Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Welcome! Apple and Google charge 30% royalty for the use of their platform - Fair not Fair?plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig explains, why Apple and Google charge Apps 30%? Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World’s Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You’re About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won’t let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] You're buying apps from those app stores. Did you know that the app stores take your commission, shocker, and some people are very upset about this, and particularly Facebook, as it turns out, we'll tell you why?

    Hello everybody. Craig Peterson here. Thanks for being with us today. This is a great weekend. I love the weekends. I love it when they come around, take a little bit of time and enjoy it. Hey, Apple, these guys, right? Apple's built a pretty darn big business nurse. In fact, right now, I think Apple's still the most highly valued business ever.

    It's like the first business in history to hit a 2 billion or trillion, I should say. A dollar, a valuation. That's just an absolutely amazing kid right down to this. Apple is doing some just frankly, astounding things. Now Apple has never been one to really create a market. There were some amazing MP3 players before Apple came out with their iPod.

    There were other smart devices before Apple came up Newton or, the iPhone as we have today. Of course, there were other operating systems around before Macko S which was is based on a Unix operating system. We'll leave it at that don't want to get too geeky on everybody. Apple, of course, came up with the iPad, which is just a bigger smart device, right?

    They weren't the first ones to have a tablet, but what they've been able to do is really capture people's imagination and help them to make a big change in their lives with technology. One of the things Apple has stressed and has been very good at is trying to keep our information safe. I mentioned Google in the last segment and Google.

    Is a company that's just trying to suck up everything and sell everything about you. Apple is not trying to do that at all. Apple wants to make money. Yeah. But it wants to make money because you like them. So you buy an app. When you buy an app off of that app store, Guess what happens? Apple we'll charge the developer a fee.

    Now I don't consider that to be very surprising, I guess I don't know about you, but Apple, they made this ecosystem. They own this ecosystem. Apple has done just amazing things with it. It has people who review the software. That's submitted for inclusion in the apps to make sure that there's no bad code in there.

    That's going to try and steal your data. Now, nothing to a hundred percent. But they do. Police did pretty darn well. They also advertise it. The apps they promote the apps. They give the developers, this, all the software. They need to develop apps for a hundred bucks. You can join the whole Apple developers program, do all kinds of stuff, even camp with a new programming language called Swift.

    So there is an article this week in ARS Technica. That's talking about-face now. Again. Oh, let's talk about what happens here. You buy an app off of the app store. Apple gets 30%. Of that revenue. So if you pay a dollar, Apple gets 30 cents just to keep this simple. The same thing is true for the Google play store.

    Now, the reason I'm bringing this all up is that we just had some big news out there about some of these app stores and apps being banned. From the Apple store. So it started first with the Apple store and then Google jumped right on it very quickly. Fortnite is out there saying, you can't ban us from the store.

    why was it banned? it has to do again with this payment system. If you buy an app for 10 bucks, Apple gets 30% of that. So they'll get three bucks, but you notice a lot of apps have in-app purchases. That's particularly true when you start talking about these games and Fortnite is Epic games.

    It's just a perfect example of that. You want to move further along in the game, you want to buy some additional virtual property inside the game. Remember how your assets trying to tax that, you want to do any of that stuff. They might charge you 50 cents or a buck. How about candy crush, right?

    How many people have I seen playing candy crush and they pay to play it and they pay to get cheats in candy crush? I remember getting cheats for doom way back when I found out what they were, I didn't pay for them little sneeze there. People are using these in-app purchases and that's where the problem's coming in.

    Now, of course, they'd rather you didn't. They have to pay 30% that developers right to Apple, but Apple's rules, state quite clearly that an app developer, she really has to use them. The purchase features that Apple provides them with. Which also, by the way, provide you with protection so that you don't have to worry about how good is the developer's store that's might be storing my credit card information, et cetera, but they say you have to use our technology.

    If you are going to be selling something inside your app. That's where the big problem came in the big divide because Epic games decided they were going to just set it up. So yeah, you can get the app. why not have the app for free? Yeah. It's for free on the app store. Then if you want to upgrade, just you just go to go, yeah.

    Go to our website there. They're over at Epic games and, we'll give you a 20% discount. So there's still making more money than they would have. If they had gone through the Apple app store. So Apple got very upset with them and not only did Apple but Google when they can figure it out, what was going on and this kind of Daisy chained into the WordPress app and everything else that it really got amazing here.

    So Apple found out about something Facebook was going to do inside the Facebook app. Facebook put something in there to warn users of the Facebook app that Apple would take 30% of the in-event payments. So if you registered for any event, a cooking class, whatever it might be on Facebook, Apple would take 30%.

    Facebook is trying to be actually for over a year now, make it so their platform can be used for training where you can sell it information products, where they can be sold. You can just go there. So they were going to put a message in there saying Apple is going to take 30% of the event payments, Apple wasn't too happy about that.

    And they nixed that message, frankly. Then Facebook announced a new feature. For paid events earlier this month, so that you could host these workout sessions, happy hours, whatever you wanted to charge people to participate in. In its announcement, Facebook said that on its site, that it was not taking a cut of customer's payments.

    So businesses could keep up a hundred percent of the revenue they generate over on the Android platform because Google was not going to charge that commission on events. So back and forth and back and forth. The big question that it comes down to is whose platform is it? And I want all of you guys that are business people out there to remember that and remember that well, whose platform is it?

    Is it Facebook's platform? If you're on the facebook.com site, is it Apple's platform if you were writing or using an iOS app? So whose customer is it? Is it Facebook's customer. Is it Apple's customer? Is it Google's customer or is it your customer? So remember that because, in reality, any of these companies can change any of their rules at almost any time.

    So always make sure if you are communicating with your customers or prospects that you. Drive them off of that platform onto something you own like a website so that you can continue to communicate with them, even if Apple and Google and Facebook decide to up to an eight percent tax if you will. All right, Steve, go round.

    When we get back, we're going to be talking about it. The seven signs that you're about to get hit by ransomware. A great article out on dark reading. Make sure you sign up for my newsletter. Craig peterson.com/subscribe. Stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Staying Safe from Ransomware plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Ransomware and what you need to keep safe. Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World's Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You're About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won't let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] If you're a business and you're under attack, how would you know. You've got to have the right tools in place, the right training, the right response. In fact, if you're a regulated business, it's the law. So let's run through some of the ransomware signs.

    Hi everybody. Craig Peterson here.

    What are the signs that you might have ransomware or that you are about to get hit with a hack of some sort, there are a lot of things to be concerned about out there? So many businesses have multiple different systems and they try and have their poor, it, people, security, people monitor all of them.

    And then when something's underway, none of this stuff is integrated. Very difficult to use. In fact why, as I was preparing for this segment today, I was out poking around and I found this article on dark reading and they have a big ad there for somebody bill DNS, DB. It's like a superpower for threat hunters.

    That is a very narrow tool and the right way to do all of this is to have something that's watching everyone, everything going on your network, on your computers, on your switches, everything that's coming in from the outside, pulling it together with the DNS stuff and trying to figure out is this something you should be worried about?

    And we're going to see more and more automation as time goes on. That's really going to be doing that, then, that's a really good thing. As far as I'm concerned. You might have a memory of last year. I don't know Tony. Tony is quite the year. Isn't it? Where last weekend, the pretty much whole internet went down and they went down in a big and nasty way and it was caused because a company bought another company and they bought level three and level three was actually a very high-end internet provider.

    That handled a lot of the internet backbone they still do. They were bought by a company that had previously brought the internet down by making a big booboo. They did the exact same thing this last weekend. They brought a down through some routing protocols that are BGP and how they were doing it.

    they use some. anyways, we won't get into all of the details, but it really stunk because all of a sudden now, All kinds of portions of the internet no longer worked. you couldn't get online. All of the major guys, Amazon and Google, et cetera, got problems. Some of them completely knocked off the air.

    And I think it was like a six-hour stretch. It took them a long time to get back online. Now, the first thing we started to do is figure out, wait a minute. Are we under attack? Is someone trying to attack our customers? And we hadn't gotten any act of alarm for many of our AI systems that monitor all of our customers' networks.

    So we're trying to figure out, what else is going on? So we got on and manually started looking. We didn't see anything that was terribly suspicious, just the normal hack attempts. We get multiples of those every second, sometimes, but at least a dozen every minute, a hack attack against our customers.

    so we then said, maybe it's a little further out. So we went on LTE on our phones so that we were not using our internal networks that were having some sort of problem.. That didn't work either. It was just absolutely amazing. So we were able to get a link up and figure out what was going on.

    And yes, indeed looking at our BGP tables, there were some major problems happening. We saw this happen before China routed our data. In fact, to all of the phone calls from the Washington DC area. At one point, they routed them all through China. Russia has done this to us before. man, in some ways we're just too trusting.

    but I don't know. So we were trying to figure out what was happening now. The good news for us is we have a big integrated system, which in this case turned out to be a little bit of bad news, because just like this tool, I just mentioned to you, this DNS tool, our systems also relied on the internet because we have a huge database we use from Cisco.

    If it has billions of transactions in it that are on the internet. So we can look and compare and see, Hey, is this being seen somewhere else? Is this something we should be looking into and digging into? And the answer turned out to be no, it's, it really was a BGP problem or robbing problem.

    And I don't know. Why level three was sold to this company. That's messed up the internet before, but, they did again last weekend based on everything I've been reading out there. So how can you tell if you're a small, medium business, You've got a couple of hundred employees, maybe a hundred and you are most likely you're using.

    A break, fix shop, and you've got one or two people internally that kind of like computers and they got their MCSC or some other basic certification. You're trying to figure out what's going on. So let's do, I'm going to go through now. This is, this will take a couple of segments, frankly, and if you miss any part of this, make sure you go to my website, Craig peterson.com.

    You'll see the podcast section there and you can go ahead and have a listen so you can catch the rest of it. Attackers, they're trying to get in your network. They'll try lots of ways from these emails, phishing attacks through direct attacks, it's against your network, connected devices, including the internet of things, devices, and so many businesses, just don't know what they're doing.

    They haven't updated some of theirs. Their routers or other devices, and that gets to be a problem. first off, if you are a mid-sized business and you don't have heavy regulatory requirements, then I read, I really recommend you. Look at Meraki. Very good gear. Auto-updates. You're going to pay every year.

    It isn't one of these things where you buy it, you set it and forget it. Ron Popeil did not make this router, but that's how most companies treat the routers and the firewalls. they buy it, they set it and they forget it. The Meraki keeps itself up to date. You pay every year, they maintain the hardware.

    If there's a problem, they'll replace it. I absolutely love it. That's what I use for my kind of lower-tier business customers. Now there's prosumer hardware. You can look at as well, but if you're a business, really, you start at the Meraki level. If you have real regulations that HIPAA or up, you then have to look at the full Cisco stuff.

    So they'll go after your router at the edge or your firewall at the edge. If you have not patched it, you are now in big trouble and the patch might even just be a fairly recent one that came out. Look at what's happened again and again, and it happened with Equifax. I think it was six or eight months that patch had been out and they hadn't applied it yet.

    And they got nailed, right? They lost pretty much all of the personal information of everyone in the country, plus Canada, plus some other countries, pretty bad stuff. Thinking what would happen to your business if you were breached and once they get into your network. That's when bad things can start happening.

    But in reality, you usually have a couple of days to, as much as a week, maybe a little bit more 10 days before they start moving laterally within the business. So there will be signed. We're going to talk about what those signs are, but there will be signs that somebody is messing around with your network.

    They may have gotten in at the network edge, cause you haven't updated or patched your firewall or your router or maybe some other way that they got it. So we'll be getting to those as soon as we get. Back again, if you miss this, make sure you go online. Craig peterson.com. So you know what some of those signs are, but they basically get a foothold, right?

    Think of the world. Then you grab an Island in the Pacific and the new use that as a launching base to continue your tack for out. Yeah. That's what these guys do and we're finding more and more. When it comes to ransomware and we're going to talk about that specifically because ransomware is such a very big problem that they're doing is probing your network.

    So they get in, they start looking around saying, what data do they have? How much might that be? Be worth and then they will ramp up your data, not by encrypting it, but they'll say, Hey, listen, if you don't pay up, we're going to release it to the world. Then you could have some serious problems.

    So stick around. We're going to be right back. We're going to be getting into these seven signs. I'm about to get hit with ransomware. Cause guess what? We're already in there. Yeah. You're listening to Craig Peterson. Thanks for being with me. Stick around. Because we'll be right back and get my newsletter.

    Craig peterson.com/subscribe.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Staying Safe from Ransomware plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Ransomware and what you need to keep safe. Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World’s Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You’re About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won’t let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] If you're a business and you're under attack, how would you know. You've got to have the right tools in place, the right training, the right response. In fact, if you're a regulated business, it's the law. So let's run through some of the ransomware signs.

    Hi everybody. Craig Peterson here.

    What are the signs that you might have ransomware or that you are about to get hit with a hack of some sort, there are a lot of things to be concerned about out there? So many businesses have multiple different systems and they try and have their poor, it, people, security, people monitor all of them.

    And then when something's underway, none of this stuff is integrated. Very difficult to use. In fact why, as I was preparing for this segment today, I was out poking around and I found this article on dark reading and they have a big ad there for somebody bill DNS, DB. It's like a superpower for threat hunters.

    That is a very narrow tool and the right way to do all of this is to have something that's watching everyone, everything going on your network, on your computers, on your switches, everything that's coming in from the outside, pulling it together with the DNS stuff and trying to figure out is this something you should be worried about?

    And we're going to see more and more automation as time goes on. That's really going to be doing that, then, that's a really good thing. As far as I'm concerned. You might have a memory of last year. I don't know Tony. Tony is quite the year. Isn't it? Where last weekend, the pretty much whole internet went down and they went down in a big and nasty way and it was caused because a company bought another company and they bought level three and level three was actually a very high-end internet provider.

    That handled a lot of the internet backbone they still do. They were bought by a company that had previously brought the internet down by making a big booboo. They did the exact same thing this last weekend. They brought a down through some routing protocols that are BGP and how they were doing it.

    they use some. anyways, we won't get into all of the details, but it really stunk because all of a sudden now, All kinds of portions of the internet no longer worked. you couldn't get online. All of the major guys, Amazon and Google, et cetera, got problems. Some of them completely knocked off the air.

    And I think it was like a six-hour stretch. It took them a long time to get back online. Now, the first thing we started to do is figure out, wait a minute. Are we under attack? Is someone trying to attack our customers? And we hadn't gotten any act of alarm for many of our AI systems that monitor all of our customers' networks.

    So we're trying to figure out, what else is going on? So we got on and manually started looking. We didn't see anything that was terribly suspicious, just the normal hack attempts. We get multiples of those every second, sometimes, but at least a dozen every minute, a hack attack against our customers.

    so we then said, maybe it's a little further out. So we went on LTE on our phones so that we were not using our internal networks that were having some sort of problem.. That didn't work either. It was just absolutely amazing. So we were able to get a link up and figure out what was going on.

    And yes, indeed looking at our BGP tables, there were some major problems happening. We saw this happen before China routed our data. In fact, to all of the phone calls from the Washington DC area. At one point, they routed them all through China. Russia has done this to us before. man, in some ways we're just too trusting.

    but I don't know. So we were trying to figure out what was happening now. The good news for us is we have a big integrated system, which in this case turned out to be a little bit of bad news, because just like this tool, I just mentioned to you, this DNS tool, our systems also relied on the internet because we have a huge database we use from Cisco.

    If it has billions of transactions in it that are on the internet. So we can look and compare and see, Hey, is this being seen somewhere else? Is this something we should be looking into and digging into? And the answer turned out to be no, it's, it really was a BGP problem or robbing problem.

    And I don't know. Why level three was sold to this company. That's messed up the internet before, but, they did again last weekend based on everything I've been reading out there. So how can you tell if you're a small, medium business, You've got a couple of hundred employees, maybe a hundred and you are most likely you're using.

    A break, fix shop, and you've got one or two people internally that kind of like computers and they got their MCSC or some other basic certification. You're trying to figure out what's going on. So let's do, I'm going to go through now. This is, this will take a couple of segments, frankly, and if you miss any part of this, make sure you go to my website, Craig peterson.com.

    You'll see the podcast section there and you can go ahead and have a listen so you can catch the rest of it. Attackers, they're trying to get in your network. They'll try lots of ways from these emails, phishing attacks through direct attacks, it's against your network, connected devices, including the internet of things, devices, and so many businesses, just don't know what they're doing.

    They haven't updated some of theirs. Their routers or other devices, and that gets to be a problem. first off, if you are a mid-sized business and you don't have heavy regulatory requirements, then I read, I really recommend you. Look at Meraki. Very good gear. Auto-updates. You're going to pay every year.

    It isn't one of these things where you buy it, you set it and forget it. Ron Popeil did not make this router, but that's how most companies treat the routers and the firewalls. they buy it, they set it and they forget it. The Meraki keeps itself up to date. You pay every year, they maintain the hardware.

    If there's a problem, they'll replace it. I absolutely love it. That's what I use for my kind of lower-tier business customers. Now there's prosumer hardware. You can look at as well, but if you're a business, really, you start at the Meraki level. If you have real regulations that HIPAA or up, you then have to look at the full Cisco stuff.

    So they'll go after your router at the edge or your firewall at the edge. If you have not patched it, you are now in big trouble and the patch might even just be a fairly recent one that came out. Look at what's happened again and again, and it happened with Equifax. I think it was six or eight months that patch had been out and they hadn't applied it yet.

    And they got nailed, right? They lost pretty much all of the personal information of everyone in the country, plus Canada, plus some other countries, pretty bad stuff. Thinking what would happen to your business if you were breached and once they get into your network. That's when bad things can start happening.

    But in reality, you usually have a couple of days to, as much as a week, maybe a little bit more 10 days before they start moving laterally within the business. So there will be signed. We're going to talk about what those signs are, but there will be signs that somebody is messing around with your network.

    They may have gotten in at the network edge, cause you haven't updated or patched your firewall or your router or maybe some other way that they got it. So we'll be getting to those as soon as we get. Back again, if you miss this, make sure you go online. Craig peterson.com. So you know what some of those signs are, but they basically get a foothold, right?

    Think of the world. Then you grab an Island in the Pacific and the new use that as a launching base to continue your tack for out. Yeah. That's what these guys do and we're finding more and more. When it comes to ransomware and we're going to talk about that specifically because ransomware is such a very big problem that they're doing is probing your network.

    So they get in, they start looking around saying, what data do they have? How much might that be? Be worth and then they will ramp up your data, not by encrypting it, but they'll say, Hey, listen, if you don't pay up, we're going to release it to the world. Then you could have some serious problems.

    So stick around. We're going to be right back. We're going to be getting into these seven signs. I'm about to get hit with ransomware. Cause guess what? We're already in there. Yeah. You're listening to Craig Peterson. Thanks for being with me. Stick around. Because we'll be right back and get my newsletter.

    Craig peterson.com/subscribe.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Staying Safe from Ransomware plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Ransomware and what you need to keep safe. Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World’s Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You’re About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won’t let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] If you're a business and you're under attack, how would you know. You've got to have the right tools in place, the right training, the right response. In fact, if you're a regulated business, it's the law. So let's run through some of the ransomware signs.

    Hi everybody. Craig Peterson here.

    What are the signs that you might have ransomware or that you are about to get hit with a hack of some sort, there are a lot of things to be concerned about out there? So many businesses have multiple different systems and they try and have their poor, it, people, security, people monitor all of them.

    And then when something's underway, none of this stuff is integrated. Very difficult to use. In fact why, as I was preparing for this segment today, I was out poking around and I found this article on dark reading and they have a big ad there for somebody bill DNS, DB. It's like a superpower for threat hunters.

    That is a very narrow tool and the right way to do all of this is to have something that's watching everyone, everything going on your network, on your computers, on your switches, everything that's coming in from the outside, pulling it together with the DNS stuff and trying to figure out is this something you should be worried about?

    And we're going to see more and more automation as time goes on. That's really going to be doing that, then, that's a really good thing. As far as I'm concerned. You might have a memory of last year. I don't know Tony. Tony is quite the year. Isn't it? Where last weekend, the pretty much whole internet went down and they went down in a big and nasty way and it was caused because a company bought another company and they bought level three and level three was actually a very high-end internet provider.

    That handled a lot of the internet backbone they still do. They were bought by a company that had previously brought the internet down by making a big booboo. They did the exact same thing this last weekend. They brought a down through some routing protocols that are BGP and how they were doing it.

    they use some. anyways, we won't get into all of the details, but it really stunk because all of a sudden now, All kinds of portions of the internet no longer worked. you couldn't get online. All of the major guys, Amazon and Google, et cetera, got problems. Some of them completely knocked off the air.

    And I think it was like a six-hour stretch. It took them a long time to get back online. Now, the first thing we started to do is figure out, wait a minute. Are we under attack? Is someone trying to attack our customers? And we hadn't gotten any act of alarm for many of our AI systems that monitor all of our customers' networks.

    So we're trying to figure out, what else is going on? So we got on and manually started looking. We didn't see anything that was terribly suspicious, just the normal hack attempts. We get multiples of those every second, sometimes, but at least a dozen every minute, a hack attack against our customers.

    so we then said, maybe it's a little further out. So we went on LTE on our phones so that we were not using our internal networks that were having some sort of problem.. That didn't work either. It was just absolutely amazing. So we were able to get a link up and figure out what was going on.

    And yes, indeed looking at our BGP tables, there were some major problems happening. We saw this happen before China routed our data. In fact, to all of the phone calls from the Washington DC area. At one point, they routed them all through China. Russia has done this to us before. man, in some ways we're just too trusting.

    but I don't know. So we were trying to figure out what was happening now. The good news for us is we have a big integrated system, which in this case turned out to be a little bit of bad news, because just like this tool, I just mentioned to you, this DNS tool, our systems also relied on the internet because we have a huge database we use from Cisco.

    If it has billions of transactions in it that are on the internet. So we can look and compare and see, Hey, is this being seen somewhere else? Is this something we should be looking into and digging into? And the answer turned out to be no, it's, it really was a BGP problem or robbing problem.

    And I don't know. Why level three was sold to this company. That's messed up the internet before, but, they did again last weekend based on everything I've been reading out there. So how can you tell if you're a small, medium business, You've got a couple of hundred employees, maybe a hundred and you are most likely you're using.

    A break, fix shop, and you've got one or two people internally that kind of like computers and they got their MCSC or some other basic certification. You're trying to figure out what's going on. So let's do, I'm going to go through now. This is, this will take a couple of segments, frankly, and if you miss any part of this, make sure you go to my website, Craig peterson.com.

    You'll see the podcast section there and you can go ahead and have a listen so you can catch the rest of it. Attackers, they're trying to get in your network. They'll try lots of ways from these emails, phishing attacks through direct attacks, it's against your network, connected devices, including the internet of things, devices, and so many businesses, just don't know what they're doing.

    They haven't updated some of theirs. Their routers or other devices, and that gets to be a problem. first off, if you are a mid-sized business and you don't have heavy regulatory requirements, then I read, I really recommend you. Look at Meraki. Very good gear. Auto-updates. You're going to pay every year.

    It isn't one of these things where you buy it, you set it and forget it. Ron Popeil did not make this router, but that's how most companies treat the routers and the firewalls. they buy it, they set it and they forget it. The Meraki keeps itself up to date. You pay every year, they maintain the hardware.

    If there's a problem, they'll replace it. I absolutely love it. That's what I use for my kind of lower-tier business customers. Now there's prosumer hardware. You can look at as well, but if you're a business, really, you start at the Meraki level. If you have real regulations that HIPAA or up, you then have to look at the full Cisco stuff.

    So they'll go after your router at the edge or your firewall at the edge. If you have not patched it, you are now in big trouble and the patch might even just be a fairly recent one that came out. Look at what's happened again and again, and it happened with Equifax. I think it was six or eight months that patch had been out and they hadn't applied it yet.

    And they got nailed, right? They lost pretty much all of the personal information of everyone in the country, plus Canada, plus some other countries, pretty bad stuff. Thinking what would happen to your business if you were breached and once they get into your network. That's when bad things can start happening.

    But in reality, you usually have a couple of days to, as much as a week, maybe a little bit more 10 days before they start moving laterally within the business. So there will be signed. We're going to talk about what those signs are, but there will be signs that somebody is messing around with your network.

    They may have gotten in at the network edge, cause you haven't updated or patched your firewall or your router or maybe some other way that they got it. So we'll be getting to those as soon as we get. Back again, if you miss this, make sure you go online. Craig peterson.com. So you know what some of those signs are, but they basically get a foothold, right?

    Think of the world. Then you grab an Island in the Pacific and the new use that as a launching base to continue your tack for out. Yeah. That's what these guys do and we're finding more and more. When it comes to ransomware and we're going to talk about that specifically because ransomware is such a very big problem that they're doing is probing your network.

    So they get in, they start looking around saying, what data do they have? How much might that be? Be worth and then they will ramp up your data, not by encrypting it, but they'll say, Hey, listen, if you don't pay up, we're going to release it to the world. Then you could have some serious problems.

    So stick around. We're going to be right back. We're going to be getting into these seven signs. I'm about to get hit with ransomware. Cause guess what? We're already in there. Yeah. You're listening to Craig Peterson. Thanks for being with me. Stick around. Because we'll be right back and get my newsletter.

    Craig peterson.com/subscribe.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! What you can look for to determine if you are under attack plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses the signs that you may be under attack and what to do about it.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World's Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You're About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won't let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] So what's the first sign that you are about to get hit by ransomware? that's what we're going to talk about right now. We're going to go through some of these signs. What does it mean to you as a business? You've got a hundred, 200 employees or maybe more, maybe less. This could be bad.

    Hey Craig, Peterson here. Thanks for joining me. I appreciate the time you're spending with me today. I have really been enjoying it. Of course on WGAN are going to be continuing after that top of the hour. So make sure you stay with us, but we've got a whole other hour left. So what is going on here when somebody is trying to break in we're generically calling this ransomware because that is frankly.

    One of the major attack vectors that we're seeing right now is the whole ransomware attack. What does that mean to you? So that's exactly where we're going. You should be seeing some signs. So let's talk about the signs that I have seen. One is that your email is weird. No. I know that's not a great definition.

    But that's what I always hear. So something weird is going on with our email. Craig, would you bring your team in and have a look at this for us? We're not quite sure what, and it might be that there are emails that are being received by your clients or maybe your vendors. You're trying to straighten it out.

    What's what, when what, and he can't quite figure it out. So that's a very common one. We get called in on to do some research and try and find out what is going on. So there's number one. Another one is if you're in that a hundred to 250 employee range that we're working with a lot if you have an active directory server and for some reason, Logins are failing.

    So the concept behind this is Microsoft. Once again, took some technology, Kerberos technology, let's steal it and use it and mess it up while we're at it and create it, this whole active directory concept, which is a major hack. It's just Microsoft. But anyway, yeah. The idea is you have an active directory server and that server can provide file servers.

    It can provide DNS, it can give you your DHCP or internet addresses. It can put everything together in one place, including log-ins, access control, lists. All kinds of things that will really help your network. So don't get me wrong here. I think you should be using active directory if you have a Microsoft based network. You really should. Because you're going to be much better off than if you try and maintain a hundred desktops manually. Okay. There really is no choice in this, but if you're, we're starting to see log-in failures, people are saying, yeah, I'm trying to log in. I can't get in what's going on.

    Okay. That's a sign. If you're getting VPN connections, failing and your VPN server just isn't working right. So those are the very basics. So let's get into a little bit more detail here. If you go on to your active directory server, it is going to show multiple log-in failures. That's a very big deal here.

    If you're seeing three login fails in a row, particularly from your remote desktop servers, you might be in trouble. A remote desktop is one of the ways. The bad guys are getting in because there are a number of known vulnerabilities in them. Most people, again, haven't patched them up and businesses just didn't have time to prepare for the whole COVID-19 thing.

    So they sent people home and their systems weren't set up. So keep an eye. If you have an active directory server, keep an eye on it. The log-in errors you might be having. If you're using a remote desktop. Particularly if you're exposing the server directly to the internet, it's a very big problem.

    Bruce brute force attacks, Bruce force a very big deal here. Because we're seeing these all of the time, you should be keeping an eye on your firewall and your firewall should be logging. In fact, if you're a regulated industry, it has to be logging and you have to have an accurate time source. So if you have all of this data and it's logging it and it's alerting you.

    That there are a lot of attacks underway. that might be a sign that ransomware is heading your way and you turn well better, make sure that you have everything patched up. Okay. That's just a really good idea. The bottom line also. You should look for your brute force attacks, not just on your firewall, but again, on your remote desktop system.

    Once they're inside your network, the bad guys are going to start looking for passwords, password files, various types of zip files, doc files, word texts, all of those sorts of things. Nowadays, they are running. Basically shell scripts. Microsoft came out with what they call power shell yet another rip-off.

    And, they didn't do a particularly good job on it and it is particularly vulnerable and that's a bad thing. A lot of those PowerShell attacks that are underway are non-disc resident. They are memory resident, which means that none of your antivirus software is going to catch any of it. Okay. A very big deal there.

    Also, keep an eye on phishing emails. These things have been coming in for a long time. Some of them have very strange domain names, keeping high out with your analysis tools. Again, hopefully, you've got a whole integrated system. That's looking at all of this stuff, these new domains that are coming into your network, do you flag them?

    Does your firewall have the ability to flag them? So all of a sudden you're seeing a bunch of people going to xyz.com and no one's ever gone there before. You should have a flag for that, because oftentimes what's happening is the bad guys have some software that's trying to exfiltrate trying to take your data out of your network.

    To use against you. That's where open DNS can come in. very well handy. Cisco umbrella. That's what we use there. The free version or inexpensive versions for home. Check it out. Cisco umbrella. I think it's an umbrella.com but Cisco umbrella and that will help dramatically. With the exfiltration of data with phishing domains, et cetera, stopping them from being nasty, next time, or this is on an article, dark reading, and he's got a lot of good information in here.

    recently adding some things, taking some things. Yeah. I'm using my actual experience As to what's happening up here. But. Questions that are really being raised about a particular machine. This is from an incident response manager. My name is Peter McKenzie saying. questions that everyday users aren't normally asking, is this a Mac or Windows?

    What's the domain and company name? What kind of admin rights is the computer? Yeah, if you're getting those coming into your help desk, you may have a big bloom, frankly. Okay. Also, security tools that aren't being used by your security people. So keep an eye out for that. There are a number of pieces of security software that I teach people how to use that are going to really help you with digging into everything.

    But to have a look at the few of them that are out there, things like process hacker, IO bit, and PC Hunter. So they're legitimate tools, but not being used by just a regular user. So keep an eye on what's running on the machines. Timestamps can be very weird. So keep an eye on that. Some VPN servers do have information about the time of the source of the VPN.

    So if all of a sudden you're seeing time connections that are coming in a really weird time zones like Russia, China, wherever it might be. There's another sign. The ransomware might be on the way in, if not in already. Then traffic, all of a sudden goes up. You have a huge spike going to somewhere. I don't know the internet.

    Maybe you can trace it to the dark web. Maybe you can't, but questionable places. Now keep an eye out for that. Unusual DNS requests. A very good thing to watch out for, but again, that's why you use Umbrella. It will keep tabs on those and it'll stop better than 90% of these bad guys from being able to install software that can call home.

    And that's very important. You may not be able to tell a tour site. I teach this again. You can use Tor and the onion network in order to hide your identity to a degree it's none of this is absolutely perfect again, but the bad guys use it and they use it a whole lot. So what we do with our clients is we block these TOR entrance/exit sites, these onion network sites. So that bottom line, the bad guys just can't get in. They can't do anything about it. I think that's really important to do That is your top sign that you're about to get hit with ransomware and they all revolve around keeping an eye out for what's going on in your network.

    What you should be doing, what you shouldn't be doing when it comes to your security software. If you own a business, if you're C level responsible for some of this stuff, make sure you get some training, make sure your people get some training because a lot of these attacks are actually based on ignorance.

    That's where people don't know that you should not be clicking on that type of email. People don't know how to determine whether or not a URL is a legitimate URL either. Now we have all kinds of pieces of training for security that we provide to our clients and the tracks who's doing what and helps to meet all of the regulations, whether it's HIPAA or you name it.

    But if you don't have anything really simple little quiz training, you can do. Is available online for free from Google. Now, this is just a, it's a few questions, but it helps to educate users about fishing. You can find it online. Just go to phishing quiz, all one-word fishing. P H I S H I N G phishing quiz dot with Google.

    Dotcom and you can take that quiz. It's very simple to do. It's fun. I got a hundred door, And, they have emails and it acts kinda like Gmail for reading the emails and shows you what you should be looking for in order to catch some fishing. Going on with your email. So check that out again.

    The phishing quiz dealt with google.com. It's at a minimum and, your MSSP or managed security services provider should be providing you with training for all of your employees and tracking it to and giving you reports to make sure that you are compliant with all of the regulations out there. thanks for sticking with me here for the first hour.

    We're going to be back here on WGAN after the top of the hour. Of course, news and everything else. Make sure to join me every Wednesday, the morning at about seven 30 with Matt Gagnon, as we discuss the latest tech news out. There and visit me online. Craig peterson.com. If you missed any part of today's show, you'll find it right there in your favorite podcast app.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! What you can look for to determine if you are under attack plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses the signs that you may be under attack and what to do about it.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World’s Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You’re About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won’t let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] So what's the first sign that you are about to get hit by ransomware? that's what we're going to talk about right now. We're going to go through some of these signs.  What does it mean to you as a business? You've got a hundred, 200 employees or maybe more, maybe less. This could be bad.

    Hey Craig, Peterson here. Thanks for joining me. I appreciate the time you're spending with me today. I have really been enjoying it. Of course on WGAN are going to be continuing after that top of the hour. So make sure you stay with us, but we've got a whole other hour left. So what is going on here when somebody is trying to break in we're generically calling this ransomware because that is frankly.

    One of the major attack vectors that we're seeing right now is the whole ransomware attack.  What does that mean to you? So that's exactly where we're going. You should be seeing some signs. So let's talk about the signs that I have seen. One is that your email is weird. No. I know that's not a great definition.

    But that's what I always hear. So something weird is going on with our email. Craig, would you bring your team in and have a look at this for us? We're not quite sure what, and it might be that there are emails that are being received by your clients or maybe your vendors.  You're trying to straighten it out.

    What's what, when what, and he can't quite figure it out. So that's a very common one. We get called in on to do some research and try and find out what is going on.  So there's number one. Another one is if you're in that a hundred to 250 employee range that we're working with a lot if you have an active directory server and for some reason, Logins are failing.

    So the concept behind this is Microsoft. Once again, took some technology, Kerberos technology, let's steal it and use it and mess it up while we're at it and create it, this whole active directory concept, which is a major hack. It's just Microsoft. But anyway, yeah. The idea is you have an active directory server and that server can provide file servers.

    It can provide DNS, it can give you your DHCP or internet addresses. It can put everything together in one place, including log-ins, access control, lists. All kinds of things that will really help your network. So don't get me wrong here. I think you should be using active directory if you have a Microsoft based network. You really should. Because you're going to be much better off than if you try and maintain a hundred desktops manually. Okay. There really is no choice in this, but if you're, we're starting to see log-in failures, people are saying, yeah, I'm trying to log in. I can't get in what's going on.

    Okay. That's a sign. If you're getting VPN connections, failing and your VPN server just isn't working right. So those are the very basics. So let's get into a little bit more detail here. If you go on to your active directory server, it is going to show multiple log-in failures. That's a very big deal here.

    If you're seeing three login fails in a row, particularly from your remote desktop servers, you might be in trouble. A remote desktop is one of the ways. The bad guys are getting in because there are a number of known vulnerabilities in them.  Most people, again, haven't patched them up and businesses just didn't have time to prepare for the whole COVID-19 thing.

    So they sent people home and their systems weren't set up. So keep an eye. If you have an active directory server, keep an eye on it.  The log-in errors you might be having. If you're using a remote desktop.  Particularly if you're exposing the server directly to the internet, it's a very big problem.

    Bruce brute force attacks, Bruce force a very big deal here. Because we're seeing these all of the time, you should be keeping an eye on your firewall and your firewall should be logging. In fact, if you're a regulated industry, it has to be logging and you have to have an accurate time source. So if you have all of this data and it's logging it and it's alerting you.

    That there are a lot of attacks underway. that might be a sign that ransomware is heading your way and you turn well better, make sure that you have everything patched up. Okay.  That's just a really good idea. The bottom line also. You should look for your brute force attacks, not just on your firewall, but again, on your remote desktop system.

    Once they're inside your network, the bad guys are going to start looking for passwords, password files, various types of zip files, doc files, word texts, all of those sorts of things. Nowadays, they are running. Basically shell scripts. Microsoft came out with what they call power shell yet another rip-off.

    And, they didn't do a particularly good job on it and it is particularly vulnerable and that's a bad thing.  A lot of those PowerShell attacks that are underway are non-disc resident. They are memory resident, which means that none of your antivirus software is going to catch any of it. Okay. A very big deal there.

    Also, keep an eye on phishing emails. These things have been coming in for a long time. Some of them have very strange domain names, keeping high out with your analysis tools. Again, hopefully, you've got a whole integrated system. That's looking at all of this stuff, these new domains that are coming into your network, do you flag them?

    Does your firewall have the ability to flag them? So all of a sudden you're seeing a bunch of people going to xyz.com and no one's ever gone there before. You should have a flag for that, because oftentimes what's happening is the bad guys have some software that's trying to exfiltrate trying to take your data out of your network.

    To use against you.  That's where open DNS can come in. very well handy. Cisco umbrella. That's what we use there. The free version or inexpensive versions for home. Check it out. Cisco umbrella. I think it's an umbrella.com but Cisco umbrella and that will help dramatically. With the exfiltration of data with phishing domains, et cetera, stopping them from being nasty, next time, or this is on an article, dark reading, and he's got a lot of good information in here.

    recently adding some things, taking some things. Yeah. I'm using my actual experience As to what's happening up here. But. Questions that are really being raised about a particular machine.  This is from an incident response manager. My name is Peter McKenzie saying. questions that everyday users aren't normally asking, is this a Mac or Windows?

    What's the domain and company name? What kind of admin rights is the computer? Yeah, if you're getting those coming into your help desk, you may have a big bloom, frankly. Okay. Also, security tools that aren't being used by your security people. So keep an eye out for that. There are a number of pieces of security software that I teach people how to use that are going to really help you with digging into everything.

    But to have a look at the few of them that are out there, things like process hacker, IO bit, and PC Hunter. So they're legitimate tools, but not being used by just a regular user. So keep an eye on what's running on the machines. Timestamps can be very weird. So keep an eye on that. Some VPN servers do have information about the time of the source of the VPN.

    So if all of a sudden you're seeing time connections that are coming in a really weird time zones like Russia, China, wherever it might be. There's another sign. The ransomware might be on the way in, if not in already.  Then traffic, all of a sudden goes up. You have a huge spike going to somewhere. I don't know the internet.

    Maybe you can trace it to the dark web. Maybe you can't, but questionable places. Now keep an eye out for that. Unusual DNS requests. A very good thing to watch out for, but again, that's why you use Umbrella. It will keep tabs on those and it'll stop better than 90% of these bad guys from being able to install software that can call home.

    And that's very important. You may not be able to tell a tour site. I teach this again. You can use Tor and the onion network in order to hide your identity to a degree it's none of this is absolutely perfect again, but the bad guys use it and they use it a whole lot. So what we do with our clients is we block these TOR entrance/exit sites, these onion network sites. So that bottom line, the bad guys just can't get in. They can't do anything about it.  I think that's really important to do That is your top sign that you're about to get hit with ransomware and they all revolve around keeping an eye out for what's going on in your network.

    What you should be doing, what you shouldn't be doing when it comes to your security software.  If you own a business, if you're C level responsible for some of this stuff, make sure you get some training, make sure your people get some training because a lot of these attacks are actually based on ignorance.

    That's where people don't know that you should not be clicking on that type of email. People don't know how to determine whether or not a URL is a legitimate URL either. Now we have all kinds of pieces of training for security that we provide to our clients and the tracks who's doing what and helps to meet all of the regulations, whether it's HIPAA or you name it.

    But if you don't have anything really simple little quiz training, you can do. Is available online for free from Google. Now, this is just a, it's a few questions, but it helps to educate users about fishing. You can find it online. Just go to phishing quiz, all one-word fishing. P H I S H I N G phishing quiz dot with Google.

    Dotcom and you can take that quiz. It's very simple to do. It's fun. I got a hundred door, And, they have emails and it acts kinda like Gmail for reading the emails and shows you what you should be looking for in order to catch some fishing. Going on with your email. So check that out again.

    The phishing quiz dealt with google.com. It's at a minimum and, your MSSP or managed security services provider should be providing you with training for all of your employees and tracking it to and giving you reports to make sure that you are compliant with all of the regulations out there. thanks for sticking with me here for the first hour.

    We're going to be back here on WGAN after the top of the hour. Of course, news and everything else. Make sure to join me every Wednesday, the morning at about seven 30 with Matt Gagnon, as we discuss the latest tech news out. There and visit me online. Craig peterson.com. If you missed any part of today's show, you'll find it right there in your favorite podcast app.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! What you can look for to determine if you are under attack plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses the signs that you may be under attack and what to do about it.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World’s Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You’re About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won’t let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] So what's the first sign that you are about to get hit by ransomware? that's what we're going to talk about right now. We're going to go through some of these signs.  What does it mean to you as a business? You've got a hundred, 200 employees or maybe more, maybe less. This could be bad.

    Hey Craig, Peterson here. Thanks for joining me. I appreciate the time you're spending with me today. I have really been enjoying it. Of course on WGAN are going to be continuing after that top of the hour. So make sure you stay with us, but we've got a whole other hour left. So what is going on here when somebody is trying to break in we're generically calling this ransomware because that is frankly.

    One of the major attack vectors that we're seeing right now is the whole ransomware attack.  What does that mean to you? So that's exactly where we're going. You should be seeing some signs. So let's talk about the signs that I have seen. One is that your email is weird. No. I know that's not a great definition.

    But that's what I always hear. So something weird is going on with our email. Craig, would you bring your team in and have a look at this for us? We're not quite sure what, and it might be that there are emails that are being received by your clients or maybe your vendors.  You're trying to straighten it out.

    What's what, when what, and he can't quite figure it out. So that's a very common one. We get called in on to do some research and try and find out what is going on.  So there's number one. Another one is if you're in that a hundred to 250 employee range that we're working with a lot if you have an active directory server and for some reason, Logins are failing.

    So the concept behind this is Microsoft. Once again, took some technology, Kerberos technology, let's steal it and use it and mess it up while we're at it and create it, this whole active directory concept, which is a major hack. It's just Microsoft. But anyway, yeah. The idea is you have an active directory server and that server can provide file servers.

    It can provide DNS, it can give you your DHCP or internet addresses. It can put everything together in one place, including log-ins, access control, lists. All kinds of things that will really help your network. So don't get me wrong here. I think you should be using active directory if you have a Microsoft based network. You really should. Because you're going to be much better off than if you try and maintain a hundred desktops manually. Okay. There really is no choice in this, but if you're, we're starting to see log-in failures, people are saying, yeah, I'm trying to log in. I can't get in what's going on.

    Okay. That's a sign. If you're getting VPN connections, failing and your VPN server just isn't working right. So those are the very basics. So let's get into a little bit more detail here. If you go on to your active directory server, it is going to show multiple log-in failures. That's a very big deal here.

    If you're seeing three login fails in a row, particularly from your remote desktop servers, you might be in trouble. A remote desktop is one of the ways. The bad guys are getting in because there are a number of known vulnerabilities in them.  Most people, again, haven't patched them up and businesses just didn't have time to prepare for the whole COVID-19 thing.

    So they sent people home and their systems weren't set up. So keep an eye. If you have an active directory server, keep an eye on it.  The log-in errors you might be having. If you're using a remote desktop.  Particularly if you're exposing the server directly to the internet, it's a very big problem.

    Bruce brute force attacks, Bruce force a very big deal here. Because we're seeing these all of the time, you should be keeping an eye on your firewall and your firewall should be logging. In fact, if you're a regulated industry, it has to be logging and you have to have an accurate time source. So if you have all of this data and it's logging it and it's alerting you.

    That there are a lot of attacks underway. that might be a sign that ransomware is heading your way and you turn well better, make sure that you have everything patched up. Okay.  That's just a really good idea. The bottom line also. You should look for your brute force attacks, not just on your firewall, but again, on your remote desktop system.

    Once they're inside your network, the bad guys are going to start looking for passwords, password files, various types of zip files, doc files, word texts, all of those sorts of things. Nowadays, they are running. Basically shell scripts. Microsoft came out with what they call power shell yet another rip-off.

    And, they didn't do a particularly good job on it and it is particularly vulnerable and that's a bad thing.  A lot of those PowerShell attacks that are underway are non-disc resident. They are memory resident, which means that none of your antivirus software is going to catch any of it. Okay. A very big deal there.

    Also, keep an eye on phishing emails. These things have been coming in for a long time. Some of them have very strange domain names, keeping high out with your analysis tools. Again, hopefully, you've got a whole integrated system. That's looking at all of this stuff, these new domains that are coming into your network, do you flag them?

    Does your firewall have the ability to flag them? So all of a sudden you're seeing a bunch of people going to xyz.com and no one's ever gone there before. You should have a flag for that, because oftentimes what's happening is the bad guys have some software that's trying to exfiltrate trying to take your data out of your network.

    To use against you.  That's where open DNS can come in. very well handy. Cisco umbrella. That's what we use there. The free version or inexpensive versions for home. Check it out. Cisco umbrella. I think it's an umbrella.com but Cisco umbrella and that will help dramatically. With the exfiltration of data with phishing domains, et cetera, stopping them from being nasty, next time, or this is on an article, dark reading, and he's got a lot of good information in here.

    recently adding some things, taking some things. Yeah. I'm using my actual experience As to what's happening up here. But. Questions that are really being raised about a particular machine.  This is from an incident response manager. My name is Peter McKenzie saying. questions that everyday users aren't normally asking, is this a Mac or Windows?

    What's the domain and company name? What kind of admin rights is the computer? Yeah, if you're getting those coming into your help desk, you may have a big bloom, frankly. Okay. Also, security tools that aren't being used by your security people. So keep an eye out for that. There are a number of pieces of security software that I teach people how to use that are going to really help you with digging into everything.

    But to have a look at the few of them that are out there, things like process hacker, IO bit, and PC Hunter. So they're legitimate tools, but not being used by just a regular user. So keep an eye on what's running on the machines. Timestamps can be very weird. So keep an eye on that. Some VPN servers do have information about the time of the source of the VPN.

    So if all of a sudden you're seeing time connections that are coming in a really weird time zones like Russia, China, wherever it might be. There's another sign. The ransomware might be on the way in, if not in already.  Then traffic, all of a sudden goes up. You have a huge spike going to somewhere. I don't know the internet.

    Maybe you can trace it to the dark web. Maybe you can't, but questionable places. Now keep an eye out for that. Unusual DNS requests. A very good thing to watch out for, but again, that's why you use Umbrella. It will keep tabs on those and it'll stop better than 90% of these bad guys from being able to install software that can call home.

    And that's very important. You may not be able to tell a tour site. I teach this again. You can use Tor and the onion network in order to hide your identity to a degree it's none of this is absolutely perfect again, but the bad guys use it and they use it a whole lot. So what we do with our clients is we block these TOR entrance/exit sites, these onion network sites. So that bottom line, the bad guys just can't get in. They can't do anything about it.  I think that's really important to do That is your top sign that you're about to get hit with ransomware and they all revolve around keeping an eye out for what's going on in your network.

    What you should be doing, what you shouldn't be doing when it comes to your security software.  If you own a business, if you're C level responsible for some of this stuff, make sure you get some training, make sure your people get some training because a lot of these attacks are actually based on ignorance.

    That's where people don't know that you should not be clicking on that type of email. People don't know how to determine whether or not a URL is a legitimate URL either. Now we have all kinds of pieces of training for security that we provide to our clients and the tracks who's doing what and helps to meet all of the regulations, whether it's HIPAA or you name it.

    But if you don't have anything really simple little quiz training, you can do. Is available online for free from Google. Now, this is just a, it's a few questions, but it helps to educate users about fishing. You can find it online. Just go to phishing quiz, all one-word fishing. P H I S H I N G phishing quiz dot with Google.

    Dotcom and you can take that quiz. It's very simple to do. It's fun. I got a hundred door, And, they have emails and it acts kinda like Gmail for reading the emails and shows you what you should be looking for in order to catch some fishing. Going on with your email. So check that out again.

    The phishing quiz dealt with google.com. It's at a minimum and, your MSSP or managed security services provider should be providing you with training for all of your employees and tracking it to and giving you reports to make sure that you are compliant with all of the regulations out there. thanks for sticking with me here for the first hour.

    We're going to be back here on WGAN after the top of the hour. Of course, news and everything else. Make sure to join me every Wednesday, the morning at about seven 30 with Matt Gagnon, as we discuss the latest tech news out. There and visit me online. Craig peterson.com. If you missed any part of today's show, you'll find it right there in your favorite podcast app.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! Russia offered 1 Million to Cripple Tesla plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig talks about a Russian that offered someone 1 Million to cripple Tesla. Wow.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World's Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You're About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won't let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hopefully you were able to get those seven signed. Actually, I think I got closer to 10 or maybe 11. Okay. It was a dozen. These are signs that you are up to be a victim of a ransomware attack. we're going to talk now about a direct attack. Bad guys.

    hi everybody. Craig Peterson here. Thanks for joining me today. If you missed what we were just talking about, you can find it [email protected] or of course your favorite podcast app. I knew there was a word for it and the things they're joining me here in WGAN I'm on all. So every Wednesday with Mr. Matt. Gagnon at about seven 30. We discuss the latest topics of the week and next week's topics will be next week.

    I don't know what they will be right now because we monitor a whole lot of different news feeds and try and figure out what are the top stories you guys need to know to understand a little bit more about the tech that's out there as well as of course, security is cybersecurity is what I do.

    When people are ready to move their business to the next level, that's when they contact me. I'm not somebody out there constantly pounding on people. I really want you to come and engage me when it's your time. I wish more businesses were that way. I just despise it. When I'm getting nothing but pitches from some of these companies out there.

    I just don't think it's worthwhile. So that's what I do anyway. I've been doing that now for about 30 years, which is a long time. That in this case is cybersecurity. I don't even want to mention how long I've been doing networking and the whole internet thing, because that goes back to the mid-seventies.

    Oh my gosh. It makes me almost feel like I'm a little old. let's talk about an article here from ARS Technica. This week, we talked about Elon Musk about him just today, in fact about, Oh, just phenomenal thing he's doing to help people who have these physical. Disabilities. Everything from, you're missing a hand, all the way up through you are locked in and it's just phenomenal.

    Don't know what he's doing there with his Starlink. It's just incredible with what's going to be happening very soon now. With these lower earth orbit satellites. We talked about this one a couple of weeks ago. I gave you the web URL to go to, you can get the internet from him for two bucks a month, which is just phenomenal, but it, you can't just get it.

    You have to be accepted as part of this beta program and everything. So I think he's doing it right. But if you do get in, I think it's a pretty darn cool thing. he has also of course got space X, the boring company, as I mentioned earlier, but he has this Gigafactory. This is really a cool thing. It is located out in the middle of nowhere in Nevada and what he's doing there is designing and building really next-generation, whole new technology, as much as he can do it right now, batteries.

    Think about what he's doing with his cars, he needs batteries, and the batteries he's been using tended to be basically the same batteries that are in your laptop. Then he puts them by the hundreds, into the car and Presto Magico. He has a battery pack. He's trying to move beyond that. Use some newer technology.

    We talked to him about a year or so ago about some of the new lithium Blass batteries that were being developed. It's very cool. They are out there now by the way. Yeah, they have some very interesting. properties basically you can charge them up almost instantly. It just, there's just so many so fast.

    And these were invented by the guy that invented the lithium cobalt oxide and the lithium-ion phosphate electrical materials. Of course, that led to lithium-ion batteries. So this guy's very into it. Internal back I came back, by the way, is researching the battery to see if they can't use it.

    To store extra power. Cause remember Hydro-Quebec is very much based on hydroelectric dams. in fact, in most of Canada, certainly Ontario and Quebec, they don't talk about the power lines down or that there's a power company truck outside. It's always hydro it's a hydro company. If you're not familiar with that terminology, you might think that the water department is outside, but it's not.

    But how do you store the electricity that you're making from? Let's say you have solar roof panels. How do you store it on a massive scale from a nuclear power plant or a hydro plant tour, a windmill farm? There that's a huge problem with it. What happens when. The sun just doesn't come out because it's been snowing for a week.

    You don't have any power, right? Not if you're entirely reliant on it. Just those solar cells. If the wind stops blowing, you're not going to get any power out of those wonderful big turbines that are sitting out there in the field. It's again and again, that's one of the nice things about high hydro too, by the way, is that.

    It is easy to store that is Tricity. Cause all you have to do is slow down the flow of the water. Let it back up a little bit. Who cares? Slow it down during the evening when there's less demand overnight and then speed it up again in the daytime. It's something that kind of what has been done in some of these hotels up in bed, I guess before where to keep them or air conditioning costs down.

    They want to use that electricity at night cheaper. What do they do? Some of these hotels have massive. Freeze plants at night time, they'll go ahead and freeze huge amounts of water. While the electricity is cheap and then during the day they will use that water. Now, the ice there it'll melt and they'll use that for cooling for the whole casino.

    It's really quite cool what they're doing, but storage, the energy is the big problem for the future when we're getting less and less reliant on. Petroleum products. So very cool glass batteries. There are other technologies that are out there. But what was happening here is that Elon Musk built this huge factory that had all kinds of problems too, by the way.

    We talked about this before a couple of years ago when this w factory first started getting going, but the factory is under attack. It's interesting to see here because we've got an arrest now, apparently, and this was divulged on Tuesday in a criminal complaint and it accused a Russian man of offering a million dollars to the employee of this Nevada company.

    In exchange for the employee in infecting the company's network. So there's a different way of getting ransomware or spyware, the company, isn't it. You pay somebody some money and in exchange, when that was all done, he was going to, and really cripple. Tesla this whole factory, the code from the FBI sting that by the way, recorded this guy face to face discussing their proposal.

    He says the purpose of the conspiracy was to recruit an employee of a company to transmit well, malware provided by the co-conspirators into the company's computer system. Exfiltrate data from the company's network and threatened to disclose the data online, unless the company paid the co-conspirators ransom demand.

    Now, this isn't just happening with Tesla. This is happening every day. It's happened already to thousands of businesses. You've got a hundred employees, you got 200 employees and we come in there and we find that there's data being exfiltrated. How did these back doors get into your network? Did they get in because of what it was apparently happening here, where the Russians were trying to hire somebody to get in?

    Was it a fishing attack? Was it some malware that was brought in? it's really hard to say, apparently, this Russian who was 27 years old, traveled from Russia to Nevada, and then. That trip rear-ended in him meeting with this unnamed employee multiple times. The initial offer was a half a million dollars and that failed to clinch the deal.

    And so the defendant doubled the offer. Not so according to prosecutors, this is all alleged. They certainly do seem to have some evidence here, but we'll see. We'll see as time goes on, exactly what ends upcoming. From all of this, but the idea behind this is something that's very prevalent right now, and it is the bad guys want to get your data exfiltrated which means remove it from the computers now own model mean remove as in delete, get a copy of it, and then threatened to release it.

    Now think about what kind of a position that puts your business in they're threatening to release this information. It could be patient information. It could be information that is about your accounts payable or receivables bank accounts. Maybe your customers. Bank accounts or other information like social security numbers, credit cards, et cetera.

    So a lot of people will pay more for that. Then they'll pay for a decryption key for your standard malware. That's out there ransomware. Okay. So it's a different kind. We're seeing it more and more, or I'm getting alerts from the FBI about it more and more., it's interesting to see what he did. This is a, and an old tactic.

    I don't know that it was the Russian government involved, or it was just organized crime. Isn't that kind of sad too. It's almost equating their government with organized crime, but apparently this guy wind dine booze the employee. When discussing. Particularly sensitive details had conversations in cars, interesting.

    The FBI had surveillance in the restaurants and bars and otherwise, the employee recorded it. So this is a very big deal. Obviously very ostentatious money, the audacity, and recklessness of this Russian that was doing it, which also makes you think it really wasn't the Russian government that was directly behind this, but one of the benefits.

    So your typical cybercrime is you don't have to expose yourselves by flying to the United States or. Other risky jurisdictions to have malware installed on a company's computer network. There are much better and easier ways to do that. All right. Stick around. Cause when we come back, we are going to be talking about a confirmation from a story we had just a couple of weeks ago.

    I was talking about something. Everybody needs to hear. You're listening to Craig Peterson on WGAN and online Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Russia offered 1 Million to Cripple Tesla plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig talks about a Russian that offered someone 1 Million to cripple Tesla.  Wow.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World’s Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You’re About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won’t let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hopefully you were able to get those seven signed. Actually, I think I got closer to 10 or maybe 11. Okay. It was a dozen. These are signs that you are up to be a victim of a ransomware attack. we're going to talk now about a direct attack. Bad guys.

    hi everybody. Craig Peterson here. Thanks for joining me today. If you missed what we were just talking about, you can find it [email protected] or of course your favorite podcast app. I knew there was a word for it and the things they're joining me here in WGAN I'm on all. So every Wednesday with Mr. Matt. Gagnon at about seven 30. We discuss the latest topics of the week and next week's topics will be next week.

    I don't know what they will be right now because we monitor a whole lot of different news feeds and try and figure out what are the top stories you guys need to know to understand a little bit more about the tech that's out there as well as of course, security is cybersecurity is what I do.

    When people are ready to move their business to the next level, that's when they contact me. I'm not somebody out there constantly pounding on people. I really want you to come and engage me when it's your time. I wish more businesses were that way. I just despise it. When I'm getting nothing but pitches from some of these companies out there.

    I just don't think it's worthwhile. So that's what I do anyway. I've been doing that now for about 30 years, which is a long time. That in this case is cybersecurity. I don't even want to mention how long I've been doing networking and the whole internet thing, because that goes back to the mid-seventies.

    Oh my gosh. It makes me almost feel like I'm a little old. let's talk about an article here from ARS Technica. This week, we talked about Elon Musk about him just today, in fact about, Oh, just phenomenal thing he's doing to help people who have these physical. Disabilities. Everything from, you're missing a hand, all the way up through you are locked in and it's just phenomenal.

    Don't know what he's doing there with his Starlink. It's just incredible with what's going to be happening very soon now. With these lower earth orbit satellites. We talked about this one a couple of weeks ago. I gave you the web URL to go to, you can get the internet from him for two bucks a month, which is just phenomenal, but it, you can't just get it.

    You have to be accepted as part of this beta program and everything. So I think he's doing it right. But if you do get in, I think it's a pretty darn cool thing. he has also of course got space X, the boring company, as I mentioned earlier, but he has this Gigafactory. This is really a cool thing. It is located out in the middle of nowhere in Nevada and what he's doing there is designing and building really next-generation, whole new technology, as much as he can do it right now, batteries.

    Think about what he's doing with his cars, he needs batteries, and the batteries he's been using tended to be basically the same batteries that are in your laptop. Then he puts them by the hundreds, into the car and Presto Magico. He has a battery pack. He's trying to move beyond that. Use some newer technology.

    We talked to him about a year or so ago about some of the new lithium Blass batteries that were being developed. It's very cool. They are out there now by the way. Yeah, they have some very interesting. properties basically you can charge them up almost instantly. It just, there's just so many so fast.

    And these were invented by the guy that invented the lithium cobalt oxide and the lithium-ion phosphate electrical materials. Of course, that led to lithium-ion batteries. So this guy's very into it. Internal back I came back, by the way, is researching the battery to see if they can't use it.

    To store extra power. Cause remember Hydro-Quebec is very much based on hydroelectric dams. in fact, in most of Canada, certainly Ontario and Quebec, they don't talk about the power lines down or that there's a power company truck outside. It's always hydro it's a hydro company. If you're not familiar with that terminology, you might think that the water department is outside, but it's not.

    But how do you store the electricity that you're making from? Let's say you have solar roof panels. How do you store it on a massive scale from a nuclear power plant or a hydro plant tour, a windmill farm? There that's a huge problem with it. What happens when. The sun just doesn't come out because it's been snowing for a week.

    You don't have any power, right? Not if you're entirely reliant on it. Just those solar cells. If the wind stops blowing, you're not going to get any power out of those wonderful big turbines that are sitting out there in the field. It's again and again, that's one of the nice things about high hydro too, by the way, is that.

    It is easy to store that is Tricity. Cause all you have to do is slow down the flow of the water. Let it back up a little bit. Who cares? Slow it down during the evening when there's less demand overnight and then speed it up again in the daytime. It's something that kind of what has been done in some of these hotels up in bed, I guess before where to keep them or air conditioning costs down.

    They want to use that electricity at night cheaper. What do they do? Some of these hotels have massive. Freeze plants at night time, they'll go ahead and freeze huge amounts of water. While the electricity is cheap and then during the day they will use that water. Now, the ice there it'll melt and they'll use that for cooling for the whole casino.

    It's really quite cool what they're doing, but storage, the energy is the big problem for the future when we're getting less and less reliant on. Petroleum products. So very cool glass batteries. There are other technologies that are out there. But what was happening here is that Elon Musk built this huge factory that had all kinds of problems too, by the way.

    We talked about this before a couple of years ago when this w factory first started getting going, but the factory is under attack. It's interesting to see here because we've got an arrest now, apparently, and this was divulged on Tuesday in a criminal complaint and it accused a Russian man of offering a million dollars to the employee of this Nevada company.

    In exchange for the employee in infecting the company's network. So there's a different way of getting ransomware or spyware, the company, isn't it. You pay somebody some money and in exchange, when that was all done, he was going to, and really cripple. Tesla this whole factory, the code from the FBI sting that by the way, recorded this guy face to face discussing their proposal.

    He says the purpose of the conspiracy was to recruit an employee of a company to transmit well, malware provided by the co-conspirators into the company's computer system. Exfiltrate data from the company's network and threatened to disclose the data online, unless the company paid the co-conspirators ransom demand.

    Now, this isn't just happening with Tesla. This is happening every day. It's happened already to thousands of businesses. You've got a hundred employees, you got 200 employees and we come in there and we find that there's data being exfiltrated. How did these back doors get into your network? Did they get in because of what it was apparently happening here, where the Russians were trying to hire somebody to get in?

    Was it a fishing attack? Was it some malware that was brought in? it's really hard to say, apparently, this Russian who was 27 years old, traveled from Russia to Nevada, and then. That trip rear-ended in him meeting with this unnamed employee multiple times. The initial offer was a half a million dollars and that failed to clinch the deal.

    And so the defendant doubled the offer. Not so according to prosecutors, this is all alleged. They certainly do seem to have some evidence here, but we'll see. We'll see as time goes on, exactly what ends upcoming. From all of this, but the idea behind this is something that's very prevalent right now, and it is the bad guys want to get your data exfiltrated which means remove it from the computers now own model mean remove as in delete, get a copy of it, and then threatened to release it.

    Now think about what kind of a position that puts your business in they're threatening to release this information. It could be patient information. It could be information that is about your accounts payable or receivables bank accounts. Maybe your customers. Bank accounts or other information like social security numbers, credit cards, et cetera.

    So a lot of people will pay more for that. Then they'll pay for a decryption key for your standard malware. That's out there ransomware. Okay. So it's a different kind. We're seeing it more and more, or I'm getting alerts from the FBI about it more and more., it's interesting to see what he did. This is a, and an old tactic.

    I don't know that it was the Russian government involved, or it was just organized crime. Isn't that kind of sad too. It's almost equating their government with organized crime, but apparently this guy wind dine booze the employee. When discussing. Particularly sensitive details had conversations in cars, interesting.

    The FBI had surveillance in the restaurants and bars and otherwise, the employee recorded it. So this is a very big deal. Obviously very ostentatious money, the audacity, and recklessness of this Russian that was doing it, which also makes you think it really wasn't the Russian government that was directly behind this, but one of the benefits.

    So your typical cybercrime is you don't have to expose yourselves by flying to the United States or. Other risky jurisdictions to have malware installed on a company's computer network. There are much better and easier ways to do that. All right. Stick around. Cause when we come back, we are going to be talking about a confirmation from a story we had just a couple of weeks ago.

    I was talking about something. Everybody needs to hear. You're listening to Craig Peterson on WGAN and online Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Russia offered 1 Million to Cripple Tesla plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig talks about a Russian that offered someone 1 Million to cripple Tesla.  Wow.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Musk says that Neuralink implants are close to ready for human testing

    Is China the World’s Greatest Cyber Power?

    Russian tourist offered employees $1 million to cripple Tesla with malware

    Ransomware Red Flags: 7 Signs You’re About to Get Hit

    IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo

    Apple won’t let Facebook tell users about 30% Apple tax on events

    Tesla with Autopilot hits cop car - driver admits he was watching a movie

    iOS 14 Privacy settings will tank ad targeting business, Facebook warns

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hopefully you were able to get those seven signed. Actually, I think I got closer to 10 or maybe 11. Okay. It was a dozen. These are signs that you are up to be a victim of a ransomware attack. we're going to talk now about a direct attack. Bad guys.

    hi everybody. Craig Peterson here. Thanks for joining me today. If you missed what we were just talking about, you can find it [email protected] or of course your favorite podcast app. I knew there was a word for it and the things they're joining me here in WGAN I'm on all. So every Wednesday with Mr. Matt. Gagnon at about seven 30. We discuss the latest topics of the week and next week's topics will be next week.

    I don't know what they will be right now because we monitor a whole lot of different news feeds and try and figure out what are the top stories you guys need to know to understand a little bit more about the tech that's out there as well as of course, security is cybersecurity is what I do.

    When people are ready to move their business to the next level, that's when they contact me. I'm not somebody out there constantly pounding on people. I really want you to come and engage me when it's your time. I wish more businesses were that way. I just despise it. When I'm getting nothing but pitches from some of these companies out there.

    I just don't think it's worthwhile. So that's what I do anyway. I've been doing that now for about 30 years, which is a long time. That in this case is cybersecurity. I don't even want to mention how long I've been doing networking and the whole internet thing, because that goes back to the mid-seventies.

    Oh my gosh. It makes me almost feel like I'm a little old. let's talk about an article here from ARS Technica. This week, we talked about Elon Musk about him just today, in fact about, Oh, just phenomenal thing he's doing to help people who have these physical. Disabilities. Everything from, you're missing a hand, all the way up through you are locked in and it's just phenomenal.

    Don't know what he's doing there with his Starlink. It's just incredible with what's going to be happening very soon now. With these lower earth orbit satellites. We talked about this one a couple of weeks ago. I gave you the web URL to go to, you can get the internet from him for two bucks a month, which is just phenomenal, but it, you can't just get it.

    You have to be accepted as part of this beta program and everything. So I think he's doing it right. But if you do get in, I think it's a pretty darn cool thing. he has also of course got space X, the boring company, as I mentioned earlier, but he has this Gigafactory. This is really a cool thing. It is located out in the middle of nowhere in Nevada and what he's doing there is designing and building really next-generation, whole new technology, as much as he can do it right now, batteries.

    Think about what he's doing with his cars, he needs batteries, and the batteries he's been using tended to be basically the same batteries that are in your laptop. Then he puts them by the hundreds, into the car and Presto Magico. He has a battery pack. He's trying to move beyond that. Use some newer technology.

    We talked to him about a year or so ago about some of the new lithium Blass batteries that were being developed. It's very cool. They are out there now by the way. Yeah, they have some very interesting. properties basically you can charge them up almost instantly. It just, there's just so many so fast.

    And these were invented by the guy that invented the lithium cobalt oxide and the lithium-ion phosphate electrical materials. Of course, that led to lithium-ion batteries. So this guy's very into it. Internal back I came back, by the way, is researching the battery to see if they can't use it.

    To store extra power. Cause remember Hydro-Quebec is very much based on hydroelectric dams. in fact, in most of Canada, certainly Ontario and Quebec, they don't talk about the power lines down or that there's a power company truck outside. It's always hydro it's a hydro company. If you're not familiar with that terminology, you might think that the water department is outside, but it's not.

    But how do you store the electricity that you're making from? Let's say you have solar roof panels. How do you store it on a massive scale from a nuclear power plant or a hydro plant tour, a windmill farm? There that's a huge problem with it. What happens when. The sun just doesn't come out because it's been snowing for a week.

    You don't have any power, right? Not if you're entirely reliant on it. Just those solar cells. If the wind stops blowing, you're not going to get any power out of those wonderful big turbines that are sitting out there in the field. It's again and again, that's one of the nice things about high hydro too, by the way, is that.

    It is easy to store that is Tricity. Cause all you have to do is slow down the flow of the water. Let it back up a little bit. Who cares? Slow it down during the evening when there's less demand overnight and then speed it up again in the daytime. It's something that kind of what has been done in some of these hotels up in bed, I guess before where to keep them or air conditioning costs down.

    They want to use that electricity at night cheaper. What do they do? Some of these hotels have massive. Freeze plants at night time, they'll go ahead and freeze huge amounts of water. While the electricity is cheap and then during the day they will use that water. Now, the ice there it'll melt and they'll use that for cooling for the whole casino.

    It's really quite cool what they're doing, but storage, the energy is the big problem for the future when we're getting less and less reliant on. Petroleum products. So very cool glass batteries. There are other technologies that are out there. But what was happening here is that Elon Musk built this huge factory that had all kinds of problems too, by the way.

    We talked about this before a couple of years ago when this w factory first started getting going, but the factory is under attack. It's interesting to see here because we've got an arrest now, apparently, and this was divulged on Tuesday in a criminal complaint and it accused a Russian man of offering a million dollars to the employee of this Nevada company.

    In exchange for the employee in infecting the company's network. So there's a different way of getting ransomware or spyware, the company, isn't it. You pay somebody some money and in exchange, when that was all done, he was going to, and really cripple. Tesla this whole factory, the code from the FBI sting that by the way, recorded this guy face to face discussing their proposal.

    He says the purpose of the conspiracy was to recruit an employee of a company to transmit well, malware provided by the co-conspirators into the company's computer system. Exfiltrate data from the company's network and threatened to disclose the data online, unless the company paid the co-conspirators ransom demand.

    Now, this isn't just happening with Tesla. This is happening every day. It's happened already to thousands of businesses. You've got a hundred employees, you got 200 employees and we come in there and we find that there's data being exfiltrated. How did these back doors get into your network? Did they get in because of what it was apparently happening here, where the Russians were trying to hire somebody to get in?

    Was it a fishing attack? Was it some malware that was brought in? it's really hard to say, apparently, this Russian who was 27 years old, traveled from Russia to Nevada, and then. That trip rear-ended in him meeting with this unnamed employee multiple times. The initial offer was a half a million dollars and that failed to clinch the deal.

    And so the defendant doubled the offer. Not so according to prosecutors, this is all alleged. They certainly do seem to have some evidence here, but we'll see. We'll see as time goes on, exactly what ends upcoming. From all of this, but the idea behind this is something that's very prevalent right now, and it is the bad guys want to get your data exfiltrated which means remove it from the computers now own model mean remove as in delete, get a copy of it, and then threatened to release it.

    Now think about what kind of a position that puts your business in they're threatening to release this information. It could be patient information. It could be information that is about your accounts payable or receivables bank accounts. Maybe your customers. Bank accounts or other information like social security numbers, credit cards, et cetera.

    So a lot of people will pay more for that. Then they'll pay for a decryption key for your standard malware. That's out there ransomware. Okay. So it's a different kind. We're seeing it more and more, or I'm getting alerts from the FBI about it more and more., it's interesting to see what he did. This is a, and an old tactic.

    I don't know that it was the Russian government involved, or it was just organized crime. Isn't that kind of sad too. It's almost equating their government with organized crime, but apparently this guy wind dine booze the employee. When discussing. Particularly sensitive details had conversations in cars, interesting.

    The FBI had surveillance in the restaurants and bars and otherwise, the employee recorded it. So this is a very big deal. Obviously very ostentatious money, the audacity, and recklessness of this Russian that was doing it, which also makes you think it really wasn't the Russian government that was directly behind this, but one of the benefits.

    So your typical cybercrime is you don't have to expose yourselves by flying to the United States or. Other risky jurisdictions to have malware installed on a company's computer network. There are much better and easier ways to do that. All right. Stick around. Cause when we come back, we are going to be talking about a confirmation from a story we had just a couple of weeks ago.

    I was talking about something. Everybody needs to hear. You're listening to Craig Peterson on WGAN and online Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…