Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Welcome! Automation and Security Jobs plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig's taking a look at Artificial Intelligence and what it may mean to the future of employment. Do you have to be worried right now?

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Could Automation Kill the Security Analyst?

    ---

    Automated Machine-Generated Transcript:

    Could artificial intelligence affect your job? And what does it mean to different business sectors? Well, if you're in a higher pain job, you might be surprised what Brookings Institute had to say.

    [00:00:18] Hey, welcome back, Craig Peter sauna here, we have had a busy, busy day today. And if you missed any part of today's show, you can go online and find it on your favorite podcasting app. And I'd love to get a little feedback from you. I had one of our listeners just a couple of weeks ago when I asked to show me where you are listening.

    [00:00:41] He took a picture of the dashboard of his car. He had it playing there in the car. I thought that was pretty darn cool. And I'd love to know from you too. Where are you listening to the podcast? What are you doing? And you can just email me M E and Craig peterson.com. You know, the thing about podcasts is I know how many downloads there have been, but that doesn't tell me much.

    [00:01:05] It doesn't tell me if the person that downloaded it actually listened to it. If they listen to it in Timbuktu, over in Northern Africa, in case you wonder where that is, or if they're listening to it in downtown Boston, it doesn't tell me anything about anybody. You know, the podcast might just be going into Nowheresville.

    [00:01:25] Now I know people who listened to him on the radio. Are listening, but I have a similar problem, right? Because I think we could do different things with the show based on where you are and what you're doing. I imagine that a lot of people listen to it while they're driving to and from work. Which is really, you know, very commonplace to listen to it.

    [00:01:49] Other people listen to it in the gym, and I know at least one of you listens to it in the truck driving around doing chores on the weekend. But if you would please do let me know. You can just send me a picture or send me a note to [email protected]. Last week I asked for you guys to reach out and, and let me know what you thought about having a show dedicated.

    [00:02:13] To windows updates. And I didn't really get a lot of positive responses to that. So I'm going to have to read into that, that you're not interested in understanding how to do updates and windows. If you, if you're one of those people that wants to know, make sure you email [email protected] and let me know, maybe it makes more sense to do it as a deeper dive.

    [00:02:37] It's something. Better for a webinar or I think the radio it's tough. Right? How do I explain click here, do this, you know, I can't explain the concepts and I'm going to try and do that next weekend here on the show so that everybody understands basically what's going on. And then maybe what we'll try and do is have a webinar where I'm really just delving deeply into it and helping you guys understand it.

    [00:03:05] And I've done these before on it. So it's nothing new to me. So we started out today talking about an application that is absolutely fantastic when it comes to your security and they're adding a new feature to it that will do automatic face blurring. And I gave you a couple of other options. And then we started talking about the new secure DNS settings for Chrome and Firefox and how they can help in some cases.

    [00:03:34] And they will definitely hurt and other cases. So if you are responsible for the network at your business, you're going to have to listen to that. And then we talked about insider threats. This is crazy 60% of our insider threats. Involve employees in planning on leaving. So, what are some of those signs that an employee might be a flight risk or that they're taking data?

    [00:04:02] What are the most common ways that they're stealing our information? I went over that today too. And then I started talking about the iPhone looters and I track all because I is, is there no low to the stupidity of criminals sometimes? Right here. They are stealing iPhones and of course, Apple's protecting them.

    [00:04:24] And then they're posting pictures on Twitter saying, Hey, look at what my iPhone said. It says an Apple is tracking me. Yeah. And now, so is anybody who saw you on Twitter? Uh, we went into something that many small businesses don't realize they've got to pay a lot more attention to, and that is security. If you are a government.

    [00:04:46] Sub sub-subcontractor, right? These regulations that the federal government has to roll down Hill. And if you're involved with anything that goes, boom, you know, military-type stuff. Man alive, the things they're doing right now with the new CMMC regulations. And I talked about how we helped a couple of businesses out just this week with some major security problems they weren't even aware of.

    [00:05:15] And now what'll happen with these new, new regulations in place, even if all you're doing. Is making a passive component for one of these military contractors that sell to the military, uh, you know, assembles it and sells it. You just make one small component. You could be out of business because of fines.

    [00:05:36] There are now 10-year prison sentences, everything else. So we talked about that. We talked about Google getting sued for at least $5 billion over some claimed, um, Inconsistency, shall we say incognito mode? Ain't incognito mode. Let's just leave it at that. A zoom. We just talked about that in how their defenders are citing legitimate reasons to not have end-to-end encryption.

    [00:06:06] And what that means. And we also talked about what the electronic frontier foundation had to say on that. And if you know those guys and gals, you certainly know what they probably said, and you'd probably be right. So let's get into this study. This is a study that came out from the Brookings Institute about jobs that are going to be lost when it comes to.

    [00:06:31] AI. Now we used to say, Oh, you're gonna lose your job to a robot. Well, that has happened. Obviously some manufacturing jobs are now being done by robots. But what we're talking about right now is intelligence. It's one thing to have a robot that's just repeatedly doing a specific job, but maybe. It has some cameras on it that allowed to adjust a little bit so that it has less of a tight tolerance for finding that bolt.

    [00:06:58] It wants to put the nut on too. So that's stage one in that's already happened. Now we're looking at AI artificial intelligence that can do a lot more. So what they found, and this is kind of interesting because the study was put together by a Ph.D. student and he took a whole different way of looking at it and his professors agreed with it and they published it.

    [00:07:25] And it's just, it's fascinating to look at it. He's got a lot of stats in there, but here are the basic findings number one. Artificial intelligence could affect work in virtually every occupational group. Now we know this, I don't think this is a big surprise to anybody it's going to affect trucking because these trucks are going to self-drive et cetera.

    [00:07:48] Right. So it's going to kind of hurt everywhere. But number two, Two says that better-paid white-collar occupations may be the most exposed to artificial intelligence, as well as some manufacturing and agricultural positions. Now that's interesting. And they have some graphs in this report that are showing.

    [00:08:11] That those people that have a high school education or less are basically the going to be the least effective. Those people with a bachelor's degree are the most likely to be affected. And that's typically your middle managers and then slightly less affected by AI and losing their jobs. Are those people with advanced degrees?

    [00:08:38] But when you think about those advanced degrees in business finance, Man. Those are the types of things that artificial intelligence can easily do. In fact, do better than most humans. The same. Thing's true in tech industries, they're going to be more exposed as well as natural resource and production industries.

    [00:08:59] Now I want to get into security analyst jobs here in just a minute because I think this is fascinating, but AI looks most destined to affect men. Prime age workers and white and Asian American workers. And number five in the findings was bigger. Higher tech Metro areas and communities heavily involved in manufacturing are likely to experience the most AI-related disruption.

    [00:09:31] Security is important, right? And security analysts are out there looking at what's going on, trying to figure out what they should do. And a great little article that was up on dark reading called could automation kill the security analyst because we were just talking about it, right? The higher, the skill, the higher the degree, the more likely you're going to lose your job to artificial intelligence.

    [00:09:58] Well, how about on the security front? Well there another study that was done over a thousand, it security practice practitioners in the US and the UK it's done by the Panama Institute. And they're saying, wow, wait a minute. Automation and I T security workers must work hand in hand to achieve maximum effectiveness.

    [00:10:23] Automation will never replace the need for the human element, especially for security professionals who have the expertise to manage these new technologies. In fact, 68% of respondents said they believe human involvement is important when using automation. So they've got five tips here to become proficient in how automation technologies operate, seek out an experienced mentor.

    [00:10:52] And right now we are actually mentoring a couple of people. They don't work for my company, worked for other companies, helping them out with their security roles, highlight, and understanding of automation, technologies, benchmark, how automation is being used, and get involved in organizations to share best.

    [00:11:11] Practices. And that's part of what we've been very involved in for many years. AI is going to be a huge, huge disruptor, but just like all of the big disruptors in the past, I don't see artificial intelligence as being an absolutely horrific thing. Look at what happened with, of course of a horse and buggy getting displaced by infernal combustion engines.

    [00:11:38] And we ended up at the Teamsters. Yeah, we got the union out of it, but in reality, we have more jobs now than we used to have, and they're more skilled jobs and that's what we're going to expect to happen in the future. The steam engine did the same thing. The fire probably did the same thing and the wheels certainly did the same.

    [00:11:59] But we've always had more and more people. And I am hoping I'm looking forward to the star Trek day, where we have the ability to have unlimited energy. And turn that energy into the matter so that we can own kind of have higher pursuits is going to be an interesting thing. But if you want more information on this and more, you'll find it right on my website.

    [00:12:23] Craig peterson.com. All of this week's articles are posted there as is the podcast. So check it out, make sure you get my newsletter. So you get the information. On special pieces of training, the popups, some doing as well as all of the new technology for the week, the things you need to know, and the things that you can share with your friends and family to help them understand some of the stuff.

    [00:12:50] You can be the hero to have a great week and we'll be back and next Saturday, one til three right here.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    14 min
  • Welcome! Collaboration, Zoom, Web-Ex and Encryption plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Today Craig’s got a deep-dive into Anti-Virus software. Which should you use? What is anti-Virus’s pioneer saying? What’s the future?

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Zoom defenders cite legit reasons to not end-to-end encrypt free calls

    ---

    Automated Machine-Generated Transcript:

    If you're like most people in the online world you have used zoom, you might even have put it in place for your business. They've now come out and said they are going to have end-to-end encryption. What's this all about?

    [00:00:17] Hi everybody. Craig Peterson here. Welcome back. Thanks for joining us. We're going to talk a little bit about zoom right now. You've heard me. I'm sure. Talked about it before and how I am constantly nagging you guys that if you are a business, you should not use zoom for anything that might be proprietary.

    [00:00:42] Zoom has been nailed and criticized multiple, multiple times. Zoom has been caught, lying about doing encryption more than once. Zoom was caught routing customer calls through China. Can you imagine that you're using Zoom? You're a business and your calls are going to China. They were caught installing a server on the Mac iOS application platform.

    [00:01:12] Now this is really, really something. This was the final straw. This is where we absolutely laid down the law with our employees and our customers. You may not use Zoom. Even if you installed zoom from Macko Wes zoom had a piece of software that constantly phoned home information. Even after you want to install the Mac zoom application, this list just goes on and on.

    [00:01:44] If you bought a higher-end zoom system for your business. And you had one of their controllers in your office, you know, a physical piece of hardware server. It had a brand it's his crazy, basically a zero-day back door wide open that they had put in purposely. That exposed every device on your network to hackers on the internet, anybody on the internet, can you believe that it's absolutely crazy.

    [00:02:21] Another company we were at just this week, we were doing some analysis, replacing firewalls with something much, much, much better. And. We're looking at the firewall configuration. Right? Cause you want to do that. You want to make sure, okay. We're putting in a new firewall that has way more features that can monitor what's going on.

    [00:02:42] That's going to block evilness. That's going to keep itself up to date. Right? All things that the basic firewalls that you buy online are not gonna be able to do for you. So we're looking at the configuration of their existing firewall. Now imagine our shock and amazement. When we saw that the firewall had a port wide open, the HTTPS port, the port you would use for a server that had the port wide open from the outside world.

    [00:03:15] In other words, anybody can connect to it. And that connected directly to their database server internally to SQL server, which wasn't even patched up. It's absolutely incredible. What's going on? We've got to pull up our socks. You have to do an audit. You know, I think I might do that again. What about a year and a half ago we had over a thousand people.

    [00:03:41] That we did free cyber health assessments for a lot of them were just home users, a number of businesses. And I have already sent out an email to businesses on my email list saying, Hey, listen, I will pay to have some of my security people talk to you now. Obviously we got to schedule it and everything else, but, um, Talk to you and fix your problems, not sell you a thing.

    [00:04:06] These are fire jumper, certified security people. Okay. They know what they're doing, but zoom, this is what they're doing. Right. And on top of it, they have most of the development done in China. So the developers aren't costing them hardly anything. Can you believe this? Right? It's a, it's easy to use, but it is a security.

    [00:04:29] Nightmare. What we use is WebEx teams. That's what we install for our clients. We have WebEx teams, phones. We have WebEx teams, apps on all of our smart devices, right. That's what we use. It is secure and to, and we actually control the security where we have the security keys and everything else.

    [00:04:53] So it has some of the highest levels of security on it. That's what we use. If you're not going to use WebEx teams, you might consider using Microsoft teams, which is okay. But again, Microsoft misrepresents, just like we talked about Google, uh, the, the levels of security you have. Now, if you dig into the documentation, Microsoft is going to be telling you the truth.

    [00:05:20] Okay. They're not lying, but the marketers. Excuse me. They just don't understand this stuff well enough, frankly, to make marketing materials because they end up misrepresenting. It goes on and on. Anyhow. So if you have looked. In Twitter, for instance, and you keep track of security stuff. Cause I know a lot of you guys you're the best and the brightest out there, you are watching some of these security conversations that are going on over on Twitter, but you've, I'm sure seen zoom just ripped.

    [00:05:56] Ripped ripped for his plans to enable end to end the encrypted video. What they're doing right now is an encrypted video from your computer using their 256-bit key, which is, uh, not great, but they encrypt it to their servers. And basically anybody can hop onto any of these zoom calls or they put a few things in place.

    [00:06:19] That's going to make it a little bit easier, a little bit better. But what they're saying is we're going to add end to end encryption and they have put a document up on Github, which is a website that's used by open source developers, zooms, put a document up there saying, okay, this is what we're planning on doing.

    [00:06:37] For our security strategy. What do you guys think? We'll see what happens, but Zoom is only going to be providing this end to end encryption for the video and audio and files for their paid customers. So when I looked around a little bit, I found our friends over at the electronic found frontier foundation, really complaining about this.

    [00:07:04] Because what they're saying is the people that cannot afford to have their messages exposed, cannot afford to pay for the encryption, the quote, right from their site here, we applaud zoom for building strong. And to end encryption into their service, but by limiting this security enhancement to pay the accounts, Zoom is denying privacy protections to the participant who may need them most.

    [00:07:38] And of course, they're talking about people primarily in third world countries. And giving people special access. Like if, if they gave the FBI or local law enforcement special access to these encrypted sessions, if it's available to one government it's available to more than one government. Right. And so they're concerned about that too.

    [00:08:01] And I, I think that's absolutely legitimate to be concerned about that, but. We'll see what happens here because what zoom is planning on doing is only having this end to end encryption for the paid accounts because they do not want these pedophiles. And some of the terrorists here are domestic terrorists in the US as well as internationally zoom doesn't want them using their platform to plot.

    [00:08:30] Plan coordinate, organize, et cetera. Now I talked earlier about signal and what signal is doing and Signal is end to end encrypted, no matter what, right. It is absolutely free. And that's what Moxie Marlinspike put out and why he did it. WhatsApp is the same way, but, uh, well, we'll see what happens with zoom because they're figuring, Hey, if you are paying for an account, You have a credit card that you're paying with there's some way of pain and that can be tracked by law enforcement if they need to track it.

    [00:09:07] So we'll just leave it at that, right. It's going to make it easy enough. And if you're not paying for it, which is how most of these pedophiles and others are apparently doing it. Do you using free accounts while then you get what you deserve? So don't use Zoom. I can't trust them. They've lied to us again and again and again.

    [00:09:26] And it's been proven multiple times. They're under investigation right now by a couple of federal agencies for some of these lies and misrepresentations. Don't use zoom use WebEx teams, which is what we use. And we use it with our customers, or maybe look at Microsoft teams, stick around. We've got I'll wrap up.

    [00:09:50] And one more thing. When we get back, you're listening to Craig Peterson on WGAN.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Collaboration, Zoom, Web-Ex and Encryption plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Today Craig’s got a deep-dive into Anti-Virus software. Which should you use? What is anti-Virus’s pioneer saying? What’s the future?

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Zoom defenders cite legit reasons to not end-to-end encrypt free calls

    ---

    Automated Machine-Generated Transcript:

    If you're like most people in the online world you have used zoom, you might even have put it in place for your business. They've now come out and said they are going to have end-to-end encryption. What's this all about?

    [00:00:17] Hi everybody. Craig Peterson here. Welcome back. Thanks for joining us. We're going to talk a little bit about zoom right now. You've heard me. I'm sure. Talked about it before and how I am constantly nagging you guys that if you are a business, you should not use zoom for anything that might be proprietary.

    [00:00:42] Zoom has been nailed and criticized multiple, multiple times. Zoom has been caught, lying about doing encryption more than once. Zoom was caught routing customer calls through China. Can you imagine that you're using Zoom? You're a business and your calls are going to China. They were caught installing a server on the Mac iOS application platform.

    [00:01:12] Now this is really, really something. This was the final straw. This is where we absolutely laid down the law with our employees and our customers. You may not use Zoom. Even if you installed zoom from Macko Wes zoom had a piece of software that constantly phoned home information. Even after you want to install the Mac zoom application, this list just goes on and on.

    [00:01:44] If you bought a higher-end zoom system for your business. And you had one of their controllers in your office, you know, a physical piece of hardware server. It had a brand it's his crazy, basically a zero-day back door wide open that they had put in purposely. That exposed every device on your network to hackers on the internet, anybody on the internet, can you believe that it's absolutely crazy.

    [00:02:21] Another company we were at just this week, we were doing some analysis, replacing firewalls with something much, much, much better. And. We're looking at the firewall configuration. Right? Cause you want to do that. You want to make sure, okay. We're putting in a new firewall that has way more features that can monitor what's going on.

    [00:02:42] That's going to block evilness. That's going to keep itself up to date. Right? All things that the basic firewalls that you buy online are not gonna be able to do for you. So we're looking at the configuration of their existing firewall. Now imagine our shock and amazement. When we saw that the firewall had a port wide open, the HTTPS port, the port you would use for a server that had the port wide open from the outside world.

    [00:03:15] In other words, anybody can connect to it. And that connected directly to their database server internally to SQL server, which wasn't even patched up. It's absolutely incredible. What's going on? We've got to pull up our socks. You have to do an audit. You know, I think I might do that again. What about a year and a half ago we had over a thousand people.

    [00:03:41] That we did free cyber health assessments for a lot of them were just home users, a number of businesses. And I have already sent out an email to businesses on my email list saying, Hey, listen, I will pay to have some of my security people talk to you now. Obviously we got to schedule it and everything else, but, um, Talk to you and fix your problems, not sell you a thing.

    [00:04:06] These are fire jumper, certified security people. Okay. They know what they're doing, but zoom, this is what they're doing. Right. And on top of it, they have most of the development done in China. So the developers aren't costing them hardly anything. Can you believe this? Right? It's a, it's easy to use, but it is a security.

    [00:04:29] Nightmare. What we use is WebEx teams. That's what we install for our clients. We have WebEx teams, phones. We have WebEx teams, apps on all of our smart devices, right. That's what we use. It is secure and to, and we actually control the security where we have the security keys and everything else.

    [00:04:53] So it has some of the highest levels of security on it. That's what we use. If you're not going to use WebEx teams, you might consider using Microsoft teams, which is okay. But again, Microsoft misrepresents, just like we talked about Google, uh, the, the levels of security you have. Now, if you dig into the documentation, Microsoft is going to be telling you the truth.

    [00:05:20] Okay. They're not lying, but the marketers. Excuse me. They just don't understand this stuff well enough, frankly, to make marketing materials because they end up misrepresenting. It goes on and on. Anyhow. So if you have looked. In Twitter, for instance, and you keep track of security stuff. Cause I know a lot of you guys you're the best and the brightest out there, you are watching some of these security conversations that are going on over on Twitter, but you've, I'm sure seen zoom just ripped.

    [00:05:56] Ripped ripped for his plans to enable end to end the encrypted video. What they're doing right now is an encrypted video from your computer using their 256-bit key, which is, uh, not great, but they encrypt it to their servers. And basically anybody can hop onto any of these zoom calls or they put a few things in place.

    [00:06:19] That's going to make it a little bit easier, a little bit better. But what they're saying is we're going to add end to end encryption and they have put a document up on Github, which is a website that's used by open source developers, zooms, put a document up there saying, okay, this is what we're planning on doing.

    [00:06:37] For our security strategy. What do you guys think? We'll see what happens, but Zoom is only going to be providing this end to end encryption for the video and audio and files for their paid customers. So when I looked around a little bit, I found our friends over at the electronic found frontier foundation, really complaining about this.

    [00:07:04] Because what they're saying is the people that cannot afford to have their messages exposed, cannot afford to pay for the encryption, the quote, right from their site here, we applaud zoom for building strong. And to end encryption into their service, but by limiting this security enhancement to pay the accounts, Zoom is denying privacy protections to the participant who may need them most.

    [00:07:38] And of course, they're talking about people primarily in third world countries. And giving people special access. Like if, if they gave the FBI or local law enforcement special access to these encrypted sessions, if it's available to one government it's available to more than one government. Right. And so they're concerned about that too.

    [00:08:01] And I, I think that's absolutely legitimate to be concerned about that, but. We'll see what happens here because what zoom is planning on doing is only having this end to end encryption for the paid accounts because they do not want these pedophiles. And some of the terrorists here are domestic terrorists in the US as well as internationally zoom doesn't want them using their platform to plot.

    [00:08:30] Plan coordinate, organize, et cetera. Now I talked earlier about signal and what signal is doing and Signal is end to end encrypted, no matter what, right. It is absolutely free. And that's what Moxie Marlinspike put out and why he did it. WhatsApp is the same way, but, uh, well, we'll see what happens with zoom because they're figuring, Hey, if you are paying for an account, You have a credit card that you're paying with there's some way of pain and that can be tracked by law enforcement if they need to track it.

    [00:09:07] So we'll just leave it at that, right. It's going to make it easy enough. And if you're not paying for it, which is how most of these pedophiles and others are apparently doing it. Do you using free accounts while then you get what you deserve? So don't use Zoom. I can't trust them. They've lied to us again and again and again.

    [00:09:26] And it's been proven multiple times. They're under investigation right now by a couple of federal agencies for some of these lies and misrepresentations. Don't use zoom use WebEx teams, which is what we use. And we use it with our customers, or maybe look at Microsoft teams, stick around. We've got I'll wrap up.

    [00:09:50] And one more thing. When we get back, you're listening to Craig Peterson on WGAN.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Collaboration, Zoom, Web-Ex and Encryption plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Today Craig's got a deep-dive into Anti-Virus software. Which should you use? What is anti-Virus's pioneer saying? What's the future?

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Zoom defenders cite legit reasons to not end-to-end encrypt free calls

    ---

    Automated Machine-Generated Transcript:

    If you're like most people in the online world you have used zoom, you might even have put it in place for your business. They've now come out and said they are going to have end-to-end encryption. What's this all about?

    [00:00:17] Hi everybody. Craig Peterson here. Welcome back. Thanks for joining us. We're going to talk a little bit about zoom right now. You've heard me. I'm sure. Talked about it before and how I am constantly nagging you guys that if you are a business, you should not use zoom for anything that might be proprietary.

    [00:00:42] Zoom has been nailed and criticized multiple, multiple times. Zoom has been caught, lying about doing encryption more than once. Zoom was caught routing customer calls through China. Can you imagine that you're using Zoom? You're a business and your calls are going to China. They were caught installing a server on the Mac iOS application platform.

    [00:01:12] Now this is really, really something. This was the final straw. This is where we absolutely laid down the law with our employees and our customers. You may not use Zoom. Even if you installed zoom from Macko Wes zoom had a piece of software that constantly phoned home information. Even after you want to install the Mac zoom application, this list just goes on and on.

    [00:01:44] If you bought a higher-end zoom system for your business. And you had one of their controllers in your office, you know, a physical piece of hardware server. It had a brand it's his crazy, basically a zero-day back door wide open that they had put in purposely. That exposed every device on your network to hackers on the internet, anybody on the internet, can you believe that it's absolutely crazy.

    [00:02:21] Another company we were at just this week, we were doing some analysis, replacing firewalls with something much, much, much better. And. We're looking at the firewall configuration. Right? Cause you want to do that. You want to make sure, okay. We're putting in a new firewall that has way more features that can monitor what's going on.

    [00:02:42] That's going to block evilness. That's going to keep itself up to date. Right? All things that the basic firewalls that you buy online are not gonna be able to do for you. So we're looking at the configuration of their existing firewall. Now imagine our shock and amazement. When we saw that the firewall had a port wide open, the HTTPS port, the port you would use for a server that had the port wide open from the outside world.

    [00:03:15] In other words, anybody can connect to it. And that connected directly to their database server internally to SQL server, which wasn't even patched up. It's absolutely incredible. What's going on? We've got to pull up our socks. You have to do an audit. You know, I think I might do that again. What about a year and a half ago we had over a thousand people.

    [00:03:41] That we did free cyber health assessments for a lot of them were just home users, a number of businesses. And I have already sent out an email to businesses on my email list saying, Hey, listen, I will pay to have some of my security people talk to you now. Obviously we got to schedule it and everything else, but, um, Talk to you and fix your problems, not sell you a thing.

    [00:04:06] These are fire jumper, certified security people. Okay. They know what they're doing, but zoom, this is what they're doing. Right. And on top of it, they have most of the development done in China. So the developers aren't costing them hardly anything. Can you believe this? Right? It's a, it's easy to use, but it is a security.

    [00:04:29] Nightmare. What we use is WebEx teams. That's what we install for our clients. We have WebEx teams, phones. We have WebEx teams, apps on all of our smart devices, right. That's what we use. It is secure and to, and we actually control the security where we have the security keys and everything else.

    [00:04:53] So it has some of the highest levels of security on it. That's what we use. If you're not going to use WebEx teams, you might consider using Microsoft teams, which is okay. But again, Microsoft misrepresents, just like we talked about Google, uh, the, the levels of security you have. Now, if you dig into the documentation, Microsoft is going to be telling you the truth.

    [00:05:20] Okay. They're not lying, but the marketers. Excuse me. They just don't understand this stuff well enough, frankly, to make marketing materials because they end up misrepresenting. It goes on and on. Anyhow. So if you have looked. In Twitter, for instance, and you keep track of security stuff. Cause I know a lot of you guys you're the best and the brightest out there, you are watching some of these security conversations that are going on over on Twitter, but you've, I'm sure seen zoom just ripped.

    [00:05:56] Ripped ripped for his plans to enable end to end the encrypted video. What they're doing right now is an encrypted video from your computer using their 256-bit key, which is, uh, not great, but they encrypt it to their servers. And basically anybody can hop onto any of these zoom calls or they put a few things in place.

    [00:06:19] That's going to make it a little bit easier, a little bit better. But what they're saying is we're going to add end to end encryption and they have put a document up on Github, which is a website that's used by open source developers, zooms, put a document up there saying, okay, this is what we're planning on doing.

    [00:06:37] For our security strategy. What do you guys think? We'll see what happens, but Zoom is only going to be providing this end to end encryption for the video and audio and files for their paid customers. So when I looked around a little bit, I found our friends over at the electronic found frontier foundation, really complaining about this.

    [00:07:04] Because what they're saying is the people that cannot afford to have their messages exposed, cannot afford to pay for the encryption, the quote, right from their site here, we applaud zoom for building strong. And to end encryption into their service, but by limiting this security enhancement to pay the accounts, Zoom is denying privacy protections to the participant who may need them most.

    [00:07:38] And of course, they're talking about people primarily in third world countries. And giving people special access. Like if, if they gave the FBI or local law enforcement special access to these encrypted sessions, if it's available to one government it's available to more than one government. Right. And so they're concerned about that too.

    [00:08:01] And I, I think that's absolutely legitimate to be concerned about that, but. We'll see what happens here because what zoom is planning on doing is only having this end to end encryption for the paid accounts because they do not want these pedophiles. And some of the terrorists here are domestic terrorists in the US as well as internationally zoom doesn't want them using their platform to plot.

    [00:08:30] Plan coordinate, organize, et cetera. Now I talked earlier about signal and what signal is doing and Signal is end to end encrypted, no matter what, right. It is absolutely free. And that's what Moxie Marlinspike put out and why he did it. WhatsApp is the same way, but, uh, well, we'll see what happens with zoom because they're figuring, Hey, if you are paying for an account, You have a credit card that you're paying with there's some way of pain and that can be tracked by law enforcement if they need to track it.

    [00:09:07] So we'll just leave it at that, right. It's going to make it easy enough. And if you're not paying for it, which is how most of these pedophiles and others are apparently doing it. Do you using free accounts while then you get what you deserve? So don't use Zoom. I can't trust them. They've lied to us again and again and again.

    [00:09:26] And it's been proven multiple times. They're under investigation right now by a couple of federal agencies for some of these lies and misrepresentations. Don't use zoom use WebEx teams, which is what we use. And we use it with our customers, or maybe look at Microsoft teams, stick around. We've got I'll wrap up.

    [00:09:50] And one more thing. When we get back, you're listening to Craig Peterson on WGAN.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! Incognito Mode and Why it May Not Protect You, and more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    We have all heard of Incognito Mode on our Browsers, but what you may not know is that it may not be protecting you. Listen in and I will explain why.

     

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Google sued for at least $5 billion over-claimed ‘Incognito mode’ grab of ‘potentially embarrassing’ browsing data

    ---

    Automated Machine-Generated Transcript:

    Now isn't that interesting incognito mode, right? When you're going into incognito mode, it's when you want your data to be private. So a lot of people go to Incognito mode when they're doing some shopping, maybe they're Googling things and they don't want to see a hundred thousand ads for a hair straightener over the next three weeks when the ads come up.

    [00:00:25] So they switch into incognito mode. I, you know, I think that's a reasonable thing to try and I'm going to give you as well as some names of a couple of products you'd probably want to look at and I've done some training on and we should probably release some training on them again. But anyways, free stuff.

    [00:00:44] Incognito mode is apparently. Not going to block that information. So of course, the lawsuit talks here about the pervasive data tracking Google does. They know who your friends are, your hobbies, what you like to eat, the movies you watch wearing when you like to shop your favorite vacation destinations, and the suits alleging that whether or not you are using incognito mode, Google?

    [00:01:16] Is still collecting it. So we'll see what happens here. Uh, the language is really kind of where it's focused here. The language Google is using to explain incognito mode. It says that incognito mode allows users to quote, browse the web privately, and quote. And Google pointing to advisories to the user that explained private browsing doesn't mean data is not collected.

    [00:01:46] So Google is going to defend itself, of course, but you know, incognito mode, these private modes are not private. So don't think that just because you're turning it on that you're not being tracked. All right. Don't think that just you turned it on that your computer doesn't have little turds left, lying around that can be used to figure out what you did and how you did it.

    [00:02:11] And unbeknownst to most users, Google is constantly tracking everything you read and request click by click page by page in real-time because a lot of the websites have Google cookies on them that allows Google analytics and Google ad manager now to know where you've gone and what you have done. So don't trust it.

    [00:02:34] So I promised I would give you some alternatives. Uh, first let's just mention Safari kugel, also intercepts browsing data when the private modes are used on all other browsers, including Safari. Right? So don't think this is just a Chrome problem. Google is collecting it everywhere and it has to do primarily with the cookies, but also you can now identify.

    [00:03:02] A browser, a specific computer without ever reading a cookie by looking at what that configuration is for that computer because that becomes quite a little fingerprint as well. What software do you have installed? How much memory what's the processor, but a version of the operating system, et cetera, et cetera.

    [00:03:20] Right? So they can really track you down. So what I do is I recommend a couple of things. First of all, if you really want to browse privately on the web. Use Epic -E P I C. Epic browser.com is where you'll find it. It is based on Google Chrome, but they have removed all of the tracking information from it.

    [00:03:44] So that's the first one. The second thing is Epic. It isn't going to work for everybody and it's not going to work for every website. That's for sure. So what you probably want to do is get a couple of privacy plugins that you can use. Privacy. Badger is one that I recommend and I, in my training courses, I show you how to get it and how to install it.

    [00:04:09] You block origin is another good one. That you probably should look at it installing. And there are a few others that I recommend as well, depending on what you're trying to do, but that's the only way you are going to get some privacy online. Ultimately, if you want the ultimate in privacy in one, in one way, right?

    [00:04:30] In another way, it's a little less than the ultimate, but generally speaking, it's ultimate and privacy. Do this. Get the tour browser T O R. It runs on the onion network. You're going to find it to be a lot slower than all the other browsers out there. And you are getting lumped in with some very bad people that use the Tor browser.

    [00:04:53] So, you know, take that into account as well. When you're looking at it, should you use it? Should you not use it? That's going to be up to you, but if you absolutely want to make sure that your data is not being captured by your ISP and that your data is not. Being stored on your computer, a good way to get there.

    [00:05:14] At least most of the way there is to use the Tor browser. Now there are other tools you can use. Maybe I'll, I'll put together some courses on that. You have to let me know if you're interested, where there are secure operating systems and other things you can use, to try and keep your information. Sure.

    [00:05:30] Because listen secure. If you have your retirement, do you really want to have that all stolen? If your retirement set up in your business, do you want your business shut down? There's a lot of good reasons to try and keep your data safe. So stick around. We're going to be right back. We're going to be talking about zoom and end to end encryption.

    [00:05:54] This is Craig Peterson here, and visit me online. Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

     

    7 min
  • Welcome! Incognito Mode and Why it May Not Protect You, and more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    We have all heard of Incognito Mode on our Browsers, but what you may not know is that it may not be protecting you. Listen in and I will explain why.

     

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Google sued for at least $5 billion over-claimed ‘Incognito mode’ grab of ‘potentially embarrassing’ browsing data

    ---

    Automated Machine-Generated Transcript:

    Now isn't that interesting incognito mode, right? When you're going into incognito mode, it's when you want your data to be private. So a lot of people go to Incognito mode when they're doing some shopping, maybe they're Googling things and they don't want to see a hundred thousand ads for a hair straightener over the next three weeks when the ads come up.

    [00:00:25] So they switch into incognito mode. I, you know, I think that's a reasonable thing to try and I'm going to give you as well as some names of a couple of products you'd probably want to look at and I've done some training on and we should probably release some training on them again. But anyways, free stuff.

    [00:00:44] Incognito mode is apparently. Not going to block that information. So of course, the lawsuit talks here about the pervasive data tracking Google does. They know who your friends are, your hobbies, what you like to eat, the movies you watch wearing when you like to shop your favorite vacation destinations, and the suits alleging that whether or not you are using incognito mode, Google?

    [00:01:16] Is still collecting it. So we'll see what happens here. Uh, the language is really kind of where it's focused here. The language Google is using to explain incognito mode. It says that incognito mode allows users to quote, browse the web privately, and quote. And Google pointing to advisories to the user that explained private browsing doesn't mean data is not collected.

    [00:01:46] So Google is going to defend itself, of course, but you know, incognito mode, these private modes are not private. So don't think that just because you're turning it on that you're not being tracked. All right. Don't think that just you turned it on that your computer doesn't have little turds left, lying around that can be used to figure out what you did and how you did it.

    [00:02:11] And unbeknownst to most users, Google is constantly tracking everything you read and request click by click page by page in real-time because a lot of the websites have Google cookies on them that allows Google analytics and Google ad manager now to know where you've gone and what you have done. So don't trust it.

    [00:02:34] So I promised I would give you some alternatives. Uh, first let's just mention Safari kugel, also intercepts browsing data when the private modes are used on all other browsers, including Safari. Right? So don't think this is just a Chrome problem. Google is collecting it everywhere and it has to do primarily with the cookies, but also you can now identify.

    [00:03:02] A browser, a specific computer without ever reading a cookie by looking at what that configuration is for that computer because that becomes quite a little fingerprint as well. What software do you have installed? How much memory what's the processor, but a version of the operating system, et cetera, et cetera.

    [00:03:20] Right? So they can really track you down. So what I do is I recommend a couple of things. First of all, if you really want to browse privately on the web. Use Epic -E P I C. Epic browser.com is where you'll find it. It is based on Google Chrome, but they have removed all of the tracking information from it.

    [00:03:44] So that's the first one. The second thing is Epic. It isn't going to work for everybody and it's not going to work for every website. That's for sure. So what you probably want to do is get a couple of privacy plugins that you can use. Privacy. Badger is one that I recommend and I, in my training courses, I show you how to get it and how to install it.

    [00:04:09] You block origin is another good one. That you probably should look at it installing. And there are a few others that I recommend as well, depending on what you're trying to do, but that's the only way you are going to get some privacy online. Ultimately, if you want the ultimate in privacy in one, in one way, right?

    [00:04:30] In another way, it's a little less than the ultimate, but generally speaking, it's ultimate and privacy. Do this. Get the tour browser T O R. It runs on the onion network. You're going to find it to be a lot slower than all the other browsers out there. And you are getting lumped in with some very bad people that use the Tor browser.

    [00:04:53] So, you know, take that into account as well. When you're looking at it, should you use it? Should you not use it? That's going to be up to you, but if you absolutely want to make sure that your data is not being captured by your ISP and that your data is not. Being stored on your computer, a good way to get there.

    [00:05:14] At least most of the way there is to use the Tor browser. Now there are other tools you can use. Maybe I'll, I'll put together some courses on that. You have to let me know if you're interested, where there are secure operating systems and other things you can use, to try and keep your information. Sure.

    [00:05:30] Because listen secure. If you have your retirement, do you really want to have that all stolen? If your retirement set up in your business, do you want your business shut down? There's a lot of good reasons to try and keep your data safe. So stick around. We're going to be right back. We're going to be talking about zoom and end to end encryption.

    [00:05:54] This is Craig Peterson here, and visit me online. Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

     

    7 min
  • Welcome! Incognito Mode and Why it May Not Protect You, and more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    We have all heard of Incognito Mode on our Browsers, but what you may not know is that it may not be protecting you. Listen in and I will explain why.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    Google sued for at least $5 billion over-claimed 'Incognito mode' grab of 'potentially embarrassing' browsing data

    ---

    Automated Machine-Generated Transcript:

    Now isn't that interesting incognito mode, right? When you're going into incognito mode, it's when you want your data to be private. So a lot of people go to Incognito mode when they're doing some shopping, maybe they're Googling things and they don't want to see a hundred thousand ads for a hair straightener over the next three weeks when the ads come up.

    [00:00:25] So they switch into incognito mode. I, you know, I think that's a reasonable thing to try and I'm going to give you as well as some names of a couple of products you'd probably want to look at and I've done some training on and we should probably release some training on them again. But anyways, free stuff.

    [00:00:44] Incognito mode is apparently. Not going to block that information. So of course, the lawsuit talks here about the pervasive data tracking Google does. They know who your friends are, your hobbies, what you like to eat, the movies you watch wearing when you like to shop your favorite vacation destinations, and the suits alleging that whether or not you are using incognito mode, Google?

    [00:01:16] Is still collecting it. So we'll see what happens here. Uh, the language is really kind of where it's focused here. The language Google is using to explain incognito mode. It says that incognito mode allows users to quote, browse the web privately, and quote. And Google pointing to advisories to the user that explained private browsing doesn't mean data is not collected.

    [00:01:46] So Google is going to defend itself, of course, but you know, incognito mode, these private modes are not private. So don't think that just because you're turning it on that you're not being tracked. All right. Don't think that just you turned it on that your computer doesn't have little turds left, lying around that can be used to figure out what you did and how you did it.

    [00:02:11] And unbeknownst to most users, Google is constantly tracking everything you read and request click by click page by page in real-time because a lot of the websites have Google cookies on them that allows Google analytics and Google ad manager now to know where you've gone and what you have done. So don't trust it.

    [00:02:34] So I promised I would give you some alternatives. Uh, first let's just mention Safari kugel, also intercepts browsing data when the private modes are used on all other browsers, including Safari. Right? So don't think this is just a Chrome problem. Google is collecting it everywhere and it has to do primarily with the cookies, but also you can now identify.

    [00:03:02] A browser, a specific computer without ever reading a cookie by looking at what that configuration is for that computer because that becomes quite a little fingerprint as well. What software do you have installed? How much memory what's the processor, but a version of the operating system, et cetera, et cetera.

    [00:03:20] Right? So they can really track you down. So what I do is I recommend a couple of things. First of all, if you really want to browse privately on the web. Use Epic -E P I C. Epic browser.com is where you'll find it. It is based on Google Chrome, but they have removed all of the tracking information from it.

    [00:03:44] So that's the first one. The second thing is Epic. It isn't going to work for everybody and it's not going to work for every website. That's for sure. So what you probably want to do is get a couple of privacy plugins that you can use. Privacy. Badger is one that I recommend and I, in my training courses, I show you how to get it and how to install it.

    [00:04:09] You block origin is another good one. That you probably should look at it installing. And there are a few others that I recommend as well, depending on what you're trying to do, but that's the only way you are going to get some privacy online. Ultimately, if you want the ultimate in privacy in one, in one way, right?

    [00:04:30] In another way, it's a little less than the ultimate, but generally speaking, it's ultimate and privacy. Do this. Get the tour browser T O R. It runs on the onion network. You're going to find it to be a lot slower than all the other browsers out there. And you are getting lumped in with some very bad people that use the Tor browser.

    [00:04:53] So, you know, take that into account as well. When you're looking at it, should you use it? Should you not use it? That's going to be up to you, but if you absolutely want to make sure that your data is not being captured by your ISP and that your data is not. Being stored on your computer, a good way to get there.

    [00:05:14] At least most of the way there is to use the Tor browser. Now there are other tools you can use. Maybe I'll, I'll put together some courses on that. You have to let me know if you're interested, where there are secure operating systems and other things you can use, to try and keep your information. Sure.

    [00:05:30] Because listen secure. If you have your retirement, do you really want to have that all stolen? If your retirement set up in your business, do you want your business shut down? There's a lot of good reasons to try and keep your data safe. So stick around. We're going to be right back. We're going to be talking about zoom and end to end encryption.

    [00:05:54] This is Craig Peterson here, and visit me online. Craig peterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    7 min
  • Welcome! Password Requirements for Military Contractors and General Business Best Practices and more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig fills you in the Best Security Practices for Passwords and What is absolutely required by anyone who is contracting with the US Military.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    What Government Contractors Need to Know About NIST, DFARS Password Reqs

    ---

    Automated Machine-Generated Transcript:

    Hey, does your business make something that might be used all ultimately by a government contractor? Did you know that all of the requirements that they have rolled downhill right into your lap? That's what we're going to talk about.

    [00:00:22] Hey everybody. Welcome. This is Craig Peterson. I'm so glad you guys are here. There are so many things to understand in this whole world of security and technology is frankly, it's just very, very confusing. It's impossible to catch up on. I'll give you that. And it's very hard to keep up on. So what I've been trying to do here on the show, and then.

    [00:00:44] And in the webinars that I've been putting on is to help you guys understand it, turn it into English, make it something that's workable. I had quite a week last week, very, very eyeopening to me because I've been working with a few different companies this justice last week that had major security problems and were completely unaware of it.

    To me, that is just completely unreasonable, right? Well, I shouldn't say they weren't unaware of them. One of them was the pizza shop that I mentioned, and they knew something was up because the payment card industry guys knocked on their door and say, it said, Hey, we got to do an audit.

    [00:01:27] And they came in, took one, look at the equipment that they had. Back in the, you know, computer room, if you want to call it that, you know, where the server is and immediately failed them. That's all they had to do was see that links us Rotter is sitting up on the wall because the link says is not good enough for businesses to keep your data safe.

    [00:01:49] And frankly, the same thing is true for many of the other products out there. Now there's a lot of other levels that go beyond where. The payment card industry is requiring. And one of those is for government subcontractors. I have quite a few clients that are government subcontractors, and I think every one of them came to me because they had.

    [00:02:14] Problems there they were trying to solve something was wrong. It was, it was, computers were slow emails. Weren't getting routed properly. Some of their customers were getting emails that actually weren't sent by them and yet had their return address on them. Right. Those sorts of problems. So we got involved and had a look and figured things out.

    [00:02:36] And you've heard a few of those stories here. Well, this week was interesting because one of the listeners for the show reached out to me. He got a job. Helping out a business that is a small business. It is, you know, by small, small business standards, it's a decent-sized business, but they make components that are used by the federal government, by the military.

    [00:03:03] And they were not doing what needed to be done. Not at all. And they think that they should be able to be ready in the next 18 months for the lowest level. And maybe they will, but based on what they do, uh, they got to get a lot more ready, a lot higher. Right. That's the basic definition here. Is, if you make something that either goes boom or at attaches to something that goes, boom, you have to comply with something called DFARs.

    [00:03:40] And I tar now DFARs is the defense federal acquisition regulation supplement much easier to just say DFAR is isn't it. And this is a set of standards that apply to civilians. And defense agencies in the United States, ITAR gets even higher level and it requires compliance, but I tar basically means yeah.

    [00:04:04] Yeah. Things go, boom. Okay. So if you make a component, so I have clients that make something as simple as power supplies. And those power supplies are used by military contractors and they go into various types of devices, another client, we went out to them and to help them out, they decided not to spend the money they needed to spend.

    [00:04:28] I have no idea what they ended up doing, but they make cable harnesses that are used in military systems. And they weren't even close to being compliant, which is, you know, the typical thing that we see. So here's your problem, frankly, because of the new teeth that are in place now where they've taken and they moved it to something called CMMC and the CMMC is requiring them to do.

    [00:04:58] Even more and it has even more teeth on it. It's absolutely amazing. So we've, this is in place to help protect federal contract information. And a lot of these manufacturers say, Hey, you know, it's not going to happen to me. I make power supplies. I make screws. I make assemblies. And in some cases they make much more fancy stuff, but.

    [00:05:23] It does. It applies to all of you and organizations that failed to comply with these rules can get hit badly with massive fines, class, oxygen, lawsuits, and also jail time for the owners of the business, for the people who are supposed to be running the business. Real jail time. We're talking about 10-year terms for some of these things.

    [00:05:50] So we have to be careful. We have to look at what we're doing and we have to understand if what we're doing is the right thing. So how does this apply to you? Well, if you are just a regular civilian, I think you should be happy that finally the federal government. Is trying to protect our information.

    [00:06:14] Right. We've had the Chinese attacking us and we've been in these businesses where the Chinese had backdoors installed. And what does that mean? What's a backdoor while he imagines that your computers that contain your proprietary information are directly accessible by the Chinese. So that means whether or not it's military, your computer, the information on it is now in the hands of the Chinese.

    [00:06:44] And in the case of one of our clients, what that means is all of his designs. All of his clients lists all of everything that he has worked his whole life for. He now gets to compete against a Chinese manufacturer that has been given all of that stuff. So imagine that happened to you. What does that mean?

    [00:07:05] It, it means that our military isn't as secure as we had hoped it'd been. And we could go through all kinds of stories here. I, I really want to kind of stay focused, but what this means is we need to make sure, especially in this kind of post COVID world, that all of our systems are up to date. All of our systems are properly secured.

    [00:07:31] So this, this company, this week, one of these companies this week, they had put in VPNs and they had used some slightly higher-end equipment. You can't just go and buy SonicWall off of the shelves over at staples, but it does not meet any of these federal guidelines. And what really, really upsets me here is that.

    [00:07:57]They do a search online for the model of hardware, software, whatever it is they're using. And they're looking for an instance for compliance and it says, yeah, we're DFARs compliant when they are not compliant. It just. Ah, I don't know what to do about it. Maybe it's just me, right? Maybe I'm just a little bit too uptight here, but they're conning people.

    [00:08:24] They're conning you. And if you've attended my webinars, you know how these VPN companies are, conning is how these privacy protection companies are. Conning how the antivirus vendors are calling you. And I'm also seeing this for our, our military subcontractors. All of them that I've been involved with have been conned.

    [00:08:46] And now that's not true with the really big ones. Right. I deal with small businesses, 500 employees, and smaller, but. Man. They don't even know what they don't know. And that's part of the problem. Right? That's always part of the problem. So there are a few things I want you guys to, to understand and know, cause this applies to everybody.

    [00:09:09] First of all. Nest. This is a government organization that comes out with standards. It's a national Institute of standards and technology. And remember, they used to advise that you have these super-duper fancy passwords that are hard to remember and a different password on every machine. And you had to change them every month or two.

    [00:09:32] Well, they have relaxed that now, and they follow the same guidance that I've been preaching for years, which is. Have a passphrase, a set of words that you remember that you're not going to forget and that you can type in pretty quickly, but it may be 30, 40 characters long. And then use that in conjunction with a good password manager, like one password that is going to keep all of the passwords for you.

    [00:09:59] So you have the one big, really good master password and then a whole bunch of. A password stored in your password manager. Now let's see multifactor authentication is the next one I have on my list. And it is not what it used to be. Unfortunately, a multifactor authentication. Now a lot of people are looking at it as well.

    [00:10:22] Uh, it's just a text message. I'm gonna need a text message. Well, okay. That's, isn't that wonderful, but that is not true. Multifactor authentication, you know, multifactor authentication means something that, you know, along with something that you have, like a mobile app or security key. So be careful with this.

    [00:10:41] And again, if you're government contractor, you've got to use. Special types of key chain storage like TPM or TEA. If you need more information, by all means, reach out to M E [email protected]. But if you're looking at getting some of this federal government money, By being a contractor, or if your devices are used or materials are used by military contractors realize that your neck is really on the line.

    [00:11:13] Now with CMMC long jail term, backbreaking fines, it will put you out of business. If you get audited, or if you lose some of this data, Hey, when we come back, we're going to talk about a lawsuit and, and I think this one's going somewhere. Google got sued for at least $5 billion because Incognito mode is not the incognito mode they've been advertising.

    [00:11:42] Hey, how sad for fun? Make sure you sign up. You get all of the information for business for home. Craig peterson.com/subscribes to crown. I'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Password Requirements for Military Contractors and General Business Best Practices and more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig fills you in the Best Security Practices for Passwords and What is absolutely required by anyone who is contracting with the US Military.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    What Government Contractors Need to Know About NIST, DFARS Password Reqs

    ---

    Automated Machine-Generated Transcript:

    Hey, does your business make something that might be used all ultimately by a government contractor? Did you know that all of the requirements that they have rolled downhill right into your lap? That's what we're going to talk about.

    [00:00:22] Hey everybody. Welcome. This is Craig Peterson. I'm so glad you guys are here. There are so many things to understand in this whole world of security and technology is frankly, it's just very, very confusing. It's impossible to catch up on. I'll give you that. And it's very hard to keep up on. So what I've been trying to do here on the show, and then.

    [00:00:44] And in the webinars that I've been putting on is to help you guys understand it, turn it into English, make it something that's workable. I had quite a week last week, very, very eyeopening to me because I've been working with a few different companies this justice last week that had major security problems and were completely unaware of it.

    To me, that is just completely unreasonable, right? Well, I shouldn't say they weren't unaware of them. One of them was the pizza shop that I mentioned, and they knew something was up because the payment card industry guys knocked on their door and say, it said, Hey, we got to do an audit.

    [00:01:27] And they came in, took one, look at the equipment that they had. Back in the, you know, computer room, if you want to call it that, you know, where the server is and immediately failed them. That's all they had to do was see that links us Rotter is sitting up on the wall because the link says is not good enough for businesses to keep your data safe.

    [00:01:49] And frankly, the same thing is true for many of the other products out there. Now there's a lot of other levels that go beyond where. The payment card industry is requiring. And one of those is for government subcontractors. I have quite a few clients that are government subcontractors, and I think every one of them came to me because they had.

    [00:02:14] Problems there they were trying to solve something was wrong. It was, it was, computers were slow emails. Weren't getting routed properly. Some of their customers were getting emails that actually weren't sent by them and yet had their return address on them. Right. Those sorts of problems. So we got involved and had a look and figured things out.

    [00:02:36] And you've heard a few of those stories here. Well, this week was interesting because one of the listeners for the show reached out to me. He got a job. Helping out a business that is a small business. It is, you know, by small, small business standards, it's a decent-sized business, but they make components that are used by the federal government, by the military.

    [00:03:03] And they were not doing what needed to be done. Not at all. And they think that they should be able to be ready in the next 18 months for the lowest level. And maybe they will, but based on what they do, uh, they got to get a lot more ready, a lot higher. Right. That's the basic definition here. Is, if you make something that either goes boom or at attaches to something that goes, boom, you have to comply with something called DFARs.

    [00:03:40] And I tar now DFARs is the defense federal acquisition regulation supplement much easier to just say DFAR is isn't it. And this is a set of standards that apply to civilians. And defense agencies in the United States, ITAR gets even higher level and it requires compliance, but I tar basically means yeah.

    [00:04:04] Yeah. Things go, boom. Okay. So if you make a component, so I have clients that make something as simple as power supplies. And those power supplies are used by military contractors and they go into various types of devices, another client, we went out to them and to help them out, they decided not to spend the money they needed to spend.

    [00:04:28] I have no idea what they ended up doing, but they make cable harnesses that are used in military systems. And they weren't even close to being compliant, which is, you know, the typical thing that we see. So here's your problem, frankly, because of the new teeth that are in place now where they've taken and they moved it to something called CMMC and the CMMC is requiring them to do.

    [00:04:58] Even more and it has even more teeth on it. It's absolutely amazing. So we've, this is in place to help protect federal contract information. And a lot of these manufacturers say, Hey, you know, it's not going to happen to me. I make power supplies. I make screws. I make assemblies. And in some cases they make much more fancy stuff, but.

    [00:05:23] It does. It applies to all of you and organizations that failed to comply with these rules can get hit badly with massive fines, class, oxygen, lawsuits, and also jail time for the owners of the business, for the people who are supposed to be running the business. Real jail time. We're talking about 10-year terms for some of these things.

    [00:05:50] So we have to be careful. We have to look at what we're doing and we have to understand if what we're doing is the right thing. So how does this apply to you? Well, if you are just a regular civilian, I think you should be happy that finally the federal government. Is trying to protect our information.

    [00:06:14] Right. We've had the Chinese attacking us and we've been in these businesses where the Chinese had backdoors installed. And what does that mean? What's a backdoor while he imagines that your computers that contain your proprietary information are directly accessible by the Chinese. So that means whether or not it's military, your computer, the information on it is now in the hands of the Chinese.

    [00:06:44] And in the case of one of our clients, what that means is all of his designs. All of his clients lists all of everything that he has worked his whole life for. He now gets to compete against a Chinese manufacturer that has been given all of that stuff. So imagine that happened to you. What does that mean?

    [00:07:05] It, it means that our military isn't as secure as we had hoped it'd been. And we could go through all kinds of stories here. I, I really want to kind of stay focused, but what this means is we need to make sure, especially in this kind of post COVID world, that all of our systems are up to date. All of our systems are properly secured.

    [00:07:31] So this, this company, this week, one of these companies this week, they had put in VPNs and they had used some slightly higher-end equipment. You can't just go and buy SonicWall off of the shelves over at staples, but it does not meet any of these federal guidelines. And what really, really upsets me here is that.

    [00:07:57]They do a search online for the model of hardware, software, whatever it is they're using. And they're looking for an instance for compliance and it says, yeah, we're DFARs compliant when they are not compliant. It just. Ah, I don't know what to do about it. Maybe it's just me, right? Maybe I'm just a little bit too uptight here, but they're conning people.

    [00:08:24] They're conning you. And if you've attended my webinars, you know how these VPN companies are, conning is how these privacy protection companies are. Conning how the antivirus vendors are calling you. And I'm also seeing this for our, our military subcontractors. All of them that I've been involved with have been conned.

    [00:08:46] And now that's not true with the really big ones. Right. I deal with small businesses, 500 employees, and smaller, but. Man. They don't even know what they don't know. And that's part of the problem. Right? That's always part of the problem. So there are a few things I want you guys to, to understand and know, cause this applies to everybody.

    [00:09:09] First of all. Nest. This is a government organization that comes out with standards. It's a national Institute of standards and technology. And remember, they used to advise that you have these super-duper fancy passwords that are hard to remember and a different password on every machine. And you had to change them every month or two.

    [00:09:32] Well, they have relaxed that now, and they follow the same guidance that I've been preaching for years, which is. Have a passphrase, a set of words that you remember that you're not going to forget and that you can type in pretty quickly, but it may be 30, 40 characters long. And then use that in conjunction with a good password manager, like one password that is going to keep all of the passwords for you.

    [00:09:59] So you have the one big, really good master password and then a whole bunch of. A password stored in your password manager. Now let's see multifactor authentication is the next one I have on my list. And it is not what it used to be. Unfortunately, a multifactor authentication. Now a lot of people are looking at it as well.

    [00:10:22] Uh, it's just a text message. I'm gonna need a text message. Well, okay. That's, isn't that wonderful, but that is not true. Multifactor authentication, you know, multifactor authentication means something that, you know, along with something that you have, like a mobile app or security key. So be careful with this.

    [00:10:41] And again, if you're government contractor, you've got to use. Special types of key chain storage like TPM or TEA. If you need more information, by all means, reach out to M E [email protected]. But if you're looking at getting some of this federal government money, By being a contractor, or if your devices are used or materials are used by military contractors realize that your neck is really on the line.

    [00:11:13] Now with CMMC long jail term, backbreaking fines, it will put you out of business. If you get audited, or if you lose some of this data, Hey, when we come back, we're going to talk about a lawsuit and, and I think this one's going somewhere. Google got sued for at least $5 billion because Incognito mode is not the incognito mode they've been advertising.

    [00:11:42] Hey, how sad for fun? Make sure you sign up. You get all of the information for business for home. Craig peterson.com/subscribes to crown. I'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Password Requirements for Military Contractors and General Business Best Practices and more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig fills you in the Best Security Practices for Passwords and What is absolutely required by anyone who is contracting with the US Military.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    What Government Contractors Need to Know About NIST, DFARS Password Reqs

    ---

    Automated Machine-Generated Transcript:

    Hey, does your business make something that might be used all ultimately by a government contractor? Did you know that all of the requirements that they have rolled downhill right into your lap? That's what we're going to talk about.

    [00:00:22] Hey everybody. Welcome. This is Craig Peterson. I'm so glad you guys are here. There are so many things to understand in this whole world of security and technology is frankly, it's just very, very confusing. It's impossible to catch up on. I'll give you that. And it's very hard to keep up on. So what I've been trying to do here on the show, and then.

    [00:00:44] And in the webinars that I've been putting on is to help you guys understand it, turn it into English, make it something that's workable. I had quite a week last week, very, very eyeopening to me because I've been working with a few different companies this justice last week that had major security problems and were completely unaware of it.

    To me, that is just completely unreasonable, right? Well, I shouldn't say they weren't unaware of them. One of them was the pizza shop that I mentioned, and they knew something was up because the payment card industry guys knocked on their door and say, it said, Hey, we got to do an audit.

    [00:01:27] And they came in, took one, look at the equipment that they had. Back in the, you know, computer room, if you want to call it that, you know, where the server is and immediately failed them. That's all they had to do was see that links us Rotter is sitting up on the wall because the link says is not good enough for businesses to keep your data safe.

    [00:01:49] And frankly, the same thing is true for many of the other products out there. Now there's a lot of other levels that go beyond where. The payment card industry is requiring. And one of those is for government subcontractors. I have quite a few clients that are government subcontractors, and I think every one of them came to me because they had.

    [00:02:14] Problems there they were trying to solve something was wrong. It was, it was, computers were slow emails. Weren't getting routed properly. Some of their customers were getting emails that actually weren't sent by them and yet had their return address on them. Right. Those sorts of problems. So we got involved and had a look and figured things out.

    [00:02:36] And you've heard a few of those stories here. Well, this week was interesting because one of the listeners for the show reached out to me. He got a job. Helping out a business that is a small business. It is, you know, by small, small business standards, it's a decent-sized business, but they make components that are used by the federal government, by the military.

    [00:03:03] And they were not doing what needed to be done. Not at all. And they think that they should be able to be ready in the next 18 months for the lowest level. And maybe they will, but based on what they do, uh, they got to get a lot more ready, a lot higher. Right. That's the basic definition here. Is, if you make something that either goes boom or at attaches to something that goes, boom, you have to comply with something called DFARs.

    [00:03:40] And I tar now DFARs is the defense federal acquisition regulation supplement much easier to just say DFAR is isn't it. And this is a set of standards that apply to civilians. And defense agencies in the United States, ITAR gets even higher level and it requires compliance, but I tar basically means yeah.

    [00:04:04] Yeah. Things go, boom. Okay. So if you make a component, so I have clients that make something as simple as power supplies. And those power supplies are used by military contractors and they go into various types of devices, another client, we went out to them and to help them out, they decided not to spend the money they needed to spend.

    [00:04:28] I have no idea what they ended up doing, but they make cable harnesses that are used in military systems. And they weren't even close to being compliant, which is, you know, the typical thing that we see. So here's your problem, frankly, because of the new teeth that are in place now where they've taken and they moved it to something called CMMC and the CMMC is requiring them to do.

    [00:04:58] Even more and it has even more teeth on it. It's absolutely amazing. So we've, this is in place to help protect federal contract information. And a lot of these manufacturers say, Hey, you know, it's not going to happen to me. I make power supplies. I make screws. I make assemblies. And in some cases they make much more fancy stuff, but.

    [00:05:23] It does. It applies to all of you and organizations that failed to comply with these rules can get hit badly with massive fines, class, oxygen, lawsuits, and also jail time for the owners of the business, for the people who are supposed to be running the business. Real jail time. We're talking about 10-year terms for some of these things.

    [00:05:50] So we have to be careful. We have to look at what we're doing and we have to understand if what we're doing is the right thing. So how does this apply to you? Well, if you are just a regular civilian, I think you should be happy that finally the federal government. Is trying to protect our information.

    [00:06:14] Right. We've had the Chinese attacking us and we've been in these businesses where the Chinese had backdoors installed. And what does that mean? What's a backdoor while he imagines that your computers that contain your proprietary information are directly accessible by the Chinese. So that means whether or not it's military, your computer, the information on it is now in the hands of the Chinese.

    [00:06:44] And in the case of one of our clients, what that means is all of his designs. All of his clients lists all of everything that he has worked his whole life for. He now gets to compete against a Chinese manufacturer that has been given all of that stuff. So imagine that happened to you. What does that mean?

    [00:07:05] It, it means that our military isn't as secure as we had hoped it'd been. And we could go through all kinds of stories here. I, I really want to kind of stay focused, but what this means is we need to make sure, especially in this kind of post COVID world, that all of our systems are up to date. All of our systems are properly secured.

    [00:07:31] So this, this company, this week, one of these companies this week, they had put in VPNs and they had used some slightly higher-end equipment. You can't just go and buy SonicWall off of the shelves over at staples, but it does not meet any of these federal guidelines. And what really, really upsets me here is that.

    [00:07:57]They do a search online for the model of hardware, software, whatever it is they're using. And they're looking for an instance for compliance and it says, yeah, we're DFARs compliant when they are not compliant. It just. Ah, I don't know what to do about it. Maybe it's just me, right? Maybe I'm just a little bit too uptight here, but they're conning people.

    [00:08:24] They're conning you. And if you've attended my webinars, you know how these VPN companies are, conning is how these privacy protection companies are. Conning how the antivirus vendors are calling you. And I'm also seeing this for our, our military subcontractors. All of them that I've been involved with have been conned.

    [00:08:46] And now that's not true with the really big ones. Right. I deal with small businesses, 500 employees, and smaller, but. Man. They don't even know what they don't know. And that's part of the problem. Right? That's always part of the problem. So there are a few things I want you guys to, to understand and know, cause this applies to everybody.

    [00:09:09] First of all. Nest. This is a government organization that comes out with standards. It's a national Institute of standards and technology. And remember, they used to advise that you have these super-duper fancy passwords that are hard to remember and a different password on every machine. And you had to change them every month or two.

    [00:09:32] Well, they have relaxed that now, and they follow the same guidance that I've been preaching for years, which is. Have a passphrase, a set of words that you remember that you're not going to forget and that you can type in pretty quickly, but it may be 30, 40 characters long. And then use that in conjunction with a good password manager, like one password that is going to keep all of the passwords for you.

    [00:09:59] So you have the one big, really good master password and then a whole bunch of. A password stored in your password manager. Now let's see multifactor authentication is the next one I have on my list. And it is not what it used to be. Unfortunately, a multifactor authentication. Now a lot of people are looking at it as well.

    [00:10:22] Uh, it's just a text message. I'm gonna need a text message. Well, okay. That's, isn't that wonderful, but that is not true. Multifactor authentication, you know, multifactor authentication means something that, you know, along with something that you have, like a mobile app or security key. So be careful with this.

    [00:10:41] And again, if you're government contractor, you've got to use. Special types of key chain storage like TPM or TEA. If you need more information, by all means, reach out to M E [email protected]. But if you're looking at getting some of this federal government money, By being a contractor, or if your devices are used or materials are used by military contractors realize that your neck is really on the line.

    [00:11:13] Now with CMMC long jail term, backbreaking fines, it will put you out of business. If you get audited, or if you lose some of this data, Hey, when we come back, we're going to talk about a lawsuit and, and I think this one's going somewhere. Google got sued for at least $5 billion because Incognito mode is not the incognito mode they've been advertising.

    [00:11:42] Hey, how sad for fun? Make sure you sign up. You get all of the information for business for home. Craig peterson.com/subscribes to crown. I'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…