? Or should you again have specialties? No, it's like you've got a department inside your business that might do the finance stuff. You've got another department that obviously handles IT. You got sales, you got marketing. They're all fine-tuned. It is very difficult to find a third party that's fine-tuned, if you will, to cover everything that you might need from an IT side.
Well, we have been finding out some very interesting numbers lately. There's a great article I have up on my website from DarkReading. That's talking about this.
Basically, most of these MSPs or managed IT providers managed services providers. Have become a major gateway for the bad guys to break into small and medium businesses. I mean major gateway.
We've seen this ourselves just as recently as last week. We've been working with some managed service providers now to provide them with managed service security services because it's impossible for them to do the best job.
I just saw a mailing I got today from a company called SonicWall. They make firewalls, which are just fine for businesses that aren't heavily regulated, but they do not meet the requirements for more heavily regulated businesses. SonicWall's out there sending out these mailings saying, We've got it all. All you need is us.
That also reminds me of a mailing I got from Microsoft and I saved it. I just could not believe this. This must have been 20 years ago now maybe a little longer, actually, when I think of it, we're saying, Hey, listen, security is a real problem, but if you have Windows XP and Microsoft office, rest assured that your security is virtually guaranteed. I shook my head at that, decades ago in this sort of stuff still happening today. So many companies are out there lying and misrepresenting.
Now. I get it, you guys, this is not your forte. It's not the forte, cybersecurity of most managed services providers. Frankly, I think the vast majority of these companies that are trying to help you out with the IT, just don't realize what they should be doing and what's required of you, right?
You go to them because they are the experts. They tell you what you need, right. Isn't that the reason to write the checks. I've found the same thing being true inside a lot of companies where you have your own IT people and those IT people are trying to keep things straight.
And man, I've been working on this cybersecurity quiz thing. What are the main activators behind cybersecurity and where are you at? It's a self-evaluation thing that you can do as a business. Right now I've got the technical ones all done, and I'm working on one for the business owner C-level to understand where they're at and where they might need to go with it.
For years, cybersecurity has really been the area that big businesses, enterprises, what we used to call them here. And the enterprise was like a big business, a publicly-traded company. Nowadays we're adopting more of the European definition of enterprise, which is any business out there, but cybersecurity is been really the area that large businesses don't have to worry about.
What the bad guys have found that small and midsize businesses have also been the target of attacks, but historically those attacks have been the broad-based phishing attacks, or they're trying to run a worm around the internet. It's just a target of opportunity. From small business and medium business standpoint, the number of times they might be hacked or the damages caused were probably reasonable, you could get insurance for it.
But that has all changed now. The insurance companies and we've talked about a couple of these on the show before, are not paying out the policies. If you have a cyber insurance rider, for instance, as a regular end user, just a home user, many home policies now come with a cyber insurance rider. So if your identity is stolen, they will help you to recover the damage that was done, right. You can never really recover identity. You're not going to get it. Back. It's not gonna all of a sudden become safe, but they all help you with the damage. So anything that was bought in your name it'll, they'll back it out, any bad credit report backs them out. The same thing was available for the small, medium, and, even the large business markets where you pay a rider, and then if you do get attacked then okay, the insurance will pay for it.
When you look at the numbers, I think you might come to a different realization. Where right now about a year, a quarter of all businesses are hacked per year. There is some security event that occurs in about a quarter of all, all businesses. That's a lot. What was the fee for your premium as a small business? Was that fee just an add on, an extra 25 bucks a year, a quarter a month, whatever is, I, I know biggie. Well, what's happened is the insurance companies have realized that they can put requirements on you. That's one of the things we do. We have special scanning software that allows us to scan a network and look for standard insurance requirements. You know, the stuff the insurance companies usually want. No, we're not the only ones, I'm not the lone ranger out here.
There are other companies that have these tools. There are some free checklists you can find online. I would encourage you to use them. Nowadays, if your information is stolen, if you are hacked, they're going to go through that list and say, did you comply with this? Did you comply with that? Did you comply with the other thing? If not, they're going to fight you.
That's true for the mega-breaches like Equifax has been fighting their insurance company in the courts. We've seen everything all the way down to little companies that are fighting it in the courts. Then on top of it, not only is a cyber insurance stuff, a threat, and a problem. It goes to the next level. And the next level, when it comes to all of this is. Is your business going to survive?
You got hacked and you have to fight with the insurance company. If the regulators find out, if your business is regulated, which nowadays is pretty much every business out there, what is it 300 million? Oh, it, you won't get into that right now. All of the people here in the US plus the businesses and all of the hundreds of thousands of regulations anyways.
What's going to happen when the regulators find out you were hacked? That's when the real problems come up. The regulators are going to come in and there is a checklist, whether it's a NIST checklist, the CMMC, the HIPAA/HITECH, whatever it is, you are going to be held responsible.
So. What are the bad guys found? It's kind of like going back to the Willie Sutton misquote, right? Which is why did he Rob banks all that's where the money was. Turns out that isn't a legitimate quote, but you know, that's okay. He, he robbed the banks or bank robbers, Rob banks, because they keep cash there. They keep gold. They keep silver, back in the day. So they'd go in and Rob them.
Well, where are all of the keys to the kingdom when it comes to your computers? Well, they live in the IT department. Don't they, IT can get on, can give you access to stuff. They can take away access from staff, right? That's what it does. And they can be pissed off and leave your employ. If they leave your employment, what happens? Do you have automated systems that remove access for the IT people?
Cybercriminals have now figured out that these low-end small businesses that are out there calling themselves managed services providers, managed IT providers are a great way. If they break into one of those, we've seen major security holes for the tools almost all of these companies are using. If they break into one, those, they now have the keys to the kingdom for 50-100 companies out there. So be very, very, very careful.
Cybercriminals understand the average managed services provider cannot keep your data safe internally inside their own networks or in yours. So just like that Pandora's box is open.
Hey, you're listening to Craig Peterson. If you're going to hop in the car, the truck, and drive, hopefully, you've got Siri with you, maybe Google, maybe Alexa can listen to us there.
Just say, Hey, Alexa, play WGAN stick around. Cause we'll be right back.
You're listening to Craig Peterson.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed