
Sign up to save your podcasts
Or


Welcome!
Craig explains Hacker's new bag of tricks. They are buying pre-made COVID-19 templates to fleece unsuspecting users.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand 'Drama Therapy' And 'Journalism' as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR's tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia's GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] Hey, welcome back, everybody. Craig Peterson here on WGAN. It's our last half hour together today, but we'll be back again next week. One till three here on WGAN every Saturday. Of course, I'm on with Matt Gagnon during drive times on Wednesday morning at seven 34, as we discuss the latest in technology news.
You've probably been in the hearing warnings. I've certainly been talking about them with Matt, about all of the nastiness that's going on right now with the hackers. And we're talking about soup to nuts hackers here. We're talking about nation States. In other words, countries like Russia and Iran and particularly China and all of the things they're trying to do to really mess us up.
It's a shame to see that, but we
[00:01:00] also have just regular old hackers. Those people typically in Eastern Europe who are just hoping to get their hands on a hundred thousand dollars from some rich American who doesn't deserve the money, because then, wow, this is great. It's important to them in their family for years.
In fact, their extended family for years. So they're doing everything they can to get money from us. The number of hack attempts has gone way up. I've seen numbers as high a, 300% through phishing attacks and various other attacks, including direct attacks on our firewalls, our websites on basically everything that is facing the internet.
So it's a real problem out there and threat actors, these bad guys are trying to take advantage of people as part of this pandemic. They're pretending that they are the World Health
[00:02:00] Organization, the Internal Revenue Service, the Centers for Disease Control or some government agency or NGO, as they say, non-governmental organizations.
There have been a lot of them coming out pretending to be from the United Kingdom's government, the government of Canada and the government of France. That is a very big deal because they're being successful at. Unsurprisingly, the COVID-19 phishing campaigns have just taken off. I'm looking at a chart right now, different page deployments. So it hit a peak around March 26th and it's been dropping.
But here's what these pages are that I'm talking about. These are pages up on the dark web, just regular webpage type pages, and bad guys. These bad
[00:03:00] actors go there and they can download templates. Templates of emails, templates of the website. So instead of taking a day or two to come up with a great copy of a website that looks just like the World Health Organization, all they have to do is pay 10 bucks, $10. For a set of templates that they can now use to send out to you, and me, emails that look like the World Health Organization. If we click on it, take us to a website that looks like a World Health Organization or one that makes it look like your computer was infected.
A lot of these templates have multiple pages, as well as emails, malicious web domains that can be inserted. The bad guys can rent a web domain and use that. This is regular marketing.
[00:04:00] Where you might have an affiliate and you use an affiliate code in order to, track that was my lead I want to get paid if they buy.
Well, they have affiliate codes for these bad websites. It's absolutely amazing. Then these credential phishing attackers have our information that they've taken from some hack online. There are some huge databases of our email addresses, usernames names, and passwords that are out of their huge databases.
They're using these databases here to try and get you to click on something. Because they know the last four of your social security number, they know your email address, they know your name. In many cases, they might even know your bank because what they'll do is use the information that they've stolen from, whatever it is,
[00:05:00] a clothing website and use that same email address and that same password to try and log into a number of bank websites.
Are you using the same email address and password to using multiple sites? No, you're not, are you? Because that's what they're doing. That's called credential stuffing and credential fishing. We've seen these landing page deployments go down a little bit, which makes sense because again, most of the bad guys have been doing it.
So let's talk about some of these spoofed websites. What do they look like? the domain is usually a giveaway, if you're paying attention.
So for instance, they might have a wastewater treatment.co. Dot N Z. So that's particular site is a World Health Organization, branded
[00:06:00] credential fishing template.
So you go to that page, you verify quote, unquote, your email, and your password. And now you're in. Now we know that there was supposedly a hack of the World Health Organization's credentials. A hard to tell if that's absolutely true or not, but they're copying the WHO's logo, color scheme and they're trying to get you to enter in your credential.
Same thing with the United States Center for Disease Control and looking at a spoof site right now. It's cdc.gov dot Coronavirus dot secure dot server dot shorter-term rental.org. Obviously it's not really shorter-term rental. So people look at it okay. cdc.gov coronavirus. Okay. That makes sense. It says authenticate with your email provider to generate a vaccine ID. It has quick login links for outlook, g-mail, office,
[00:07:00] EA, AOL, and Yahoo. It's asking for an email address and a password. So you can receive a vaccine ID, whatever the heck that is. This is a broad web email credential phishing template.
Here's another one here. This is a see matters dot com. Of course, it's coronavirus is what they're trying to get at here. Financial aid, details. It says, after an accounting audit of our records, we discovered that you are eligible for an instant amount of $1079.83 cents worth of financial aid. Upon submission, your request will be further reviewed by our accounting team. And the amount in question will be credited to your confirmed financial institution in a timeframe of 48 hours.
Again, fake. Here's another one. This is a get my payment website that's out there. And again, these are all templates that they pay their 10 bucks and they
[00:08:00] get a set of templates.
It makes it look like it's the IRS, but again, it's not. They are, IRS is URL, and if you check the SSL key signature that's not them either. So this one is to get my payment. It asks for your social security number, your date of birth, your full name and your zip or postal code. Okay. All right there and the IRS site, how's that for fun?
if you want the real IRS site, by the way, go to irs.gov and you can click through on there.
Here's another one. Get my payment, the government of Canada it's even in French as well. Emergency Canada, emergency response benefit. These things just go on and on, Canada revenue L'Agence du Revenu du Canada de Aussi en Francais. The United Kingdom, her Majesty's revenue and customs, it goes on and on.
So the bottom line here be very careful. The bad guys are out there.
[00:09:00] They've got these ready-made COVID-19 themed websites that they're stealing. They're renting, they're putting online and they have really been making a lot of money.
All right. When we get back, we're going to talk about Britain's hard lesson about blind trust in so-called scientific data.
You're listening to Craig Peterson here on WGAN an online Craig peterson.com.
Stick around. We'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses some of the steps to take to relaunch your team after the pandemic.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand 'Drama Therapy' And 'Journalism' as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR's tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia's GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] Hey everybody. Welcome back. Craig Peterson here on WGAN and online, of course, Craig peterson.com. Do you have any questions? You can always email me, M E @craigpeterson.com. Always glad to help out. Plus if you get on my email list, you'll find out about what I'm doing this week, what the pros and cons of everything are.
I will be sure to keep you up to date. We've got some very cool stuff coming up. We're making some, I think fantastic changes that are all for the better for you guys. Get more information out and doing it in a timely fashion. I mentioned before the break, your remote team, and I told you to brace yourselves here.
There is a great article that was in the Harvard business review this last week. It's talking about relaunching your remote team. Many of us have remote teams
[00:01:00] and the remote teams are good and they're bad. But in just a few short weeks meeting tools like Zoom, Microsoft teams, we've got WebEx teams, Google chat, Slack, they've gone from kind of a supplement where we might use them for remote workers. We might use them for the team to just keep some notes to each other. It's moved from that point to where it is really. The primary way of doing business internally. Those new tools to us, right? To many of us are really replacing the bubbler, the meetings, the emails, even frankly, or workspaces in our offices before.
Sometimes we had open plans, which are now being pretty heavily frowned upon. Cubes, which a lot of places are going back to. So people have individual spaces or offices. The latest studies are showing
[00:02:00] having an office actually increases your productivity, pretty substantially. We've now gone to our bedrooms, the kids old bedroom before they moved out, home offices, kitchen tables.
I'm on every week with Jim Polito. He is the morning drive host on two of the biggest stations in Massachusetts and Jim is running the show from his kitchen table, with his dog, occasionally barking there in the back background. I
t has changed for everyone. I was at a webinar. Yeah, a three-day conference. It was held on the web, last weekend, and they're calling this the great reset and it's a term I've heard other people use as well, but the great reset means a whole different world when it comes to working from home.
As we're trying to relaunch our teams re-orient based on the
[00:03:00] new realities that are out there.
So let's go through what Harvard has to say that we really need to be paying attention to.
Number one, they say revisit your shared purpose when we have all of these team members and they're all different, a little, hopefully, they are and different people with different ways of thinking, bring different things to the business.
It's all of these different interaction styles, like the MBTI styles that really help to make our organization strong. But now that we're all at home and many of us will continue to be at home. Do the team members understand what they're supposed to be doing? Clear and specific goals.
Does everybody on a team understand what that team is supposed to be able to accomplish? What the goals are for the team. Because again, we pulled the
[00:04:00] trigger so fast on this. Many of us just didn't get it all together we're relaunching.
Management has to discuss how we can get these teams going here, let them know clearly what the business goals are.
Let them know clearly what the strategy is because most businesses have changed because of the pandemic, small businesses like mine. When something like this happens, tend to go out of business. But they come back in a completely different way. some of the same people, the same owners, but now a much different angle than what they had before.
Big businesses. They can't pivot that quickly. They're struggling to try to figure out what they should do. They go for cost-cutting measures. That's usually the first thing that they end up doing. Does your team do your teams? No, what they should be doing and have the team members themselves express their perspective. It was here
[00:05:00] on how the organization and the team's purpose might have changed.
Second here, reassess your available resources. In the last segment, we talked about VPNs, the pros and cons of VPNs. What's really going on here while this relaunch here is the time to re-examine. In the resource column, that means what information or data do you have?
What kind of budgets do have? What kind of equipment, software networks do you have? That's going to help the team advance their goals. No, I don't really have to have a detailed list. Everything that's necessary, but we need to reach a general consensus about what the team needs, what are the resources, and how do we access them?
Everybody needs to be on the same page about how the pandemic has affected the team's budget. Also the partnerships.
[00:06:00] Remember we all have vendors we buy from and we all have customers or clients that we work with and we're selling to. Do we understand how their organizations have changed because of the pandemic?
We have to next understand our team members' constraints. Many of us are working from home with our family around for the very first time. Our kids are not in school and most school districts are not reopening until the fall of 2020. How do you deal with that? It was one thing when the kids stayed with grandma and grandpa during the summer, but we're talking about a lot of months now, does that make sense?
Can we even handle that? So some of our team members may need a little bit of assistance here in figuring out how can they juggle their family responsibilities. New family responsibilities they haven't had before
[00:07:00] with their new work responsibility and the need to be available at certain times. So in many cases, the answer to that from businesses is we're going to be flexible.
We're going to allow flex hours who used to talk about mother's hours, but now the kids are home all day long. So we've got to help them with this manage deadline expectations, and also maybe rebalance some of the workloads between all of the people. Within the workgroups, we've got to reestablish norms.
We're talking about how people conduct themselves in meetings, et cetera. it's really easy to be on something like Slack and make some snarky comment or in email or on a conference call that can really be hurtful. That can really cause disharmony within a team. So we've got to figure out what the next norms are.
It's okay to wear pajama bottoms, but you gotta
[00:08:00] be dressed professionally on top. Cause that's what the cameras going to get, if that's what you want, that's great. Do that. We should also be discussing how often team members should connect virtually during the week and what digital tools they should be using.
Things like email can be great for delayed communication, but many people just drop everything into WebEx teams and expect other people to snap to whether it's WebEx teams or Slack or whatever it might be. Okay.
So when you're choosing which tools are best for discussion, we need to be very sensitive to the fact that real-time video chatis not the same as face to face interaction. Because if you were to walk by their cubicle or their workspace, you'd see, they were busy and you're not going to interrupt them right there. They're in a flow or the, maybe they're in a meeting. Dropping in on him. I'm going to be very bad when now
[00:09:00] you disrupted them because you've popped up a Zoom meeting in front of them.
Zoom fatigue is real. So think about all of these tips and tricks and techniques. You'll find more about it. On my [email protected]. Harvard business school had this article. It is great. If you're trying to manage some teams, make sure you read it. Craig peterson.com and I'm right here on WGAN. I'll be back also Wednesday morning at seven 34 with Matt.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses VPNs, How they work, and Why they might not be protecting you as much as you think.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand 'Drama Therapy' And 'Journalism' as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR's tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia's GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] Hey everybody. Craig Peterson here on WGAN. Welcome. welcome. Hey, if you missed the first hour, I just want to remind you that you can catch it online. I podcast this whole show every week on your favorite podcasting application or website. Just look for me, Craig Peterson, or visit Craig Peterson dot com. Cause I have them all there as well.
You did miss a lot that first hour because we talked about the new website attacks that are underway that are hurting you, me, as well as businesses that have just set up websites recently. It is a bad state of affairs. We talked about company identity-related breaches that are happening. The coming disruption to college. What Google Chrome is doing to stop some of these resource-draining ads. That are
[00:01:00] actually rather, I wouldn't say the malicious, but they are stealing from you. They're using your computer to mine for Bitcoin for them. I suspect this is actually going to get a lot worse. Maybe that's why Google is finally taking action with the Chrome browser.
The reason I think that this is really going to start taking off is that the Bitcoin value is about to be halved. What happens at that point, normally in the marketplace, if a stock's worth, let's say a hundred dollars and they halve it, it's worth $50. There's a lot of pressure for that stock value to increase back up to the pre-split amount, back up to the hundred dollars point.
What the problem is when it comes to these cryptocurrencies is yes indeed they can go ahead and split it and say it's worth half of what it used to be worth. But now the people that are mining for the Bitcoins are in for a whole different world. And the different world is, Hey, I can
[00:02:00] barely break even, right now, in fact, in most places like here in the Northeast, electricity is so expensive that it costs you more to mine for Bitcoin, and it cost you more than electricity than the Bitcoin is worth. So once they halve the value, now, all of a sudden it's just not worth mining anymore. So that's going to be an interesting result.
Another really interesting analysis too, of Bitcoin this week and this kind of U-shaped factor that it has based on the key sizes and little too geeky to get into here.
This is not a Bitcoin show. But it is a show about your security, what you can do and what you should do just this week, we installed some network equipment, a whole new set of network equipment for a lady named Sue down in mass and we were talking with Sue about it. We had preconfigured everything shipped it out, helped her with
[00:03:00] it. She was having some problems trying to figure out. Okay. So what plugs into what I think next time, maybe we'll just make sure everything's all plugged in before we ship it out. But we had one our guys go by, he only lives about 20 minutes away from Sue. He went and five minutes later, everything was done.
But while he was there installing this whole new network for Sue's company, there was an interesting conversation that ensued because Sue told him that I was anti-VPN. As well as a couple of other things that I was against, the truth is yeah, I'm anti these commercial VPN services that they keep trying to sell you.
I read a summary this week from a respected place. They must have people writing articles now that don't know what they're doing. I've certainly seen that, people in third world countries, second world countries, that don't know what they're doing. But they're cheap to hire as a writer. So they hire them as
[00:04:00] writers and off they go with their cheapness, not really understanding things.
This article said," Hey, yeah, you should use a VPN because it's going to keep your data safe. It keeps it encrypted. It's great. great." I, of course. Just rolled my eyes and lost respect for them.
VPNs have a use, but it's very limited use and that's what Sue had caught on when she attended one of my webinars talking about VPNs and how you can best use them. They are useful. They were invented in order to help businesses with their data and keep their data safe, connect offices together, et cetera.
They are not great for just going to your bank website. In fact, you could be in more of a security problem if you use a VPN for your bank than if you don't use a VPN for your bank. So I'll just keep that all straight.
I figured now's a good time to talk about this. There's a great article in
[00:05:00] dark reading this week that I put up on my website as well. You can find it there.
This article is talking about challenges that exist with VPNs, and this is really a big deal. A VPN can be a step in the right direction. If someone's trying to use a VPN, they're probably trying to do the right thing, but it's really not a be-all and end-all when it comes to security. Not only does it fall short in many ways, but as I've explained in my webinars, it takes a lot longer to explain than I have time for right now. If you want to catch a criminal, you go to where the criminals are.
If you want to find people that are trying to keep their information secret or quiet, you go to where the VPN exit points are and that's exactly what's been happening. It isn't just the five eyes or the nine eyes or the 14 eyes it's organized crime. It's just all over the place. Be very careful. In March of 2020, all of a sudden
[00:06:00] everything changed. Everything shifted. We saw a huge shift in people starting to work from home. Some businesses had to stay open. They didn't necessarily have to have the employees right there in the office. And according to them, Gartner survey, that just happened here with chief financial officers. Gartner's reporting that 74% of organizations will move at least 5% of their previously onsite workforce to permanently remote positions following them pandemic. That is pretty good. Three-quarters of all businesses. Are going to move, give or take one 20th of their onsite workers to offsite.
I was going to have a major impact on everything, on real estate and obviously the technology side too. But let's talk a little bit about VPNs right now and what are they good for? What are they not good for? So point number one. VPNs now,
[00:07:00] remember I said they're great for businesses, point to point, they replaced the leased lines. That's what they were invented for initially.
But typical traditional VPNs have a device that's at the business office. That piece, that device, that piece of hardware can usually only handle a certain number of users. That's also true with the data line that's coming into your office. If you don't have enough bandwidth to support all of these things. People accessing their desktops, or in some cases I know businesses that have a database running at the main office.
Then there are clients, there's software on people's remote workstations that make hundreds of not thousands of requests against this database. That's not the best way to do it by the way.
If you're interested, maybe we can talk about that sometime. I'll put something up in one of the webinars.
Here's the problem with that?
[00:08:00] The VPN and the data lines can only handle just so much data. Many businesses came up with the specs for their VPN appliances. Pre- COVID-19, Pre pandemic. How many people were actually fully using it?
Then, for instance, we have a client an auto dealer, and the only time they used the VPN was when the comptroller was out of training or something, it might happen during the weekend. One of the supervisors would have to hop on.
That's a lot different than once a pandemic starts. Now there are all of a sudden focused on their websites and their online sales and everything else that's going on. So it's a huge difference. So that surge and teleworking that occurred really made these VPNs fail.
Companies struggling to figure out how to scale to support so many users. So that's part of what had been helping businesses with. There's a lot of creative approaches
[00:09:00] going on, such as limiting VPN use to certain workers. There have been businesses that have been taking the shifts and moving them around.
So there's a shift that starts at eight. I need another one that starts at 10 and another one that starts at noon so that there are fewer people on the VPN. Maybe they're only on the VPN for a certain number of hours, but frankly, those are not long term viable strategies. VPNs are also failing to balance productivity and security.
Because let me tell you productivity and security have been at loggerheads with each other for a very long time and VPNs don't fix this problem. In fact, they make it worse. Because now not only are you overloading the VPN, all of the gateways and the firewalls are slowing down everybody's productivity. These home users on their home networks with home computers that are
[00:10:00] infected are now connecting to the network and that infection's getting transferred.
Unfortunately, that transfer is to the main office. Hey, a VPN ain't gonna help with that.
Mobile devices. VPNs are encrypted and the encryption that they use is very complex and it causes problems on our devices. Our mobile devices were not made to handle that. They have to continually update their keys, they're sharing the public keys and their session key. They just can't handle it. Frankly, VPNs are not built for the modern workforce.
There are so many ways this really should be done and unfortunately is not being done. VPNs. They are not a panacea.
When we come back, let's talk about our remote teams. We've had months. Time to relaunch.
[00:11:00] You're listening to Craig Peterson right here on WGAN and [email protected].
Stick around. I'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig explains why he knows that these commercial VPN companies are lying to you and what you can do about it.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand 'Drama Therapy' And 'Journalism' as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR's tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia's GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] If you've been using a VPN service. My gosh, I've got news for you. We're going to talk about what happened this week.
Hey, it's Craig Peterson here. Thanks for joining me. If you want to get my whole show, all of the segments, you'll find them [email protected]. We're starting to do a lot more videos, so make sure you check that out. We might even be doing some of these shows live Facebook and YouTube lives as well.
Let me know what you think. What's the best. A way for you to maybe watch some of this video. Is it one of these lives is just going to the website. Do you prefer, you listened to me on the radio? you can find me podcast almost everywhere and I always ask them, so your question's right here. You can just email [email protected].
Let me know what
[00:01:00] works best for you guys. Okay. I know on the radio, it's absolutely fantastic. And I have a lot of followers there and I love answering your questions. I always get back to you. It might take me a few days, depending on what's going on. Sometimes we get hot on a project or we're trying to secure a company.
That's had a hack. We just had one. Where the company's CFO's laptop was having some problems. And so the MSP, the managed services provider that had them as a client called us up, knowing that we are experts in the cybersecurity front and said, Hey, what should I do? What can I do? this is it's just weird.
And so we got involved and we found it, the CFO's laptop. The chief financial officer, a company that I don't know is I think it's 30 million a year. Had been hacked and had, what's known as an act of Chinese back door, which
[00:02:00] means that the Chinese or getting in and looking at anything they wanted to, whenever they wanted to, et cetera, go very bad stuff.
You don't want that to happen to you? That's for sure. So this is why I'm doing the training. I'm trying to help everybody understand this. We do it on the radio, but we also do it live in person on video. So we do webinars and things too, as well as our newsletter. you can get everything you want for free online and going to one place, one consistent place.
you can trust somebody like me. Who has been doing it information technology for more than 40 years and has been doing cybersecurity for more than 20 years. I think I'm a good place to go. The one-stop-shop for all this information. So thanks to the seem to me here. You can hear me every week.
Right here. You can go online to Craig peterson.com/subscribe bribe. And that'll get you on my newsletter
[00:03:00] in the, in there, I'll have some links to some of the videos and some of the pieces of training we're doing, and I'm going to also be doing some things like the Facebook lives and other YouTube lives and things.
and so if you're interested in that, make sure you let me know. I'll probably send an email out, asking people if you're interested and then I will, We'll let you know when we're going live and what the topic will be, and you can always ask questions and that's the whole idea behind those lives, right?
A little bit. So, let's get into our VPN problem. I did a big training on VPNs of few times. I did 22 webinars on some training in the March timeframe this year. And VPN hands are something that almost no one really understands to me. It's been very disappointing. So let's start about, let's talk about what a VPN is.
Let's start at the very beginning I had, for instance, going to my
[00:04:00] home office. Back in the day, this would 30 years ago now I don't drink really? Yeah. Somewhere around 30 years ago. And I had two T-one data lines coming into my home and we were Watchers unheard of back in the day. So each of those T-one lines was about one and a half megabits.
So I had almost three megabits worth of data coming in. In and out of my house and I had some web servers and I use them for my business and stuff way back then. Oh, same business I have today, by the way. And it was just funny. What was the stamp gene? How expensive it was now? I also had my main office cause I owned a building and I had 50 employees.
In the building and I needed to be able to share data back and forth and have, get, have access to the file. Servers have one centralized phone system, All of that sort of stuff. And 30 years ago, the only way to do that was to have
[00:05:00] lease line, come into my house, and also have a leased line going from my house to the office building.
And then once it got to the building, of course, we owned the hall. Own the whole building. And back then it was all wires, little coaxial cables that ran around for ethernet and we'd got to the building and it got dispersed to the points that needed to be at and went into our data center that we have there and everything else.
Along came the VPN technology. And it was a godsend because I was spending $5,000 a month to connect to my office at my house, to my office in our building. Mine. Can't in my building to my house $5,000 a month in 30, 30 years ago. Okay. So that was serious money. I don't know what 5,000 is worth today with inflation, probably 25.
probably not that much, but, it's worth a lot more. So when VPNs came in
[00:06:00] and internet connections got cheaper, I no longer had to pay, to have a least align, a dedicated, aligned, going from my office to my office building. Now, what I could do is just have an internet connection at both sides and then use a VPN and my networks, we're all connected.
That's what VPN stands for. It's a virtual private network. It lets one point get to the other point. And the way we're using them today is where the problem starts because what we're doing now is you have a VPN then going from your home network or from your laptop to the office, you have now connected all of the devices in your home.
Okay. Or on your network. If your whole network is VPN, all of those devices are now connected. To the other side where the VPN server is.
[00:07:00] So if you have any malware, if you have any of these Chinese back doors, they can not only get on your computer. They can get on any computer, the VPN hooked up to if it's not configured properly if it's not monitored properly if you don't have intrusion detection and prevention systems on both sides of that VPN.
And when you're using one of these free VPN services or the commercial VPN services, you don't have that at all. Now, many of us are looking at it saying, I'm using XYZ VPN. I heard it advertised here or there. My friends use it and it's five bucks a month or 10 bucks a month or 20 bucks a month.
They cannot provide you with the service you need for that. And in my webinar on VPN, I actually. Break down the numbers and show you how it's completely infeasible for
[00:08:00] them to provide it at those types of numbers. So what do they do? they track you. They sell your data and also the bad guys. If your VPN isn't with a bad guy, cause some of these VPNs are actually hosted by Ben, add guys to purposely track you.
Okay. Purposely steal your data. Now, if you want to go where the money is, you Rob a bank, right? Isn't that the whole idea? why did you Rob banks? Because that's where the money was now. Sutton. Apparently never said that, but the concepts are a good ones. So if you want to steal people's data that people want to keep secure because they're doing banking or other things on it.
Where are you going to stake out? Where are you going to put down those tent posts? Where are you going to be watching everyone going in and out? You're going to be watching the VPN server
[00:09:00] at the other side. So you're paying for a VPN service or heaven forbid using a free one. And you're going from your laptop.
Securely probably depends. We go into details on that in the VPN, webinar, and pieces of training, you go fairly securely from your laptop to the VPN server, which is hosted in a data center, probably a public day data center and is under attack. And if they're not maintaining that properly and they get nailed with a zero-day attack, all kinds of stuff can get exposed including you.
So if you're trying to go to your bank and you're using a VPN, cause you're sitting in a cafe, you're going from the cafe. To the VPN service provider. And remember you are also now going from the VPM service provider through the internet, to your bank. These VPNs do not terminate at your bank. These VPNs
[00:10:00] terminate at the VP and servers though, whoever's hosting it.
So VPN mentor revealed this week. That they found seven virtual private networks left 1.2 terabytes of private user data online. 1.2 terabyte. That's a lot. Okay. A terabyte is 1,024 gigabytes. And in case you don't know, so the impacted services were UFO, VPN fast VPN free VPN, super VPN flash, VPN, secure VPN, and rabbit VPN.
Now it had personally identifiable information for potentially over 20 million VPN users. Why would 20 million users email addresses home addresses passwords in plain text, by the way, IP addresses? Why would that take 1.2 terabytes? it wouldn't however,
[00:11:00] they had full logs of everywhere. They went online.
And all of those services that I named are quote, no-log VPN services, meaning, Oh, we don't track you. We don't log you. We're not selling your data. Guess what? This is absolute proof of that. They're not no-log that they were logging. And that probably means that they were selling that data wide log it.
Why use up all of that space. If you're not going to use it somehow. So be careful guys. Okay. yeah, it's, there's a lot of detail. I've got the article up on my [email protected]. Great article from security affairs, but, It's that's a lot of arms, one sentence. It's a real problem. VPNs are a real problem.
So make sure you attend my VPN training, where we go into detail on this. I
[00:12:00] don't sell a VPN. Okay. That you can use privately. We do commercial VPNs and we do them. All right. For employees. Connecting to the businesses and it has to be done, Or you are hyper exposed. Anyways, take care of everybody.
Make sure you visit me online. Sign up for my email list. Craig peterson.com/subscribe.
We're going to lose some radio stations. Others are sticking with me.
So stick around through the news. Cause we'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses the Hack that could cost you your business.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand 'Drama Therapy' And 'Journalism' as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR's tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia's GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] Hey, have you been paying attention? And I know you have, 'cause you're the best and brightest, you know about phishing and not to click on links you don't know about. there's another one, and this next one is taking advantage of your knowledge about phishing.
Hey Craig, Peterson here. Thanks for joining me.
Let's talk a little bit about it. Yes, we've man, we've beaten. I think the phishing horse to death bottom line because phishing has been such a problem for so long, but for those that aren't really up-on it, you've heard the term, a little bit about, don't click on things, phishing.
It has been very effective lately. We have a lot of people working from home. That's going to continue for months and years to come, frankly, a very high percentage of us. It'll just be at home, in a bedroom or in the living room on the couch.
[00:01:00] That's been happening a lot. those of us who are sitting at home.
Are probably not as aware as we should be to all of the problems that are going on out there. Now we have some training for employees. A lot of places have stuff. I really love what we have and we have training for if you're in HIPAA. if you are CMMC I tar D FARs, right? All of these different regulations that are out there, even PCI training that walks people through and gives them questions and reminds them about the training.
If your business does not have this sort of training. Get it right? Whether you get it from me or you get it from someone else, please get that training so that you can keep up on all of these techniques. The bad guys are using phishing is where they are sending out messages, trying to get you to do
[00:02:00] something right.
Trying to get you to react. what kind of reaction are we talking about here? They can be just a link that you click on. The email looks legit, right? I've been getting every week email, supposedly from Amazon telling me that my. Amazon Prime membership has expired. it hasn't the card did. And now because my credit card on file has been expired.
So has my Amazon membership, right? no, none of that's true, but some of these emails you take a second glance. You say, Whoa, wait a minute then. Okay. That looks legit. It's got Amazon's logo. It's worded like Amazon might word it. And then if you click on it, it's going to take you to a site that pretends to be Amazon and asks you for your credit card update.
So you're going to give a credit card number you're going to give. an expiration date, right? You're going to put all of this stuff
[00:03:00] in, cause you don't want to lose your Amazon prime membership. Now I'm just using Amazon prime as an example, this is happening all the way across the board with tons of.
Banks credit unions. Financial institutions are a really great target. I've seen them from supposedly, right? E-bay I've seen them from the IRS law enforcement. All right. All the way across the board, it is a serious problem. So how do we deal with that problem while we care, but what we're clicking on, but I want to talk about a simple hack may not have heard about before that can just destroy your business and what it is done?
What these guys are doing is called Typosquatting papal, squatting, and typos squatting is where you think you're going to google.com, but maybe you ended
[00:04:00] [email protected]. You forgot the E or maybe it's Google with three O's. Instead of google.com or if you have one of these home routers, even if you're a business and you're not using at least pro or hardware, like the Cisco go hardware.
Then you've got an additional problem because what the bad guys have been doing is taking over control of your router. So many of them have never been patched via Rob, have you ever updated your rudder? Have you ever. They did the firmware new router, right? Most people don't and most rodders don't do it automatically, and they only will do it for me, maybe a couple of years, even if they do it automatically, I just had a client.
We were helping out. We were grading them to the prosumer, the Cisco go hardware. And. She said, yeah, I have been, I check every week. That's how diligent she was. So
[00:05:00] she went to the vendor's website, checked what the latest release of firmware was, and then checked her machine to see what release of more she had.
Guess what it was the same release. But it had been two years since the manufacturer had issued any updates to the firmware. So her modem was completely vulnerable. So make sure you do have a modem that is not only up to date, but really, even for home users, you've got to get the prosumer stuff. I recommend the Cisco stuff.
You don't have to get it from me. But Cisco goes something you might want to look at. You can get it online. I think it's even available on Amazon. I've seen it over there before, and it's not that much more expensive if you just buy it and do it yourself. If you want me to do it, obviously we're going to get involved to help configure it and help you install it and everything.
So there are additional charges, but let's get back to typesquatting. That's
[00:06:00] different than the pad guys taking over your router. And when you type in the correct google.com, you're going to two of them. Okay. Okay. Many of these types of domains. Are either purchased for resale. They redirect you to a real offer and it a shady way.
Many times what they're doing is they'll use a coupon if you will code that gives them credit for the sale. So you're, you are actually going to the real Amazon. And what happens is there's a referral. Bounty, if you will, that they are paid by sending you to Amazon, even though they didn't really send you to Amazon.
So there's a lot of stuff that they're doing. And so forth labs found that roughly 2.7% of 15,000 domain names that they looked at. Two and a half, 2.7% were associated with some form of
[00:07:00] cybercrime, including hacking phishing online fraud or spamming. If you think that 2.7% is a small number, remember there's at least 360 million registered domain.
So let's do a little bit of mathematics here. If we say (360) 100-0000. Times 0.027. So that's 2.7%. So that is nine, almost 10 million websites. If those numbers, if you can really just interpolate it across all registered domains. So there's a lot of easy examples of type typo. Squatting. Security research has found a perfect.
Replica of reddit.com, Tom, which is one of the five most visited websites online under
[00:08:00] reddit.co. Which is.co is Columbia's domain by the way. So they had even acquired an SSL certificate for reddit.co. So the majority of the web browsers wouldn't even tell you that there might be a problem. So we gotta be very careful.
We've seen campaigns in the past for Netflix dot O M again, a typo, right? You meant to type.com Citibank dot O M. Which is, by the way, Oman's, domain suffix. Now that doesn't mean that Columbia or Oman are actively involved in this, or even that the people that did this are from Columbia or Amman. It just means it was the domain was registered there.
Registrars are what it's called. Cameroon's other popular one.cm, Hulu, Netflix, 12 million visits over a three month period. That's pretty amazing here. So anyway, let's not do that. Be careful with typos
[00:09:00] squatting, pay close attention. When you're typing in the URLs. I have seen based on my website, just X, a lot of people use Google.
Instead of typing in the direct URL. So pay attention to that. All right. Stick around. When we come back, we've got a mortar cocktail. We're going to get into the whole VPN story this week. I've got a big I told you so pink is the bottom line here and make sure you're on my email list.
You can sign up at Craig peterson.com/subscribe.
Stick around because we'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig finishes his discussion on Stalkerware and then gets into IOS and Android.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand 'Drama Therapy' And 'Journalism' as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR's tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia's GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] Hi everybody. Craig Peterson here. We've been talking about stalkerware. I'm going to finish that up right now. And then we're getting into that simple hack that could tank your business. In fact, all of your retirement and savings as well.
This is Craig Peterson. I'm so glad to have you guys with us today. We are also on [email protected]. You can get my newsletter just by going to Craig peterson.com/subscribe. You'll get all of my show notes every week. The notes that I used for this show, as well as the notes that I'm using for my appearances on various radio stations throughout New England.
And also now I am starting to put together some videos, little training videos that we will be releasing too. So keep an eye out for those. Let's finish up the whole thing about stock aware and iOS. Of course
[00:01:00] Apple's operating system for the iPhone, as well as for the iPad. In the last segment, I told you how to get into the settings to look, to see if your device was managed.
IOS is a difficult one when it comes to stock or where the easiest way for the bad guys to track you is by using mobile device management. As I mentioned a little bit earlier, so that's all well and good, right? But there are ways of hiding software on the Apple device, and it's almost impossible for you to detect it's there.
That's how bad some of this stuff is. And Apple does not make it easy for you to get in and look around unlike Android, that. Pretty darn easy to get in and poke around if you know what you're doing and Apple does that, they restrict it for really good security reasons. The types of reasons that you would hope
[00:02:00] Apple or one of these other companies was actually do it, which is because of course, they don't want.
Bad guys doing bad things on your phone. So the access to this sort of thing is restricted. So that makes it difficult. So you might have to just go on some clues. So what are the clues? In this case, and this is true for Android. The clues are that your phone is running hot. Your phone is getting slow.
You're not sure what's happening. Maybe your data plan is getting eaten up. Those are all pretty bad things to happen to you. And they're all things that might indicate that there is a problem, keyboard, keys if they have a leg. Yeah. Your type. Remember that there are no real keyboards on phones anymore.
It's all touch screen. But if you're typing on that screen and you notice that it takes
[00:03:00] a while. For those, it's a fraction of a second for those characters to come up. Whereas before it was instantaneous, that also could be assigned that there's a key logger on the device. All right. you're running out of space.
That's a dead giveaway because if you're not downloading it a lot of stuff, why would you be running out of space on your phone? So look at all of those things also on iOS at the very top of the screen. There's a little thing that indicates that, right up here on the upper right-hand side, it indicates that their location services are being used.
Now that is legitimate in some cases, but it could be a bad guy monitoring you this stock or where. So again, if you want to look at location services, If they're at least using those legitimately, you can go into your settings, location services, and you can see all of the programs that have requested
[00:04:00] access to your location.
And then the ones that have had it recently, we'll have a little blue arrow next to them to let you know that it's been used recently. And that's going to tell you a whole lot too. Okay. let's see. Let's move on here to our Android friends. I am not a fan, of antivirus software. Cause it's pretty much useless, but there are some things that can do if you're not doing anything to protect yourself.
So on the Android side, there's Kaspersky as well as some others. Now, Apple does not allow anti-virus software. On their Apple app store for good reason, because it gained access to a lot of things that are shouldn't have access to it often can be malicious and in the iOS world as a general rule, it's not going to do any good to for you anyways, but on the.
Android side. If you go to the google play store,
[00:05:00] you'll see a bunch of different antiviruses. Now, Kaspersky is another one that's like antivirus, right? Kaspersky is a Russian company and they have had antivirus software for quite a while. And their antivirus software is actually illegal to use in the federal government.
Now you might ask why is that the case? there are ties alleged to between Kaspersky Labs and the Russian government and maybe even the Russian mafia. That's why? So the federal government has removed Kaspersky, antivirus software from all of their devices. And frankly, you probably should too, but this is one case where again if you're not that worried about it and you like inexpensive and you don't care if the Ruski ruskis again and get access to your information, you might want to look for it for that because of Kaspersky labs.
With their
[00:06:00] antivirus software now has a feature that allows you to check for spyware, which is really cool. So they've really upgraded their antivirus pro, where they upgraded the software last year. And yeah, we'll tell you about stock or wherever. So those jealous partners who want to spy on their ex and lovers.
They can find out. So 2018, I'm looking at some stats right now because ski lab products detected stock or whatever, programmed on 60,000, almost unique mobile devices proving the severity of the threat according to yes Bursky. So have a look at it. It is called their mobile antivirus product and they detected not a virus, colon monitor.
That's what they'll do. Yeah. So I have a look at that. I am looking at their stats. There are a bunch of different pieces of spyware that they've detected. Did, stock to where is real
[00:07:00] don't fool yourself. I will want to get, let you guys know about a couple of things I'm doing right now. We are going to be talking in the next segment about this simple hack that can just total your business.
We're also going to be talking about VPN, but I can't dive into them at the level that I'd like to be able to hear on the radio. And if you're watching this on video, this is again, it's a short video to give you some basic understandings. So if you want more, if you want a step by step walkthrough where I am clicking on it, and you are looking over my shoulder, what I'm doing, you have to attend one of my pieces of training or watch one of the training videos if you've registered.
So there is only one way to do that as well. And that is to go to Craig peterson.com/subscribe. Now that's going to get you on to my
[00:08:00] newsletter list. Now, the newsletter list, isn't something where I'm just pounding you constantly, right? I really want to help you guys out. And I went through just yesterday.
All of the. Collateral materials that we produced. Do you remember last summer? I did the security summer where we had a different white paper that we had written and distributed every day. And some of these were two pages. Some of them are five or six pages. Plus we've had small business security guides.
You've got the security reboot guide. We've got a whole bunch of stuff. I counted them. There are over 50 of those that we have written and given away. Very important stuff for small businesses, very important stuff for home users as well. And you can always ignore some of that technical detail.
If you're a home user, you're sitting there and say, I'm not that
[00:09:00] technical. I don't know what to do. Okay. But it is very important. And if you're thinking about maybe. Not just getting into a computer security career, but make a few more bucks at the office because now you can say, Hey, I know this about security or better yet.
You've taken some courses that we offer as well as others, but some courses. That you've got a certificate now, and you can get, maybe get that raise that you've been hoping to get forever. So make sure you check it out.
Craig peterson.com/subscribe online, stick around.
We'll be right back. When you talk about the simple hack, what are the bad guys doing right now that mess with us?
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses Stalkerware and explains why you should be concerned.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand 'Drama Therapy' And 'Journalism' as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR's tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia's GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
[00:00:00] Hey, there is one simple hack that could ruin your business and ruin your credit and steal all of your money. And they're going after it today, against you.
Craig Peterson, you recognize the voice so glad to be with you. You can find me online at Craig. Peterson.com. We got trainings coming up for people. It's really important to understand what's happening? How you can protect yourself? How you can protect your business? And we're going to be talking a lot about that here today.
We're going to talk about this simple hack that can tank your whole business. We'll talk about VPNs. We have before. And I'm not a fan of, I'll tell you a little bit more about why I had a whole training course on VPNs and the dangers of VPNs. And huge dangers people just started using them.
So we'll get into that a little bit. I love this whole
[00:01:00] drama therapy. Now being branded as STEM science, technology engineering mathematics will tell you why universities are doing that. And the DOJ here telling one America news network that. Maybe they should call the FBI about NPR. So a kid into that Google is peeking into Android data.
Again. Now we've talked about this before. It's absolutely not to a Google gets away with, and it turns out they're doing something that Microsoft did years ago and got sued by every government in the world and lost every government in the world. So what's Google up to there for you. Poor Android users.
Russia's. Hackers they're GRU hackers have hit the U S government. We're going to talk about that one and your next smartphone may be a lot harder to scratch. And of course, we'll get into that one as well. So a whole lot to talk about today. But first, we're going to talk about
[00:02:00] how to find smartware. it is smart, but this is stock they're on your phone.
Now you may not be aware of this, but there are ways to monitor everything that you're doing on your phone and the best way to do it really is installing one of these apps that kind of hide now. This is particularly true for Android. This is true for you. Windows PCs to a slide, the lesser degree. It is true for your max as well.
So with the stocker where what you can do is look at the keystrokes, record them all. Do screen captures, usually grabs a frame if you will. What's on the screen every minute or so, so that it's not chewing up all of your disc space, but you can go all the way up to a live video so that you are tracking everything that's going on while someone's logged into a computer.
[00:03:00] So it's designed specifically because it is stalker where to run in the background of the computer. To make it very hard to see. And most of the antivirus software out there just won't catch it. If you have the advanced malware protection that's available through us and from Cisco then yeah.
You're probably going to be able to detect it, but it is designed to hide. So there's a high degree of probability that it is hiding and it's probably hiding pretty darn it's keeping tabs on. Everything on your phone. So your personal details are going to get leaked out. And we're talking about having access to all of your contacts, all of your applications, knowing what's going on, it may show up as an application on your phone.
It may not show up as an application. Same thing on your windows side. And this is a rich source of information for people,
[00:04:00] because if they can get the stock aware on your computer, they know pretty much everything they might need to know about you. You've gotta be very careful. It can track your location, record your phone calls.
Obviously your text messages steal the passwords to the social media accounts or email account or access that you're logging into through your phone reveal, your contacts, photos. Emails and even end to end encrypted communications, because remember what happens with these things like WhatsApp, et cetera, you have to be able to read that message.
Don't you, it's not good to you. If it shows you a bunch of Google. That is the recorded, encrypted, I should say message that was passed through. You need to see the clear text. So if you can see the clear text on the device, the stocker work and see it as well. Now we've found that in for
[00:05:00] the most part, the stock aware is really aimed at people that.
That, might be involved as activists. For instance, you have a lot of government agencies that do it. you have no activists. Of course, we're talking about socialists countries, right? It's illegal to do it here in the U S but every socialist country out there. Does it to some degree or another, the more socialist you are, the more they do it.
Like China, for instance of courses using stock or where by demand, it's the law. You will go to jail. If you don't have stock go. Where on your smartphone? Venezuela, Brazil. Cuba, some examples of some very socialist countries that are doing all of this, where you don't have the rights that you might want right there.
The typical Marxists socialist countries that are out there. So the average person doesn't have to worry about it too much. Is that what's your thinking? Because in fact, what happened is that the average person, right?
[00:06:00] Can be the target of stocker, where if that person has someone that wants to monitor them.
So who might want to monitor you for instance? obviously, maybe a lover, ex girlfriend, boyfriend, ex lover, maybe a jealous person. Who's just a third. Party, maybe your best friend, right? You we're always hearing about somebody marrying the husband or the brother or sister of someone that they're dating anybody who has physical access to your device could potentially.
Put stock aware on it. And that's where I'm constantly warning people. If you work with China, be very cautious. And if you go to China, the same thing applies because they will go into hotel rooms. They've been caught doing it before and they'll copy all of the contents of your computer. So I'll make sure everything is encrypted.
You probably want to turn off your computer.
[00:07:00] Entirely all the way down so that they can't use some of the techniques that will look into the memory of the computer to try and find the encryption key, because it is kept in the memory. There's some really cool techniques to do that. It's some pretty simple one.
So shut it all the way down. But. These people that want to monitor us. If they have access to it, they can do it. victims of domestic abuse. They're a common, person that could have stock or where the abuser puts it on the phone, because usually abuse is about controlling somebody. And if you're controlling them, you want to see what they're doing, what they're saying online.
It's a very modern concern, but it's a real. Concern. We need to be careful of a motherboard had a really good little article on it recently. Now, one of the things that is happening right now to fight back are the ads for the stocker where ads have been appearing all
[00:08:00] over social media. So you can go to Facebook and see had for stock or where, It's monitors spy on. and so now there's new. Policies that are just going into effect. I think they might go into effect August, but w new policies are going to affect by all these major social media sites that say we will not accept advertising for stocker war, but unfortunately there is a loophole when it comes to advertising for style or where, because that's same software.
Can be advertised as something to monitor your kids online. And we all want to do that. Don't we, while I'm on a monitor or kids and make sure they're not going to bad places and even more, we want to make sure they're not being influenced by a bad influence, maybe bit of a pedophile or something. You just don't want that to happen.
So what do you do? If you are a Mac user, I want you to visit this site right
[00:09:00] now. I want you to write this down. It's called objective C as an S E. So go to objective dash C. Pretty sure that's where it is. Let me just double check here on my note. Yeah, it's subjective-c.com. Now this guy's a security researcher, his name's Patrick Wartell.
He works at damp, J a M F, which is a great company that has all kinds of software for monitoring computers and controlling them. Making sure certain software's installed software is updated. Remote control, everything else. Okay. Jamf, if you want to check that out, we don't use them. We use some software from IBM.
That actually has some real security validation to it, but, he said the best way, easiest way is to just keep your device out of the hands of someone that might be a starker. Okay. So that's obvious. And, that doesn't mean that it's always going to happen. Kaspersky labs have some good
[00:10:00] points here.
they're saying that the industry is messed up. They use a stronger word than that. And everybody providing these services are one of the worst people on this planet. Okay. Not that he has any opinion about the matter, right? For iOS, if you have an iPhone or an I pad, usually what they use is device management.
So go to your settings, general profiles and device management. So go there right now on your phone. This is how to check to see if you might have stock or were installed, go to their settings, general profiles and device management. And. If you don't see the device management in there, it's a reasonable thing, because that means there is no device management.
And so therefore there's almost certainly no stock or where regular stock or where. However, if there is device management, don't panic. Because it might be legitimate. If your phone is a business phone,
[00:11:00] it's probably legitimate, but that's the easiest way to do it. There should be a remove management option in the settings as well.
When we get back, we're going to do a little bit more of a dive here. What if you have windows? What if you have Android? We're going to talk about that.
You're listening to Craig Peterson. Make sure you visit me online right now. Sign up for my email list. Craig peterson.com/subscribe.
I've got some treats for you when you subscribe and you'll get my weekly newsletter and info about some of the trainings I'm doing.
All right, take care. We'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses VPNs, How they work, and Why they might not be protecting you as much as you think.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand ‘Drama Therapy’ And ‘Journalism’ as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR’s tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia’s GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] Hey everybody. Craig Peterson here on WGAN. Welcome. welcome. Hey, if you missed the first hour, I just want to remind you that you can catch it online. I podcast this whole show every week on your favorite podcasting application or website. Just look for me, Craig Peterson, or visit Craig Peterson dot com. Cause I have them all there as well.
You did miss a lot that first hour because we talked about the new website attacks that are underway that are hurting you, me, as well as businesses that have just set up websites recently. It is a bad state of affairs. We talked about company identity-related breaches that are happening. The coming disruption to college. What Google Chrome is doing to stop some of these resource-draining ads. That are
[00:01:00] actually rather, I wouldn't say the malicious, but they are stealing from you. They're using your computer to mine for Bitcoin for them. I suspect this is actually going to get a lot worse. Maybe that's why Google is finally taking action with the Chrome browser.
The reason I think that this is really going to start taking off is that the Bitcoin value is about to be halved. What happens at that point, normally in the marketplace, if a stock's worth, let's say a hundred dollars and they halve it, it's worth $50. There's a lot of pressure for that stock value to increase back up to the pre-split amount, back up to the hundred dollars point.
What the problem is when it comes to these cryptocurrencies is yes indeed they can go ahead and split it and say it's worth half of what it used to be worth. But now the people that are mining for the Bitcoins are in for a whole different world. And the different world is, Hey, I can
[00:02:00] barely break even, right now, in fact, in most places like here in the Northeast, electricity is so expensive that it costs you more to mine for Bitcoin, and it cost you more than electricity than the Bitcoin is worth. So once they halve the value, now, all of a sudden it's just not worth mining anymore. So that's going to be an interesting result.
Another really interesting analysis too, of Bitcoin this week and this kind of U-shaped factor that it has based on the key sizes and little too geeky to get into here.
This is not a Bitcoin show. But it is a show about your security, what you can do and what you should do just this week, we installed some network equipment, a whole new set of network equipment for a lady named Sue down in mass and we were talking with Sue about it. We had preconfigured everything shipped it out, helped her with
[00:03:00] it. She was having some problems trying to figure out. Okay. So what plugs into what I think next time, maybe we'll just make sure everything's all plugged in before we ship it out. But we had one our guys go by, he only lives about 20 minutes away from Sue. He went and five minutes later, everything was done.
But while he was there installing this whole new network for Sue's company, there was an interesting conversation that ensued because Sue told him that I was anti-VPN. As well as a couple of other things that I was against, the truth is yeah, I'm anti these commercial VPN services that they keep trying to sell you.
I read a summary this week from a respected place. They must have people writing articles now that don't know what they're doing. I've certainly seen that, people in third world countries, second world countries, that don't know what they're doing. But they're cheap to hire as a writer. So they hire them as
[00:04:00] writers and off they go with their cheapness, not really understanding things.
This article said," Hey, yeah, you should use a VPN because it's going to keep your data safe. It keeps it encrypted. It's great. great." I, of course. Just rolled my eyes and lost respect for them.
VPNs have a use, but it's very limited use and that's what Sue had caught on when she attended one of my webinars talking about VPNs and how you can best use them. They are useful. They were invented in order to help businesses with their data and keep their data safe, connect offices together, et cetera.
They are not great for just going to your bank website. In fact, you could be in more of a security problem if you use a VPN for your bank than if you don't use a VPN for your bank. So I'll just keep that all straight.
I figured now's a good time to talk about this. There's a great article in
[00:05:00] dark reading this week that I put up on my website as well. You can find it there.
This article is talking about challenges that exist with VPNs, and this is really a big deal. A VPN can be a step in the right direction. If someone's trying to use a VPN, they're probably trying to do the right thing, but it's really not a be-all and end-all when it comes to security. Not only does it fall short in many ways, but as I've explained in my webinars, it takes a lot longer to explain than I have time for right now. If you want to catch a criminal, you go to where the criminals are.
If you want to find people that are trying to keep their information secret or quiet, you go to where the VPN exit points are and that's exactly what's been happening. It isn't just the five eyes or the nine eyes or the 14 eyes it's organized crime. It's just all over the place. Be very careful. In March of 2020, all of a sudden
[00:06:00] everything changed. Everything shifted. We saw a huge shift in people starting to work from home. Some businesses had to stay open. They didn't necessarily have to have the employees right there in the office. And according to them, Gartner survey, that just happened here with chief financial officers. Gartner's reporting that 74% of organizations will move at least 5% of their previously onsite workforce to permanently remote positions following them pandemic. That is pretty good. Three-quarters of all businesses. Are going to move, give or take one 20th of their onsite workers to offsite.
I was going to have a major impact on everything, on real estate and obviously the technology side too. But let's talk a little bit about VPNs right now and what are they good for? What are they not good for? So point number one. VPNs now,
[00:07:00] remember I said they're great for businesses, point to point, they replaced the leased lines. That's what they were invented for initially.
But typical traditional VPNs have a device that's at the business office. That piece, that device, that piece of hardware can usually only handle a certain number of users. That's also true with the data line that's coming into your office. If you don't have enough bandwidth to support all of these things. People accessing their desktops, or in some cases I know businesses that have a database running at the main office.
Then there are clients, there's software on people's remote workstations that make hundreds of not thousands of requests against this database. That's not the best way to do it by the way.
If you're interested, maybe we can talk about that sometime. I'll put something up in one of the webinars.
Here's the problem with that?
[00:08:00] The VPN and the data lines can only handle just so much data. Many businesses came up with the specs for their VPN appliances. Pre- COVID-19, Pre pandemic. How many people were actually fully using it?
Then, for instance, we have a client an auto dealer, and the only time they used the VPN was when the comptroller was out of training or something, it might happen during the weekend. One of the supervisors would have to hop on.
That's a lot different than once a pandemic starts. Now there are all of a sudden focused on their websites and their online sales and everything else that's going on. So it's a huge difference. So that surge and teleworking that occurred really made these VPNs fail.
Companies struggling to figure out how to scale to support so many users. So that's part of what had been helping businesses with. There's a lot of creative approaches
[00:09:00] going on, such as limiting VPN use to certain workers. There have been businesses that have been taking the shifts and moving them around.
So there's a shift that starts at eight. I need another one that starts at 10 and another one that starts at noon so that there are fewer people on the VPN. Maybe they're only on the VPN for a certain number of hours, but frankly, those are not long term viable strategies. VPNs are also failing to balance productivity and security.
Because let me tell you productivity and security have been at loggerheads with each other for a very long time and VPNs don't fix this problem. In fact, they make it worse. Because now not only are you overloading the VPN, all of the gateways and the firewalls are slowing down everybody's productivity. These home users on their home networks with home computers that are
[00:10:00] infected are now connecting to the network and that infection's getting transferred.
Unfortunately, that transfer is to the main office. Hey, a VPN ain't gonna help with that.
Mobile devices. VPNs are encrypted and the encryption that they use is very complex and it causes problems on our devices. Our mobile devices were not made to handle that. They have to continually update their keys, they're sharing the public keys and their session key. They just can't handle it. Frankly, VPNs are not built for the modern workforce.
There are so many ways this really should be done and unfortunately is not being done. VPNs. They are not a panacea.
When we come back, let's talk about our remote teams. We've had months. Time to relaunch.
[00:11:00] You're listening to Craig Peterson right here on WGAN and [email protected].
Stick around. I'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig explains why he knows that these commercial VPN companies are lying to you and what you can do about it.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand ‘Drama Therapy’ And ‘Journalism’ as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR’s tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia’s GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] If you've been using a VPN service. My gosh, I've got news for you. We're going to talk about what happened this week.
Hey, it's Craig Peterson here. Thanks for joining me. If you want to get my whole show, all of the segments, you'll find them [email protected]. We're starting to do a lot more videos, so make sure you check that out. We might even be doing some of these shows live Facebook and YouTube lives as well.
Let me know what you think. What's the best. A way for you to maybe watch some of this video. Is it one of these lives is just going to the website. Do you prefer, you listened to me on the radio? you can find me podcast almost everywhere and I always ask them, so your question's right here. You can just email [email protected].
Let me know what
[00:01:00] works best for you guys. Okay. I know on the radio, it's absolutely fantastic. And I have a lot of followers there and I love answering your questions. I always get back to you. It might take me a few days, depending on what's going on. Sometimes we get hot on a project or we're trying to secure a company.
That's had a hack. We just had one. Where the company's CFO's laptop was having some problems. And so the MSP, the managed services provider that had them as a client called us up, knowing that we are experts in the cybersecurity front and said, Hey, what should I do? What can I do? this is it's just weird.
And so we got involved and we found it, the CFO's laptop. The chief financial officer, a company that I don't know is I think it's 30 million a year. Had been hacked and had, what's known as an act of Chinese back door, which
[00:02:00] means that the Chinese or getting in and looking at anything they wanted to, whenever they wanted to, et cetera, go very bad stuff.
You don't want that to happen to you? That's for sure. So this is why I'm doing the training. I'm trying to help everybody understand this. We do it on the radio, but we also do it live in person on video. So we do webinars and things too, as well as our newsletter. you can get everything you want for free online and going to one place, one consistent place.
you can trust somebody like me. Who has been doing it information technology for more than 40 years and has been doing cybersecurity for more than 20 years. I think I'm a good place to go. The one-stop-shop for all this information. So thanks to the seem to me here. You can hear me every week.
Right here. You can go online to Craig peterson.com/subscribe bribe. And that'll get you on my newsletter
[00:03:00] in the, in there, I'll have some links to some of the videos and some of the pieces of training we're doing, and I'm going to also be doing some things like the Facebook lives and other YouTube lives and things.
and so if you're interested in that, make sure you let me know. I'll probably send an email out, asking people if you're interested and then I will, We'll let you know when we're going live and what the topic will be, and you can always ask questions and that's the whole idea behind those lives, right?
A little bit. So, let's get into our VPN problem. I did a big training on VPNs of few times. I did 22 webinars on some training in the March timeframe this year. And VPN hands are something that almost no one really understands to me. It's been very disappointing. So let's start about, let's talk about what a VPN is.
Let's start at the very beginning I had, for instance, going to my
[00:04:00] home office. Back in the day, this would 30 years ago now I don't drink really? Yeah. Somewhere around 30 years ago. And I had two T-one data lines coming into my home and we were Watchers unheard of back in the day. So each of those T-one lines was about one and a half megabits.
So I had almost three megabits worth of data coming in. In and out of my house and I had some web servers and I use them for my business and stuff way back then. Oh, same business I have today, by the way. And it was just funny. What was the stamp gene? How expensive it was now? I also had my main office cause I owned a building and I had 50 employees.
In the building and I needed to be able to share data back and forth and have, get, have access to the file. Servers have one centralized phone system, All of that sort of stuff. And 30 years ago, the only way to do that was to have
[00:05:00] lease line, come into my house, and also have a leased line going from my house to the office building.
And then once it got to the building, of course, we owned the hall. Own the whole building. And back then it was all wires, little coaxial cables that ran around for ethernet and we'd got to the building and it got dispersed to the points that needed to be at and went into our data center that we have there and everything else.
Along came the VPN technology. And it was a godsend because I was spending $5,000 a month to connect to my office at my house, to my office in our building. Mine. Can't in my building to my house $5,000 a month in 30, 30 years ago. Okay. So that was serious money. I don't know what 5,000 is worth today with inflation, probably 25.
probably not that much, but, it's worth a lot more. So when VPNs came in
[00:06:00] and internet connections got cheaper, I no longer had to pay, to have a least align, a dedicated, aligned, going from my office to my office building. Now, what I could do is just have an internet connection at both sides and then use a VPN and my networks, we're all connected.
That's what VPN stands for. It's a virtual private network. It lets one point get to the other point. And the way we're using them today is where the problem starts because what we're doing now is you have a VPN then going from your home network or from your laptop to the office, you have now connected all of the devices in your home.
Okay. Or on your network. If your whole network is VPN, all of those devices are now connected. To the other side where the VPN server is.
[00:07:00] So if you have any malware, if you have any of these Chinese back doors, they can not only get on your computer. They can get on any computer, the VPN hooked up to if it's not configured properly if it's not monitored properly if you don't have intrusion detection and prevention systems on both sides of that VPN.
And when you're using one of these free VPN services or the commercial VPN services, you don't have that at all. Now, many of us are looking at it saying, I'm using XYZ VPN. I heard it advertised here or there. My friends use it and it's five bucks a month or 10 bucks a month or 20 bucks a month.
They cannot provide you with the service you need for that. And in my webinar on VPN, I actually. Break down the numbers and show you how it's completely infeasible for
[00:08:00] them to provide it at those types of numbers. So what do they do? they track you. They sell your data and also the bad guys. If your VPN isn't with a bad guy, cause some of these VPNs are actually hosted by Ben, add guys to purposely track you.
Okay. Purposely steal your data. Now, if you want to go where the money is, you Rob a bank, right? Isn't that the whole idea? why did you Rob banks? Because that's where the money was now. Sutton. Apparently never said that, but the concepts are a good ones. So if you want to steal people's data that people want to keep secure because they're doing banking or other things on it.
Where are you going to stake out? Where are you going to put down those tent posts? Where are you going to be watching everyone going in and out? You're going to be watching the VPN server
[00:09:00] at the other side. So you're paying for a VPN service or heaven forbid using a free one. And you're going from your laptop.
Securely probably depends. We go into details on that in the VPN, webinar, and pieces of training, you go fairly securely from your laptop to the VPN server, which is hosted in a data center, probably a public day data center and is under attack. And if they're not maintaining that properly and they get nailed with a zero-day attack, all kinds of stuff can get exposed including you.
So if you're trying to go to your bank and you're using a VPN, cause you're sitting in a cafe, you're going from the cafe. To the VPN service provider. And remember you are also now going from the VPM service provider through the internet, to your bank. These VPNs do not terminate at your bank. These VPNs
[00:10:00] terminate at the VP and servers though, whoever's hosting it.
So VPN mentor revealed this week. That they found seven virtual private networks left 1.2 terabytes of private user data online. 1.2 terabyte. That's a lot. Okay. A terabyte is 1,024 gigabytes. And in case you don't know, so the impacted services were UFO, VPN fast VPN free VPN, super VPN flash, VPN, secure VPN, and rabbit VPN.
Now it had personally identifiable information for potentially over 20 million VPN users. Why would 20 million users email addresses home addresses passwords in plain text, by the way, IP addresses? Why would that take 1.2 terabytes? it wouldn't however,
[00:11:00] they had full logs of everywhere. They went online.
And all of those services that I named are quote, no-log VPN services, meaning, Oh, we don't track you. We don't log you. We're not selling your data. Guess what? This is absolute proof of that. They're not no-log that they were logging. And that probably means that they were selling that data wide log it.
Why use up all of that space. If you're not going to use it somehow. So be careful guys. Okay. yeah, it's, there's a lot of detail. I've got the article up on my [email protected]. Great article from security affairs, but, It's that's a lot of arms, one sentence. It's a real problem. VPNs are a real problem.
So make sure you attend my VPN training, where we go into detail on this. I
[00:12:00] don't sell a VPN. Okay. That you can use privately. We do commercial VPNs and we do them. All right. For employees. Connecting to the businesses and it has to be done, Or you are hyper exposed. Anyways, take care of everybody.
Make sure you visit me online. Sign up for my email list. Craig peterson.com/subscribe.
We're going to lose some radio stations. Others are sticking with me.
So stick around through the news. Cause we'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses the Hack that could cost you your business.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
How to find Stalkerware on your smartphone
This Simple Hack Could Tank Your Business
7 VPN services left data of millions of users exposed online
Universities Brand ‘Drama Therapy’ And ‘Journalism’ as STEM Majors to Circumvent Immigration Policy
DoJ suggested OANN should call FBI about NPR’s tipline, emails show
Google reportedly peeks into Android data to gain edge over third-party apps
Russia’s GRU hackers hit US government and energy targets
Your next smartphone will be a lot harder to scratch
---
Automated Machine-Generated Transcript:
[00:00:00] Hey, have you been paying attention? And I know you have, 'cause you're the best and brightest, you know about phishing and not to click on links you don't know about. there's another one, and this next one is taking advantage of your knowledge about phishing.
Hey Craig, Peterson here. Thanks for joining me.
Let's talk a little bit about it. Yes, we've man, we've beaten. I think the phishing horse to death bottom line because phishing has been such a problem for so long, but for those that aren't really up-on it, you've heard the term, a little bit about, don't click on things, phishing.
It has been very effective lately. We have a lot of people working from home. That's going to continue for months and years to come, frankly, a very high percentage of us. It'll just be at home, in a bedroom or in the living room on the couch.
[00:01:00] That's been happening a lot. those of us who are sitting at home.
Are probably not as aware as we should be to all of the problems that are going on out there. Now we have some training for employees. A lot of places have stuff. I really love what we have and we have training for if you're in HIPAA. if you are CMMC I tar D FARs, right? All of these different regulations that are out there, even PCI training that walks people through and gives them questions and reminds them about the training.
If your business does not have this sort of training. Get it right? Whether you get it from me or you get it from someone else, please get that training so that you can keep up on all of these techniques. The bad guys are using phishing is where they are sending out messages, trying to get you to do
[00:02:00] something right.
Trying to get you to react. what kind of reaction are we talking about here? They can be just a link that you click on. The email looks legit, right? I've been getting every week email, supposedly from Amazon telling me that my. Amazon Prime membership has expired. it hasn't the card did. And now because my credit card on file has been expired.
So has my Amazon membership, right? no, none of that's true, but some of these emails you take a second glance. You say, Whoa, wait a minute then. Okay. That looks legit. It's got Amazon's logo. It's worded like Amazon might word it. And then if you click on it, it's going to take you to a site that pretends to be Amazon and asks you for your credit card update.
So you're going to give a credit card number you're going to give. an expiration date, right? You're going to put all of this stuff
[00:03:00] in, cause you don't want to lose your Amazon prime membership. Now I'm just using Amazon prime as an example, this is happening all the way across the board with tons of.
Banks credit unions. Financial institutions are a really great target. I've seen them from supposedly, right? E-bay I've seen them from the IRS law enforcement. All right. All the way across the board, it is a serious problem. So how do we deal with that problem while we care, but what we're clicking on, but I want to talk about a simple hack may not have heard about before that can just destroy your business and what it is done?
What these guys are doing is called Typosquatting papal, squatting, and typos squatting is where you think you're going to google.com, but maybe you ended
[00:04:00] [email protected]. You forgot the E or maybe it's Google with three O's. Instead of google.com or if you have one of these home routers, even if you're a business and you're not using at least pro or hardware, like the Cisco go hardware.
Then you've got an additional problem because what the bad guys have been doing is taking over control of your router. So many of them have never been patched via Rob, have you ever updated your rudder? Have you ever. They did the firmware new router, right? Most people don't and most rodders don't do it automatically, and they only will do it for me, maybe a couple of years, even if they do it automatically, I just had a client.
We were helping out. We were grading them to the prosumer, the Cisco go hardware. And. She said, yeah, I have been, I check every week. That's how diligent she was. So
[00:05:00] she went to the vendor's website, checked what the latest release of firmware was, and then checked her machine to see what release of more she had.
Guess what it was the same release. But it had been two years since the manufacturer had issued any updates to the firmware. So her modem was completely vulnerable. So make sure you do have a modem that is not only up to date, but really, even for home users, you've got to get the prosumer stuff. I recommend the Cisco stuff.
You don't have to get it from me. But Cisco goes something you might want to look at. You can get it online. I think it's even available on Amazon. I've seen it over there before, and it's not that much more expensive if you just buy it and do it yourself. If you want me to do it, obviously we're going to get involved to help configure it and help you install it and everything.
So there are additional charges, but let's get back to typesquatting. That's
[00:06:00] different than the pad guys taking over your router. And when you type in the correct google.com, you're going to two of them. Okay. Okay. Many of these types of domains. Are either purchased for resale. They redirect you to a real offer and it a shady way.
Many times what they're doing is they'll use a coupon if you will code that gives them credit for the sale. So you're, you are actually going to the real Amazon. And what happens is there's a referral. Bounty, if you will, that they are paid by sending you to Amazon, even though they didn't really send you to Amazon.
So there's a lot of stuff that they're doing. And so forth labs found that roughly 2.7% of 15,000 domain names that they looked at. Two and a half, 2.7% were associated with some form of
[00:07:00] cybercrime, including hacking phishing online fraud or spamming. If you think that 2.7% is a small number, remember there's at least 360 million registered domain.
So let's do a little bit of mathematics here. If we say (360) 100-0000. Times 0.027. So that's 2.7%. So that is nine, almost 10 million websites. If those numbers, if you can really just interpolate it across all registered domains. So there's a lot of easy examples of type typo. Squatting. Security research has found a perfect.
Replica of reddit.com, Tom, which is one of the five most visited websites online under
[00:08:00] reddit.co. Which is.co is Columbia's domain by the way. So they had even acquired an SSL certificate for reddit.co. So the majority of the web browsers wouldn't even tell you that there might be a problem. So we gotta be very careful.
We've seen campaigns in the past for Netflix dot O M again, a typo, right? You meant to type.com Citibank dot O M. Which is, by the way, Oman's, domain suffix. Now that doesn't mean that Columbia or Oman are actively involved in this, or even that the people that did this are from Columbia or Amman. It just means it was the domain was registered there.
Registrars are what it's called. Cameroon's other popular one.cm, Hulu, Netflix, 12 million visits over a three month period. That's pretty amazing here. So anyway, let's not do that. Be careful with typos
[00:09:00] squatting, pay close attention. When you're typing in the URLs. I have seen based on my website, just X, a lot of people use Google.
Instead of typing in the direct URL. So pay attention to that. All right. Stick around. When we come back, we've got a mortar cocktail. We're going to get into the whole VPN story this week. I've got a big I told you so pink is the bottom line here and make sure you're on my email list.
You can sign up at Craig peterson.com/subscribe.
Stick around because we'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed