Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Welcome! What is up with the Popularity of these Geofence Warrants -- Lazy Investigators!plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses geofence warrants and why they are so popular with law enforcement investigators. Has the court seen enough? Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can't Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don't forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Welcome back everybody. The fed had been out there using stingrays and other devices to watch where you're at. We're going to talk about that right now, and a new core ruling against the feds for some of the stuff they've been doing to spy.

    We're not just talking about spying on the bad guys. This isn't a FISA court thing. This is in fact, the feds taking the lazy way out. So think about you. If you were a police officer trying to investigate a crime, what's the easiest way for you to figure out who was in the area when a bank was robbed?

    Okay. I'm going to give you one second. What's the easiest way. it turns out that apparently the easiest way is to just send a letter to Google asking them for information about every phone within a 100-meter radius of where a suspected crime occurred.

    Now, isn't that an interesting thing, right? Isn't that an interesting way to do it?

    You might say, I've got an iPhone I don't have Google. So they're not going to be able to give that information to the fed. Do you have any Google apps on your phone that might be keeping track of your location? Things like, oh, I don't know. Google maps for instance.

    That could be a bit of a problem because federal courts in the Chicago area have now rejected government warrant applications three times. The government has applied for a warrant to force Google to produce a list of smartphones that were near a couple of places where the feds thought that crimes might have occurred, during the specified 45-minute intervals.

    Now, this recent ruling was handed down just last week and was recently made public and ARS Technica is talking about this. Now the numbers are frankly, striking here because these decisions really haven't significant impact. Google has reported. The growth in the law enforcement use of what are being called geo-fence searches.

    Are you familiar with geofencing? On your Android or your iPhone you can say, Hey, I'm on my to-do list here. I got a pickup toilet paper when I get near the grocery store because we all know there's no toilet paper in grocery stores. So when you drive by the grocery store, you can have a little, geofence set up on your phone that says, Hey, remember you got to get toilet paper. Then you can run to the grocery store, pick up your toilet paper, and be on your way.

    Geo-fencing when we're talking about these types of searches means a little bit different, but almost the same. That is Google gets or Apple gets a demand from the police, a warrant, that says, tell me about every phone that was within again, a hundred meters, 300 feet of this business of this area during this 45 minute period.

    Now, what we're seeing here is a 1500% increase in these types of warrants between 2017 and 2018. And then it jumped up again. Another 600%. percentages don't mean much unless you have the raw numbers. Let me give you the raw numbers. Google says that they received 180 geofence search requests a week.

    During 2019, that kinda adds up. At least I think it adds up. So let me see 180 a week. And let's just say there are 52 weeks in a year. Oh my gosh. That's almost 10,000 of these warrants that Google has to respond to every day. And if we say 180 a week and we divided by, Oh, I don't know. let's say the police work seven days a week.

    That means 25 warrants per day, almost 26 warrants per day. So that's a couple of full-time people just to respond to these. Of course, it also has to go over to the legal side and everything else. It gets to be a real problem. Google is a very popular target for these warns because almost everyone uses Google products in one way or another.

    Think of our cars, how many of our cars have Android in them? How many of them are using Google maps? How many of our cars have GPS on them? All of that is being tracked by Google. Yes, indeed. Android controls a majority of the smartphone market right now. As I mentioned earlier, even those of us who have I-phones might be using Gmail or Google maps.

    So this is going to be an ongoing problem. I think it needs to be solved at a bit of a higher level than just district courts in various States out there. now for years, the. Police have gone after the cell phone companies to ask where a phone was that the whole idea of a tower location. What will happen is, am I trying to triangulate you more frequently? However, all of the phone companies will have is just data that you were connected to this cell tower, which means you, it was probably the closest cell tower to you because that's the idea, right? You'll hop between the South towers, depending on which one is the strongest. This is a kind of a Dragnet approach. Something I do not approve of and many courts don't approve of just because it makes it easier for the police doesn't mean it's constitutional. In one case last year, Google was required to hand over information on almost 1500 users to federal investigators, working on a Wisconsin arson case.

    We've also seen. Cases where a guy was running his bicycle back and forth on this back street. Not like he was right in front of one house, but he got nailed because he was on that street at the wrong time. Although ultimately they figured out he had nothing to do with the crime, so they just turned his life upside down.

    So we'll see what happens. This Chicago case apparently is being, appealed, and if the appeal goes through, it could place new limits on these broad government data requests, which I think is ultimately a pretty good deal. By the way, what were they investigating? it turns out they're investigating a case where there were stolen pharmaceuticals, apparently sold on the black market and investigators believe that the bad guys stole the pharmaceuticals from this drug store or a clinic, and then traveled to another one to ship them to customers like a FedEx or ups stores. So to help them investigate, the suspect, the investigators asked Google for data about every smartphone that was near either this drug store or the medical clinic or FedEx or ups during a particular 45-minute window, one window, the first location, two windows on different days of the second. So the application was rejected. It was said to be too broad. The government narrowed its request too much narrower areas right around the buildings, but the courts rejected them all.

    The court said none of them complied with the Fourth Amendment's requirement that warrant particularly described the persons or things to be seized. Interesting. Very interesting. I know. What do you think about this? these all persons warrants are generally considered to be unconstitutional that's part of the reason we have the fourth amendment because the King was issuing these very vague big in the general warrant, the gave his military officers, governors and others, the ability to just go in and harass anybody they basically wanted to. So I tend to agree with the courts on this one. Sometimes, I disagree sometimes I agree, but then, in order to really justify this kind of a geo-fence search the government, according to this judge needs to show that everyone in the geofenced areas likely to be involved in the crime.

    So how does this work when we're talking about these domestic terrorists that are burning down, buildings, cars dragging people from cars, beating them. Are we going to see these types of cases, as well as the geofence? Ultimately we will see. But again, it's another reason.

    Not only do the bad guys have apps that are attracting you. And I talk about those a lot, but the good guys are too. And. They might just upturn your life for what turns out to be not particularly good reason and something that's probably against the fourth amendment.

    Alright. When we come back, we're going to talk about a business problem right now, and that has to do with it. Security person, now there's a huge shortage, but what's the cost. When you lose the security person, you're listening to Craig Peterson, WGAN.

    Stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! What is up with the Popularity of these Geofence Warrants -- Lazy Investigators!plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses geofence warrants and why they are so popular with law enforcement investigators.  Has the court seen enough? Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

     

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Welcome back everybody. The fed had been out there using stingrays and other devices to watch where you're at. We're going to talk about that right now, and a new core ruling against the feds for some of the stuff they've been doing to spy.

     We're not just talking about spying on the bad guys. This isn't a FISA court thing. This is in fact, the feds taking the lazy way out. So think about you. If you were a police officer trying to investigate a crime, what's the easiest way for you to figure out who was in the area when a bank was robbed?

    Okay. I'm going to give you one second. What's the easiest way. it turns out that apparently the easiest way is to just send a letter to Google asking them for information about every phone within a 100-meter radius of where a suspected crime occurred.

    Now, isn't that an interesting thing, right? Isn't that an interesting way to do it?

    You might say, I've got an iPhone I don't have Google. So they're not going to be able to give that information to the fed. Do you have any Google apps on your phone that might be keeping track of your location? Things like, oh, I don't know. Google maps for instance.

    That could be a bit of a problem because federal courts in the Chicago area have now rejected government warrant applications three times. The government has applied for a warrant to force Google to produce a list of smartphones that were near a couple of places where the feds thought that crimes might have occurred, during the specified 45-minute intervals.

    Now, this recent ruling was handed down just last week and was recently made public and ARS Technica is talking about this. Now the numbers are frankly, striking here because these decisions really haven't significant impact. Google has reported. The growth in the law enforcement use of what are being called geo-fence searches.

    Are you familiar with geofencing? On your Android or your iPhone you can say, Hey, I'm on my to-do list here. I got a pickup toilet paper when I get near the grocery store because we all know there's no toilet paper in grocery stores. So when you drive by the grocery store, you can have a little, geofence set up on your phone that says, Hey, remember you got to get toilet paper. Then you can run to the grocery store, pick up your toilet paper, and be on your way.

    Geo-fencing when we're talking about these types of searches means a little bit different, but almost the same. That is Google gets or Apple gets a demand from the police, a warrant, that says, tell me about every phone that was within again, a hundred meters, 300 feet of this business of this area during this 45 minute period.

    Now, what we're seeing here is a 1500% increase in these types of warrants between 2017 and 2018. And then it jumped up again. Another 600%. percentages don't mean much unless you have the raw numbers. Let me give you the raw numbers. Google says that they received 180 geofence search requests a week.

    During 2019, that kinda adds up. At least I think it adds up. So let me see 180 a week. And let's just say there are 52 weeks in a year. Oh my gosh. That's almost 10,000 of these warrants that Google has to respond to every day. And if we say 180 a week and we divided by, Oh, I don't know. let's say the police work seven days a week.

    That means 25 warrants per day, almost 26 warrants per day. So that's a couple of full-time people just to respond to these. Of course, it also has to go over to the legal side and everything else. It gets to be a real problem. Google is a very popular target for these warns because almost everyone uses Google products in one way or another.

    Think of our cars, how many of our cars have Android in them? How many of them are using Google maps? How many of our cars have GPS on them?  All of that is being tracked by Google. Yes, indeed. Android controls a majority of the smartphone market right now.  As I mentioned earlier, even those of us who have I-phones might be using Gmail or Google maps.

    So this is going to be an ongoing problem. I think it needs to be solved at a bit of a higher level than just district courts in various States out there. now for years, the. Police have gone after the cell phone companies to ask where a phone was that the whole idea of a tower location. What will happen is, am I trying to triangulate you more frequently? However, all of the phone companies will have is just data that you were connected to this cell tower, which means you, it was probably the closest cell tower to you because that's the idea, right? You'll hop between the South towers, depending on which one is the strongest. This is a kind of a Dragnet approach. Something I do not approve of and many courts don't approve of just because it makes it easier for the police doesn't mean it's constitutional. In one case last year, Google was required to hand over information on almost 1500 users to federal investigators, working on a Wisconsin arson case.

    We've also seen. Cases where a guy was running his bicycle back and forth on this back street. Not like he was right in front of one house, but he got nailed because he was on that street at the wrong time. Although ultimately they figured out he had nothing to do with the crime, so they just turned his life upside down.

    So we'll see what happens. This Chicago case apparently is being, appealed, and if the appeal goes through, it could place new limits on these broad government data requests, which I think is ultimately a pretty good deal. By the way, what were they investigating? it turns out they're investigating a case where there were stolen pharmaceuticals, apparently sold on the black market and investigators believe that the bad guys stole the pharmaceuticals from this drug store or a clinic, and then traveled to another one to ship them to customers like a FedEx or ups stores. So to help them investigate, the suspect, the investigators asked Google for data about every smartphone that was near either this drug store or the medical clinic or FedEx or ups during a particular 45-minute window, one window, the first location, two windows on different days of the second. So the application was rejected. It was said to be too broad. The government narrowed its request too much narrower areas right around the buildings, but the courts rejected them all.

    The court said none of them complied with the Fourth Amendment's requirement that warrant particularly described the persons or things to be seized. Interesting. Very interesting. I know. What do you think about this? these all persons warrants are generally considered to be unconstitutional that's part of the reason we have the fourth amendment because the King was issuing these very vague big in the general warrant, the gave his military officers, governors and others, the ability to just go in and harass anybody they basically wanted to. So I tend to agree with the courts on this one. Sometimes, I disagree sometimes I agree, but then, in order to really justify this kind of a geo-fence search the government, according to this judge needs to show that everyone in the geofenced areas likely to be involved in the crime.

    So how does this work when we're talking about these domestic terrorists that are burning down, buildings, cars dragging people from cars, beating them. Are we going to see these types of cases, as well as the geofence? Ultimately we will see. But again, it's another reason.

    Not only do the bad guys have apps that are attracting you. And I talk about those a lot, but the good guys are too. And. They might just upturn your life for what turns out to be not particularly good reason and something that's probably against the fourth amendment.

    Alright. When we come back, we're going to talk about a business problem right now, and that has to do with it. Security person, now there's a huge shortage, but what's the cost. When you lose the security person, you're listening to Craig Peterson, WGAN.

    Stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! What is up with the Popularity of these Geofence Warrants -- Lazy Investigators!plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses geofence warrants and why they are so popular with law enforcement investigators.  Has the court seen enough? Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

     

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Welcome back everybody. The fed had been out there using stingrays and other devices to watch where you're at. We're going to talk about that right now, and a new core ruling against the feds for some of the stuff they've been doing to spy.

     We're not just talking about spying on the bad guys. This isn't a FISA court thing. This is in fact, the feds taking the lazy way out. So think about you. If you were a police officer trying to investigate a crime, what's the easiest way for you to figure out who was in the area when a bank was robbed?

    Okay. I'm going to give you one second. What's the easiest way. it turns out that apparently the easiest way is to just send a letter to Google asking them for information about every phone within a 100-meter radius of where a suspected crime occurred.

    Now, isn't that an interesting thing, right? Isn't that an interesting way to do it?

    You might say, I've got an iPhone I don't have Google. So they're not going to be able to give that information to the fed. Do you have any Google apps on your phone that might be keeping track of your location? Things like, oh, I don't know. Google maps for instance.

    That could be a bit of a problem because federal courts in the Chicago area have now rejected government warrant applications three times. The government has applied for a warrant to force Google to produce a list of smartphones that were near a couple of places where the feds thought that crimes might have occurred, during the specified 45-minute intervals.

    Now, this recent ruling was handed down just last week and was recently made public and ARS Technica is talking about this. Now the numbers are frankly, striking here because these decisions really haven't significant impact. Google has reported. The growth in the law enforcement use of what are being called geo-fence searches.

    Are you familiar with geofencing? On your Android or your iPhone you can say, Hey, I'm on my to-do list here. I got a pickup toilet paper when I get near the grocery store because we all know there's no toilet paper in grocery stores. So when you drive by the grocery store, you can have a little, geofence set up on your phone that says, Hey, remember you got to get toilet paper. Then you can run to the grocery store, pick up your toilet paper, and be on your way.

    Geo-fencing when we're talking about these types of searches means a little bit different, but almost the same. That is Google gets or Apple gets a demand from the police, a warrant, that says, tell me about every phone that was within again, a hundred meters, 300 feet of this business of this area during this 45 minute period.

    Now, what we're seeing here is a 1500% increase in these types of warrants between 2017 and 2018. And then it jumped up again. Another 600%. percentages don't mean much unless you have the raw numbers. Let me give you the raw numbers. Google says that they received 180 geofence search requests a week.

    During 2019, that kinda adds up. At least I think it adds up. So let me see 180 a week. And let's just say there are 52 weeks in a year. Oh my gosh. That's almost 10,000 of these warrants that Google has to respond to every day. And if we say 180 a week and we divided by, Oh, I don't know. let's say the police work seven days a week.

    That means 25 warrants per day, almost 26 warrants per day. So that's a couple of full-time people just to respond to these. Of course, it also has to go over to the legal side and everything else. It gets to be a real problem. Google is a very popular target for these warns because almost everyone uses Google products in one way or another.

    Think of our cars, how many of our cars have Android in them? How many of them are using Google maps? How many of our cars have GPS on them?  All of that is being tracked by Google. Yes, indeed. Android controls a majority of the smartphone market right now.  As I mentioned earlier, even those of us who have I-phones might be using Gmail or Google maps.

    So this is going to be an ongoing problem. I think it needs to be solved at a bit of a higher level than just district courts in various States out there. now for years, the. Police have gone after the cell phone companies to ask where a phone was that the whole idea of a tower location. What will happen is, am I trying to triangulate you more frequently? However, all of the phone companies will have is just data that you were connected to this cell tower, which means you, it was probably the closest cell tower to you because that's the idea, right? You'll hop between the South towers, depending on which one is the strongest. This is a kind of a Dragnet approach. Something I do not approve of and many courts don't approve of just because it makes it easier for the police doesn't mean it's constitutional. In one case last year, Google was required to hand over information on almost 1500 users to federal investigators, working on a Wisconsin arson case.

    We've also seen. Cases where a guy was running his bicycle back and forth on this back street. Not like he was right in front of one house, but he got nailed because he was on that street at the wrong time. Although ultimately they figured out he had nothing to do with the crime, so they just turned his life upside down.

    So we'll see what happens. This Chicago case apparently is being, appealed, and if the appeal goes through, it could place new limits on these broad government data requests, which I think is ultimately a pretty good deal. By the way, what were they investigating? it turns out they're investigating a case where there were stolen pharmaceuticals, apparently sold on the black market and investigators believe that the bad guys stole the pharmaceuticals from this drug store or a clinic, and then traveled to another one to ship them to customers like a FedEx or ups stores. So to help them investigate, the suspect, the investigators asked Google for data about every smartphone that was near either this drug store or the medical clinic or FedEx or ups during a particular 45-minute window, one window, the first location, two windows on different days of the second. So the application was rejected. It was said to be too broad. The government narrowed its request too much narrower areas right around the buildings, but the courts rejected them all.

    The court said none of them complied with the Fourth Amendment's requirement that warrant particularly described the persons or things to be seized. Interesting. Very interesting. I know. What do you think about this? these all persons warrants are generally considered to be unconstitutional that's part of the reason we have the fourth amendment because the King was issuing these very vague big in the general warrant, the gave his military officers, governors and others, the ability to just go in and harass anybody they basically wanted to. So I tend to agree with the courts on this one. Sometimes, I disagree sometimes I agree, but then, in order to really justify this kind of a geo-fence search the government, according to this judge needs to show that everyone in the geofenced areas likely to be involved in the crime.

    So how does this work when we're talking about these domestic terrorists that are burning down, buildings, cars dragging people from cars, beating them. Are we going to see these types of cases, as well as the geofence? Ultimately we will see. But again, it's another reason.

    Not only do the bad guys have apps that are attracting you. And I talk about those a lot, but the good guys are too. And. They might just upturn your life for what turns out to be not particularly good reason and something that's probably against the fourth amendment.

    Alright. When we come back, we're going to talk about a business problem right now, and that has to do with it. Security person, now there's a huge shortage, but what's the cost. When you lose the security person, you're listening to Craig Peterson, WGAN.

    Stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Losing your Cybersecurity Talent Could Cost You Your Business plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why you need to try to keep your Cybersecurity Talent and what it can cost you if you lose them.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can't Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don't forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Let's see there's Sue. There is Guy. There are Mary and a couple of other people. I can't remember everyone's names right now, but they are all listeners to the show and they have all changed careers. Here's what's going on.

    Hey, if you enjoy my show here on WGAN and [email protected], you might want to think about a career in cybersecurity. Now, there are a lot of people who have already started that whole career path, who can start pretty simply. And it's really one of these careers as Guy had told me that you feel like an imposter, right? Imposter syndrome. Runs rampant, particularly when you're first starting.

    I've been doing cybersecurity for many decades now. And I can tell you, I still feel like an imposter at times, so it's pretty normal, but there are a lot of jobs out there in the cybersecurity career path that is open right now. Everything from just starting out, just barely, Hey, I am a brand new guy, gal, and I want to do cybersecurity all the way on, up through CISOs, and all of that sort of stuff.

    So you might know already, my company is a managed security services provider. That's what we specialize in. We're not a company that goes out and tweaks your computer so that, a hard drive that's failing, just doesn't fail anymore. Although we do that for some of our customers.

    We emphasize and focus on cybersecurity. We're looking at some of these stats we're seeing anywhere from a half-familiar and open jobs in 2020 in cybersecurity, all the way on, up through one and a half million open jobs. And I've seen estimates as high as two and a half to 3 million people needed brand new people never been in cybersecurity before. Two and a half to 3 million new people here in the US that will be needed in cybersecurity by 2025. So a half a million right now, that ain't bad is it.

    Now I want to warn everybody that is in business and is looking for a cybersecurity person that you do need to have at least one person who is extremely well versed in cybersecurity and that means they've got to have a minimum of five years on the job, cybersecurity experience. The future of your enterprise is entirely dependent on them believe it or not. There are so many businesses that are being hacked one way or the other, and you cannot skimp on this. Can't skimp on it at all.

    I'm looking at it web page that just bothers me. This is a story here from the Freelance Star in Fredericksburg, Maryland, and this is September 7th, 2020. Stafford based cyber bytes foundation to offer a one-week cybersecurity certification course. Yeah. So if you live there in Maryland, back there by Joe Biden, wherever he lives now, and you want to be a cybersecurity professional, all you have to do is take this one-week certificate course and you too can be a cybersecurity expert, right?

    They're saying in this article that if considering a career in cybersecurity, you will be one week away from certification will prepare you for an entry-level position in the field. I've thought for a long time, I should be teaching some courses to people who want to really understand cybersecurity.

    Cause I can bet you anything that the poor people that are teaching this course are not true experts. I can also guarantee you that after having a whole week of experience in the classroom, you're not fit to do much in the cybersecurity business. You can probably turn on a computer and follow some basic instructions. That's it?

    I'm thinking about these people that are listeners to the show that have gone into cybersecurity. Most of them have done about six months didn't give or take in cybersecurity courses and they come out and really in six months of just intensive, all you're doing a cybersecurity training.

    You realize that you don't know enough. Okay. But at least they realize that after one week. I'm not sure people realize that they really don't know what they're doing. This is starting out here in two initial courses is gonna prepare you for the CompTIA security plus exam that tells you just how extensive that exam isn't.

    Of course, there's a cost just under a thousand dollars. They're approved and certified by the state council of higher education.

    It's just, wow. Wow, incredible.

    So I brought all of that up because. This article that I have up on my website and was in this week's newsletter is talking about the hidden costs of losing security talent.

    We've got to be careful as business people because we are losing talent. We're not respecting them. We're not paying them enough or we're giving them too much to do. Too many businesses look at cybersecurity as a cost center. They don't realize that it's not just a cost center. It's critical. It's essential for their business.

    And if they market correctly, frankly, It is a big plus on the marketing and sales side. How many of your competitors we're actually doing what they should be doing? So the cybersecurity talent is going to cost you money. You've got to provide them with the training you, my guys, my cybersecurity people spend about a third of their time, a third one-third of their time, not being productive, but actually attending courses, doing red team blue team exercises.

    Okay, this is not something you can really skimp on. In fact, you cannot do it yourself. I have seen the hard numbers. You cannot do cybersecurity as a business with less than about 500 employees. Can't do it adequately. You just can't. You can't get the right people. They don't have the right training. They can't afford to do what they need to do. Okay.

    So keep that in mind. Now you can have a managed security services company come in. Be careful, make sure they don't just have the one week certificate or the CompTIA security plus make sure they know what they're doing.

    But replacing an experienced security analyst where they're looking for an annual salary of a hundred thousand dollars, that's just salary plus load on top of that. And remember, 30% of the time, a third of the time they are going to be in class if they're doing things right. When they leave that company, it typically takes eight months to replace them and almost four months to train a replacement. So that's about a year. A full year of lost productivity. It's always possible that your company could lose a second person during that time as well. So be very careful, a bad hire. According to the US department of labor is going to cost at least 30% of the employees.

    First-year earnings for a security analyst, frankly, we're talking about costing you 50 to a hundred thousand. If you don't get hacked, in the interim. At which point you could lose the whole business. It's very big. It's a very big problem. So keep in mind everybody, when you're looking at this, first of all, I think it's a great career path.

    If you like a challenge. If you like things that are different. If you are not really big into just messing around but you really want to learn things and do things. Cybersecurity, I think is a great way to go, but it's continual learning.

    You've got to keep on top of this. It is more than a full-time job.

    All right. When we get back, we are going to hit a couple more articles from my newsletter week and, that's kinda it. I think this week's show.

    So you'll find me online, of course, Craig peterson.com. You're listening to me on WGAN. We'll be back on Wednesday morning. I am every Wednesday during drive time with Matt Gagnon.

    We have little fun with this, and we're going to be talking about cybersecurity on your back to school lists and tips for triaging risks. If your credentials are exposed, I'm going to give you a website that you have to go to see if your data has been stolen and leaked on the dark web. I'll give you that URL and a whole lot more when we get back.

    So stick around, we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Losing your Cybersecurity Talent Could Cost You Your Business plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why you need to try to keep your Cybersecurity Talent and what it can cost you if you lose them.  

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Let's see there's Sue. There is Guy. There are Mary and a couple of other people. I can't remember everyone's names right now, but they are all listeners to the show and they have all changed careers. Here's what's going on.

    Hey, if you enjoy my show here on WGAN and [email protected], you might want to think about a career in cybersecurity. Now, there are a lot of people who have already started that whole career path, who can start pretty simply. And it's really one of these careers as Guy had told me that you feel like an imposter, right? Imposter syndrome. Runs rampant, particularly when you're first starting. 

    I've been doing cybersecurity for many decades now. And I can tell you, I still feel like an imposter at times, so it's pretty normal, but there are a lot of jobs out there in the cybersecurity career path that is open right now. Everything from just starting out, just barely, Hey, I am a brand new guy, gal, and I want to do cybersecurity all the way on, up through CISOs, and all of that sort of stuff.

    So you might know already, my company is a managed security services provider. That's what we specialize in. We're not a company that goes out and tweaks your computer so that, a hard drive that's failing, just doesn't fail anymore. Although we do that for some of our customers.

    We emphasize and focus on cybersecurity. We're looking at some of these stats we're seeing anywhere from a half-familiar and open jobs in 2020 in cybersecurity, all the way on, up through one and a half million open jobs. And I've seen estimates as high as two and a half to 3 million people needed brand new people never been in cybersecurity before. Two and a half to 3 million new people here in the US that will be needed in cybersecurity by 2025. So a half a million right now, that ain't bad is it.

    Now I want to warn everybody that is in business and is looking for a cybersecurity person that you do need to have at least one person who is extremely well versed in cybersecurity and that means they've got to have a minimum of five years on the job, cybersecurity experience. The future of your enterprise is entirely dependent on them believe it or not. There are so many businesses that are being hacked one way or the other, and you cannot skimp on this. Can't skimp on it at all.

    I'm looking at it web page that just bothers me. This is a story here from the Freelance Star in Fredericksburg, Maryland, and this is September 7th, 2020. Stafford based cyber bytes foundation to offer a one-week cybersecurity certification course. Yeah. So if you live there in Maryland, back there by Joe Biden, wherever he lives now, and you want to be a cybersecurity professional, all you have to do is take this one-week certificate course and you too can be a cybersecurity expert, right?

    They're saying in this article that if considering a career in cybersecurity, you will be one week away from certification will prepare you for an entry-level position in the field. I've thought for a long time, I should be teaching some courses to people who want to really understand cybersecurity.

    Cause I can bet you anything that the poor people that are teaching this course are not true experts. I can also guarantee you that after having a whole week of experience in the classroom, you're not fit to do much in the cybersecurity business. You can probably turn on a computer and follow some basic instructions. That's it?

    I'm thinking about these people that are listeners to the show that have gone into cybersecurity. Most of them have done about six months didn't give or take in cybersecurity courses and they come out and really in six months of just intensive, all you're doing a cybersecurity training.

    You realize that you don't know enough. Okay. But at least they realize that after one week. I'm not sure people realize that they really don't know what they're doing.  This is starting out here in two initial courses is gonna prepare you for the CompTIA security plus exam that tells you just how extensive that exam isn't.

    Of course, there's a cost just under a thousand dollars. They're approved and certified by the state council of higher education.

    It's just, wow. Wow, incredible.

    So I brought all of that up because. This article that I have up on my website and was in this week's newsletter is talking about the hidden costs of losing security talent.

    We've got to be careful as business people because we are losing talent. We're not respecting them. We're not paying them enough or we're giving them too much to do. Too many businesses look at cybersecurity as a cost center. They don't realize that it's not just a cost center. It's critical. It's essential for their business.

    And if they market correctly, frankly, It is a big plus on the marketing and sales side. How many of your competitors we're actually doing what they should be doing? So the cybersecurity talent is going to cost you money. You've got to provide them with the training you, my guys, my cybersecurity people spend about a third of their time, a third one-third of their time, not being productive, but actually attending courses, doing red team blue team exercises.

    Okay, this is not something you can really skimp on. In fact, you cannot do it yourself. I have seen the hard numbers. You cannot do cybersecurity as a business with less than about 500 employees. Can't do it adequately. You just can't. You can't get the right people. They don't have the right training. They can't afford to do what they need to do. Okay.

    So keep that in mind. Now you can have a managed security services company come in. Be careful, make sure they don't just have the one week certificate or the CompTIA security plus make sure they know what they're doing.

    But replacing an experienced security analyst where they're looking for an annual salary of a hundred thousand dollars, that's just salary plus load on top of that. And remember, 30% of the time, a third of the time they are going to be in class if they're doing things right. When they leave that company, it typically takes eight months to replace them and almost four months to train a replacement. So that's about a year. A full year of lost productivity. It's always possible that your company could lose a second person during that time as well. So be very careful, a bad hire. According to the US department of labor is going to cost at least 30% of the employees.

    First-year earnings for a security analyst, frankly, we're talking about costing you 50 to a hundred thousand. If you don't get hacked, in the interim. At which point you could lose the whole business. It's very big. It's a very big problem. So keep in mind everybody, when you're looking at this, first of all, I think it's a great career path.

    If you like a challenge. If you like things that are different. If you are not really big into just messing around but you really want to learn things and do things. Cybersecurity, I think is a great way to go, but it's continual learning.

    You've got to keep on top of this. It is more than a full-time job.

    All right. When we get back, we are going to hit a couple more articles from my newsletter week and, that's kinda it. I think this week's show.

    So you'll find me online, of course, Craig peterson.com. You're listening to me on WGAN. We'll be back on Wednesday morning. I am every Wednesday during drive time with Matt Gagnon.

    We have little fun with this, and we're going to be talking about cybersecurity on your back to school lists and tips for triaging risks. If your credentials are exposed, I'm going to give you a website that you have to go to see if your data has been stolen and leaked on the dark web. I'll give you that URL and a whole lot more when we get back.

    So stick around, we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Losing your Cybersecurity Talent Could Cost You Your Business plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why you need to try to keep your Cybersecurity Talent and what it can cost you if you lose them.  

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Let's see there's Sue. There is Guy. There are Mary and a couple of other people. I can't remember everyone's names right now, but they are all listeners to the show and they have all changed careers. Here's what's going on.

    Hey, if you enjoy my show here on WGAN and [email protected], you might want to think about a career in cybersecurity. Now, there are a lot of people who have already started that whole career path, who can start pretty simply. And it's really one of these careers as Guy had told me that you feel like an imposter, right? Imposter syndrome. Runs rampant, particularly when you're first starting. 

    I've been doing cybersecurity for many decades now. And I can tell you, I still feel like an imposter at times, so it's pretty normal, but there are a lot of jobs out there in the cybersecurity career path that is open right now. Everything from just starting out, just barely, Hey, I am a brand new guy, gal, and I want to do cybersecurity all the way on, up through CISOs, and all of that sort of stuff.

    So you might know already, my company is a managed security services provider. That's what we specialize in. We're not a company that goes out and tweaks your computer so that, a hard drive that's failing, just doesn't fail anymore. Although we do that for some of our customers.

    We emphasize and focus on cybersecurity. We're looking at some of these stats we're seeing anywhere from a half-familiar and open jobs in 2020 in cybersecurity, all the way on, up through one and a half million open jobs. And I've seen estimates as high as two and a half to 3 million people needed brand new people never been in cybersecurity before. Two and a half to 3 million new people here in the US that will be needed in cybersecurity by 2025. So a half a million right now, that ain't bad is it.

    Now I want to warn everybody that is in business and is looking for a cybersecurity person that you do need to have at least one person who is extremely well versed in cybersecurity and that means they've got to have a minimum of five years on the job, cybersecurity experience. The future of your enterprise is entirely dependent on them believe it or not. There are so many businesses that are being hacked one way or the other, and you cannot skimp on this. Can't skimp on it at all.

    I'm looking at it web page that just bothers me. This is a story here from the Freelance Star in Fredericksburg, Maryland, and this is September 7th, 2020. Stafford based cyber bytes foundation to offer a one-week cybersecurity certification course. Yeah. So if you live there in Maryland, back there by Joe Biden, wherever he lives now, and you want to be a cybersecurity professional, all you have to do is take this one-week certificate course and you too can be a cybersecurity expert, right?

    They're saying in this article that if considering a career in cybersecurity, you will be one week away from certification will prepare you for an entry-level position in the field. I've thought for a long time, I should be teaching some courses to people who want to really understand cybersecurity.

    Cause I can bet you anything that the poor people that are teaching this course are not true experts. I can also guarantee you that after having a whole week of experience in the classroom, you're not fit to do much in the cybersecurity business. You can probably turn on a computer and follow some basic instructions. That's it?

    I'm thinking about these people that are listeners to the show that have gone into cybersecurity. Most of them have done about six months didn't give or take in cybersecurity courses and they come out and really in six months of just intensive, all you're doing a cybersecurity training.

    You realize that you don't know enough. Okay. But at least they realize that after one week. I'm not sure people realize that they really don't know what they're doing.  This is starting out here in two initial courses is gonna prepare you for the CompTIA security plus exam that tells you just how extensive that exam isn't.

    Of course, there's a cost just under a thousand dollars. They're approved and certified by the state council of higher education.

    It's just, wow. Wow, incredible.

    So I brought all of that up because. This article that I have up on my website and was in this week's newsletter is talking about the hidden costs of losing security talent.

    We've got to be careful as business people because we are losing talent. We're not respecting them. We're not paying them enough or we're giving them too much to do. Too many businesses look at cybersecurity as a cost center. They don't realize that it's not just a cost center. It's critical. It's essential for their business.

    And if they market correctly, frankly, It is a big plus on the marketing and sales side. How many of your competitors we're actually doing what they should be doing? So the cybersecurity talent is going to cost you money. You've got to provide them with the training you, my guys, my cybersecurity people spend about a third of their time, a third one-third of their time, not being productive, but actually attending courses, doing red team blue team exercises.

    Okay, this is not something you can really skimp on. In fact, you cannot do it yourself. I have seen the hard numbers. You cannot do cybersecurity as a business with less than about 500 employees. Can't do it adequately. You just can't. You can't get the right people. They don't have the right training. They can't afford to do what they need to do. Okay.

    So keep that in mind. Now you can have a managed security services company come in. Be careful, make sure they don't just have the one week certificate or the CompTIA security plus make sure they know what they're doing.

    But replacing an experienced security analyst where they're looking for an annual salary of a hundred thousand dollars, that's just salary plus load on top of that. And remember, 30% of the time, a third of the time they are going to be in class if they're doing things right. When they leave that company, it typically takes eight months to replace them and almost four months to train a replacement. So that's about a year. A full year of lost productivity. It's always possible that your company could lose a second person during that time as well. So be very careful, a bad hire. According to the US department of labor is going to cost at least 30% of the employees.

    First-year earnings for a security analyst, frankly, we're talking about costing you 50 to a hundred thousand. If you don't get hacked, in the interim. At which point you could lose the whole business. It's very big. It's a very big problem. So keep in mind everybody, when you're looking at this, first of all, I think it's a great career path.

    If you like a challenge. If you like things that are different. If you are not really big into just messing around but you really want to learn things and do things. Cybersecurity, I think is a great way to go, but it's continual learning.

    You've got to keep on top of this. It is more than a full-time job.

    All right. When we get back, we are going to hit a couple more articles from my newsletter week and, that's kinda it. I think this week's show.

    So you'll find me online, of course, Craig peterson.com. You're listening to me on WGAN. We'll be back on Wednesday morning. I am every Wednesday during drive time with Matt Gagnon.

    We have little fun with this, and we're going to be talking about cybersecurity on your back to school lists and tips for triaging risks. If your credentials are exposed, I'm going to give you a website that you have to go to see if your data has been stolen and leaked on the dark web. I'll give you that URL and a whole lot more when we get back.

    So stick around, we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Put Cybersecurity on Your Back to School List plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why Cybersecurity is important and a must-not-forget item for your Back to School preparations. Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can't Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don't forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, it's back to school time. We're going to talk about cybersecurity on the back to school list for parents, for children, and for school administrators. And then what do you do if your credentials have been exposed online?

    Hey everybody, Craig Peterson here. WGAN and online, of course, Craig peterson.com. You will find all kinds of great information there. We've got a new website, we've got a whole bunch of stuff coming up here. So keep an eye out for that. I think you're going to really like it. So let's get into cybersecurity.

    Now we're going back to school. Our kids are back at school. We're probably working from home, right now that's a majority of people in the United States that aren't in, manufacturing jobs or hands-on jobs. That is a very big deal and it means some potentially bad things as well. So what are those bad things potentially that I'm talking about?

    If we have computers in our homes and we have kids on those computers and those kids are going. Who knows where online, including to the school and a parent is at home. And that computer's on the same day network is a kid's computer. You're in trouble. I've talked many times before about how these hacks and hackers bread, when it comes to a company, how they spread in your home, and what they do is.

    Kind of think of it like the military, they get a beachhead. So they attack and they have now a footing inside the network and then they start spreading laterally. So if your kid's computer does not have the advanced malware protection on it, that it needs, if it's not configured properly, if that kid's installing software on it and that software gets out or is hacked or is a hack, to begin with.

    That computer can now be used to spread malware onto your computer. So whether you using a computer from the office at home, or maybe you are using your home computer. At home, the bad guys are now in your network and now start to spread within your network. Now think of that, multiplied out. Even further, kids are bringing computers into school.

    If you go into school one or two days a week. You probably never brought a computer into school before because the kids who were there five days a week. But now they're there one or two days a week and they bring the computer in so they can show the homework so they can get some assignments. Now things are spreading.

    Do you think that the Wuhan virus spreads like crazy? what do you think happens when a child or a teacher brings an infected computer into a school while it's going to spread like wildfire? And what do you think happens when you have an infected computer on your network at home? it's going to try and spread like wildfire and it probably can, if you're not doing all of the right things now, as I said in the last segment, I should probably do some more courses on this, but that's part of what we're aiming at here to really help you guys out.

    Yeah, that gets to be a problem. Doesn't it? It's spreading. So if it spreads onto the computer you're using from work, and let's say that you've made the mistake of using a VPN into the office and that's not properly firewalled at the office or on your computer. That mistake that VPN mistake could cost you dearly because now you are spreading that malware or you're allowing the hacker access by piggybacking on your computer, into the business.

    Now, I know that might sound complicated, but it is very easy to do. And the bad you guys have tools that they can buy for as little as 10 to $20 on the black market, it allowed them to do everything I just described very easily. So if you are a school administrator, You need cybersecurity. It drives me crazy.

    I was on a zoom call earlier in the week and the only thing they use is zoom. I had to explain to them, Hey, I have clients that are. DOD subcontractors. They sell stuff to military installations. They sell stuff that used by DOD contractors. Therefore, I can not use zoom because Zoom is not secure. The same thing's true when we're talking about using zoom in schools and in regular businesses. We cannot use it. Schools have seen an increase in these debilitating ransomware attacks, even with the FBI alert this summer about it going on. I remember the first time I was speaking at an insurance conference and I was up there.

    I was their keynote speaker and talking about the problems that we were seeing in business and in schools. With these ransomware attacks. And afterward, one of the attendees came up and told me about his entire school district had been hit with ransomware. What do you think's going to happen when somebody brings a laptop into school, or somebody brings that laptop from home into work or they're using VPNs. VPNs are providing a network, a path for that ransomware to spread and it spread to wherever it can. It'll spread onto your file servers, spreads high and low across everything.

    So be very careful. Okay. major problems with the remote desktop protocol. RDP from Microsoft, that I know a lot of you guys are using to connect to work, make sure it's patched up.

    Slap yourself on the back of the hand for using RDP, especially if it's exposed to the internet, the same thing with a VPN. So we're going to do training on this. I'm going to help you guys understand it. I don't want you to feel bad about this. Okay. Cause you just didn't know.

    The vendors are lying to you. Okay. you're using this stuff that you shouldn't be using because they're telling you should be using it. I was flabbergasted this week. I got an email from a security vendor that sells security hardware and software, and they said, the only thing you need is our one product. Which is not even close to being true.

    What do you do right? I can tell you what I do. I let you guys know about it. Okay. So we're going to be doing a lot of training on that starting next week. So I'll make sure you are on my newsletter list. Newsletter members are the ones that are going to be getting this information, and it's going to be short.

    You can read it and just a few minutes and it's going to be educational. Okay. Important stuff now. I'm going to talk about exposed credentials. What do you do if your username, your email, address your password, maybe some personally identifiable information? Is found out there on the internet. What do you do?

    We've got over 15 billion exposed credentials available online, for free? In most cases, the bank has don't have to pay for them. Did you little shadows conduct a study this year? And they found that nearly two-thirds of the credentials available on the dark and by the way, the open-source or the clear web markets duplicates and 80%, of them are in clear text format.

    Many of these are employee credentials that pose a significant risk to organizations because they are in the hands of cybercriminals. So the security team needs to assess all of the things, exposed employee credentials to help make sure that everything's taken care of.

    So what should you do? first of all, I want you to go to a website. I should just put this Craig Peterson so you can find it easily, but go to a website called have I been pwned? You've probably heard me say this before, but it's worth checking again. Check it frequently. Now have I been pwned dispelled, P W N E D. Have I been PW, D d.com. And you enter your email address and it'll tell you what it finds.

    So I used my Craig and mainstream.net email that I've had for 30 years now. And I, I know it's been exposed and you already know, I use different passwords on every website. In fact, I tend to use. Different email addresses and there are some tricks to that. And I'll do some training on that for you guys too.

    What can you do? How can you do it? But, there are some tricks so that you can really, I have one mailbox, but to have what looked to be millions, if you wanted them of different email addresses, which is very good. Have I been pwned has seen my mainstream.net email. It has been found on 12 breached webs sites and one paste.

    A paste by the way is a site where they just put all of this stuff together and upload it as one big file. Basically think of it a big zip file place. And so it lists through all of these. And I went through this a couple of weeks ago here on the air, but have I been poned.com? That's where I want you guys to go.

    Okay. So not all exposed usernames and passwords, present a threat. You have to look at them and figure out, okay, am I using that username? But it says on, have I been pwned as having in stolen? Am I using that anywhere else? Am I using that password anywhere else? Make sure that you have a password manager.

    I like one password. That's what we use. We also use something called Thycotic, but I also am really pretty happy now with the latest versions of LastPass. So look up LastPass as well. So use a password manager, always generate new passwords. let's see the same stolen leaked employee credentials. Keep on surfacing online.

    Have I been pwned is going to help you with some of that stuff. You got to get rid of all of that weed out. All of those duplicates, make sure the credentials are genuine and then go to those websites. Go ahead and change them. And use one password use last pass. It's very important to do all of that stuff.

    And then on an ongoing basis, make sure you monitor for stolen or elite credentials. So that means if you can go ahead and on, have I been pwned again, PWNED dot com on, notify me, put in your email address, it's going to send you a confirmation email. Once you've confirmed. It'll email you, anytime it find your email on any new hacks out on the dark web.

    All right, everybody, have a great weekend. Make sure that you are on my list. Cause we're starting this up this week, little kind of micro training, and we're going to do other pieces of training as well, but there's only one way to find out about it and that's to be on my newsletter list. Craig peterson.com/subscribe.

    Believe me. This is not going to harass you. This is going to help you learn even more. All right. Learn. And I always give you things that you can do just like to have I been pwned.

    So have a great week. I will be back Wednesday, with Matt, at seven 30 in the morning.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! Put Cybersecurity on Your Back to School List plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why Cybersecurity is important and a must-not-forget item for your Back to School preparations. Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

     

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, it's back to school time. We're going to talk about cybersecurity on the back to school list for parents, for children, and for school administrators. And then what do you do if your credentials have been exposed online?

    Hey everybody, Craig Peterson here. WGAN and online, of course, Craig peterson.com. You will find all kinds of great information there. We've got a new website, we've got a whole bunch of stuff coming up here. So keep an eye out for that. I think you're going to really like it. So let's get into cybersecurity.

    Now we're going back to school. Our kids are back at school. We're probably working from home, right now that's a majority of people in the United States that aren't in, manufacturing jobs or hands-on jobs. That is a very big deal and it means some potentially bad things as well. So what are those bad things potentially that I'm talking about?

    If we have computers in our homes and we have kids on those computers and those kids are going. Who knows where online, including to the school and a parent is at home. And that computer's on the same day network is a kid's computer. You're in trouble. I've talked many times before about how these hacks and hackers bread, when it comes to a company, how they spread in your home, and what they do is.

    Kind of think of it like the military, they get a beachhead. So they attack and they have now a footing inside the network and then they start spreading laterally. So if your kid's computer does not have the advanced malware protection on it, that it needs, if it's not configured properly, if that kid's installing software on it and that software gets out or is hacked or is a hack, to begin with.

    That computer can now be used to spread malware onto your computer. So whether you using a computer from the office at home, or maybe you are using your home computer. At home, the bad guys are now in your network and now start to spread within your network. Now think of that, multiplied out. Even further, kids are bringing computers into school.

    If you go into school one or two days a week. You probably never brought a computer into school before because the kids who were there five days a week. But now they're there one or two days a week and they bring the computer in so they can show the homework so they can get some assignments. Now things are spreading.

    Do you think that the Wuhan virus spreads like crazy? what do you think happens when a child or a teacher brings an infected computer into a school while it's going to spread like wildfire? And what do you think happens when you have an infected computer on your network at home? it's going to try and spread like wildfire and it probably can, if you're not doing all of the right things now, as I said in the last segment, I should probably do some more courses on this, but that's part of what we're aiming at here to really help you guys out.

    Yeah, that gets to be a problem. Doesn't it? It's spreading. So if it spreads onto the computer you're using from work, and let's say that you've made the mistake of using a VPN into the office and that's not properly firewalled at the office or on your computer. That mistake that VPN mistake could cost you dearly because now you are spreading that malware or you're allowing the hacker access by piggybacking on your computer, into the business.

    Now, I know that might sound complicated, but it is very easy to do. And the bad you guys have tools that they can buy for as little as 10 to $20 on the black market, it allowed them to do everything I just described very easily. So if you are a school administrator, You need cybersecurity. It drives me crazy.

    I was on a zoom call earlier in the week and the only thing they use is zoom. I had to explain to them, Hey, I have clients that are. DOD subcontractors. They sell stuff to military installations. They sell stuff that used by DOD contractors. Therefore, I can not use zoom because Zoom is not secure. The same thing's true when we're talking about using zoom in schools and in regular businesses. We cannot use it. Schools have seen an increase in these debilitating ransomware attacks, even with the FBI alert this summer about it going on. I remember the first time I was speaking at an insurance conference and I was up there.

    I was their keynote speaker and talking about the problems that we were seeing in business and in schools. With these ransomware attacks. And afterward, one of the attendees came up and told me about his entire school district had been hit with ransomware. What do you think's going to happen when somebody brings a laptop into school, or somebody brings that laptop from home into work or they're using VPNs. VPNs are providing a network, a path for that ransomware to spread and it spread to wherever it can. It'll spread onto your file servers, spreads high and low across everything.

    So be very careful. Okay. major problems with the remote desktop protocol. RDP from Microsoft, that I know a lot of you guys are using to connect to work, make sure it's patched up.

    Slap yourself on the back of the hand for using RDP, especially if it's exposed to the internet, the same thing with a VPN. So we're going to do training on this. I'm going to help you guys understand it. I don't want you to feel bad about this. Okay. Cause you just didn't know.

    The vendors are lying to you. Okay. you're using this stuff that you shouldn't be using because they're telling you should be using it. I was flabbergasted this week. I got an email from a security vendor that sells security hardware and software, and they said, the only thing you need is our one product. Which is not even close to being true.

    What do you do right? I can tell you what I do. I let you guys know about it. Okay. So we're going to be doing a lot of training on that starting next week. So I'll make sure you are on my newsletter list. Newsletter members are the ones that are going to be getting this information, and it's going to be short.

    You can read it and just a few minutes and it's going to be educational. Okay. Important stuff now. I'm going to talk about exposed credentials. What do you do if your username, your email, address your password, maybe some personally identifiable information? Is found out there on the internet. What do you do?

    We've got over 15 billion exposed credentials available online, for free? In most cases, the bank has don't have to pay for them. Did you little shadows conduct a study this year? And they found that nearly two-thirds of the credentials available on the dark and by the way, the open-source or the clear web markets duplicates and 80%, of them are in clear text format.

    Many of these are employee credentials that pose a significant risk to organizations because they are in the hands of cybercriminals. So the security team needs to assess all of the things, exposed employee credentials to help make sure that everything's taken care of.

    So what should you do? first of all, I want you to go to a website. I should just put this Craig Peterson so you can find it easily, but go to a website called have I been pwned? You've probably heard me say this before, but it's worth checking again. Check it frequently. Now have I been pwned dispelled, P W N E D. Have I been PW, D d.com. And you enter your email address and it'll tell you what it finds.

    So I used my Craig and mainstream.net email that I've had for 30 years now. And I, I know it's been exposed and you already know, I use different passwords on every website. In fact, I tend to use. Different email addresses and there are some tricks to that. And I'll do some training on that for you guys too.

    What can you do? How can you do it? But, there are some tricks so that you can really, I have one mailbox, but to have what looked to be millions, if you wanted them of different email addresses, which is very good. Have I been pwned has seen my mainstream.net email. It has been found on 12 breached webs sites and one paste.

    A paste by the way is a site where they just put all of this stuff together and upload it as one big file. Basically think of it a big zip file place. And so it lists through all of these. And I went through this a couple of weeks ago here on the air, but have I been poned.com? That's where I want you guys to go.

    Okay. So not all exposed usernames and passwords, present a threat. You have to look at them and figure out, okay, am I using that username? But it says on, have I been pwned as having in stolen? Am I using that anywhere else? Am I using that password anywhere else? Make sure that you have a password manager.

    I like one password. That's what we use. We also use something called Thycotic, but I also am really pretty happy now with the latest versions of LastPass. So look up LastPass as well. So use a password manager, always generate new passwords. let's see the same stolen leaked employee credentials. Keep on surfacing online.

    Have I been pwned is going to help you with some of that stuff. You got to get rid of all of that weed out. All of those duplicates, make sure the credentials are genuine and then go to those websites. Go ahead and change them. And use one password use last pass. It's very important to do all of that stuff.

    And then on an ongoing basis, make sure you monitor for stolen or elite credentials. So that means if you can go ahead and on, have I been pwned again, PWNED dot com on, notify me, put in your email address, it's going to send you a confirmation email. Once you've confirmed. It'll email you, anytime it find your email on any new hacks out on the dark web.

    All right, everybody, have a great weekend. Make sure that you are on my list. Cause we're starting this up this week, little kind of micro training, and we're going to do other pieces of training as well, but there's only one way to find out about it and that's to be on my newsletter list. Craig peterson.com/subscribe.

    Believe me. This is not going to harass you. This is going to help you learn even more. All right. Learn. And I always give you things that you can do just like to have I been pwned.

    So have a great week. I will be back Wednesday, with Matt, at seven 30 in the morning.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! Put Cybersecurity on Your Back to School List plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why Cybersecurity is important and a must-not-forget item for your Back to School preparations. Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

     

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, it's back to school time. We're going to talk about cybersecurity on the back to school list for parents, for children, and for school administrators. And then what do you do if your credentials have been exposed online?

    Hey everybody, Craig Peterson here. WGAN and online, of course, Craig peterson.com. You will find all kinds of great information there. We've got a new website, we've got a whole bunch of stuff coming up here. So keep an eye out for that. I think you're going to really like it. So let's get into cybersecurity.

    Now we're going back to school. Our kids are back at school. We're probably working from home, right now that's a majority of people in the United States that aren't in, manufacturing jobs or hands-on jobs. That is a very big deal and it means some potentially bad things as well. So what are those bad things potentially that I'm talking about?

    If we have computers in our homes and we have kids on those computers and those kids are going. Who knows where online, including to the school and a parent is at home. And that computer's on the same day network is a kid's computer. You're in trouble. I've talked many times before about how these hacks and hackers bread, when it comes to a company, how they spread in your home, and what they do is.

    Kind of think of it like the military, they get a beachhead. So they attack and they have now a footing inside the network and then they start spreading laterally. So if your kid's computer does not have the advanced malware protection on it, that it needs, if it's not configured properly, if that kid's installing software on it and that software gets out or is hacked or is a hack, to begin with.

    That computer can now be used to spread malware onto your computer. So whether you using a computer from the office at home, or maybe you are using your home computer. At home, the bad guys are now in your network and now start to spread within your network. Now think of that, multiplied out. Even further, kids are bringing computers into school.

    If you go into school one or two days a week. You probably never brought a computer into school before because the kids who were there five days a week. But now they're there one or two days a week and they bring the computer in so they can show the homework so they can get some assignments. Now things are spreading.

    Do you think that the Wuhan virus spreads like crazy? what do you think happens when a child or a teacher brings an infected computer into a school while it's going to spread like wildfire? And what do you think happens when you have an infected computer on your network at home? it's going to try and spread like wildfire and it probably can, if you're not doing all of the right things now, as I said in the last segment, I should probably do some more courses on this, but that's part of what we're aiming at here to really help you guys out.

    Yeah, that gets to be a problem. Doesn't it? It's spreading. So if it spreads onto the computer you're using from work, and let's say that you've made the mistake of using a VPN into the office and that's not properly firewalled at the office or on your computer. That mistake that VPN mistake could cost you dearly because now you are spreading that malware or you're allowing the hacker access by piggybacking on your computer, into the business.

    Now, I know that might sound complicated, but it is very easy to do. And the bad you guys have tools that they can buy for as little as 10 to $20 on the black market, it allowed them to do everything I just described very easily. So if you are a school administrator, You need cybersecurity. It drives me crazy.

    I was on a zoom call earlier in the week and the only thing they use is zoom. I had to explain to them, Hey, I have clients that are. DOD subcontractors. They sell stuff to military installations. They sell stuff that used by DOD contractors. Therefore, I can not use zoom because Zoom is not secure. The same thing's true when we're talking about using zoom in schools and in regular businesses. We cannot use it. Schools have seen an increase in these debilitating ransomware attacks, even with the FBI alert this summer about it going on. I remember the first time I was speaking at an insurance conference and I was up there.

    I was their keynote speaker and talking about the problems that we were seeing in business and in schools. With these ransomware attacks. And afterward, one of the attendees came up and told me about his entire school district had been hit with ransomware. What do you think's going to happen when somebody brings a laptop into school, or somebody brings that laptop from home into work or they're using VPNs. VPNs are providing a network, a path for that ransomware to spread and it spread to wherever it can. It'll spread onto your file servers, spreads high and low across everything.

    So be very careful. Okay. major problems with the remote desktop protocol. RDP from Microsoft, that I know a lot of you guys are using to connect to work, make sure it's patched up.

    Slap yourself on the back of the hand for using RDP, especially if it's exposed to the internet, the same thing with a VPN. So we're going to do training on this. I'm going to help you guys understand it. I don't want you to feel bad about this. Okay. Cause you just didn't know.

    The vendors are lying to you. Okay. you're using this stuff that you shouldn't be using because they're telling you should be using it. I was flabbergasted this week. I got an email from a security vendor that sells security hardware and software, and they said, the only thing you need is our one product. Which is not even close to being true.

    What do you do right? I can tell you what I do. I let you guys know about it. Okay. So we're going to be doing a lot of training on that starting next week. So I'll make sure you are on my newsletter list. Newsletter members are the ones that are going to be getting this information, and it's going to be short.

    You can read it and just a few minutes and it's going to be educational. Okay. Important stuff now. I'm going to talk about exposed credentials. What do you do if your username, your email, address your password, maybe some personally identifiable information? Is found out there on the internet. What do you do?

    We've got over 15 billion exposed credentials available online, for free? In most cases, the bank has don't have to pay for them. Did you little shadows conduct a study this year? And they found that nearly two-thirds of the credentials available on the dark and by the way, the open-source or the clear web markets duplicates and 80%, of them are in clear text format.

    Many of these are employee credentials that pose a significant risk to organizations because they are in the hands of cybercriminals. So the security team needs to assess all of the things, exposed employee credentials to help make sure that everything's taken care of.

    So what should you do? first of all, I want you to go to a website. I should just put this Craig Peterson so you can find it easily, but go to a website called have I been pwned? You've probably heard me say this before, but it's worth checking again. Check it frequently. Now have I been pwned dispelled, P W N E D. Have I been PW, D d.com. And you enter your email address and it'll tell you what it finds.

    So I used my Craig and mainstream.net email that I've had for 30 years now. And I, I know it's been exposed and you already know, I use different passwords on every website. In fact, I tend to use. Different email addresses and there are some tricks to that. And I'll do some training on that for you guys too.

    What can you do? How can you do it? But, there are some tricks so that you can really, I have one mailbox, but to have what looked to be millions, if you wanted them of different email addresses, which is very good. Have I been pwned has seen my mainstream.net email. It has been found on 12 breached webs sites and one paste.

    A paste by the way is a site where they just put all of this stuff together and upload it as one big file. Basically think of it a big zip file place. And so it lists through all of these. And I went through this a couple of weeks ago here on the air, but have I been poned.com? That's where I want you guys to go.

    Okay. So not all exposed usernames and passwords, present a threat. You have to look at them and figure out, okay, am I using that username? But it says on, have I been pwned as having in stolen? Am I using that anywhere else? Am I using that password anywhere else? Make sure that you have a password manager.

    I like one password. That's what we use. We also use something called Thycotic, but I also am really pretty happy now with the latest versions of LastPass. So look up LastPass as well. So use a password manager, always generate new passwords. let's see the same stolen leaked employee credentials. Keep on surfacing online.

    Have I been pwned is going to help you with some of that stuff. You got to get rid of all of that weed out. All of those duplicates, make sure the credentials are genuine and then go to those websites. Go ahead and change them. And use one password use last pass. It's very important to do all of that stuff.

    And then on an ongoing basis, make sure you monitor for stolen or elite credentials. So that means if you can go ahead and on, have I been pwned again, PWNED dot com on, notify me, put in your email address, it's going to send you a confirmation email. Once you've confirmed. It'll email you, anytime it find your email on any new hacks out on the dark web.

    All right, everybody, have a great weekend. Make sure that you are on my list. Cause we're starting this up this week, little kind of micro training, and we're going to do other pieces of training as well, but there's only one way to find out about it and that's to be on my newsletter list. Craig peterson.com/subscribe.

    Believe me. This is not going to harass you. This is going to help you learn even more. All right. Learn. And I always give you things that you can do just like to have I been pwned.

    So have a great week. I will be back Wednesday, with Matt, at seven 30 in the morning.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Internet of Things Root Access, Wordpress Vulnerability, Apps and Reverse Image Search

    Welcome!

    Good morning, everybody. WTAG experienced some issues which prevented me from joining Jim on Tuesday. But this morning he reached out and had me on. Jim and I discussed The Internet of Things and why Businesses must be careful when they are attaching all these cool gadgets to their networks. Then we got into the WordPress Vulnerability that is hitting business websites hard. Then Jim asked about Apps and China. Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    Craig Peterson (2): [00:00:00] So you ask yourself, how can this app be free? Really? Whoever developed it had to put hundreds or thousands of hours into developing that app, how could they possibly afford for it to be free?

    I had a bit of a surprise this morning. This is Craig Peterson.

    Craig Peterson (2): [00:00:15] I got a text from Mr. Jim Polito asking if I could come on today because their board was so messed up on Tuesday, they couldn't get me on. But he really wanted me on this week. So that was fun.

    We freewheeled today. Although normally we stick with the topics that I have sent him that I also include in the newsletter. We go into deep dive on my radio show on the weekend. And of course, those are podcasts as well, but it was fun. I was a little bit of a different thing today. So here we go with Mr. Jim Polito.

    No week would be complete without a visit from our good friend and tech talk guru. Craig Peterson. Missed him on Tuesday.

    Jim Polito: [00:00:53] Can't wrap up the week without a visit from the man. Good morning, Craig.

    Craig Peterson (2): [00:00:58] Hey, Good morning. I want to correct the thing that Fake Bernie said this morning and that is Connecticut river is entirely a New Hampshire. Vermont doesn't even have a border on the river, let alone the ocean.

    Jim Polito: [00:01:14] I thought they had.

    Craig Peterson (2): [00:01:15] Did you realize that?

    Jim Polito: [00:01:15] No. No. So the state line is on the other side of the river.

    Craig Peterson (2): [00:01:21] It is. It came from years ago. It was an order in council signed by King George, the third back in 1764 because remember Vermont was part of New Hampshire. And then yeah, New York, in fact, we've even got ski Hills that tried to re-annex themselves a few years ago to New Hampshire, tired of all of the taxes and everything.

    But, yeah, so what had happened is that New York said, No No Vermont is ours. Then so King George says, okay, I'm going to settle this. So he established the border between New Hampshire and Vermont. It could be the Western bank of the Connecticut River and then the US Supreme court in 1933, upheld that.

    So normally when you go across a bridge, I don't know if you've noticed, but usually in the middle it says, you're now doomed during the state of, whatever it might be, where Joe Biden might be from this week. But, when you're going from, Vermont, New Hampshire to Vermont, you don't see the sign until you hit the ground on the Vermont side.

    Jim Polito: [00:02:22] Hey, you're right. I was Chesterfield New Hampshire over the weekend and I went and did the bridge there. There's the old bridge right next to the new one. And cause they never knocked down the old one. You're right, you get over the bridge, you come to the rotary, but there's the sign before you get into the rotary. Welcome to Vermont.

    Craig Peterson (2): [00:02:42] Yeah. Yeah, exactly. I don't know if that's like the only one, but it's really weird. A little bit of history actually knew. How's that for strange?

    Jim Polito: [00:02:50] No, that's why you're the man. And, and King George, the third, how do you like that coming up with the idea? No, it's on the banks of Connecticut.

    Back in those days, The Connecticut River used to flood and break its banks. Oh, the Vermont border was a moving target. all right. I want to talk about some of the stuff that you, gave us today, but what is top of mind for Craig Peterson right now? By this top of the most brilliant man in tech wake up on Thursday morning, which is not typical for him.

    What does he wake up and say, but that other people won't understand by the way?

    Craig Peterson (2): [00:03:29] Oh, okay. details. so yeah, the big thing, and I'm going to talk about this on my show on Saturday here, but the big thing that has to do with the internet of things, hardware, again. Now we're talking about all of these lights that we have that may be voice-activated, and now it's everything.

    If you're a business, I can't tell you how many businesses I've walked into that have. These hick vision cameras on the wall, security cameras. They've got automatically lights that come on when entering rooms, et cetera. So there is a little bit of a study that was just conducted and they found that about 85% of the devices that were tested could and be completely 100% hacked.

    It's called complete root access on these devices. This is a real problem because we're making these IoT devices, the internet of things. They've got to be small. They have to be cheap. At least we want them to be cheap. So what they do is just cost reduce cost reduce, cost reduce, and what you end up with is a little computer.

    It has to be a computer inside that can talk to, of course, your wi-fi in order to send its messages. And they just leave out all concepts of security, frankly. They come pre-configured with default usernames and passwords. These things come also with the ability to be completely hacked because they cannot get updates, so many of them. They never get re flashed. In fact, this particular investigation showed that they could be completely re-flashed by hackers. So we're surrounding ourselves with all of this wonderful equipment, all of this really cool stuff. At the same time, we're exposing ourselves and we're exposing our businesses to some of the worst hacks that have ever been going on, and frankly, that's a huge problem. I'm going to talk about that one this weekend. And similar to that, I gotta bring up one more thing while I'm on my soapbox. And that is, we know we're supposed to update our computers, right? And so you go ahead and you update windows, you're reluctant to do it. Cause is it going to break. What's going to happen.

    If you're on a Mac, it just happens for you automatically and it's extremely rare that anything breaks or an iPhone. Android, of course, you got the problems and trying to do updates.

    The biggest problem we're finding right now is that people think that they have turned on automatic updates and they're safe. Without thinking about the dozens of other apps or programs that they have on their computer that need to be updated. To a business 99% of the time they say, yeah, we're 99% patched up. we're fine. But then you dig into it at all, then you find out, they haven't updated flash. Oh, they haven't updated their web browsers. Oh, they've got all of these plugins, these extensions on the web browser that are known to be major security hazards.

    So my whole message this weekend and this morning are, Yes, you've got to patch up and right now. Over 350,000 websites out there that are hosted, that are run on WordPress, which is most business websites have a critical flaw, critical, and we've seen before where ISIS goes ahead and they hack one of our websites, Jim, and then they have uploaded videos of the beheading of Americans and American soldiers onto and attacks against the soldiers to onto our business website. Then they share that with all of their friends and it's unbeknownst to you sometimes. They just hide it and they're using it for touch and go places. The bad guys are using it for child pornography.

    They're using them for attacking other websites. They are putting in skimmers, just like ATM skimmers that we've seen before, right into the website checkout pages.

    So that's my big thing today and I'm going to be talking about it more on Saturday. It's terrible.

    Jim Polito: [00:07:47] We're talking with Craig Peterson, our good friend, our tech talk guru, and some of the concerns, Craig, I'm going to call an audible.

    I have the list of stuff that you brought to us, but something came up personally for me yesterday. I wanted to do a reverse image lookup. I wanted to find the origin of a picture. And, there's a lot of different ways you can do that. But one of the ways that your smartphone will steer you toward is getting an app to do that, and of course, I'm on Apple.

    Here's my question. I started looking at all the PR of course, I don't want to pay for it. I want a free app. And I started looking at all the free apps available to do a reverse image lookup. Now, for those of you who don't know, here's a reverse image. Look up. you take a picture that you have, you put it into an app and the app tells you the other places on the internet that they can find it.

    So I, I did that, but I'm looking at all these apps. Then for some reason popped up on my phone who created the app and there were, and this isn't certainly a racist thing, but there was a lot of what appears here to me to be Chinese names. I said, okay, this could be someone in the United States, who's from China. Or could these all be Chinese apps from China?

    So my question was how good of a cop is Apple when it comes to allowing its apps in the Apple app store. Cause I thought to myself, wait a minute. If Apple is offering it's gotta be safe. Am I being naive?

    Craig Peterson (2): [00:09:32] No, you are not a few things that come out over the last few weeks. One is there is a library that a lot of application developers are using that tracks you and your data and the application developers are paid for it.

    So you ask yourself, how can this app be free? Really? Whoever developed it had to put hundreds or thousands of hours into developing that app. How could they possibly afford for it to be free? So the big problem over the last few weeks was, Oh my gosh, there's this the library that app developers are using for Apple and for Android that they're getting paid to include in their app and Apple wasn't noticing it.

    Then there's another problem app and requires apps to be signed on your Mac as well as your iPhone and there are ways around that. It was also found out that Apple had, this is just the last week, approved some malware to run on Mac. Now this is unbeknownst to Apple and we have to step back a little bit, and look this isn't just Apple this is Google as well. Although Apple historically has done a better job. But in both cases on the app store from Apple and the Google play store, they use software to scan the apps, to look for potential malicious stuff. They've done an okay job over the years.

    That's part of the reason Apple gets 30% of any proceeds from apps that are on there.

    Jim Polito: [00:11:07] Yeah

    Craig Peterson (2): [00:11:07] You brought up China. China has been flooding both app stores. Then, of course, socialist government over there wanting to get our information because once your socialist, you've squashed most, if not all innovation. So the only way you can grow is to steal it from other people that aren't socialist.

    Jim Polito: [00:11:27] It's true. it's true.

    Craig Peterson (2): [00:11:28] Yeah, absolutely true. And so they've been very, It's strong or, front line thinking here on getting apps into the app stores that can leak data. Because again, they just need a little bit of data from this app. Maybe a little bit of data from that app. Get your contacts from this app, pull them all together. And now they've got a very good picture of you. Who do you work for? Where do you live? What kind of data might you have access to? Then they're using that to go spearfishing. So to answer your question, Apple does a, quite good job of vetting the apps.

    Google does a good job on betting the apps. But there are many ways to obscure the code and frankly, Yeah. Having written all articles over the years and worked on a lot of different people's code, I can tell you that obfuscation seems to be the middle of the name of every programmer are known to demand, where are it's impossible to try and figure out what they're doing sometimes takes a while.

    So I can't blame Apple and Google for letting some of that, this stuff into the store, but they're pretty careful about it, but this thing twice, Why is the app free? Why is the app cheap? What else are they getting out of me?

    Jim Polito: [00:12:43] Let me just ask you a quick question and then, Oh, go ahead. Go ahead.

    Craig Peterson (2): [00:12:47] No, I was going to say when it comes to reverse image this is a great tip for everybody that's listening. If you are in the dating realm or your kids or grandkids or whatever it might be, or out there dating. Google regular Google search has an image search on it. One of the best things you can do is take that photo that you found on the dating site and run it through the Google reverse image search and see if it's a stock photo or if it's just someone else.

    Because so many of our seniors as well, they're not dating, but they're, the reaching out, some of them are lonely and you've got to make sure that this person is legit. And what Jim did with the reverse image search, just use Google. It is a wonderful idea

    Jim Polito: [00:13:32] See, learn from my mistakes. Excellent.

    Phil, I have since deleted the app, but who knows, there's probably code somewhere in my phone right now, from the Chinese and, and they know I'm friendly with you. So I'm I'm the enemy.

    How can folks get in touch with you?

    Craig Peterson (2): [00:13:50] Why don't you check out my website? I've got a new one going up here either this weekend or next week at Craig peterson.com.

    You can get my newsletter. You can get all of the articles and background that I talked about here on Saturdays at 11. You can also of course digging a little bit more. Ask me questions, all of that. Just Craigpeterson.com.

    Jim Polito: [00:14:13] Craig. Thank you. 11 o'clock Saturday. Be listening. Thank you, sir, for doing the extra duty this week and we'll catch up with you next week.

    Craig Peterson (2): [00:14:22] All right. Take care. It was fun.

    Jim Polito: [00:14:24] It was fun. Hey, when we return a very important thing you want to back the blue, I'll tell you how it's my final word. You're listening to the Jim Polito show your safe space.

    Craig Peterson (2): [00:14:35] And safe it was. Take care, everybody.

    We'll be back this weekend. Bye-bye.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    15 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…