Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Welcome! What caused the Demise of Flash plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses The End of Flash and what caused its demise.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    The rise and fall of Adobe Flash

    National Security Agency warns that VPNs could be vulnerable to cyberattacks

    Schools already struggled with cybersecurity. Then came COVID-19

    Study Finds 15 Billion Stolen, Exposed Credentials in Criminal Markets

    As Offices Reopen, Hardware from Home Threatens Security

    Augmented reality heads-up displays for cars are finally a real thing

    Android 10 has the fastest update rate ever, hits 16% of users in 10 months

    Twitter breach exposes one of tech's biggest threats: Its own employees

    ---

    Automated Machine-Generated Transcript:

    [00:00:00] We're going to talk about killing Flash. Did Steve jobs start the death of Adobe Flash Macromedia? Remember all those guys?

    Hey, you're listening to Craig Peterson and watching me too. I am getting. Good at trying to post stuff on my website and YouTube videos stuff that is, and I've been updating all of my studio here and it may look kind of the same behind me here on the camera, but believe me, there are a lot of differences.

    We're fixing things, I'm producing more stuff. We are going to be having a great, great. year this year, as we get more and more information to you, just like in the last segment here, where we were talking about DNS and what it means to you and how frankly, this Microsoft bug could be the next big ransomware attack vehicle out there.

    Absolutely amazing.

    [00:01:00] Well Flash, of course, you all know Flash, right? I don't need to really show you Flash. It was designed five years ago. Give or take right now maybe a little bit. And the idea behind Flash was let's give the internet some movement. If you weren't around back then in the mid-nineties, the internet was mostly text-based.

    There were all a whole lot of what we would call brochureware sites at the time. Back in the early nineties, I was, I tried to convince businesses they needed to be online and people just weren't listening to me. It's just not worth the investment. Right.

    [00:02:00] Of course, now it's people are trying to figure it out. How can I do this? How can I get online? And many people's questions, revolved, run hugger. Make this. More pretty. And that's how Flash kind of started the story on it is absolutely fascinating. And I have it, my [email protected]. It goes on for pages and pages, but how these two guys, they struggle.

    They, I had some success in business. They sold the company eight years. They're trying to figure out what should we do? How should we do this? They kind of stumbled on a couple of things that just did not work at all. They went to a couple of big trade shows and sold absolutely none of their product, which was, has sketching product for some of these early.

    PDA portable digital assistants that were out there is really kind of a cool product. They only ever sold two of them, by the way. So they tried some things. So if you are an entrepreneur and you are sitting there saying, OMG, it's not selling, I'm not doing the right thing. Everything's coming to an end.

    [00:03:00] A friend of mine, Steve Pavlina sent out note just this week that I read that I really, really appreciated. He was talking about how we have to stand up for our principles and, and he was specifically talking about our principals, when it comes to our life and our life values, what do we want to do? How do we wanna do it? When do we want to do it? These two guys never gave up and they didn't know exactly what they wanted to do, but they didn't know they wanted to do something.

    And they wanted to make sure that while they were doing it, they were enjoying it. Right. I guess that makes sense. Certainly seems to make sense to me, as well.

    So that's exactly what they did. They, they went out and they tried a few different things. As I said, it took him about eight years. Then they came up with this thing that allowed animation.

    [00:04:00] And if you remember around 96 is when some of this animation really started to hit we're using Flash or are websites where the entire site was coded up using Adobe Flash and Adobe Flash was really cool. It did some wonderful things, frankly. I was quite impressed with it at the time, and I decided I'm going to learn Flash and maybe fly.

    She's going to be my future as well. It was, it was really cool. They got a review from a writer in a magazine and they don't remember the writer's name, but the writer got a preview copy of it and said, Hey, listen, why don't you add some port for buttons, which was easy for them to do so they quickly added support for play button, fast forward button, rewind buttons.

    And then they started adding more programmatic stuff to it. And before you know, it. Flash took over the web. And that was kind of around 99, when a foot had graphics that were moving any sort of video, it was all Flash-based. In fact, a lot of the streaming video that was happening back then in the early two thousands was based on Flash, which is really kind of different when you think about it nowadays. Right.

    [00:05:00] Things went well through the, the arts, if you will, the double ops here at the beginning of the century for them. And they kind of sold out and moved around and Adobe ended up owning it and integrating it with some of the tools that Adobe had, then came 2010. On April 29th, 2010, I've got that right in front of me here.

    Steve jobs published an open letter. He called it Thoughts on Flash. This was probably the beginning of the end for Flash. Now Flash was already known at the time for some security problems because it was really an almost an operating system more than a programming language. It allowed them to access stuff on the computer, make some changes, move things around, read files.

    [00:06:00] Does that start to ring bells for you? About how dangerous Flash just might be? Well, it was, and Steve jobs brought that up in his open letter. And he also said in that open letter, the number one reason max crash is Flash. So Steve jobs was complaining about reliability problems, about security problems and about performance problems.

    We remember what else happened 2010? The iPhone happened. And Steve jobs is working on that. And he decided right then and there that frankly Flash falls short. And those are, those are actually Steve Jobs words, Flash falls short, and it was never included in any version of iOS. So it wasn't on the iPhone. It wasn't on the later introduced iPad. Absolutely nothing.

    [00:07:00] Well, the industry response was kind of mixed because there are a lot of people who had decided yeah. You know, Flashes the way they had big investments in Flash and they couldn't see it going away. But in November, 2011, Adobe pivoted and adopted the new standard.

    The one that Steve jobs was promoting than the rest of the internet was behind, it was called HTML five. HTML five allowed your browser to basically act like an operating system. It can actually run multiple programs simultaneously for you, and it could do all of the animation and more than Flash could do it.

    Could display videos. HTML five is the answer we're still living with today. A decade later almost. And. When Adobe decided that we're not going to be targeting Flash players anymore, but all of our tools, which were originally developed for Flash by these guys. Those tools are now adapted to use and spit out if you will, HTML five.

    [00:08:00] So did Steve jobs killed Flash? Well yeah, kinda, he started it. But I think Flash, Adobe killed it itself. Certainly in November, 2011, Adobe switching over to its HTML five was a very big deal. They didn't keep up on patches. They didn't keep up on the security problems, you know, and they kind of did, but it was, was the stepchild problem that you have, they just didn't care enough about it.

    Which is I think a real problem, some great quotes in this article, again, up on Craig peterson.com about what they were doing. They were saying, Hey, listen, this is causing bloating as well. It's not working well on mobile devices because mobile devices don't have as much computeing as a desktop computer does, not even close and they have to use battery.

    [00:09:00] And so you're doing something heavy, like interpreting Flash on a browser. That's running on Java. That's being interpreted. I know on a little snap dragon chip or whatever, it might be on an Android device. You're really slow and you're really hogging resources. So Flash is gone burry it it's dead. It is no longer supported in many browsers.

    And by the end of 2020, it's going to be completely gone. Even from Google Chrome.

    Wow. We are going through fast today. When we get back, we'll get into Google here and how they're getting sued again for tracking people, even though they said they're not. Yes, indeed.

    Make sure you go online right now. Craig peterson.com/subscribe and we'll be right back.

    Stick around.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! DNS and DNS Hacking plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses DNS and DNS Hacking and why DNS is so important if you are worried about security.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    The rise and fall of Adobe Flash

    National Security Agency warns that VPNs could be vulnerable to cyberattacks

    Schools already struggled with cybersecurity. Then came COVID-19

    Study Finds 15 Billion Stolen, Exposed Credentials in Criminal Markets

    As Offices Reopen, Hardware from Home Threatens Security

    Augmented reality heads-up displays for cars are finally a real thing

    Android 10 has the fastest update rate ever, hits 16% of users in 10 months

    Twitter breach exposes one of tech's biggest threats: Its own employees

    ---

    Automated Machine-Generated Transcript:

    [00:00:00] Craig Peterson: Hey, it only took 17 years to patch. It can't be that bad. Can it? Hello, Microsoft. Why have you had the brakes on this for so long and what it means to you?

    Hey everybody, Craig Peterson here. Thanks for joining me. We're going to talk right now about a couple of things. One of these is the bug that took Microsoft 17 years to fix that you better fix right now. Because it's in the wild. Yes, indeed. we're going to talk about Adobe flash, that little pesky pieces software that we've been using for many, many years, but as it turns out, it's been a real pain, right.

    Buggy stuff, you know, really the two big ones that you have to worry about all the time. Have been Flash and have been Java. Both of those have had more than their fair share of nightmares associated with [00:01:00] them. I just hate some of this stuff because it has been so nasty. So buggy, it's hard to even think about when you get right down to it.

    Right. Well, here's, what's going on right now with Microsoft here. There was a,  released the, just here within the last week. That fixes what appears to be a very dangerous, so longstanding bug in Windows DNS. Now DNS is the domain name system. The domain name service is what I've called it for years. We go into a lot of detail on DNS in our hacker killer course.

    We, basically have to because you need to understand the DNS and how it works. If you're going to run an office and all of the computers in it. Right. So we go into a whole lot of detail on that, but DNS.

    [00:02:00] The bottom line is what you type into your browser. So Craig Peterson dot com for instance, and turns it into an address like one, two, three main street, any town USA. Even with the zip code. So it turns it into this, this set of octet in IPV four nomenclature, IPV six, it's just this massive, huge address that can address anything that mankind should be able to make over the next year and thousand years, maybe more you can address every pebble of sand on a beach.

    Okay. It's just a huge amount of address space.

    So DNS is important for your computer, cause it's not just typing google.com or Craig peterson.com or it could be bank of america.com into the browser. It's all of the software on your computer that is using the internet. Because in order to get from your computer to the computer, it really wants to talk to. It needs to know the address.

    [00:03:00] So what happens is it asks your ISP typically. So, you know, again, when you computer boots that use the DHCP, it gets an IP address. Again, we cover all of this in the hacker killer course, but it gets an IP address and when it gets that information from your DHCP server, it's also getting an IP address for the DNS server.

    Now sometimes the DNS server is your ISP internet service provider, like a Comcast or the telephone company, the, or whomever it is your using to get on the internet. And that's frankly, pretty common. That's where it's located out there for your ISP, from your ISP. So what'll happen is your computer will now go and ask your ISP computer.

    [00:04:00] How do I get to Craig peterson.com all at least what's the address of Craig peterson.com getting there? Well, that's a lot more detailed. We probably won't get into that on the show, but involves OSPF and BGP and just all kinds of other running protocols. But anyhow, I'll have to see the address. I need to get there.

    So when Microsoft wants to do an update, It uses the name. So it goes to update.microsoft.com. This is an example, right? In reality, it goes to a bunch of different sites, or when the Adobe software update or when Google software, anything wants to update or use a resource like a database online. It's going to go to DNS. DNS is just that important.

    Now there have been some problems with DNS over the years, and one of the biggest problems is how can I be sure that I'm talking to an authoritative server. In other words, if I want Craig Peterson's IP address and I get it back from a DNS server. Do I really know that's Craig or is that some hacker?

    [00:05:00] That's trying to get me to go to their site instead of my bank site. So one of the ways that were put together here to try and fix this problem is DNS sec. There are some other ones out there now that are some I don't like. They're using DNS over HTTPS, which is a very simple solution. A cloud flare has it, OpenDNS has it, almost everybody has it. It is built into Firefox. Now it is built into a Chrome ish, they're rolling it out. But here's what happens with that. Instead of asking your ISP for the address for the bank, it sets up a secure. Tunnel effectively and SSL tunnel to either CloudFlare or open DNS or one of these other.

    [00:06:00] So it goes directly there and says, Hey, what's the IP address for TD bank? And at that point secure. So if I'm asking my ISP using regular DNS for an address. In reality, somebody could be sitting in between. What the hackers have been doing lately is if you have a consumer-grade router, which is most small businesses, frankly we walk into is just kind of crazy.

    But if you have a consumer-grade router and that router is not patched up. You've got problems. Now we've been into places where they've been diligent and applying patches the problem is that they haven't issued patches. This one place we went to, just a couple of weeks ago. Yeah. Yeah. I'm certain, I'm certain, I'm certain.

     I go there every week and double-check and yes, indeed. This is the firmware version that I'm supposed to have installed. When I checked on my router, it's got that firmware version. So. I'm up to date. So then we went with her and we had a little bit of a closer look at it turns out.

    [00:07:00] Yeah. Yeah, she was pretty diligent, but the vendor had not released patches in over two years.

     So again, that's why you don't use any of the consumer stuff. That's why you got to stick with prosumer. If you're. On the cheap side, if you had to keep it cost down. And you're not really that concerned about security, but you don't want this to happen to you as well as a thousand other things.

    And that's why we have a full prosumer package that we sell. That's all the hardware you need. And it's all automatically kept up to date and with getting machines and functioning properly with all the latest, you know, anti-malware software. So that prosumer stuff is important, but here's what happens.

    [00:08:00]They've been going on and connecting to routers just randomly. They just cycle through all of these addresses on the internet and they find a router that is vulnerable to the attack, and then they change the firmware in it so that your computer now asks them what the IP address is for your bank.

    So you type in TD bank.com. Your computer says, okay, who am I supposed to ask about this? Oh yeah, yeah. I'm supposed to ask my router about it. Cause that's what I found out from DHCP. So it goes ahead and asks the router about it. The router says, yeah I know bank of America or TD, or where was it you're going to?  It doesn't really matter. Here's an IP address in Russia you should be going to.

    We're seeing this happening by the tens of thousands now. So Microsoft has been trying to work their way around it. How can we do that? How do we know that an IP address is legitimate and they really messed up?

    [00:09:00] Okay. This is called SIGRed. It not only exploits Windows DNS, but it's what's called a wormable bug. Which means it can crawl through other machines once it's on your network. So be very, very careful. Both Checkpoint and Microsoft say this is a critical flaw. It scores a 10 out of 10 on the CVSs common vulnerability scoring system.

    This is bad. Make sure. You've got this patched. It's affecting practically every small and medium-sized organization in the world. It's gone unnoticed for 17 years, but no longer.

     Hey, stick around. We're going to be right back. We're going to be talking about flash and a whole lot more. Make sure you're on my list.

    So all of this work, I've done setting up this new studio doesn't go to waste and you can attend all of these free pieces of training. Craig peterson.com/subscribe.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Twitter Bitcoin Scam plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Twitter and the Insider Hack/Phishing for Bitcoin Scam against celebrities.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    The rise and fall of Adobe Flash

    National Security Agency warns that VPNs could be vulnerable to cyberattacks

    Schools already struggled with cybersecurity. Then came COVID-19

    Study Finds 15 Billion Stolen, Exposed Credentials in Criminal Markets

    As Offices Reopen, Hardware from Home Threatens Security

    Augmented reality heads-up displays for cars are finally a real thing

    Android 10 has the fastest update rate ever, hits 16% of users in 10 months

    Twitter breach exposes one of tech's biggest threats: Its own employees

    ---

    Automated Machine-Generated Transcript:

    [00:00:00] Craig Peterson: You've probably heard about the big problems happening for the big names out there. Uncle Joe's giving away millions, Elon Musk.

    That's what we're going to start by talking about. How could he miss this? Right. It happened on Wednesday this week. I talked about it Thursday morning on the radio, a few different places, in fact, and hopefully, you might have picked it up on my podcast too.

    Twitter is in quite the uproar right now because of this particular little problem. Many, many people are very, very upset and they're upset because. Twitter got hacked.

    Now, this isn't hacked in the normal terms, right? Normally when you think of hack, you think of oh there are bad guys and they're maybe trying to hit the router and trying to get in through the router and trying to take over everything.

    [00:01:00] It looks like what happened here, is that a few famous people's accounts were compromised in a very, very big way. It's kind of scary. I'm going to just double-check the latest news on this because frankly, it is just shocking.

    But here's the bottom line, there are a number of high profile accounts and they're all accounts that have that little blue checkmark next to it. Right? You've seen that before on Twitter. 

    It turns out that Twitter was very unprepared to handle this hack and they ended up turning off all of these accounts. It is just absolutely amazing. Twitter stock, of course, took a nosedive and pre-market opening here on Thursday and it was kinda everybody.

    [00:02:00] Well, we had Joe Biden, Elon Musk, Bill Gates. The very top. President Trump was not hacked. I have my theories about why that was. Apple was hacked and many others. Now, at least one of Twitter's own employees appears to have been involved in this particular hack. What happened was apparently, right we'll find out more, the FBI is investigating. Apparently what happened is the there's a tool kind of a God mode tool. Do you remember that with Uber? Where Uber employees who were watching where you and I were going, but okay. They didn't care about us, but they want to know where Beyonce was going and all of these other stars and where were they coming from, and what were their home addresses? Some of them were selling that information. Okay. Not good news so that God-mode on Uber got misused.

    Well, as it turns out here on the Twitter front, they have a similar function. Where you can go in and look at anybody's account.

    [00:03:00] Now, I mentioned Beyonce because there is a picture that was posted on [00:03:00] Twitter and taken down and posted and taken to heaven and posted of Beyonce's account using this kind of God mode. That's my phrase here, God mode account software. It was showing everything about Beyonce. What she was doing, her account was verified. She had her own domain, et cetera, et cetera.

    Well, late last year, the Department of Justice charged two Twitter employees with providing private information from Twitter to Saudi Arabian nationals, according to CNBC. What happened here with the hack in case you're not aware we'll back up a little bit here.

    [00:04:00] But these accounts were taken over apparently and they were used to send a message. Now, the message they sent was kind of shocking. It was, "Hey, I'm giving back here or due to the COVID-19" or, "You know, Uncle Joe Biden, he's always given away money." So he said, "Hey, listen, if you over the next four hours if you send me on Twitter Bitcoin to this Bitcoin account number, I'll double it." "I will double it and I'll send the money back to you." "So now you get to have a thousand dollars worth of Bitcoin. Well, now you get $2,000 with a Bitcoin, and apparently there was one guy from Japan who sent $40,000 worth of Bitcoin to the account." Well, the bad guys. I count was apparently just opened up this week and the money was moved very quickly from that Twitter account to other accounts online, which makes a lot of sense, right. Shuffle that money around, make it harder to track. All of that money is now in their hands because one of the reasons bad guys use Bitcoin is that Bitcoin has no way to return the money, to scrape it back, let's put it that way. In other words, if I send money to a Bitcoin wallet, it is there it is gone. Goodbye. Good luck. There's no way for me to take that money back.

    [00:05:00] So there's well over a hundred thousand dollars that I'm going to say it here, that some stupid people sent to people using Bitcoin on Twitter. You know what really, really, how could you do that? It just doesn't seem to make a whole lot of sense to me, but apparently it did.

    [00:06:00] Now, Twitter is saying that there was no real coordination between the hackers. Twitter saying that this was social engineering. Now, this is something I cover pretty extensively in my hacker killer cybersecurity course. The whole concept of social engineering, these are the phishing emails, these are phone calls that you might get pretending that it's somebody from it or whatever it might be. Those are all social engineering attacks and those attacks can really cause just incredible amounts of problems for you and me and for very, very good reason as well. Right. Because if we cooperate, unknowingly by clicking on the link, You know, going to a website and then entering information.

    Or in this case, we see a message from a blue checkmark Twitter account. The message says, send me money on Bitcoin. One of them said, Hey, I really want to promote Bitcoin. I think Bitcoin's the future. Which, of course, is what Bitcoin wants you to think. Right. They're going to be sitting there and saying, yeah, you're right. You're right. They're going to wait. We should be going all these fools with their bank accounts. They should be using Bitcoin. You are right. So it says, Bitcoin is a wave the future, and I really want to promote it. I really, I want to help you people who've been trying to promote it. So over there next, whatever it was, 30 minutes, four hours, if you send me Bitcoin,  Oh, doubled it. I'm giving back. Elon Musk was one of the accounts that sent this out as well. So there's a little slight degree of, you know, okay. This could be true.

    [00:07:00] But in reality, this goes back to what we've known for years. If it seems too good to be true, it's not true. Right? So maybe some of these Twitter employees were scammed using these phishing attacks. Maybe not. We've certainly seen it before with insiders.

    We've seen Facebook employees, stocking people. Remember, it's not just employees nowadays, these tools that we're talking about, these God mode type tools. Are given to contractors from all of these major companies, Uber we mentioned already, but Facebook, we already know Facebook has people who are online using these tools to decide whether or not the censor President Trump, right.

    [00:08:00] Or you or me. Or watching videos on YouTube and deciding whether or not that should be demonetized because, Oh my gosh, you said something that, you know, a 0.01% of the people might be upset about. And I'm one of that 0.01%. So I'm going to demonetize you, which means. In the real world terms, Hey, listen, if you are a conservative and do you have a YouTube channel and you say something, they don't like, you're not going to be able to make any money from that YouTube video.

    We see that all the time from Prager University and many conservative speakers. So did 200 employees cooperate with the hackers, hard to say right now, Given that last fall, Saudi Arabia was able to get a couple of Twitter employees to kind of flip for them. Then the answer to that is kind of maybe.

    [00:09:00]How long did it take to stop hackers? It took hours to stop them. Unfortunately, the last thing was posted, I think, Wednesday night at about 6:00 PM. So it took a while and Twitter attempted to slow this whole thing down.

    They blocked verified accounts, which means if you had an, a verified account and there are a lot of them out there, a lot of us in the media, in the training realm and celebrities, we have blue checks, by our names. I don't, okay. But many people do.

    So because of that, and because of the fact that a lot of these blue check accounts were being used for the scam, twitter said, okay, no more postings from blue check accounts. All right. So it took a while.

    It was just a Bitcoin scam. It could have been a lot worse. And there are a lot of businesses out there that use Twitter in order to disseminate information in real-time. So all of those businesses, and that includes a lot of entertainment businesses really got nailed by this.

    [00:10:00] I think when you start looking into this a little bit more deeply, We learn it something, there are a few things to learn, but one of the big things that we learned from this is you cannot count on using some of these platforms that are online, you can count on using some of them for your business and keeping your data safe.

    Because again, and again, and again, you know, all the way back to 20 years ago, these even the earliest social media sites were plagued by people who were working there. Who were giving the information way? Okay.

    President Trump's account was not hacked apparently, really. They were probably able to access private information. Cause you remember, they had this God mode, as I call it. Type tool that they were using. So that's kind of a very big deal. All right.

    We only got about a half, half a minute left here, so let's talk about what's up next.

    [00:11:00] We've got to talk about this, Microsoft. This is a very, very, very big deal. There's a patch out there right now. We'll tell you about that. We're going to talk also about Google. We've mentioned them before and tracking users and selling user's data. They're getting sued again because apparently. Google has not learned.

    Hey, make sure you visit me online. Go to Craig peterson.com/subscribe. I've almost got my news studio all done here. We're going to do a lot more pieces of training, a lot more live training, and we're probably going to start offering some of my courses again as well, but stick around because we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Twitter Bitcoin Scam plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Twitter and the Insider Hack/Phishing for Bitcoin Scam against celebrities.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    The rise and fall of Adobe Flash

    National Security Agency warns that VPNs could be vulnerable to cyberattacks

    Schools already struggled with cybersecurity. Then came COVID-19

    Study Finds 15 Billion Stolen, Exposed Credentials in Criminal Markets

    As Offices Reopen, Hardware from Home Threatens Security

    Augmented reality heads-up displays for cars are finally a real thing

    Android 10 has the fastest update rate ever, hits 16% of users in 10 months

    Twitter breach exposes one of tech's biggest threats: Its own employees

    ---

    Automated Machine-Generated Transcript:

    [00:00:00] Craig Peterson: You've probably heard about the big problems happening for the big names out there. Uncle Joe's giving away millions, Elon Musk.

    That's what we're going to start by talking about. How could he miss this? Right. It happened on Wednesday this week. I talked about it Thursday morning on the radio, a few different places, in fact, and hopefully, you might have picked it up on my podcast too.

    Twitter is in quite the uproar right now because of this particular little problem. Many, many people are very, very upset and they're upset because. Twitter got hacked.

    Now, this isn't hacked in the normal terms, right? Normally when you think of hack, you think of oh there are bad guys and they're maybe trying to hit the router and trying to get in through the router and trying to take over everything.

    [00:01:00] It looks like what happened here, is that a few famous people's accounts were compromised in a very, very big way. It's kind of scary. I'm going to just double-check the latest news on this because frankly, it is just shocking.

    But here's the bottom line, there are a number of high profile accounts and they're all accounts that have that little blue checkmark next to it. Right? You've seen that before on Twitter.

    It turns out that Twitter was very unprepared to handle this hack and they ended up turning off all of these accounts. It is just absolutely amazing. Twitter stock, of course, took a nosedive and pre-market opening here on Thursday and it was kinda everybody.

    [00:02:00] Well, we had Joe Biden, Elon Musk, Bill Gates. The very top. President Trump was not hacked. I have my theories about why that was. Apple was hacked and many others. Now, at least one of Twitter's own employees appears to have been involved in this particular hack. What happened was apparently, right we'll find out more, the FBI is investigating. Apparently what happened is the there's a tool kind of a God mode tool. Do you remember that with Uber? Where Uber employees who were watching where you and I were going, but okay. They didn't care about us, but they want to know where Beyonce was going and all of these other stars and where were they coming from, and what were their home addresses? Some of them were selling that information. Okay. Not good news so that God-mode on Uber got misused.

    Well, as it turns out here on the Twitter front, they have a similar function. Where you can go in and look at anybody's account.

    [00:03:00] Now, I mentioned Beyonce because there is a picture that was posted on [00:03:00] Twitter and taken down and posted and taken to heaven and posted of Beyonce's account using this kind of God mode. That's my phrase here, God mode account software. It was showing everything about Beyonce. What she was doing, her account was verified. She had her own domain, et cetera, et cetera.

    Well, late last year, the Department of Justice charged two Twitter employees with providing private information from Twitter to Saudi Arabian nationals, according to CNBC. What happened here with the hack in case you're not aware we'll back up a little bit here.

    [00:04:00] But these accounts were taken over apparently and they were used to send a message. Now, the message they sent was kind of shocking. It was, "Hey, I'm giving back here or due to the COVID-19" or, "You know, Uncle Joe Biden, he's always given away money." So he said, "Hey, listen, if you over the next four hours if you send me on Twitter Bitcoin to this Bitcoin account number, I'll double it." "I will double it and I'll send the money back to you." "So now you get to have a thousand dollars worth of Bitcoin. Well, now you get $2,000 with a Bitcoin, and apparently there was one guy from Japan who sent $40,000 worth of Bitcoin to the account." Well, the bad guys. I count was apparently just opened up this week and the money was moved very quickly from that Twitter account to other accounts online, which makes a lot of sense, right. Shuffle that money around, make it harder to track. All of that money is now in their hands because one of the reasons bad guys use Bitcoin is that Bitcoin has no way to return the money, to scrape it back, let's put it that way. In other words, if I send money to a Bitcoin wallet, it is there it is gone. Goodbye. Good luck. There's no way for me to take that money back.

    [00:05:00] So there's well over a hundred thousand dollars that I'm going to say it here, that some stupid people sent to people using Bitcoin on Twitter. You know what really, really, how could you do that? It just doesn't seem to make a whole lot of sense to me, but apparently it did.

    [00:06:00] Now, Twitter is saying that there was no real coordination between the hackers. Twitter saying that this was social engineering. Now, this is something I cover pretty extensively in my hacker killer cybersecurity course. The whole concept of social engineering, these are the phishing emails, these are phone calls that you might get pretending that it's somebody from it or whatever it might be. Those are all social engineering attacks and those attacks can really cause just incredible amounts of problems for you and me and for very, very good reason as well. Right. Because if we cooperate, unknowingly by clicking on the link, You know, going to a website and then entering information.

    Or in this case, we see a message from a blue checkmark Twitter account. The message says, send me money on Bitcoin. One of them said, Hey, I really want to promote Bitcoin. I think Bitcoin's the future. Which, of course, is what Bitcoin wants you to think. Right. They're going to be sitting there and saying, yeah, you're right. You're right. They're going to wait. We should be going all these fools with their bank accounts. They should be using Bitcoin. You are right. So it says, Bitcoin is a wave the future, and I really want to promote it. I really, I want to help you people who've been trying to promote it. So over there next, whatever it was, 30 minutes, four hours, if you send me Bitcoin, Oh, doubled it. I'm giving back. Elon Musk was one of the accounts that sent this out as well. So there's a little slight degree of, you know, okay. This could be true.

    [00:07:00] But in reality, this goes back to what we've known for years. If it seems too good to be true, it's not true. Right? So maybe some of these Twitter employees were scammed using these phishing attacks. Maybe not. We've certainly seen it before with insiders.

    We've seen Facebook employees, stocking people. Remember, it's not just employees nowadays, these tools that we're talking about, these God mode type tools. Are given to contractors from all of these major companies, Uber we mentioned already, but Facebook, we already know Facebook has people who are online using these tools to decide whether or not the censor President Trump, right.

    [00:08:00] Or you or me. Or watching videos on YouTube and deciding whether or not that should be demonetized because, Oh my gosh, you said something that, you know, a 0.01% of the people might be upset about. And I'm one of that 0.01%. So I'm going to demonetize you, which means. In the real world terms, Hey, listen, if you are a conservative and do you have a YouTube channel and you say something, they don't like, you're not going to be able to make any money from that YouTube video.

    We see that all the time from Prager University and many conservative speakers. So did 200 employees cooperate with the hackers, hard to say right now, Given that last fall, Saudi Arabia was able to get a couple of Twitter employees to kind of flip for them. Then the answer to that is kind of maybe.

    [00:09:00]How long did it take to stop hackers? It took hours to stop them. Unfortunately, the last thing was posted, I think, Wednesday night at about 6:00 PM. So it took a while and Twitter attempted to slow this whole thing down.

    They blocked verified accounts, which means if you had an, a verified account and there are a lot of them out there, a lot of us in the media, in the training realm and celebrities, we have blue checks, by our names. I don't, okay. But many people do.

    So because of that, and because of the fact that a lot of these blue check accounts were being used for the scam, twitter said, okay, no more postings from blue check accounts. All right. So it took a while.

    It was just a Bitcoin scam. It could have been a lot worse. And there are a lot of businesses out there that use Twitter in order to disseminate information in real-time. So all of those businesses, and that includes a lot of entertainment businesses really got nailed by this.

    [00:10:00] I think when you start looking into this a little bit more deeply, We learn it something, there are a few things to learn, but one of the big things that we learned from this is you cannot count on using some of these platforms that are online, you can count on using some of them for your business and keeping your data safe.

    Because again, and again, and again, you know, all the way back to 20 years ago, these even the earliest social media sites were plagued by people who were working there. Who were giving the information way? Okay.

    President Trump's account was not hacked apparently, really. They were probably able to access private information. Cause you remember, they had this God mode, as I call it. Type tool that they were using. So that's kind of a very big deal. All right.

    We only got about a half, half a minute left here, so let's talk about what's up next.

    [00:11:00] We've got to talk about this, Microsoft. This is a very, very, very big deal. There's a patch out there right now. We'll tell you about that. We're going to talk also about Google. We've mentioned them before and tracking users and selling user's data. They're getting sued again because apparently. Google has not learned.

    Hey, make sure you visit me online. Go to Craig peterson.com/subscribe. I've almost got my news studio all done here. We're going to do a lot more pieces of training, a lot more live training, and we're probably going to start offering some of my courses again as well, but stick around because we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Google, Privacy, Incognito Mode plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses privacy and why what you thought you knew may not be true. Google suits over spying and more.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    The rise and fall of Adobe Flash

    National Security Agency warns that VPNs could be vulnerable to cyberattacks

    Schools already struggled with cybersecurity. Then came COVID-19

    Study Finds 15 Billion Stolen, Exposed Credentials in Criminal Markets

    As Offices Reopen, Hardware from Home Threatens Security

    Augmented reality heads-up displays for cars are finally a real thing

    Android 10 has the fastest update rate ever, hits 16% of users in 10 months

    Twitter breach exposes one of tech's biggest threats: Its own employees

    ---

    Automated Machine-Generated Transcript:

    [00:00:00] Craig Peterson: Hey, are you a devoted user of Google tools? Hey, and you know how to hide stuff online, right? Incognito browser mode. Guess again.

    This is Craig Peterson. Thanks for joining me again, everybody. Google has had a mixed history of keeping your information safe. Right? One of the big problems with Google is how they make their money. They make their money by what? Selling your data, selling information about you. Selling it to marketers.

    Heck, they're even selling it to the police and China. They are cooperating with the Chinese government and telling them who the dissidents are. That to me is really rather scary. Right?

    [00:01:00] Facebook does the same sort of thing in China pretty much. Well, really every US company that has a nexus in China, if they want to be in China, is being forced under the socialist government, to hand over information about anybody that might want a little bit of freedom of choice in their lives.

    Personally, I think that's a problem. Many people tend to not think that. Now as part of our hacker killer cybersecurity course, I go into a lot of depth about how to keep data safe and secure.

    Even if you go over to China, believe it or not. But, Hey, listen, if you're going to China, you better have a Macbook and it better be using full disk encryption, and you better be using really good passwords.

    I would advise against using their wifi over there, et cetera, et cetera. Anyways, that's the subject for a very in-depth course. We're not going to get into right now.

    [00:02:00] How do you as a user, keep your information safe from prying eyes. There are obviously some things we don't want people to know that we're searching about. Look at @amazon.com, for instance, if you're looking for certain types of toys on Amazon, it is not going to show those in your general search history.

    They're not going to just pop up and say on the ad on a website as you're on an oh a so-called family-friendly website that is running ads that are paid for by Google. Maybe a third party who's using Google's data. It's not going to pop up about that little toy that you were searching for over at Amazon at the worst possible time. Right?

    [00:03:00] We already know that there's data that we don't want to have out there. And many times data are used to blackmail us. We've seen that very frequently recently with the hackers who go on to our computers, particularly our small, medium businesses. Steal the data that's there. They, actually have people who get on your computer and look around on the computers and then all of the other computers on the network to see what kind of information does this guy has, does this company have, right?

    What can we do to really screw them over? Right. What ends up happening? Well, they get their hands on set information and then they blackmail you. Well, there's nothing illegal necessarily about what a business does. Right? You, you sell a product. But you're concerned about your intellectual property.

    You're concerned about regulatory fines that might come into play. In fact, almost certainly would come into play in some cases, but how would you like to be the company? Like one of the ones that we came in after the fact. They were just having some email problems. So we started poking around and we found the worst case of infection. Chinese, active Chinese back doors that the FBI Boston field office says they've ever seen.

    [00:04:00]So that means that you as a business person, and in this case, is a guy in his seventies. Who'd been building this company for decades and had all of these designs, had all of these customers, his pricelist, his everything up there now stolen by the Chinese. That's socialism for you, right?

    Well, It's one thing to steal it from some poor guy, some schmuck that spent 30 years building it. And then we'll just go ahead and use slave labor in order to make it really cheap. So now you get to compete against your designs and this something that's always bothered me about the tax code.

    Here you are struggling for 10, 20, 30 years. We were just in the last segment talking about flash and how they struggled for eight years just to come up with a concept for a business that might work. They had businesses that failed.

    [00:05:00] So with the tax code. I'm struggling, let's say I'm working for, for 10, 20 years. I'm not even making minimum wage. I'm going back and forth. I'm trying different things. Then, all of a sudden, after 20 years of hard work, I'm an overnight success, right? Isn't that the way that works, an overnight success, right, that took 20 years. So I make 2 million dollars in that year, 2 million.

    Now I have to pay huge taxes on that. But wait a minute now, if you amortize it, cause I didn't get paid for the 20 years. I got paid for it at the very end of the 20 years. So how about we say, instead of making $2 million in year 20, I made a hundred thousand thousand dollars a year, right? A lot different tax bracket, right?

    [00:06:00] Anyways it's something that's always really bothered me. The whole socialist idea of the progressive tax system has really bothered me. But in China, they don't bother with that. If you're a good member of the party, you make more money. We'll steal information for you from American companies. You have no idea how often this is happening. It is absolutely insane.

    We've been involved in at least one of the 1000 investigations that are underway right now by the FBI. They just don't have enough time to investigate them all.

    So now he has lost his 20 years' worth of building this company to the socialists, who are now going to should be selling his product.

    Now, remember they didn't have to spend money developing this. They didn't have to spend money on the failures, the things that didn't work, the marketing that didn't work, the products that didn't work, the integrations that didn't work. They didn't have to spend the 20 years learning how to do all of this stuff. Figuring it out on the back of an envelope, all the way through, on, on a computer diagram system. They didn't have to do any of that. No, all they had to do was steal it. Right.

    [00:07:00] So you are a regular, small business person. You're a home user, whatever it is. So how do you keep your data safe?

    You know, this reminds me, I have a series of tutorials on keeping your browsers safe. I'm thinking maybe I should release those again. Maybe put them together as a little package. Let me know if you guys think I should. These plugins are going to help keep you safe. Email [email protected]. If you think that's a good idea, me, [email protected].

    How to keep your online browsing experience safe. I've got others too but, you know, I think that's important.

    [00:08:00] What do you do tell people are using incognito mode on their browsers, right? It's called different things in different browsers on the Google Chrome browser, call it incognito mode. There was a suit filed last month filed against Google, saying that Google was tracking people, even when they had incognito mode turned on.

    There was a lawsuit filed this last Tuesday that alleges that Google tracks, user activity through hundreds of thousands of apps, even after people opt-out of sharing information. This is a good article by CNET. You'll find it on CNET Angela Lang wrote or she's got some decent stuff. I've got up on my [email protected], but this is a very, very big deal because the lawsuit is seeking class-action status, which means that these individuals that are involved in the suit are saying, Hey, we want thousands of people potentially in on the suit. Very, very big deal.

    [00:09:00]Last month, the same law firm filed another suit, related to privacy and Google's Chrome browser. So CNET said, we reached out to Google, of course, they didn't respond in time. Isn't that the norm here? The suits filed it in the US district court for the Northern District of California. So it's in the ninth circus. We're not going to get into a whole bunch of the suit. You can find out more on my website or just do a search online, duck, duck, go search.

    Here's the bottom line incognito mode, it does not stop people from tracking you. You're still sending requests out. Remember we talked about DNS before the domain name, service or system DNS. Well, that's another way to track you.

    [00:10:00] What websites are you going to? What IP addresses are you visiting? What websites are you looking up? All of this stuff is a way to track you. So. Incognito mode isn't really doing much other than stopping certain cross-site cookies from being looked at. So it's a real, real problem.

    Now I have some training specifically on all of this browser safety and security and privacy, but the bottom line, if you want privacy, I would say stick with Safari, just for the general user.

    Now, in my courses would go into a lot more detail on different browsers, when you might want to use a tor browser, versus Epic, versus Safari, Firefox, et cetera.

    [00:11:00] In reality for the 80% rule, Safari is going to get you a long way because Safari is from Apple. Apple does not make money off of your information. Google does. Apple does not. Apple makes money by selling you hardware, and by selling you services. And that's why it's a little bit safer. Right now, by the way, Apple is in their promotion saying we are 50% faster than Google Chrome. As well as more secure and Google Chrome has removed some of the support for some of the ad word blockers and other things, things that you might want to be using.

    So Google Chrome's falling a little bit out of favor. However, on the other hand, you've got Microsoft with their latest incarnation of the Epic browser, which isn't the EPIC browser, which isn't the Epic browser. Which isn't isn't Internet Explorer. It's crazy. And we go into a lot of depth on some of that stuff on my courses.

    [00:12:00] But Microsoft Epic is now actually Google Chrome under the hood. Anyhow, stick around. We've got a lot more to talk about her at the start of the hour, and I appreciate you being with me. Make sure you go right now to Craig peterson.com/subscribe. Get on my free newsletter list and I'll be sending you information about some of the training.

    If you're interested in being in some of the FBLives. Stuff for the webinars or watching the videos. That's how you find out. It's like what we're doing right now only better. CraigPeterson.com/subscribe. Stick around. We'll be back on some stations we won't and others and of the course, we're on YouTube and CraigPeterson.com too.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! DNS and DNS Hacking plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses DNS and DNS Hacking and why DNS is so important if you are worried about security.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    The rise and fall of Adobe Flash

    National Security Agency warns that VPNs could be vulnerable to cyberattacks

    Schools already struggled with cybersecurity. Then came COVID-19

    Study Finds 15 Billion Stolen, Exposed Credentials in Criminal Markets

    As Offices Reopen, Hardware from Home Threatens Security

    Augmented reality heads-up displays for cars are finally a real thing

    Android 10 has the fastest update rate ever, hits 16% of users in 10 months

    Twitter breach exposes one of tech's biggest threats: Its own employees

    ---

    Automated Machine-Generated Transcript:

    [00:00:00] Craig Peterson: Hey, it only took 17 years to patch. It can't be that bad. Can it? Hello, Microsoft. Why have you had the brakes on this for so long and what it means to you?

    Hey everybody, Craig Peterson here. Thanks for joining me. We're going to talk right now about a couple of things. One of these is the bug that took Microsoft 17 years to fix that you better fix right now. Because it's in the wild. Yes, indeed. we're going to talk about Adobe flash, that little pesky pieces software that we've been using for many, many years, but as it turns out, it's been a real pain, right.

    Buggy stuff, you know, really the two big ones that you have to worry about all the time. Have been Flash and have been Java. Both of those have had more than their fair share of nightmares associated with [00:01:00] them. I just hate some of this stuff because it has been so nasty. So buggy, it's hard to even think about when you get right down to it.

    Right. Well, here's, what's going on right now with Microsoft here. There was a, released the, just here within the last week. That fixes what appears to be a very dangerous, so longstanding bug in Windows DNS. Now DNS is the domain name system. The domain name service is what I've called it for years. We go into a lot of detail on DNS in our hacker killer course.

    We, basically have to because you need to understand the DNS and how it works. If you're going to run an office and all of the computers in it. Right. So we go into a whole lot of detail on that, but DNS.

    [00:02:00] The bottom line is what you type into your browser. So Craig Peterson dot com for instance, and turns it into an address like one, two, three main street, any town USA. Even with the zip code. So it turns it into this, this set of octet in IPV four nomenclature, IPV six, it's just this massive, huge address that can address anything that mankind should be able to make over the next year and thousand years, maybe more you can address every pebble of sand on a beach.

    Okay. It's just a huge amount of address space.

    So DNS is important for your computer, cause it's not just typing google.com or Craig peterson.com or it could be bank of america.com into the browser. It's all of the software on your computer that is using the internet. Because in order to get from your computer to the computer, it really wants to talk to. It needs to know the address.

    [00:03:00] So what happens is it asks your ISP typically. So, you know, again, when you computer boots that use the DHCP, it gets an IP address. Again, we cover all of this in the hacker killer course, but it gets an IP address and when it gets that information from your DHCP server, it's also getting an IP address for the DNS server.

    Now sometimes the DNS server is your ISP internet service provider, like a Comcast or the telephone company, the, or whomever it is your using to get on the internet. And that's frankly, pretty common. That's where it's located out there for your ISP, from your ISP. So what'll happen is your computer will now go and ask your ISP computer.

    [00:04:00] How do I get to Craig peterson.com all at least what's the address of Craig peterson.com getting there? Well, that's a lot more detailed. We probably won't get into that on the show, but involves OSPF and BGP and just all kinds of other running protocols. But anyhow, I'll have to see the address. I need to get there.

    So when Microsoft wants to do an update, It uses the name. So it goes to update.microsoft.com. This is an example, right? In reality, it goes to a bunch of different sites, or when the Adobe software update or when Google software, anything wants to update or use a resource like a database online. It's going to go to DNS. DNS is just that important.

    Now there have been some problems with DNS over the years, and one of the biggest problems is how can I be sure that I'm talking to an authoritative server. In other words, if I want Craig Peterson's IP address and I get it back from a DNS server. Do I really know that's Craig or is that some hacker?

    [00:05:00] That's trying to get me to go to their site instead of my bank site. So one of the ways that were put together here to try and fix this problem is DNS sec. There are some other ones out there now that are some I don't like. They're using DNS over HTTPS, which is a very simple solution. A cloud flare has it, OpenDNS has it, almost everybody has it. It is built into Firefox. Now it is built into a Chrome ish, they're rolling it out. But here's what happens with that. Instead of asking your ISP for the address for the bank, it sets up a secure. Tunnel effectively and SSL tunnel to either CloudFlare or open DNS or one of these other.

    [00:06:00] So it goes directly there and says, Hey, what's the IP address for TD bank? And at that point secure. So if I'm asking my ISP using regular DNS for an address. In reality, somebody could be sitting in between. What the hackers have been doing lately is if you have a consumer-grade router, which is most small businesses, frankly we walk into is just kind of crazy.

    But if you have a consumer-grade router and that router is not patched up. You've got problems. Now we've been into places where they've been diligent and applying patches the problem is that they haven't issued patches. This one place we went to, just a couple of weeks ago. Yeah. Yeah. I'm certain, I'm certain, I'm certain.

    I go there every week and double-check and yes, indeed. This is the firmware version that I'm supposed to have installed. When I checked on my router, it's got that firmware version. So. I'm up to date. So then we went with her and we had a little bit of a closer look at it turns out.

    [00:07:00] Yeah. Yeah, she was pretty diligent, but the vendor had not released patches in over two years.

    So again, that's why you don't use any of the consumer stuff. That's why you got to stick with prosumer. If you're. On the cheap side, if you had to keep it cost down. And you're not really that concerned about security, but you don't want this to happen to you as well as a thousand other things.

    And that's why we have a full prosumer package that we sell. That's all the hardware you need. And it's all automatically kept up to date and with getting machines and functioning properly with all the latest, you know, anti-malware software. So that prosumer stuff is important, but here's what happens.

    [00:08:00]They've been going on and connecting to routers just randomly. They just cycle through all of these addresses on the internet and they find a router that is vulnerable to the attack, and then they change the firmware in it so that your computer now asks them what the IP address is for your bank.

    So you type in TD bank.com. Your computer says, okay, who am I supposed to ask about this? Oh yeah, yeah. I'm supposed to ask my router about it. Cause that's what I found out from DHCP. So it goes ahead and asks the router about it. The router says, yeah I know bank of America or TD, or where was it you're going to? It doesn't really matter. Here's an IP address in Russia you should be going to.

    We're seeing this happening by the tens of thousands now. So Microsoft has been trying to work their way around it. How can we do that? How do we know that an IP address is legitimate and they really messed up?

    [00:09:00] Okay. This is called SIGRed. It not only exploits Windows DNS, but it's what's called a wormable bug. Which means it can crawl through other machines once it's on your network. So be very, very careful. Both Checkpoint and Microsoft say this is a critical flaw. It scores a 10 out of 10 on the CVSs common vulnerability scoring system.

    This is bad. Make sure. You've got this patched. It's affecting practically every small and medium-sized organization in the world. It's gone unnoticed for 17 years, but no longer.

    Hey, stick around. We're going to be right back. We're going to be talking about flash and a whole lot more. Make sure you're on my list.

    So all of this work, I've done setting up this new studio doesn't go to waste and you can attend all of these free pieces of training. Craig peterson.com/subscribe.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! What caused the Demise of Flash plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses The End of Flash and what caused its demise.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    The rise and fall of Adobe Flash

    National Security Agency warns that VPNs could be vulnerable to cyberattacks

    Schools already struggled with cybersecurity. Then came COVID-19

    Study Finds 15 Billion Stolen, Exposed Credentials in Criminal Markets

    As Offices Reopen, Hardware from Home Threatens Security

    Augmented reality heads-up displays for cars are finally a real thing

    Android 10 has the fastest update rate ever, hits 16% of users in 10 months

    Twitter breach exposes one of tech's biggest threats: Its own employees

    ---

    Automated Machine-Generated Transcript:

    [00:00:00] We're going to talk about killing Flash. Did Steve jobs start the death of Adobe Flash Macromedia? Remember all those guys?

    Hey, you're listening to Craig Peterson and watching me too. I am getting. Good at trying to post stuff on my website and YouTube videos stuff that is, and I've been updating all of my studio here and it may look kind of the same behind me here on the camera, but believe me, there are a lot of differences.

    We're fixing things, I'm producing more stuff. We are going to be having a great, great. year this year, as we get more and more information to you, just like in the last segment here, where we were talking about DNS and what it means to you and how frankly, this Microsoft bug could be the next big ransomware attack vehicle out there.

    Absolutely amazing.

    [00:01:00] Well Flash, of course, you all know Flash, right? I don't need to really show you Flash. It was designed five years ago. Give or take right now maybe a little bit. And the idea behind Flash was let's give the internet some movement. If you weren't around back then in the mid-nineties, the internet was mostly text-based.

    There were all a whole lot of what we would call brochureware sites at the time. Back in the early nineties, I was, I tried to convince businesses they needed to be online and people just weren't listening to me. It's just not worth the investment. Right.

    [00:02:00] Of course, now it's people are trying to figure it out. How can I do this? How can I get online? And many people's questions, revolved, run hugger. Make this. More pretty. And that's how Flash kind of started the story on it is absolutely fascinating. And I have it, my [email protected]. It goes on for pages and pages, but how these two guys, they struggle.

    They, I had some success in business. They sold the company eight years. They're trying to figure out what should we do? How should we do this? They kind of stumbled on a couple of things that just did not work at all. They went to a couple of big trade shows and sold absolutely none of their product, which was, has sketching product for some of these early.

    PDA portable digital assistants that were out there is really kind of a cool product. They only ever sold two of them, by the way. So they tried some things. So if you are an entrepreneur and you are sitting there saying, OMG, it's not selling, I'm not doing the right thing. Everything's coming to an end.

    [00:03:00] A friend of mine, Steve Pavlina sent out note just this week that I read that I really, really appreciated. He was talking about how we have to stand up for our principles and, and he was specifically talking about our principals, when it comes to our life and our life values, what do we want to do? How do we wanna do it? When do we want to do it? These two guys never gave up and they didn't know exactly what they wanted to do, but they didn't know they wanted to do something.

    And they wanted to make sure that while they were doing it, they were enjoying it. Right. I guess that makes sense. Certainly seems to make sense to me, as well.

    So that's exactly what they did. They, they went out and they tried a few different things. As I said, it took him about eight years. Then they came up with this thing that allowed animation.

    [00:04:00] And if you remember around 96 is when some of this animation really started to hit we're using Flash or are websites where the entire site was coded up using Adobe Flash and Adobe Flash was really cool. It did some wonderful things, frankly. I was quite impressed with it at the time, and I decided I'm going to learn Flash and maybe fly.

    She's going to be my future as well. It was, it was really cool. They got a review from a writer in a magazine and they don't remember the writer's name, but the writer got a preview copy of it and said, Hey, listen, why don't you add some port for buttons, which was easy for them to do so they quickly added support for play button, fast forward button, rewind buttons.

    And then they started adding more programmatic stuff to it. And before you know, it. Flash took over the web. And that was kind of around 99, when a foot had graphics that were moving any sort of video, it was all Flash-based. In fact, a lot of the streaming video that was happening back then in the early two thousands was based on Flash, which is really kind of different when you think about it nowadays. Right.

    [00:05:00] Things went well through the, the arts, if you will, the double ops here at the beginning of the century for them. And they kind of sold out and moved around and Adobe ended up owning it and integrating it with some of the tools that Adobe had, then came 2010. On April 29th, 2010, I've got that right in front of me here.

    Steve jobs published an open letter. He called it Thoughts on Flash. This was probably the beginning of the end for Flash. Now Flash was already known at the time for some security problems because it was really an almost an operating system more than a programming language. It allowed them to access stuff on the computer, make some changes, move things around, read files.

    [00:06:00] Does that start to ring bells for you? About how dangerous Flash just might be? Well, it was, and Steve jobs brought that up in his open letter. And he also said in that open letter, the number one reason max crash is Flash. So Steve jobs was complaining about reliability problems, about security problems and about performance problems.

    We remember what else happened 2010? The iPhone happened. And Steve jobs is working on that. And he decided right then and there that frankly Flash falls short. And those are, those are actually Steve Jobs words, Flash falls short, and it was never included in any version of iOS. So it wasn't on the iPhone. It wasn't on the later introduced iPad. Absolutely nothing.

    [00:07:00] Well, the industry response was kind of mixed because there are a lot of people who had decided yeah. You know, Flashes the way they had big investments in Flash and they couldn't see it going away. But in November, 2011, Adobe pivoted and adopted the new standard.

    The one that Steve jobs was promoting than the rest of the internet was behind, it was called HTML five. HTML five allowed your browser to basically act like an operating system. It can actually run multiple programs simultaneously for you, and it could do all of the animation and more than Flash could do it.

    Could display videos. HTML five is the answer we're still living with today. A decade later almost. And. When Adobe decided that we're not going to be targeting Flash players anymore, but all of our tools, which were originally developed for Flash by these guys. Those tools are now adapted to use and spit out if you will, HTML five.

    [00:08:00] So did Steve jobs killed Flash? Well yeah, kinda, he started it. But I think Flash, Adobe killed it itself. Certainly in November, 2011, Adobe switching over to its HTML five was a very big deal. They didn't keep up on patches. They didn't keep up on the security problems, you know, and they kind of did, but it was, was the stepchild problem that you have, they just didn't care enough about it.

    Which is I think a real problem, some great quotes in this article, again, up on Craig peterson.com about what they were doing. They were saying, Hey, listen, this is causing bloating as well. It's not working well on mobile devices because mobile devices don't have as much computeing as a desktop computer does, not even close and they have to use battery.

    [00:09:00] And so you're doing something heavy, like interpreting Flash on a browser. That's running on Java. That's being interpreted. I know on a little snap dragon chip or whatever, it might be on an Android device. You're really slow and you're really hogging resources. So Flash is gone burry it it's dead. It is no longer supported in many browsers.

    And by the end of 2020, it's going to be completely gone. Even from Google Chrome.

    Wow. We are going through fast today. When we get back, we'll get into Google here and how they're getting sued again for tracking people, even though they said they're not. Yes, indeed.

    Make sure you go online right now. Craig peterson.com/subscribe and we'll be right back.

    Stick around.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Twitter Hack

    Welcome!

    Good morning, everybody. I was on a special appearance with Jim Polito this morning to discuss this huge Twitter hack and what happened and what can be done about it. Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    [00:00:00] Craig Peterson: So they had this God mode they got in trouble for. Well, it really seriously looks like, and there is a similar God mode on Twitter.

    It's a special appearance, command appearance, right? Yeah. Craig Peterson here and Jim Polito wanted to go into the details behind this Twitter hack. What happened? Why did it happen? What can we do about it? Does it really matter? Well, that's exactly what we were talking about.

    Jim Polito: Here's a funny one. There was a big Twitter hack yesterday and Steve Fourni, Western Mass producer sent me a text. Hey, Mr. blue check, did you get hacked. Like no. Nobody's going to hack me. There's no money to be had.

    [00:01:00] And, and who's going to accept, uh, a message from Jim Polito. But if you got a message from say, Barack Obama or Joe Biden, maybe you could be swindled out of some Bitcoin. Joining us now to sort this all out a special appearance. And we appreciate the extra time from him. Our good friend and tech talk guru, Craig Peterson.

    Good morning, sir.

    Craig Peterson: Hey, good morning, Jim. Glad to be back.

    Jim Polito: Thanks for coming. Uh, I appreciate it. I know you were here Tuesday with the guys while I was off. So thanks for coming back. So what, what exactly happened? And here's my worry, I'm hearing. This was an inside job. So what's being done at these companies to protect people, you know, uh, people like me, Craig, you know, not just me, but others. Is this an inside job at Twitter?

    Craig Peterson: Well, think of all of the people yourself included, obviously, but businesses use Twitter to disseminate real-time news. This is a very, very big deal. And 10 years ago, you might remember Twitter got fined.

    [00:02:00] They paid a fine too, I think it was the FTC thing that, uh, they straightened out their act too, because back then, They got hacked again. So here's what it looks like happened. This is kind of interesting. This is from an article on vice.com, but one of the sources told the reporters here that this is a quote.

    We used a rep that literally done all the work for us. And they say that they paid this rep and there were some pictures posted of a tool. Now, do you remember the whole God mode, controversy with, you know, um, yeah? With, with the driving app?

    Jim Polito: Uber, Uber.

    Craig Peterson: Uber, why can't I remember Uber is fun.

    Jim Polito: Well, 'cause you're brilliant and you get too much stuff in the brain as Einstein did. So we would forget his address, you know,

    [00:03:00] Craig Peterson: With Uber, they had this thing called God mode and it turned out that their employees and contractors were sharing exactly where various celebrities were in Uber cars, where they were picked up, they figured out where their homes were because of course, that's where the phone sleeps at night, right. Is in people's homes. So they had this God mode, they got in trouble for, well, it really seriously looks like, and there is a similar God mode on Twitter.

    Apparently Twitter has an app and screenshots of it were posted on Twitter and have been shared elsewhere, that I'll allow people who are using this tool to do anything. And it's fine. This screenshot was posted on Twitter of Beyonce's account in this tool, in this God mode where they can get into your account can basically do anything.

    [00:04:00]  So what looks like what happened here is that there was, and this is according to Twitter. Now, this is a statement from Twitter. Some of their employees were manipulated using social engineering. So some of the employees that according to Twitter were manipulated into giving this God mode application access to this hacker group.

    The hacker group is saying, no, no, no. We planted somebody inside of Twitter that gave us access to it. The FBI is now involved. Investigating this thing, because what happened is you've been mentioning this morning is that they have these various accounts and then they started sharing messages. So for instance, uncle Joe Biden was posting things saying, Hey, listen, Then guys, you know, we, we really care about [00:05:00] you so here's what I'm going to do. They did various things on different accounts, but the bottom line message across the board was I want to give back now. This is what Elon Musk said, uncle Joe, said, uh, you know, For the next 30 minutes or in some cases it was for the next four hours, et cetera.

    If you send the Bitcoin, I'm going to give back, I'm going to double whatever amount of Bitcoin you send me and I'll double it and send it back. Now, all of these accounts were very big accounts. You've been mentioning the name of some of these accounts that were up there. Very, very prominent accounts like President Obama and of course, President Trump, apparently he was not hacked. 

    I don't know if I'd call this a hack when they're using a God mode application treated by Twitter. Right. But, um, his account wasn't used for this.  Apparently there's more than a hundred thousand dollars that have been sent to them in this Bitcoin account.

    [00:06:00] Now, for those that don't know, Bitcoin is a type of virtual currency. It's called a cryptocurrency. Now the reason bad guys love bitcoin is that you can share it, not really anonymously, but somewhat anonymously. Our government does have ways of tracing this. I heard a lecture by a secret service member about how, they cracked some of these online organizations.

    But the thing that liked the most about it is you can send money by a bitcoin. And there's absolutely no way to get that money back. Once you've spent that money. There are people. All over the world. Yeah. That has been sending this guy or these guys money. Uh, one apparently in Japan as much as $40,000 in one transaction, I guess he, he really feels the burn.

    [00:07:00] Yeah. It's just incredible

    Jim Polito: Were talking with our good friend, Craig Peterson, tech talk guru. No, no need to look at your watch or your calendar. No, it is Thursday, but he's back here because of this situation with Twitter. So first of all, I mean the obvious advice to everybody is, uh, if you start seeing messages like that, uh, from, uh, uncle Joe Biden or Barack Obama or anyone else, uh, if it's too good to be true, It's too good.

    [00:08:00]  It's like those messages I used to get that Bill Gates is giving away his, um, uh-huh. Millions of dollars and if you copy this email to 10 friends, you know, you'll, you'll get a piece of it, you know, yadda, yada, yada, and people believe it. You know, I mean, that's kind of slowed down a little bit. So you needed something more creative than people would believe, but you know, I don't think uncle Joe's going to be sending me any message soon. Yeah. I don't think

    Craig Peterson: First of all, giving away money. Yeah, what's new in there, right?

    Jim Polito: Well, but you'd be huge. He's giving away your money, you know, like tax dollars, but, but giving away his own money and then you have to do it through Bitcoin. No, thank you.

    Craig Peterson: And this isn't the first time this type of thing has happened.

    Facebook employees were using their privileged app to stalk women. Snapchat workers had a tool called Snap Lion that gave permission information on users. Myspace employees use their tool called Overlord to spy on users back in the day.

    Jim Polito: I was just going to say my ma my space. I mean, it wasn't that done in hieroglyphics.

    [00:09:00] Is that how old that didn't you need the Rosetta stone to be able to translate the trip around me based on tablets.

    Craig Peterson: Yeah. That's that was so I guess,

    Jim Polito:  I guess these companies need to be a lot more selective about who gets this God mode, this mode, where they can do whatever they want, which is probably necessary to fix some issues. But hi, they better be very careful with who they give this to.

    Craig Peterson: You know, they're not being that careful, frankly, from what I've seen, look at Facebook recently, the news, because of problems with people who are doing the monitoring, who are saying, well, you can post this. You can't, that are like a third-party.

    So, yeah, these, these tools are in the hands of not just employees, the contractors, and they're falling for scams, according to Facebook, but according to the hackers, and this has been reported a few places online, according to the hackers, this was kind of an inside job. They got someone inside there, they turned them, or got them in there in the first place and had free reign. It's no different than people getting an insider at a bank or a jewelry store or something else like they did in the old days.

    Jim Polito: Craig Peterson, Hey, Craig, let's give out, let's give out your information in case folks want to reach out to you and um, and then you'll be back Tuesday, which is great.

    [00:10:00] Absolutely. You can just email me. Craig peterson.com. It's M E at Craig peterson.com or a hit or miss with the texting. I gotta get this thing fixed. You can just text me at (855) 385-5553. I've just been too busy lately.

    The standard data and text rates apply. I appreciate it, I know you are busy and I appreciate you coming in today for some extra duty and helping us out with, to understand this and we'll catch up with you Tuesday, Craig.

    Craig Peterson: Alright, take care, Jim. Thanks

    Jim Polito: You too.

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Twitter Hack

    Welcome!

    Good morning, everybody. I was on a special appearance with Jim Polito this morning to discuss this huge Twitter hack and what happened and what can be done about it. Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    --- 

    Automated Machine Generated Transcript:

    [00:00:00] Craig Peterson: So they had this God mode they got in trouble for. Well, it really seriously looks like, and there is a similar God mode on Twitter.

    It's a special appearance, command appearance, right? Yeah. Craig Peterson here and Jim Polito wanted to go into the details behind this Twitter hack. What happened? Why did it happen? What can we do about it? Does it really matter? Well, that's exactly what we were talking about.

    Jim Polito: Here's a funny one. There was a big Twitter hack yesterday and Steve Fourni, Western Mass producer sent me a text. Hey, Mr. blue check, did you get hacked. Like no. Nobody's going to hack me. There's no money to be had.

    [00:01:00] And, and who's going to accept, uh, a message from Jim Polito. But if you got a message from say, Barack Obama or Joe Biden, maybe you could be swindled out of some Bitcoin. Joining us now to sort this all out a special appearance. And we appreciate the extra time from him. Our good friend and tech talk guru, Craig Peterson.

    Good morning, sir.

    Craig Peterson: Hey, good morning, Jim. Glad to be back.

    Jim Polito: Thanks for coming. Uh, I appreciate it. I know you were here Tuesday with the guys while I was off. So thanks for coming back. So what, what exactly happened? And here's my worry, I'm hearing. This was an inside job. So what's being done at these companies to protect people, you know, uh, people like me, Craig, you know, not just me, but others. Is this an inside job at Twitter?

    Craig Peterson: Well, think of all of the people yourself included, obviously, but businesses use Twitter to disseminate real-time news. This is a very, very big deal. And 10 years ago, you might remember Twitter got fined.

    [00:02:00] They paid a fine too, I think it was the FTC thing that, uh, they straightened out their act too, because back then, They got hacked again. So here's what it looks like happened. This is kind of interesting. This is from an article on vice.com, but one of the sources told the reporters here that this is a quote.

    We used a rep that literally done all the work for us. And they say that they paid this rep and there were some pictures posted of a tool. Now, do you remember the whole God mode, controversy with, you know, um, yeah? With, with the driving app?

    Jim Polito: Uber, Uber.

    Craig Peterson: Uber, why can't I remember Uber is fun.

    Jim Polito: Well, 'cause you're brilliant and you get too much stuff in the brain as Einstein did. So we would forget his address, you know,

    [00:03:00] Craig Peterson: With Uber, they had this thing called God mode and it turned out that their employees and contractors were sharing exactly where various celebrities were in Uber cars, where they were picked up, they figured out where their homes were because of course, that's where the phone sleeps at night, right. Is in people's homes. So they had this God mode, they got in trouble for, well, it really seriously looks like, and there is a similar God mode on Twitter.

    Apparently Twitter has an app and screenshots of it were posted on Twitter and have been shared elsewhere, that I'll allow people who are using this tool to do anything. And it's fine. This screenshot was posted on Twitter of Beyonce's account in this tool, in this God mode where they can get into your account can basically do anything.

    [00:04:00]  So what looks like what happened here is that there was, and this is according to Twitter. Now, this is a statement from Twitter. Some of their employees were manipulated using social engineering. So some of the employees that according to Twitter were manipulated into giving this God mode application access to this hacker group.

    The hacker group is saying, no, no, no. We planted somebody inside of Twitter that gave us access to it. The FBI is now involved. Investigating this thing, because what happened is you've been mentioning this morning is that they have these various accounts and then they started sharing messages. So for instance, uncle Joe Biden was posting things saying, Hey, listen, Then guys, you know, we, we really care about [00:05:00] you so here's what I'm going to do. They did various things on different accounts, but the bottom line message across the board was I want to give back now. This is what Elon Musk said, uncle Joe, said, uh, you know, For the next 30 minutes or in some cases it was for the next four hours, et cetera.

    If you send the Bitcoin, I'm going to give back, I'm going to double whatever amount of Bitcoin you send me and I'll double it and send it back. Now, all of these accounts were very big accounts. You've been mentioning the name of some of these accounts that were up there. Very, very prominent accounts like President Obama and of course, President Trump, apparently he was not hacked. 

    I don't know if I'd call this a hack when they're using a God mode application treated by Twitter. Right. But, um, his account wasn't used for this.  Apparently there's more than a hundred thousand dollars that have been sent to them in this Bitcoin account.

    [00:06:00] Now, for those that don't know, Bitcoin is a type of virtual currency. It's called a cryptocurrency. Now the reason bad guys love bitcoin is that you can share it, not really anonymously, but somewhat anonymously. Our government does have ways of tracing this. I heard a lecture by a secret service member about how, they cracked some of these online organizations.

    But the thing that liked the most about it is you can send money by a bitcoin. And there's absolutely no way to get that money back. Once you've spent that money. There are people. All over the world. Yeah. That has been sending this guy or these guys money. Uh, one apparently in Japan as much as $40,000 in one transaction, I guess he, he really feels the burn.

    [00:07:00] Yeah. It's just incredible

    Jim Polito: Were talking with our good friend, Craig Peterson, tech talk guru. No, no need to look at your watch or your calendar. No, it is Thursday, but he's back here because of this situation with Twitter. So first of all, I mean the obvious advice to everybody is, uh, if you start seeing messages like that, uh, from, uh, uncle Joe Biden or Barack Obama or anyone else, uh, if it's too good to be true, It's too good.

    [00:08:00]  It's like those messages I used to get that Bill Gates is giving away his, um, uh-huh. Millions of dollars and if you copy this email to 10 friends, you know, you'll, you'll get a piece of it, you know, yadda, yada, yada, and people believe it. You know, I mean, that's kind of slowed down a little bit. So you needed something more creative than people would believe, but you know, I don't think uncle Joe's going to be sending me any message soon. Yeah. I don't think

    Craig Peterson: First of all, giving away money. Yeah, what's new in there, right?

    Jim Polito: Well, but you'd be huge. He's giving away your money, you know, like tax dollars, but, but giving away his own money and then you have to do it through Bitcoin. No, thank you.

    Craig Peterson: And this isn't the first time this type of thing has happened.

    Facebook employees were using their privileged app to stalk women. Snapchat workers had a tool called Snap Lion that gave permission information on users. Myspace employees use their tool called Overlord to spy on users back in the day.

    Jim Polito: I was just going to say my ma my space. I mean, it wasn't that done in hieroglyphics.

    [00:09:00] Is that how old that didn't you need the Rosetta stone to be able to translate the trip around me based on tablets.

    Craig Peterson: Yeah. That's that was so I guess,

    Jim Polito:  I guess these companies need to be a lot more selective about who gets this God mode, this mode, where they can do whatever they want, which is probably necessary to fix some issues. But hi, they better be very careful with who they give this to.

    Craig Peterson: You know, they're not being that careful, frankly, from what I've seen, look at Facebook recently, the news, because of problems with people who are doing the monitoring, who are saying, well, you can post this. You can't, that are like a third-party.

    So, yeah, these, these tools are in the hands of not just employees, the contractors, and they're falling for scams, according to Facebook, but according to the hackers, and this has been reported a few places online, according to the hackers, this was kind of an inside job. They got someone inside there, they turned them, or got them in there in the first place and had free reign. It's no different than people getting an insider at a bank or a jewelry store or something else like they did in the old days.

    Jim Polito: Craig Peterson, Hey, Craig, let's give out, let's give out your information in case folks want to reach out to you and um, and then you'll be back Tuesday, which is great.

    [00:10:00] Absolutely. You can just email me. Craig peterson.com. It's M E at Craig peterson.com or a hit or miss with the texting. I gotta get this thing fixed. You can just text me at (855) 385-5553. I've just been too busy lately.

    The standard data and text rates apply. I appreciate it, I know you are busy and I appreciate you coming in today for some extra duty and helping us out with, to understand this and we'll catch up with you Tuesday, Craig.

    Craig Peterson: Alright, take care, Jim. Thanks

    Jim Polito: You too.

    --- 

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min
  • AS HEARD ON - The Jim Polito Show - WTAG 580 AM: Twitter Hack

    Welcome!

    Good morning, everybody. I was on a special appearance with Jim Polito this morning to discuss this huge Twitter hack and what happened and what can be done about it. Here we go with Jim.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Automated Machine Generated Transcript:

    [00:00:00] Craig Peterson: So they had this God mode they got in trouble for. Well, it really seriously looks like, and there is a similar God mode on Twitter.

    It's a special appearance, command appearance, right? Yeah. Craig Peterson here and Jim Polito wanted to go into the details behind this Twitter hack. What happened? Why did it happen? What can we do about it? Does it really matter? Well, that's exactly what we were talking about.

    Jim Polito: Here's a funny one. There was a big Twitter hack yesterday and Steve Fourni, Western Mass producer sent me a text. Hey, Mr. blue check, did you get hacked. Like no. Nobody's going to hack me. There's no money to be had.

    [00:01:00] And, and who's going to accept, uh, a message from Jim Polito. But if you got a message from say, Barack Obama or Joe Biden, maybe you could be swindled out of some Bitcoin. Joining us now to sort this all out a special appearance. And we appreciate the extra time from him. Our good friend and tech talk guru, Craig Peterson.

    Good morning, sir.

    Craig Peterson: Hey, good morning, Jim. Glad to be back.

    Jim Polito: Thanks for coming. Uh, I appreciate it. I know you were here Tuesday with the guys while I was off. So thanks for coming back. So what, what exactly happened? And here's my worry, I'm hearing. This was an inside job. So what's being done at these companies to protect people, you know, uh, people like me, Craig, you know, not just me, but others. Is this an inside job at Twitter?

    Craig Peterson: Well, think of all of the people yourself included, obviously, but businesses use Twitter to disseminate real-time news. This is a very, very big deal. And 10 years ago, you might remember Twitter got fined.

    [00:02:00] They paid a fine too, I think it was the FTC thing that, uh, they straightened out their act too, because back then, They got hacked again. So here's what it looks like happened. This is kind of interesting. This is from an article on vice.com, but one of the sources told the reporters here that this is a quote.

    We used a rep that literally done all the work for us. And they say that they paid this rep and there were some pictures posted of a tool. Now, do you remember the whole God mode, controversy with, you know, um, yeah? With, with the driving app?

    Jim Polito: Uber, Uber.

    Craig Peterson: Uber, why can't I remember Uber is fun.

    Jim Polito: Well, 'cause you're brilliant and you get too much stuff in the brain as Einstein did. So we would forget his address, you know,

    [00:03:00] Craig Peterson: With Uber, they had this thing called God mode and it turned out that their employees and contractors were sharing exactly where various celebrities were in Uber cars, where they were picked up, they figured out where their homes were because of course, that's where the phone sleeps at night, right. Is in people's homes. So they had this God mode, they got in trouble for, well, it really seriously looks like, and there is a similar God mode on Twitter.

    Apparently Twitter has an app and screenshots of it were posted on Twitter and have been shared elsewhere, that I'll allow people who are using this tool to do anything. And it's fine. This screenshot was posted on Twitter of Beyonce's account in this tool, in this God mode where they can get into your account can basically do anything.

    [00:04:00] So what looks like what happened here is that there was, and this is according to Twitter. Now, this is a statement from Twitter. Some of their employees were manipulated using social engineering. So some of the employees that according to Twitter were manipulated into giving this God mode application access to this hacker group.

    The hacker group is saying, no, no, no. We planted somebody inside of Twitter that gave us access to it. The FBI is now involved. Investigating this thing, because what happened is you've been mentioning this morning is that they have these various accounts and then they started sharing messages. So for instance, uncle Joe Biden was posting things saying, Hey, listen, Then guys, you know, we, we really care about [00:05:00] you so here's what I'm going to do. They did various things on different accounts, but the bottom line message across the board was I want to give back now. This is what Elon Musk said, uncle Joe, said, uh, you know, For the next 30 minutes or in some cases it was for the next four hours, et cetera.

    If you send the Bitcoin, I'm going to give back, I'm going to double whatever amount of Bitcoin you send me and I'll double it and send it back. Now, all of these accounts were very big accounts. You've been mentioning the name of some of these accounts that were up there. Very, very prominent accounts like President Obama and of course, President Trump, apparently he was not hacked.

    I don't know if I'd call this a hack when they're using a God mode application treated by Twitter. Right. But, um, his account wasn't used for this. Apparently there's more than a hundred thousand dollars that have been sent to them in this Bitcoin account.

    [00:06:00] Now, for those that don't know, Bitcoin is a type of virtual currency. It's called a cryptocurrency. Now the reason bad guys love bitcoin is that you can share it, not really anonymously, but somewhat anonymously. Our government does have ways of tracing this. I heard a lecture by a secret service member about how, they cracked some of these online organizations.

    But the thing that liked the most about it is you can send money by a bitcoin. And there's absolutely no way to get that money back. Once you've spent that money. There are people. All over the world. Yeah. That has been sending this guy or these guys money. Uh, one apparently in Japan as much as $40,000 in one transaction, I guess he, he really feels the burn.

    [00:07:00] Yeah. It's just incredible

    Jim Polito: Were talking with our good friend, Craig Peterson, tech talk guru. No, no need to look at your watch or your calendar. No, it is Thursday, but he's back here because of this situation with Twitter. So first of all, I mean the obvious advice to everybody is, uh, if you start seeing messages like that, uh, from, uh, uncle Joe Biden or Barack Obama or anyone else, uh, if it's too good to be true, It's too good.

    [00:08:00] It's like those messages I used to get that Bill Gates is giving away his, um, uh-huh. Millions of dollars and if you copy this email to 10 friends, you know, you'll, you'll get a piece of it, you know, yadda, yada, yada, and people believe it. You know, I mean, that's kind of slowed down a little bit. So you needed something more creative than people would believe, but you know, I don't think uncle Joe's going to be sending me any message soon. Yeah. I don't think

    Craig Peterson: First of all, giving away money. Yeah, what's new in there, right?

    Jim Polito: Well, but you'd be huge. He's giving away your money, you know, like tax dollars, but, but giving away his own money and then you have to do it through Bitcoin. No, thank you.

    Craig Peterson: And this isn't the first time this type of thing has happened.

    Facebook employees were using their privileged app to stalk women. Snapchat workers had a tool called Snap Lion that gave permission information on users. Myspace employees use their tool called Overlord to spy on users back in the day.

    Jim Polito: I was just going to say my ma my space. I mean, it wasn't that done in hieroglyphics.

    [00:09:00] Is that how old that didn't you need the Rosetta stone to be able to translate the trip around me based on tablets.

    Craig Peterson: Yeah. That's that was so I guess,

    Jim Polito: I guess these companies need to be a lot more selective about who gets this God mode, this mode, where they can do whatever they want, which is probably necessary to fix some issues. But hi, they better be very careful with who they give this to.

    Craig Peterson: You know, they're not being that careful, frankly, from what I've seen, look at Facebook recently, the news, because of problems with people who are doing the monitoring, who are saying, well, you can post this. You can't, that are like a third-party.

    So, yeah, these, these tools are in the hands of not just employees, the contractors, and they're falling for scams, according to Facebook, but according to the hackers, and this has been reported a few places online, according to the hackers, this was kind of an inside job. They got someone inside there, they turned them, or got them in there in the first place and had free reign. It's no different than people getting an insider at a bank or a jewelry store or something else like they did in the old days.

    Jim Polito: Craig Peterson, Hey, Craig, let's give out, let's give out your information in case folks want to reach out to you and um, and then you'll be back Tuesday, which is great.

    [00:10:00] Absolutely. You can just email me. Craig peterson.com. It's M E at Craig peterson.com or a hit or miss with the texting. I gotta get this thing fixed. You can just text me at (855) 385-5553. I've just been too busy lately.

    The standard data and text rates apply. I appreciate it, I know you are busy and I appreciate you coming in today for some extra duty and helping us out with, to understand this and we'll catch up with you Tuesday, Craig.

    Craig Peterson: Alright, take care, Jim. Thanks

    Jim Polito: You too.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    11 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…