
Sign up to save your podcasts
Or


Welcome!
Let's get into these rioters and protesters -- actually -- they are thieves and how Apple and Big Tech is figuring out just who they are.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
iPhone looters find devices disabled, with a warning they’re being tracked
---
Automated Machine Generated Transcript:
We've seen the pictures of looters on TV, heard about them here on the radio. How can you know, if what you're buying online is a stolen good or not? We're going to talk about that. And the iPhone debacle,
[00:00:19] you are listening to Craig Peter Sohn. We're here every week. You'll find me [email protected]. And if you do sign up for my emails, You'll get some amazing content. We're, I'm going through handpicked articles that I share with you. These are curated out of hundreds of thousands of articles that are published every week.
[00:00:42] I boil it down to six or eight key articles, and I'm also now including links to special. Report and I mean, special reports where I take some of the deep dives that I just can't get to in a normal newsletter. So make sure you do sign up Craig peterson.com/subscribe. That way. You can also find out about what I am doing when it comes to these free pieces of training that I conduct these webinars, as well as some of the courses that I offer.
[00:01:15] So. Greg peterson.com/subscribe. Hey, let's get into what's happening right now with these looters. My gosh, how can you protect yourself? I've seen so many businesses that have been ransacked now, right? Pictures of them from all across the country and from around the world. Now, it's really interesting to see them talking about black lives matter and how the police are going after people and killing them in countries like.
[00:01:47] Great Britain where they are not even armed for the most part. Right. And there has not been the number of problems who've seen here in the United States. Now, of course, their population is a whole lot smaller than our population is as well. But when you boil down into the numbers, I think you'll see a bit of a different story.
[00:02:07] But part of the story that I want to talk about is the technology side, many of the. Apple stores were ransacked and the bad guys, the looters. I stole iPads and iPhones, and basically anything that they could get that wasn't nailed down. And even then they managed to get some of this stuff nailed down from some of these other high-end stores.
[00:02:32] So in response, some of these stores such as Apple target, as well as the real big guys, like the Gucci's and Rolexes of the world. They shut their stores down, thus hurting the neighborhoods that the stores are located in the people working there. Obviously they don't have a job if that store's been burned to the ground has happened too many times.
[00:02:56] And they also. Don't have a place to shop. You know, there's been talk over the last governor, what 20 years about having these food deserts, where there was no place to get fresh food. And I'm really worried that ultimately. These places where we had the riot are going to end up being just like these food deserts that we're trying to get rid of.
[00:03:23] Why would I spend money to reopen my store when my insurance won't even pay for it? And I'm afraid of looters coming in in the future? Well, Apple had a solution for this and still has a solution for it. All of the devices that are in the Apple stores run as a special version of their operating system and that operating system makes it so that the device will not work.
[00:03:51] If removed from the Apple store. So some of these brain trust people that have been looting, these stores took pictures of the screens of those eye iPhones. They stole complaining, Oh my gosh, here. Look at this, and there's a message on there. Now, the one that we've been seeing the most that was posted on Twitter said, please return to Apple Walnut street.
[00:04:19] This device has been disabled and is being tracked. Local authorities will be alerted. Now I mentioned this week, while I was on the radio. On a number of different stations during drive time. And I want to go further than that right now, since we have a few more minutes than, than just the five to 10 minutes I get during drive time, you know, we don't know how many I-phones have been taken from the Apple stores and put into circulation.
[00:04:46] We do know that Apple iPhones if they are stolen, and if they have "Find My iPhone" turned on. Are very difficult for thieves to really make bank on those phones. However, can be taken apart and use for parts and used by these little guys and bigger ones too, that repair the devices. So they will pay.
[00:05:12] Someone for a broken or even a pretty well-working iPhone or iPad. And we'll, we will remove the buttons. If there are buttons on, it depends on how old it is. All of the sensors, the screens, everything, and then use them for repairs. So even though the phones were stolen and Apple has made sure that the phone will not work outside the store, That phone is still worth something.
[00:05:41] So I want you to keep that in mind too if you have an Android or an iPhone and it is set to South flock and with the iPhone, you cannot erase it either and it's to reset it and then reuse it. Remember that they still are worth something. So don't be cavalier with that iPhone. When you take it out of the store, they also have this it's, it's kind of a kill switch, frankly, here.
[00:06:08] Now they are also reporting some of these stolen phone locations. To law enforcement, which I think is pretty darn cool because then they can catch the bad guys. And we've seen cases in the past where someone's phone was stolen. They used "Find my iPhone" to locate that phone. And then they went to the police and said, Hey, my phone was stolen.
[00:06:34] And here's the location it's at. And then the police using probable cause went to that residence. And in many cases did find the device and arrested the people for possession of stolen merchandise. So I would expect some of that to happen here. Although I think Apple's trying to stay out of this as much as they can.
[00:06:57] Because they consider this to be a political issue. Now, how can you tell if something that you want to buy has been stolen while there are some pretty basic things that you can look for to try and determine if your item has been stolen? The first off is that the price of the item is just totally unreasonable.
[00:07:22] No, I don't mean it's expensive. I mean, wow. That's cheap a couple of years ago I needed to replace my pickup truck. And so I went online and we did a lot of research. You can, you can probably guess what I'm like when it comes to this. Right. So pretty thorough research. We found the exact truck that we wanted and it was a.
[00:07:46] About a 10-year-old. I think it was an F two 50 diesel with this diesel engine that just lasts forever. It's just absolutely amazing. And we found online one of those Ford trucks that were available. And the price was wonderful. We're trying to figure out why. And so we contacted the seller who said, well, Jess got mobilized, have to go over to Afghanistan and need to get rid of the truck because they were making payments on it before they left.
[00:08:18] And I figured, okay, well, that's a reasonable enough explanation. So, what I did is I then took the picture that they had posted online. This was on eBay and I went to Google. Now, if you are not familiar with this, it something you should look at. Google has an image search feature. And that image search feature allows you to upload an image or give Google the URL of an image.
[00:08:50] So I gave it this image that they had posted of that pickup truck. And I asked Google to see if it could find it online. Sure enough, it found it, it did find it in that eBay ad that I mentioned that we had found the truck in, but it also found the same truck on a dealer's lot. And of course, the price was much higher.
[00:09:14] I think that the bad guys are trying to sell it. If I remember right for five or six grand and the dealer was trying to sell it for 20 grand. So it started to smell bad because the price was just too low. When I did some research by going to Google, uploading the image, and having Google tell me if that image was used elsewhere.
[00:09:36] I was able to solve that mystery. The next thing to look for is a warning sign for stolen items is missing or inaccurate product details, misspellings, bad grammar. That's a very, very common thing. The graphics just don't look quite right. Like they were using a real cheap imitation of Photoshop in order to edit some of those pictures together.
[00:10:04] And then. An unknown seller. Now, eBay is great in this respect because you can see how long that seller has been on eBay. You can see how many items they've sold. You can see what their ratings are. You can pull all of this together. So those are our top tips here for looking for stolen items. Some of these are going to be hard to find, for instance, if you've got this wonderful Gucci bag or rather piece of clothing, Just looking for that picture online does not mean it is stolen if they're using a stock picture that might come from the Gucci site or the clothing site.
[00:10:44] Right. So that's not necessarily a dead giveaway, but it does mean you should look a little further because if you're buying used clothing, you expect a photo to have been taken. By that person's smartphone and then uploaded from there. And if you really want to dig into it, that photo probably has the GPS coordinates of where that photo was taken.
[00:11:09] What type of device took that photo and just kind of add those numbers up. But many of these sites, like The Real-Real, If you haven't checked them out, you really should. Yeah, but The Real Real has all kinds of great high-end clothes available for a very cheap price. Some of these clothes have never been worn and they're telling us that they are keeping a very close eye looking out for stolen goods, for signs of stolen goods.
[00:11:41] So sites like that, I think you'll be able to trust more than maybe an eBay. Who does try and police us, but they can't be a hundred percent successful. Amazon's kind of in the same boat have for the items on Amazon are not sold and fulfilled by Amazon. They're sold and fulfilled by. Third parties. So keep your eyes out when you are looking for some of these great deals online, because they might've come from the looters out in LA, Boston, Illinois, who knows where, Hey, when we come back, we're going to talk about some of the security requirements that are in place now.
[00:12:26] We're working from home. We're getting back in the office. If you are a government contractor or subcontractor, the government's really going to come down on you. And we're going to talk about that. What does that all mean? How is that protecting us as citizens and as taxpayers, make sure you get my weekly email, find out what's going on.
[00:12:48] Craig peterson.com/subscribe, stick around because I'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Let's get into these rioters and protesters -- actually -- they are thieves and how Apple and Big Tech is figuring out just who they are.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
iPhone looters find devices disabled, with a warning they’re being tracked
---
Automated Machine Generated Transcript:
We've seen the pictures of looters on TV, heard about them here on the radio. How can you know, if what you're buying online is a stolen good or not? We're going to talk about that. And the iPhone debacle,
[00:00:19] you are listening to Craig Peter Sohn. We're here every week. You'll find me [email protected]. And if you do sign up for my emails, You'll get some amazing content. We're, I'm going through handpicked articles that I share with you. These are curated out of hundreds of thousands of articles that are published every week.
[00:00:42] I boil it down to six or eight key articles, and I'm also now including links to special. Report and I mean, special reports where I take some of the deep dives that I just can't get to in a normal newsletter. So make sure you do sign up Craig peterson.com/subscribe. That way. You can also find out about what I am doing when it comes to these free pieces of training that I conduct these webinars, as well as some of the courses that I offer.
[00:01:15] So. Greg peterson.com/subscribe. Hey, let's get into what's happening right now with these looters. My gosh, how can you protect yourself? I've seen so many businesses that have been ransacked now, right? Pictures of them from all across the country and from around the world. Now, it's really interesting to see them talking about black lives matter and how the police are going after people and killing them in countries like.
[00:01:47] Great Britain where they are not even armed for the most part. Right. And there has not been the number of problems who've seen here in the United States. Now, of course, their population is a whole lot smaller than our population is as well. But when you boil down into the numbers, I think you'll see a bit of a different story.
[00:02:07] But part of the story that I want to talk about is the technology side, many of the. Apple stores were ransacked and the bad guys, the looters. I stole iPads and iPhones, and basically anything that they could get that wasn't nailed down. And even then they managed to get some of this stuff nailed down from some of these other high-end stores.
[00:02:32] So in response, some of these stores such as Apple target, as well as the real big guys, like the Gucci's and Rolexes of the world. They shut their stores down, thus hurting the neighborhoods that the stores are located in the people working there. Obviously they don't have a job if that store's been burned to the ground has happened too many times.
[00:02:56] And they also. Don't have a place to shop. You know, there's been talk over the last governor, what 20 years about having these food deserts, where there was no place to get fresh food. And I'm really worried that ultimately. These places where we had the riot are going to end up being just like these food deserts that we're trying to get rid of.
[00:03:23] Why would I spend money to reopen my store when my insurance won't even pay for it? And I'm afraid of looters coming in in the future? Well, Apple had a solution for this and still has a solution for it. All of the devices that are in the Apple stores run as a special version of their operating system and that operating system makes it so that the device will not work.
[00:03:51] If removed from the Apple store. So some of these brain trust people that have been looting, these stores took pictures of the screens of those eye iPhones. They stole complaining, Oh my gosh, here. Look at this, and there's a message on there. Now, the one that we've been seeing the most that was posted on Twitter said, please return to Apple Walnut street.
[00:04:19] This device has been disabled and is being tracked. Local authorities will be alerted. Now I mentioned this week, while I was on the radio. On a number of different stations during drive time. And I want to go further than that right now, since we have a few more minutes than, than just the five to 10 minutes I get during drive time, you know, we don't know how many I-phones have been taken from the Apple stores and put into circulation.
[00:04:46] We do know that Apple iPhones if they are stolen, and if they have "Find My iPhone" turned on. Are very difficult for thieves to really make bank on those phones. However, can be taken apart and use for parts and used by these little guys and bigger ones too, that repair the devices. So they will pay.
[00:05:12] Someone for a broken or even a pretty well-working iPhone or iPad. And we'll, we will remove the buttons. If there are buttons on, it depends on how old it is. All of the sensors, the screens, everything, and then use them for repairs. So even though the phones were stolen and Apple has made sure that the phone will not work outside the store, That phone is still worth something.
[00:05:41] So I want you to keep that in mind too if you have an Android or an iPhone and it is set to South flock and with the iPhone, you cannot erase it either and it's to reset it and then reuse it. Remember that they still are worth something. So don't be cavalier with that iPhone. When you take it out of the store, they also have this it's, it's kind of a kill switch, frankly, here.
[00:06:08] Now they are also reporting some of these stolen phone locations. To law enforcement, which I think is pretty darn cool because then they can catch the bad guys. And we've seen cases in the past where someone's phone was stolen. They used "Find my iPhone" to locate that phone. And then they went to the police and said, Hey, my phone was stolen.
[00:06:34] And here's the location it's at. And then the police using probable cause went to that residence. And in many cases did find the device and arrested the people for possession of stolen merchandise. So I would expect some of that to happen here. Although I think Apple's trying to stay out of this as much as they can.
[00:06:57] Because they consider this to be a political issue. Now, how can you tell if something that you want to buy has been stolen while there are some pretty basic things that you can look for to try and determine if your item has been stolen? The first off is that the price of the item is just totally unreasonable.
[00:07:22] No, I don't mean it's expensive. I mean, wow. That's cheap a couple of years ago I needed to replace my pickup truck. And so I went online and we did a lot of research. You can, you can probably guess what I'm like when it comes to this. Right. So pretty thorough research. We found the exact truck that we wanted and it was a.
[00:07:46] About a 10-year-old. I think it was an F two 50 diesel with this diesel engine that just lasts forever. It's just absolutely amazing. And we found online one of those Ford trucks that were available. And the price was wonderful. We're trying to figure out why. And so we contacted the seller who said, well, Jess got mobilized, have to go over to Afghanistan and need to get rid of the truck because they were making payments on it before they left.
[00:08:18] And I figured, okay, well, that's a reasonable enough explanation. So, what I did is I then took the picture that they had posted online. This was on eBay and I went to Google. Now, if you are not familiar with this, it something you should look at. Google has an image search feature. And that image search feature allows you to upload an image or give Google the URL of an image.
[00:08:50] So I gave it this image that they had posted of that pickup truck. And I asked Google to see if it could find it online. Sure enough, it found it, it did find it in that eBay ad that I mentioned that we had found the truck in, but it also found the same truck on a dealer's lot. And of course, the price was much higher.
[00:09:14] I think that the bad guys are trying to sell it. If I remember right for five or six grand and the dealer was trying to sell it for 20 grand. So it started to smell bad because the price was just too low. When I did some research by going to Google, uploading the image, and having Google tell me if that image was used elsewhere.
[00:09:36] I was able to solve that mystery. The next thing to look for is a warning sign for stolen items is missing or inaccurate product details, misspellings, bad grammar. That's a very, very common thing. The graphics just don't look quite right. Like they were using a real cheap imitation of Photoshop in order to edit some of those pictures together.
[00:10:04] And then. An unknown seller. Now, eBay is great in this respect because you can see how long that seller has been on eBay. You can see how many items they've sold. You can see what their ratings are. You can pull all of this together. So those are our top tips here for looking for stolen items. Some of these are going to be hard to find, for instance, if you've got this wonderful Gucci bag or rather piece of clothing, Just looking for that picture online does not mean it is stolen if they're using a stock picture that might come from the Gucci site or the clothing site.
[00:10:44] Right. So that's not necessarily a dead giveaway, but it does mean you should look a little further because if you're buying used clothing, you expect a photo to have been taken. By that person's smartphone and then uploaded from there. And if you really want to dig into it, that photo probably has the GPS coordinates of where that photo was taken.
[00:11:09] What type of device took that photo and just kind of add those numbers up. But many of these sites, like The Real-Real, If you haven't checked them out, you really should. Yeah, but The Real Real has all kinds of great high-end clothes available for a very cheap price. Some of these clothes have never been worn and they're telling us that they are keeping a very close eye looking out for stolen goods, for signs of stolen goods.
[00:11:41] So sites like that, I think you'll be able to trust more than maybe an eBay. Who does try and police us, but they can't be a hundred percent successful. Amazon's kind of in the same boat have for the items on Amazon are not sold and fulfilled by Amazon. They're sold and fulfilled by. Third parties. So keep your eyes out when you are looking for some of these great deals online, because they might've come from the looters out in LA, Boston, Illinois, who knows where, Hey, when we come back, we're going to talk about some of the security requirements that are in place now.
[00:12:26] We're working from home. We're getting back in the office. If you are a government contractor or subcontractor, the government's really going to come down on you. And we're going to talk about that. What does that all mean? How is that protecting us as citizens and as taxpayers, make sure you get my weekly email, find out what's going on.
[00:12:48] Craig peterson.com/subscribe, stick around because I'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Let's get into these rioters and protesters -- actually -- they are thieves and how Apple and Big Tech is figuring out just who they are.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
iPhone looters find devices disabled, with a warning they're being tracked
---
Automated Machine Generated Transcript:
We've seen the pictures of looters on TV, heard about them here on the radio. How can you know, if what you're buying online is a stolen good or not? We're going to talk about that. And the iPhone debacle,
[00:00:19] you are listening to Craig Peter Sohn. We're here every week. You'll find me [email protected]. And if you do sign up for my emails, You'll get some amazing content. We're, I'm going through handpicked articles that I share with you. These are curated out of hundreds of thousands of articles that are published every week.
[00:00:42] I boil it down to six or eight key articles, and I'm also now including links to special. Report and I mean, special reports where I take some of the deep dives that I just can't get to in a normal newsletter. So make sure you do sign up Craig peterson.com/subscribe. That way. You can also find out about what I am doing when it comes to these free pieces of training that I conduct these webinars, as well as some of the courses that I offer.
[00:01:15] So. Greg peterson.com/subscribe. Hey, let's get into what's happening right now with these looters. My gosh, how can you protect yourself? I've seen so many businesses that have been ransacked now, right? Pictures of them from all across the country and from around the world. Now, it's really interesting to see them talking about black lives matter and how the police are going after people and killing them in countries like.
[00:01:47] Great Britain where they are not even armed for the most part. Right. And there has not been the number of problems who've seen here in the United States. Now, of course, their population is a whole lot smaller than our population is as well. But when you boil down into the numbers, I think you'll see a bit of a different story.
[00:02:07] But part of the story that I want to talk about is the technology side, many of the. Apple stores were ransacked and the bad guys, the looters. I stole iPads and iPhones, and basically anything that they could get that wasn't nailed down. And even then they managed to get some of this stuff nailed down from some of these other high-end stores.
[00:02:32] So in response, some of these stores such as Apple target, as well as the real big guys, like the Gucci's and Rolexes of the world. They shut their stores down, thus hurting the neighborhoods that the stores are located in the people working there. Obviously they don't have a job if that store's been burned to the ground has happened too many times.
[00:02:56] And they also. Don't have a place to shop. You know, there's been talk over the last governor, what 20 years about having these food deserts, where there was no place to get fresh food. And I'm really worried that ultimately. These places where we had the riot are going to end up being just like these food deserts that we're trying to get rid of.
[00:03:23] Why would I spend money to reopen my store when my insurance won't even pay for it? And I'm afraid of looters coming in in the future? Well, Apple had a solution for this and still has a solution for it. All of the devices that are in the Apple stores run as a special version of their operating system and that operating system makes it so that the device will not work.
[00:03:51] If removed from the Apple store. So some of these brain trust people that have been looting, these stores took pictures of the screens of those eye iPhones. They stole complaining, Oh my gosh, here. Look at this, and there's a message on there. Now, the one that we've been seeing the most that was posted on Twitter said, please return to Apple Walnut street.
[00:04:19] This device has been disabled and is being tracked. Local authorities will be alerted. Now I mentioned this week, while I was on the radio. On a number of different stations during drive time. And I want to go further than that right now, since we have a few more minutes than, than just the five to 10 minutes I get during drive time, you know, we don't know how many I-phones have been taken from the Apple stores and put into circulation.
[00:04:46] We do know that Apple iPhones if they are stolen, and if they have "Find My iPhone" turned on. Are very difficult for thieves to really make bank on those phones. However, can be taken apart and use for parts and used by these little guys and bigger ones too, that repair the devices. So they will pay.
[00:05:12] Someone for a broken or even a pretty well-working iPhone or iPad. And we'll, we will remove the buttons. If there are buttons on, it depends on how old it is. All of the sensors, the screens, everything, and then use them for repairs. So even though the phones were stolen and Apple has made sure that the phone will not work outside the store, That phone is still worth something.
[00:05:41] So I want you to keep that in mind too if you have an Android or an iPhone and it is set to South flock and with the iPhone, you cannot erase it either and it's to reset it and then reuse it. Remember that they still are worth something. So don't be cavalier with that iPhone. When you take it out of the store, they also have this it's, it's kind of a kill switch, frankly, here.
[00:06:08] Now they are also reporting some of these stolen phone locations. To law enforcement, which I think is pretty darn cool because then they can catch the bad guys. And we've seen cases in the past where someone's phone was stolen. They used "Find my iPhone" to locate that phone. And then they went to the police and said, Hey, my phone was stolen.
[00:06:34] And here's the location it's at. And then the police using probable cause went to that residence. And in many cases did find the device and arrested the people for possession of stolen merchandise. So I would expect some of that to happen here. Although I think Apple's trying to stay out of this as much as they can.
[00:06:57] Because they consider this to be a political issue. Now, how can you tell if something that you want to buy has been stolen while there are some pretty basic things that you can look for to try and determine if your item has been stolen? The first off is that the price of the item is just totally unreasonable.
[00:07:22] No, I don't mean it's expensive. I mean, wow. That's cheap a couple of years ago I needed to replace my pickup truck. And so I went online and we did a lot of research. You can, you can probably guess what I'm like when it comes to this. Right. So pretty thorough research. We found the exact truck that we wanted and it was a.
[00:07:46] About a 10-year-old. I think it was an F two 50 diesel with this diesel engine that just lasts forever. It's just absolutely amazing. And we found online one of those Ford trucks that were available. And the price was wonderful. We're trying to figure out why. And so we contacted the seller who said, well, Jess got mobilized, have to go over to Afghanistan and need to get rid of the truck because they were making payments on it before they left.
[00:08:18] And I figured, okay, well, that's a reasonable enough explanation. So, what I did is I then took the picture that they had posted online. This was on eBay and I went to Google. Now, if you are not familiar with this, it something you should look at. Google has an image search feature. And that image search feature allows you to upload an image or give Google the URL of an image.
[00:08:50] So I gave it this image that they had posted of that pickup truck. And I asked Google to see if it could find it online. Sure enough, it found it, it did find it in that eBay ad that I mentioned that we had found the truck in, but it also found the same truck on a dealer's lot. And of course, the price was much higher.
[00:09:14] I think that the bad guys are trying to sell it. If I remember right for five or six grand and the dealer was trying to sell it for 20 grand. So it started to smell bad because the price was just too low. When I did some research by going to Google, uploading the image, and having Google tell me if that image was used elsewhere.
[00:09:36] I was able to solve that mystery. The next thing to look for is a warning sign for stolen items is missing or inaccurate product details, misspellings, bad grammar. That's a very, very common thing. The graphics just don't look quite right. Like they were using a real cheap imitation of Photoshop in order to edit some of those pictures together.
[00:10:04] And then. An unknown seller. Now, eBay is great in this respect because you can see how long that seller has been on eBay. You can see how many items they've sold. You can see what their ratings are. You can pull all of this together. So those are our top tips here for looking for stolen items. Some of these are going to be hard to find, for instance, if you've got this wonderful Gucci bag or rather piece of clothing, Just looking for that picture online does not mean it is stolen if they're using a stock picture that might come from the Gucci site or the clothing site.
[00:10:44] Right. So that's not necessarily a dead giveaway, but it does mean you should look a little further because if you're buying used clothing, you expect a photo to have been taken. By that person's smartphone and then uploaded from there. And if you really want to dig into it, that photo probably has the GPS coordinates of where that photo was taken.
[00:11:09] What type of device took that photo and just kind of add those numbers up. But many of these sites, like The Real-Real, If you haven't checked them out, you really should. Yeah, but The Real Real has all kinds of great high-end clothes available for a very cheap price. Some of these clothes have never been worn and they're telling us that they are keeping a very close eye looking out for stolen goods, for signs of stolen goods.
[00:11:41] So sites like that, I think you'll be able to trust more than maybe an eBay. Who does try and police us, but they can't be a hundred percent successful. Amazon's kind of in the same boat have for the items on Amazon are not sold and fulfilled by Amazon. They're sold and fulfilled by. Third parties. So keep your eyes out when you are looking for some of these great deals online, because they might've come from the looters out in LA, Boston, Illinois, who knows where, Hey, when we come back, we're going to talk about some of the security requirements that are in place now.
[00:12:26] We're working from home. We're getting back in the office. If you are a government contractor or subcontractor, the government's really going to come down on you. And we're going to talk about that. What does that all mean? How is that protecting us as citizens and as taxpayers, make sure you get my weekly email, find out what's going on.
[00:12:48] Craig peterson.com/subscribe, stick around because I'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses the danger of insider threats by those employees who are planning on leaving and behaviors that might indicate trouble.Â
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
60% of Insider Threats Involve Employees Planning to Leave
---
Automated Machine Generated Transcript:
Insider threats are real and it's not like what they're showing in the movies. Hey, not at all. And especially in this post-COVID-19 world, everything has changed. So let's talk about insiders, people in your business, and the types of threats they're presenting.
[00:00:25] Hey, you're listening to Craig Peterson. You can find me [email protected] and of course podcasts pretty much everywhere out there. Just search for my name, Craig Peterson. Well, we've been talking about some of the threats that are facing us right now. We talked about DNS already today. We've talked in the past about just dozens of different types of threats.
[00:00:50]insiders are a big threat to businesses. So what does a threat look like? Well, Securonix just. Did a report, their researchers analyzed more than 300 confirmed incidents as part of their 20, 20 Securonix insider threat report. Now what they found was very disturbing, frankly. And the most disturbing part of it, at least to me was that 62% of the threats have to do with employees, exfiltrating data.
[00:01:29] In other words, employees taking data. Out of the business. Think about where we have been with the whole Wu Han virus and the concerns about the COVID-19. We have taken our employees. Who've been coming into the office maybe since your business was founded? And said, Hey, stay home. But if you want to get paid, you still have to do some work for us.
[00:01:56] And so we're allowing them to use their computers at home, maybe to bring a business, computer home, and then we hastily set up VPNs and other equipment in order to allow them access to the servers and the information they needed to use at home. How many of us put up. Monitors on those systems to make sure they weren't downloading stuff that they shouldn't have access to.
[00:02:26] Do you have all of the permission set up properly on your file server? Do you have it set up so that if all of a sudden they're downloading all of the schematics for all of your systems, all of your designs, do you have it set up? So it's going to automatically shut them off and notify you. About what just happened?
[00:02:47] Well, if you're like most businesses, the answer to that is no, because frankly, most businesses are not taking care of security. And that's what was pointed out here in this Securonix insider threat report because we've also allowed our employees to put documents on two thumb drives and take those thumb drives home, take them on the plane with them, maybe where they get lost.
[00:03:15] But the number that is concerning about the data being at home is an 80% number. Now, this is where we get into something called a flight risk. These are employees that are within two months of leaving your organization because what they've found is that employees that are planning on leaving the business tend to start stealing data between two and eight weeks before they go.
[00:03:47] And more than 80% of the employees that are planning to leave, bring. The business's data with them. That is very, very concerning. So think about that sales guy. How many times I mentioned this before, who's planning on walking out with all your customer lists that happened to me. I had a sales guy who was calling and trying to build a business and was keeping track.
[00:04:16] Of course of everybody he had contacted. Right. Doesn't that make sense? So it's all in our database of all of the contacts that he had made and the discussions they had had, the types of needs that they had, and he downloaded all of them. And then he went to one of my competitors and he started calling all these people up again and continued on the sales process.
[00:04:46] Just like he was still working for me. So here I was, I had paid for all of this Goodwill to be developed with these leads. I had paid for his training. He was going to training two to three days a week for a few hours back before we were doing it all live on a, on WebEx. Right. So he was going to all of these pieces of training.
[00:05:10] He was taking people out to lunch. He was going to meet with them. And these prospects that were still in that sales funnel were called up by him. When he went to his new employer now, I kind of thought that I was the lone ranger here. Right. It really disappointed me. I thought I knew the guy. I thought everything would be fine.
[00:05:35] And I eventually did talk to him cause I was. Too upset to talk to him initially. And I called him up and said, so how are things going? I said, Hey, I just heard from company X. And you know, they were working with us, we're moving along. And he said that you called him and suggested that they don't work with mainstream, that they work with your new employer.
[00:06:01] And I stopped right there. Right? I didn't say another word. And he ended up responding. Yeah. Well, you know, they're my contact. I know them. I have a relationship with them. So I took them with me. Now we've seen similar things recently in the news when it comes to Tesla and Volkswagen, where Oh, they worked for me, and then he took all of this data with him.
[00:06:28] Right. You've heard about that story. I'm sure. But apparently this happens all of the time, these flight risk employees and these individuals, according to this study were involved in about 60% of the insider threats. There were analyzed in this study and insider threats, makeup in case you didn't know the majority.
[00:06:55] Of problems when it comes to data loss for the business. So what are you doing about it? Most people who are exfiltrating, the sensitive information are doing it over email. So are you monitoring their email? This was a pattern that they found in nearly 44% of the cases. Do you have special filters that are looking for this stuff?
[00:07:18] You know, when we go into a business, we put filters in place on the email, looking for things like client numbers, looking for things like employer, identification, numbers, bank, account numbers. Driver's license numbers, everything for, you know, a GDPR standpoint, the Massachusetts standpoint, the California standpoint, the new federal guidelines that are in place, right.
[00:07:42] We're looking for all of this data, but it also protects the company. Because they are trying to exfiltrate your data and take it with them to their next employer. So number one was they try and send it out by email and they'll often send it to a Gmail account or something else that they have the next most popular method is uploading it to cloud storage websites.
[00:08:11] And that's why we put a limit. On where people can go, right? We oftentimes will have the Dropbox enterprise installed or the Microsoft three 65 enterprise versions installed where they can upload files, but it is tightly controlled and we know what they're uploading. We know what they're downloading. Do you have those controls Impella in place?
[00:08:37] There are other ways that they're doing it, but we've got to pull up our socks. Now we have to, as businesses protect our investment, which for many of us is our retirement money. Right. And we have to watch our employees. I'm afraid to say. Particularly with the high rate of turnover in some industries and in the security industry, we're seeing the turnover rate that is in the sixth-month timeframe.
[00:09:05] So think about that. All of the training you did for that new insecurity employee, all of the systems that were set up. What's going to happen when they leave and take that data with them, that salesperson, the accounting people and on and on. So keep that in mind. We're seeing insider threats, being a very, very big threat to all of us out there.
[00:09:29] They'll all. When we come back, we're going to be talking about looters and the eye iPhones. We'll talk a little bit about how does Apple protects the devices that you have paid for? Because. Man, they do want a pretty penny. You're listening to Craig Peterson, stick around because we'll be right back after this and make sure you get my email.
[00:09:54] Craig peterson.com/subscribe.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses the danger of insider threats by those employees who are planning on leaving and behaviors that might indicate trouble.Â
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
60% of Insider Threats Involve Employees Planning to Leave
---
Automated Machine Generated Transcript:
Insider threats are real and it's not like what they're showing in the movies. Hey, not at all. And especially in this post-COVID-19 world, everything has changed. So let's talk about insiders, people in your business, and the types of threats they're presenting.
[00:00:25] Hey, you're listening to Craig Peterson. You can find me [email protected] and of course podcasts pretty much everywhere out there. Just search for my name, Craig Peterson. Well, we've been talking about some of the threats that are facing us right now. We talked about DNS already today. We've talked in the past about just dozens of different types of threats.
[00:00:50]insiders are a big threat to businesses. So what does a threat look like? Well, Securonix just. Did a report, their researchers analyzed more than 300 confirmed incidents as part of their 20, 20 Securonix insider threat report. Now what they found was very disturbing, frankly. And the most disturbing part of it, at least to me was that 62% of the threats have to do with employees, exfiltrating data.
[00:01:29] In other words, employees taking data. Out of the business. Think about where we have been with the whole Wu Han virus and the concerns about the COVID-19. We have taken our employees. Who've been coming into the office maybe since your business was founded? And said, Hey, stay home. But if you want to get paid, you still have to do some work for us.
[00:01:56] And so we're allowing them to use their computers at home, maybe to bring a business, computer home, and then we hastily set up VPNs and other equipment in order to allow them access to the servers and the information they needed to use at home. How many of us put up. Monitors on those systems to make sure they weren't downloading stuff that they shouldn't have access to.
[00:02:26] Do you have all of the permission set up properly on your file server? Do you have it set up so that if all of a sudden they're downloading all of the schematics for all of your systems, all of your designs, do you have it set up? So it's going to automatically shut them off and notify you. About what just happened?
[00:02:47] Well, if you're like most businesses, the answer to that is no, because frankly, most businesses are not taking care of security. And that's what was pointed out here in this Securonix insider threat report because we've also allowed our employees to put documents on two thumb drives and take those thumb drives home, take them on the plane with them, maybe where they get lost.
[00:03:15] But the number that is concerning about the data being at home is an 80% number. Now, this is where we get into something called a flight risk. These are employees that are within two months of leaving your organization because what they've found is that employees that are planning on leaving the business tend to start stealing data between two and eight weeks before they go.
[00:03:47] And more than 80% of the employees that are planning to leave, bring. The business's data with them. That is very, very concerning. So think about that sales guy. How many times I mentioned this before, who's planning on walking out with all your customer lists that happened to me. I had a sales guy who was calling and trying to build a business and was keeping track.
[00:04:16] Of course of everybody he had contacted. Right. Doesn't that make sense? So it's all in our database of all of the contacts that he had made and the discussions they had had, the types of needs that they had, and he downloaded all of them. And then he went to one of my competitors and he started calling all these people up again and continued on the sales process.
[00:04:46] Just like he was still working for me. So here I was, I had paid for all of this Goodwill to be developed with these leads. I had paid for his training. He was going to training two to three days a week for a few hours back before we were doing it all live on a, on WebEx. Right. So he was going to all of these pieces of training.
[00:05:10] He was taking people out to lunch. He was going to meet with them. And these prospects that were still in that sales funnel were called up by him. When he went to his new employer now, I kind of thought that I was the lone ranger here. Right. It really disappointed me. I thought I knew the guy. I thought everything would be fine.
[00:05:35] And I eventually did talk to him cause I was. Too upset to talk to him initially. And I called him up and said, so how are things going? I said, Hey, I just heard from company X. And you know, they were working with us, we're moving along. And he said that you called him and suggested that they don't work with mainstream, that they work with your new employer.
[00:06:01] And I stopped right there. Right? I didn't say another word. And he ended up responding. Yeah. Well, you know, they're my contact. I know them. I have a relationship with them. So I took them with me. Now we've seen similar things recently in the news when it comes to Tesla and Volkswagen, where Oh, they worked for me, and then he took all of this data with him.
[00:06:28] Right. You've heard about that story. I'm sure. But apparently this happens all of the time, these flight risk employees and these individuals, according to this study were involved in about 60% of the insider threats. There were analyzed in this study and insider threats, makeup in case you didn't know the majority.
[00:06:55] Of problems when it comes to data loss for the business. So what are you doing about it? Most people who are exfiltrating, the sensitive information are doing it over email. So are you monitoring their email? This was a pattern that they found in nearly 44% of the cases. Do you have special filters that are looking for this stuff?
[00:07:18] You know, when we go into a business, we put filters in place on the email, looking for things like client numbers, looking for things like employer, identification, numbers, bank, account numbers. Driver's license numbers, everything for, you know, a GDPR standpoint, the Massachusetts standpoint, the California standpoint, the new federal guidelines that are in place, right.
[00:07:42] We're looking for all of this data, but it also protects the company. Because they are trying to exfiltrate your data and take it with them to their next employer. So number one was they try and send it out by email and they'll often send it to a Gmail account or something else that they have the next most popular method is uploading it to cloud storage websites.
[00:08:11] And that's why we put a limit. On where people can go, right? We oftentimes will have the Dropbox enterprise installed or the Microsoft three 65 enterprise versions installed where they can upload files, but it is tightly controlled and we know what they're uploading. We know what they're downloading. Do you have those controls Impella in place?
[00:08:37] There are other ways that they're doing it, but we've got to pull up our socks. Now we have to, as businesses protect our investment, which for many of us is our retirement money. Right. And we have to watch our employees. I'm afraid to say. Particularly with the high rate of turnover in some industries and in the security industry, we're seeing the turnover rate that is in the sixth-month timeframe.
[00:09:05] So think about that. All of the training you did for that new insecurity employee, all of the systems that were set up. What's going to happen when they leave and take that data with them, that salesperson, the accounting people and on and on. So keep that in mind. We're seeing insider threats, being a very, very big threat to all of us out there.
[00:09:29] They'll all. When we come back, we're going to be talking about looters and the eye iPhones. We'll talk a little bit about how does Apple protects the devices that you have paid for? Because. Man, they do want a pretty penny. You're listening to Craig Peterson, stick around because we'll be right back after this and make sure you get my email.
[00:09:54] Craig peterson.com/subscribe.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses the danger of insider threats by those employees who are planning on leaving and behaviors that might indicate trouble.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
60% of Insider Threats Involve Employees Planning to Leave
---
Automated Machine Generated Transcript:
Insider threats are real and it's not like what they're showing in the movies. Hey, not at all. And especially in this post-COVID-19 world, everything has changed. So let's talk about insiders, people in your business, and the types of threats they're presenting.
[00:00:25] Hey, you're listening to Craig Peterson. You can find me [email protected] and of course podcasts pretty much everywhere out there. Just search for my name, Craig Peterson. Well, we've been talking about some of the threats that are facing us right now. We talked about DNS already today. We've talked in the past about just dozens of different types of threats.
[00:00:50]insiders are a big threat to businesses. So what does a threat look like? Well, Securonix just. Did a report, their researchers analyzed more than 300 confirmed incidents as part of their 20, 20 Securonix insider threat report. Now what they found was very disturbing, frankly. And the most disturbing part of it, at least to me was that 62% of the threats have to do with employees, exfiltrating data.
[00:01:29] In other words, employees taking data. Out of the business. Think about where we have been with the whole Wu Han virus and the concerns about the COVID-19. We have taken our employees. Who've been coming into the office maybe since your business was founded? And said, Hey, stay home. But if you want to get paid, you still have to do some work for us.
[00:01:56] And so we're allowing them to use their computers at home, maybe to bring a business, computer home, and then we hastily set up VPNs and other equipment in order to allow them access to the servers and the information they needed to use at home. How many of us put up. Monitors on those systems to make sure they weren't downloading stuff that they shouldn't have access to.
[00:02:26] Do you have all of the permission set up properly on your file server? Do you have it set up so that if all of a sudden they're downloading all of the schematics for all of your systems, all of your designs, do you have it set up? So it's going to automatically shut them off and notify you. About what just happened?
[00:02:47] Well, if you're like most businesses, the answer to that is no, because frankly, most businesses are not taking care of security. And that's what was pointed out here in this Securonix insider threat report because we've also allowed our employees to put documents on two thumb drives and take those thumb drives home, take them on the plane with them, maybe where they get lost.
[00:03:15] But the number that is concerning about the data being at home is an 80% number. Now, this is where we get into something called a flight risk. These are employees that are within two months of leaving your organization because what they've found is that employees that are planning on leaving the business tend to start stealing data between two and eight weeks before they go.
[00:03:47] And more than 80% of the employees that are planning to leave, bring. The business's data with them. That is very, very concerning. So think about that sales guy. How many times I mentioned this before, who's planning on walking out with all your customer lists that happened to me. I had a sales guy who was calling and trying to build a business and was keeping track.
[00:04:16] Of course of everybody he had contacted. Right. Doesn't that make sense? So it's all in our database of all of the contacts that he had made and the discussions they had had, the types of needs that they had, and he downloaded all of them. And then he went to one of my competitors and he started calling all these people up again and continued on the sales process.
[00:04:46] Just like he was still working for me. So here I was, I had paid for all of this Goodwill to be developed with these leads. I had paid for his training. He was going to training two to three days a week for a few hours back before we were doing it all live on a, on WebEx. Right. So he was going to all of these pieces of training.
[00:05:10] He was taking people out to lunch. He was going to meet with them. And these prospects that were still in that sales funnel were called up by him. When he went to his new employer now, I kind of thought that I was the lone ranger here. Right. It really disappointed me. I thought I knew the guy. I thought everything would be fine.
[00:05:35] And I eventually did talk to him cause I was. Too upset to talk to him initially. And I called him up and said, so how are things going? I said, Hey, I just heard from company X. And you know, they were working with us, we're moving along. And he said that you called him and suggested that they don't work with mainstream, that they work with your new employer.
[00:06:01] And I stopped right there. Right? I didn't say another word. And he ended up responding. Yeah. Well, you know, they're my contact. I know them. I have a relationship with them. So I took them with me. Now we've seen similar things recently in the news when it comes to Tesla and Volkswagen, where Oh, they worked for me, and then he took all of this data with him.
[00:06:28] Right. You've heard about that story. I'm sure. But apparently this happens all of the time, these flight risk employees and these individuals, according to this study were involved in about 60% of the insider threats. There were analyzed in this study and insider threats, makeup in case you didn't know the majority.
[00:06:55] Of problems when it comes to data loss for the business. So what are you doing about it? Most people who are exfiltrating, the sensitive information are doing it over email. So are you monitoring their email? This was a pattern that they found in nearly 44% of the cases. Do you have special filters that are looking for this stuff?
[00:07:18] You know, when we go into a business, we put filters in place on the email, looking for things like client numbers, looking for things like employer, identification, numbers, bank, account numbers. Driver's license numbers, everything for, you know, a GDPR standpoint, the Massachusetts standpoint, the California standpoint, the new federal guidelines that are in place, right.
[00:07:42] We're looking for all of this data, but it also protects the company. Because they are trying to exfiltrate your data and take it with them to their next employer. So number one was they try and send it out by email and they'll often send it to a Gmail account or something else that they have the next most popular method is uploading it to cloud storage websites.
[00:08:11] And that's why we put a limit. On where people can go, right? We oftentimes will have the Dropbox enterprise installed or the Microsoft three 65 enterprise versions installed where they can upload files, but it is tightly controlled and we know what they're uploading. We know what they're downloading. Do you have those controls Impella in place?
[00:08:37] There are other ways that they're doing it, but we've got to pull up our socks. Now we have to, as businesses protect our investment, which for many of us is our retirement money. Right. And we have to watch our employees. I'm afraid to say. Particularly with the high rate of turnover in some industries and in the security industry, we're seeing the turnover rate that is in the sixth-month timeframe.
[00:09:05] So think about that. All of the training you did for that new insecurity employee, all of the systems that were set up. What's going to happen when they leave and take that data with them, that salesperson, the accounting people and on and on. So keep that in mind. We're seeing insider threats, being a very, very big threat to all of us out there.
[00:09:29] They'll all. When we come back, we're going to be talking about looters and the eye iPhones. We'll talk a little bit about how does Apple protects the devices that you have paid for? Because. Man, they do want a pretty penny. You're listening to Craig Peterson, stick around because we'll be right back after this and make sure you get my email.
[00:09:54] Craig peterson.com/subscribe.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses how your DNS is being hijacked by new browser protocols known as DNS over HTTPS (DoH.)
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Using The New Chrome Secure DNS Settings To Browse Privately Is Easy
---
Automated Machine Generated Transcript:
Far too many ISP are watching where we're going and even changing our location, that URL you type in might not take you where you think you should be going.
[00:00:17] Hi everybody. Craig Peterson here. Thanks for joining me. We're here every week with all kinds of great information, keeping up to date on the latest in technology. And of course. Because I'm a security guy, a lot about security, and that's kinda what we're going to talk about right now. We all have internet service providers, whoever they are.
[00:00:40]In fact, the internet service providers even have internet service providers because they have to connect with other networks in order to get you where you want to go online. It's a strange world out there. And one of the things that the internet does and frankly has to do in order to get you to that location you want to go, is it uses something called the domain name system.
[00:01:07] Oh, you might call it the domain name service as well. But the idea behind this is to allow you to type in a URL or click on a link and that link then takes you to the correct site. Now you might be wondering what's this all about, I'm not going to get into the guts of the internet. That's not what I do.
[00:01:29] That's not my job. That's not going to affect me. Oh, my, it does because the domain name service was designed many years ago to solve a problem, but it did not consider another problem that was being created in his stead. What we've ended up with is. You guessed it, another problem, the DNS system allows you to type in that I address.
[00:01:58] And then it goes to your internet service provider and says, Hey, I want to go to google.com. Give me the address. And then. The internet service provider goes and talks upstream, finally finds out what the address for Google is. It's just like if you sent a piece of email and you addressed it to Craig Peterson in the Northeast United States, now it might get to me because some of these postal workers are very driven and they really want to help out.
[00:02:27] Right. But what are the odds that mail would actually end up in my mailbox? You know, not very good. Is it, so you have. To have a street address or maybe appeal, box number to send that true that to, maybe a rural route number as well. Who knows? Right? Depends on where you're at. If you're overseas, a military duty it's even different, but on the internet, Everything has to come down to these numbers.
[00:02:53] It's called the internet protocol, IPV four, and IPV six. Now you don't have to know all of that because all you have to do is type in google.com. Right. We already established that as an easy way to get to Google. However, Behind the scenes what's happening is that some of these internet service providers are actually intercepting your computer's requests to get to Google.
[00:03:21] And then what they're doing with that intercept is changing it sometimes. So they'll look and see, is there a site called google.com? Oh no, there's not. All right. Great. Yes. So then they send you to yet another site that's not Google. And they try and upsell you there'll be Ads all over it. There may be their own little search engine thing.
[00:03:44] That's come up on the screen that allows you to hopefully find the real google.com. On top of it all, not only are these internet service providers who were paying by the way, not only are they intercepting our DNS requests, but frequently they are also being intercepted by the bad guys. Here's what's happening there.
[00:04:09] You have a router in your home, a router in your small business. Now that router is where all of your data goes to. And from the internet now, obviously in bigger businesses, we'll set up multiple routers, multiple sites. We'll probably run a protocol called BGP that lets me route everything in between.
[00:04:30] Right? So if we have a failure, we can failover and everything just continues on. It's just wonderful. But in all of these cases, that router is a central point for all of your data going out to the internet. So what happens when a bad guy gains control of that router? And we're seeing this happen more and more now, because when was the last time you went ahead and made a change to the firmware on your router on that firewall box?
[00:05:06] Right? It probably never, most of us never touch it. We buy it, we set it and we forget it. Right. We, Ron Popeil the thing. But that's not what we need to be doing in this day and age this day and age, we're looking at the internet of things. We're looking at hundreds, maybe thousands, ultimately, of pieces of hardware in our homes.
[00:05:29] It's going to be embedded in our clothing. It's already in some of the shoes we have purses. We have. All of those devices need updates. Now that's one of the reasons we advise people to get rid of those big-box retail devices that they have like a link SIS box or who knows what, and that they're using at the network edge.
[00:05:54] We advise them to get something that's way more professional that has longterm support for it. And, you know, for my clients, we always use it. The Cisco gear. There's a whole new line that we've had great success with called them. Rocky go, you can look it up online. I'd be glad to help you with that. And then the next sec pop from that is Rocky.
[00:06:16] And then you get into the Cisco, but here's what's happening. You have not updated the firmware in your router slash firewall. Now, many times you cannot update the firmware because it is out of revision. So you bought this hardware three, four or five, six years ago as we were working just fine. Has given you the wifi.
[00:06:41] Everything is just hunky Dory. It's wonderful. And you've never thought twice about changing that firmware. And in fact, the manufacturer hasn't bothered to release updates to fix the latest, major bug security problem in their firmware. So do you see where I'm going here now? Here's what happens if you put all of this into a pot, let's stir it up.
[00:07:04] I know it's a little confusing, but here's what comes out in the end. When we take it out of the oven, the bad guys, they update the firmware. On your rudder slash firewall. That's a worst-case scenario. They actually updated and they set it up to send all of their data to Russia. All of your data, I should say to Russia or China, but what we're seeing right now is a DNS attack where they are routing all of your intranet DNS requests to them and their server. So here's what happened. Imagine you're sitting in front of your computer and you type in your bank, maybe it's TD bank.com, bank of america.com. Whatever it is. Remember your browser does not know how to get to TD bank. It doesn't know how to get to the Bank of America.
[00:07:58] So what does it do? It then sends a request out to the internet saying, Hey, what's the internet address for TD bank what's happened now? Is it sends a packet out to the internet? Hopefully to your internet service provider, but it gets intercepted. And now that packet goes to the bad guys and the bad guys say, Oh, TD bank.
[00:08:26] Yeah. Yeah. There, you know that part of town you never wanted to go into, you know, on the other side of the tracks where it's kind of dark and greasy and yeah. There's a lot of muggings and stuff. That's where TD bank is. Oh yeah. Go over there. So they will return the wrong address for TD bank. And now your browser ends up on their website, could even be a dark web website and all of your data, everything you're typing in is now being captured by them.
[00:08:58] So we have now both Firefox and Chrome who are doing something called HTTPS. DNS over HTTPS is, of course, is encryption. So it is now sending the requests for DNS encrypted end to end. That is great for consumers, usually. However, It does break security systems. So both Google and Mozilla have jumped on board here a little prematurely, but that's what's happening right now with your DNS.
[00:09:37] And what you should do is going to be based on your environment and what you're doing. Check people tell you, Hey, stick around. We're going to talk about insider threats. I bet you didn't know how prevalent they are and how they're occurring. You're listening to Craig Peterson.com. Stick around. We'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses how your DNS is being hijacked by new browser protocols known as DNS over HTTPS (DoH.)
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Using The New Chrome Secure DNS Settings To Browse Privately Is Easy
---
Automated Machine Generated Transcript:
Far too many ISP are watching where we're going and even changing our location, that URL you type in might not take you where you think you should be going.
[00:00:17] Hi everybody. Craig Peterson here. Thanks for joining me. We're here every week with all kinds of great information, keeping up to date on the latest in technology. And of course. Because I'm a security guy, a lot about security, and that's kinda what we're going to talk about right now. We all have internet service providers, whoever they are.
[00:00:40]In fact, the internet service providers even have internet service providers because they have to connect with other networks in order to get you where you want to go online. It's a strange world out there. And one of the things that the internet does and frankly has to do in order to get you to that location you want to go, is it uses something called the domain name system.
[00:01:07] Oh, you might call it the domain name service as well. But the idea behind this is to allow you to type in a URL or click on a link and that link then takes you to the correct site. Now you might be wondering what's this all about, I'm not going to get into the guts of the internet. That's not what I do.
[00:01:29] That's not my job. That's not going to affect me. Oh, my, it does because the domain name service was designed many years ago to solve a problem, but it did not consider another problem that was being created in his stead. What we've ended up with is. You guessed it, another problem, the DNS system allows you to type in that I address.
[00:01:58] And then it goes to your internet service provider and says, Hey, I want to go to google.com. Give me the address. And then. The internet service provider goes and talks upstream, finally finds out what the address for Google is. It's just like if you sent a piece of email and you addressed it to Craig Peterson in the Northeast United States, now it might get to me because some of these postal workers are very driven and they really want to help out.
[00:02:27] Right. But what are the odds that mail would actually end up in my mailbox? You know, not very good. Is it, so you have. To have a street address or maybe appeal, box number to send that true that to, maybe a rural route number as well. Who knows? Right? Depends on where you're at. If you're overseas, a military duty it's even different, but on the internet, Everything has to come down to these numbers.
[00:02:53] It's called the internet protocol, IPV four, and IPV six. Now you don't have to know all of that because all you have to do is type in google.com. Right. We already established that as an easy way to get to Google. However, Behind the scenes what's happening is that some of these internet service providers are actually intercepting your computer's requests to get to Google.
[00:03:21] And then what they're doing with that intercept is changing it sometimes. So they'll look and see, is there a site called google.com? Oh no, there's not. All right. Great. Yes. So then they send you to yet another site that's not Google. And they try and upsell you there'll be Ads all over it. There may be their own little search engine thing.
[00:03:44] That's come up on the screen that allows you to hopefully find the real google.com. On top of it all, not only are these internet service providers who were paying by the way, not only are they intercepting our DNS requests, but frequently they are also being intercepted by the bad guys. Here's what's happening there.
[00:04:09] You have a router in your home, a router in your small business. Now that router is where all of your data goes to. And from the internet now, obviously in bigger businesses, we'll set up multiple routers, multiple sites. We'll probably run a protocol called BGP that lets me route everything in between.
[00:04:30] Right? So if we have a failure, we can failover and everything just continues on. It's just wonderful. But in all of these cases, that router is a central point for all of your data going out to the internet. So what happens when a bad guy gains control of that router? And we're seeing this happen more and more now, because when was the last time you went ahead and made a change to the firmware on your router on that firewall box?
[00:05:06] Right? It probably never, most of us never touch it. We buy it, we set it and we forget it. Right. We, Ron Popeil the thing. But that's not what we need to be doing in this day and age this day and age, we're looking at the internet of things. We're looking at hundreds, maybe thousands, ultimately, of pieces of hardware in our homes.
[00:05:29] It's going to be embedded in our clothing. It's already in some of the shoes we have purses. We have. All of those devices need updates. Now that's one of the reasons we advise people to get rid of those big-box retail devices that they have like a link SIS box or who knows what, and that they're using at the network edge.
[00:05:54] We advise them to get something that's way more professional that has longterm support for it. And, you know, for my clients, we always use it. The Cisco gear. There's a whole new line that we've had great success with called them. Rocky go, you can look it up online. I'd be glad to help you with that. And then the next sec pop from that is Rocky.
[00:06:16] And then you get into the Cisco, but here's what's happening. You have not updated the firmware in your router slash firewall. Now, many times you cannot update the firmware because it is out of revision. So you bought this hardware three, four or five, six years ago as we were working just fine. Has given you the wifi.
[00:06:41] Everything is just hunky Dory. It's wonderful. And you've never thought twice about changing that firmware. And in fact, the manufacturer hasn't bothered to release updates to fix the latest, major bug security problem in their firmware. So do you see where I'm going here now? Here's what happens if you put all of this into a pot, let's stir it up.
[00:07:04] I know it's a little confusing, but here's what comes out in the end. When we take it out of the oven, the bad guys, they update the firmware. On your rudder slash firewall. That's a worst-case scenario. They actually updated and they set it up to send all of their data to Russia. All of your data, I should say to Russia or China, but what we're seeing right now is a DNS attack where they are routing all of your intranet DNS requests to them and their server. So here's what happened. Imagine you're sitting in front of your computer and you type in your bank, maybe it's TD bank.com, bank of america.com. Whatever it is. Remember your browser does not know how to get to TD bank. It doesn't know how to get to the Bank of America.
[00:07:58] So what does it do? It then sends a request out to the internet saying, Hey, what's the internet address for TD bank what's happened now? Is it sends a packet out to the internet? Hopefully to your internet service provider, but it gets intercepted. And now that packet goes to the bad guys and the bad guys say, Oh, TD bank.
[00:08:26] Yeah. Yeah. There, you know that part of town you never wanted to go into, you know, on the other side of the tracks where it's kind of dark and greasy and yeah. There's a lot of muggings and stuff. That's where TD bank is. Oh yeah. Go over there. So they will return the wrong address for TD bank. And now your browser ends up on their website, could even be a dark web website and all of your data, everything you're typing in is now being captured by them.
[00:08:58] So we have now both Firefox and Chrome who are doing something called HTTPS. DNS over HTTPS is, of course, is encryption. So it is now sending the requests for DNS encrypted end to end. That is great for consumers, usually. However, It does break security systems. So both Google and Mozilla have jumped on board here a little prematurely, but that's what's happening right now with your DNS.
[00:09:37] And what you should do is going to be based on your environment and what you're doing. Check people tell you, Hey, stick around. We're going to talk about insider threats. I bet you didn't know how prevalent they are and how they're occurring. You're listening to Craig Peterson.com. Stick around. We'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Craig discusses how your DNS is being hijacked by new browser protocols known as DNS over HTTPS (DoH.)
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Using The New Chrome Secure DNS Settings To Browse Privately Is Easy
---
Automated Machine Generated Transcript:
Far too many ISP are watching where we're going and even changing our location, that URL you type in might not take you where you think you should be going.
[00:00:17] Hi everybody. Craig Peterson here. Thanks for joining me. We're here every week with all kinds of great information, keeping up to date on the latest in technology. And of course. Because I'm a security guy, a lot about security, and that's kinda what we're going to talk about right now. We all have internet service providers, whoever they are.
[00:00:40]In fact, the internet service providers even have internet service providers because they have to connect with other networks in order to get you where you want to go online. It's a strange world out there. And one of the things that the internet does and frankly has to do in order to get you to that location you want to go, is it uses something called the domain name system.
[00:01:07] Oh, you might call it the domain name service as well. But the idea behind this is to allow you to type in a URL or click on a link and that link then takes you to the correct site. Now you might be wondering what's this all about, I'm not going to get into the guts of the internet. That's not what I do.
[00:01:29] That's not my job. That's not going to affect me. Oh, my, it does because the domain name service was designed many years ago to solve a problem, but it did not consider another problem that was being created in his stead. What we've ended up with is. You guessed it, another problem, the DNS system allows you to type in that I address.
[00:01:58] And then it goes to your internet service provider and says, Hey, I want to go to google.com. Give me the address. And then. The internet service provider goes and talks upstream, finally finds out what the address for Google is. It's just like if you sent a piece of email and you addressed it to Craig Peterson in the Northeast United States, now it might get to me because some of these postal workers are very driven and they really want to help out.
[00:02:27] Right. But what are the odds that mail would actually end up in my mailbox? You know, not very good. Is it, so you have. To have a street address or maybe appeal, box number to send that true that to, maybe a rural route number as well. Who knows? Right? Depends on where you're at. If you're overseas, a military duty it's even different, but on the internet, Everything has to come down to these numbers.
[00:02:53] It's called the internet protocol, IPV four, and IPV six. Now you don't have to know all of that because all you have to do is type in google.com. Right. We already established that as an easy way to get to Google. However, Behind the scenes what's happening is that some of these internet service providers are actually intercepting your computer's requests to get to Google.
[00:03:21] And then what they're doing with that intercept is changing it sometimes. So they'll look and see, is there a site called google.com? Oh no, there's not. All right. Great. Yes. So then they send you to yet another site that's not Google. And they try and upsell you there'll be Ads all over it. There may be their own little search engine thing.
[00:03:44] That's come up on the screen that allows you to hopefully find the real google.com. On top of it all, not only are these internet service providers who were paying by the way, not only are they intercepting our DNS requests, but frequently they are also being intercepted by the bad guys. Here's what's happening there.
[00:04:09] You have a router in your home, a router in your small business. Now that router is where all of your data goes to. And from the internet now, obviously in bigger businesses, we'll set up multiple routers, multiple sites. We'll probably run a protocol called BGP that lets me route everything in between.
[00:04:30] Right? So if we have a failure, we can failover and everything just continues on. It's just wonderful. But in all of these cases, that router is a central point for all of your data going out to the internet. So what happens when a bad guy gains control of that router? And we're seeing this happen more and more now, because when was the last time you went ahead and made a change to the firmware on your router on that firewall box?
[00:05:06] Right? It probably never, most of us never touch it. We buy it, we set it and we forget it. Right. We, Ron Popeil the thing. But that's not what we need to be doing in this day and age this day and age, we're looking at the internet of things. We're looking at hundreds, maybe thousands, ultimately, of pieces of hardware in our homes.
[00:05:29] It's going to be embedded in our clothing. It's already in some of the shoes we have purses. We have. All of those devices need updates. Now that's one of the reasons we advise people to get rid of those big-box retail devices that they have like a link SIS box or who knows what, and that they're using at the network edge.
[00:05:54] We advise them to get something that's way more professional that has longterm support for it. And, you know, for my clients, we always use it. The Cisco gear. There's a whole new line that we've had great success with called them. Rocky go, you can look it up online. I'd be glad to help you with that. And then the next sec pop from that is Rocky.
[00:06:16] And then you get into the Cisco, but here's what's happening. You have not updated the firmware in your router slash firewall. Now, many times you cannot update the firmware because it is out of revision. So you bought this hardware three, four or five, six years ago as we were working just fine. Has given you the wifi.
[00:06:41] Everything is just hunky Dory. It's wonderful. And you've never thought twice about changing that firmware. And in fact, the manufacturer hasn't bothered to release updates to fix the latest, major bug security problem in their firmware. So do you see where I'm going here now? Here's what happens if you put all of this into a pot, let's stir it up.
[00:07:04] I know it's a little confusing, but here's what comes out in the end. When we take it out of the oven, the bad guys, they update the firmware. On your rudder slash firewall. That's a worst-case scenario. They actually updated and they set it up to send all of their data to Russia. All of your data, I should say to Russia or China, but what we're seeing right now is a DNS attack where they are routing all of your intranet DNS requests to them and their server. So here's what happened. Imagine you're sitting in front of your computer and you type in your bank, maybe it's TD bank.com, bank of america.com. Whatever it is. Remember your browser does not know how to get to TD bank. It doesn't know how to get to the Bank of America.
[00:07:58] So what does it do? It then sends a request out to the internet saying, Hey, what's the internet address for TD bank what's happened now? Is it sends a packet out to the internet? Hopefully to your internet service provider, but it gets intercepted. And now that packet goes to the bad guys and the bad guys say, Oh, TD bank.
[00:08:26] Yeah. Yeah. There, you know that part of town you never wanted to go into, you know, on the other side of the tracks where it's kind of dark and greasy and yeah. There's a lot of muggings and stuff. That's where TD bank is. Oh yeah. Go over there. So they will return the wrong address for TD bank. And now your browser ends up on their website, could even be a dark web website and all of your data, everything you're typing in is now being captured by them.
[00:08:58] So we have now both Firefox and Chrome who are doing something called HTTPS. DNS over HTTPS is, of course, is encryption. So it is now sending the requests for DNS encrypted end to end. That is great for consumers, usually. However, It does break security systems. So both Google and Mozilla have jumped on board here a little prematurely, but that's what's happening right now with your DNS.
[00:09:37] And what you should do is going to be based on your environment and what you're doing. Check people tell you, Hey, stick around. We're going to talk about insider threats. I bet you didn't know how prevalent they are and how they're occurring. You're listening to Craig Peterson.com. Stick around. We'll be right back.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Today Craig discusses secure communications and how we can keep our information from being used by the bad guys.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Signal is adding automatic face blurring to help protesters
---
Automated Machine Generated Transcript:
Craig Peterson: Have you ever wondered how you can blur the pictures that you're taking on your camera? Maybe also remove location data, GPS, all of that stuff. Well, that's what we're going to talk about right now and how rioters are doing it too.
[00:00:22] Yes. Hello. Hello, Craig Peterson here. Thanks for joining me. We're on every week, you can subscribe online as well. CraigPeterson.com/subscribe and get all of my latest information.
[00:00:35] We've got a bit of a problem out there that you might have heard about. In fact, if you haven't heard about it, you're probably living under a rock somewhere.
[00:00:44] But here's the problem. We have people out in the street picketing, they're rioting. They're really trying to get their voices heard. Now what's behind it all, that's a subject for a completely different show. We're going to talk about technology as we do every week. What we're finding right now is that while they're out there taking pictures, they're doing all kinds of silly/stupid things with them. For instance, we've got them posting pictures on Twitter of illegal things they're doing, or they've done, which allows the police to get at them, right? So they're looking, what can we do? How can we keep our information private and you know what? It's actually a great topic for all of us because.
[00:01:33] All of us are under attack. We've got the bad guys going at us, trying to steal our information and then use it against us. Look at what's been happening with business email compromise with businesses that are responding to emails. They shouldn't have, it happened to Barbara Corcoran. There she is. She's one of the people you think would know better.
[00:01:56] She's on Shark Tank. She's a big-time investor who started her whole career in real estate and has done very, very well for herself. And she got fooled into sending $400,000 to the bad guys. It can happen to you her, it can happen to you. It can happen to anybody. So how do we keep our information safe? And in this day and age, young kids, you don't want necessarily the pictures online.
[00:02:25] You sure don't want GPS coordinates to be there. Well, that's where some very innovative people have been spending time lately. And. You can have the advantage that bad guys are using as well. And that is using some of these apps that are designed to keep your data safe. Many of us have been using zoom for everything from meetings through weddings, being able to attend remotely.
[00:02:56] Things that we'd never been able to really pay any attention to before because we were so far away. And of course, now we're being forced to be so far away. Well, there is a piece of software called Signal and Signal's, founder and CEO. His name is Moxie, Marlinspike. I bet that's not the name he was born with and he has developed a protocol.
[00:03:21] And an app. Now, this protocol is secure end to end. What that means is if there is someone in the middle, anywhere in the middle of your communications, they can capture data from your communications, but they can't tell what that data is. In other words, they can get the data stream, but it's encrypted.
[00:03:46] They don't know if this is a video. If this is voice, if you're sending files back and forth, they just don't know. And at this point in time, anyways, we've seen that the law enforcement agencies and certainly the bad guys have had a hard time with some of this data. So if you need to try and keep your information safe, how to, how do you do it?
[00:04:10] Well, WhatsApp is one of those pieces of software out there that's using Signal's open-source, secure messaging platform. So is Facebook Messenger, now. They're planning on introducing a new feature. Also, that lets you quickly blur people's faces when you're sharing photos. And what Signal is doing is you can set it up to automatically blur a face, and it will put a little square rectangle over what it deems to be a face.
[00:04:44] And then you can go in and modify that and make it a little bit bigger. Now, maybe you want to get rid of a little bit more stuff in the background, and while it's doing that, it's also turning it into a flat JPEG. It's removing all of the extraneous information about the camera that took the picture.
[00:05:04] What the focal length of the lens was, the lens speed, everything that might help to track it down, trace it down to the originator. It's also removing the GPS information those geocodes. Now that's very important as well because the bottom line that's how some of these bad guys are tracking us down. For instance, there are stalkers out there.
[00:05:29] Ex's ex-wives, ex-husband's ex-boyfriends, girlfriends that have been stalking their ex online. And have been grabbing photos that are posted and then look at the geocode information in it to figure out where they are at. That is a problem. If you ask me a very, very big problem, because now they have a location down to a street address, right? These things are very, very accurate within a couple of meters.
[00:06:01] So what do you do? Well, you can certainly use Signal if you are an Android user, you can even set up Signal to be your default messaging application. Now, remember if you use Signal to send a message to someone that has a regular phone, or that does not have Signal, it's going to go in the clear, which is kind of like Apple's iMessage. If you're using iMessage, your data is secure end to end, which is great. Right? But not everybody has. I message. However signal is available on all of the mobile platforms and on a few others as well. So you can now use Signal to communicate securely with someone you can use iMessage to communicate securely with someone, both of which are great.
[00:06:53] WhatsApp is also very popular. I have a mastermind group that I'm in and we use WhatsApp for group messaging as well as for individual messaging. Where we'll send a quick note to somebody else in the group saying, Hey, I noticed you sent this out today or you did this, or, Hey, this was in the news. You might want to follow up on it, et cetera.
[00:07:14] Now, with this, the blurring thing, now we're kind of asking if this is crossing a line. What we're seeing is now that there's obviously great use for encryption. Very good encryption. When it's me sending you a message so that a bad guy does not intercept it and then use it against us. Just steal our money or cause all kinds of havoc, right?
[00:07:42] Blackmail, you name. It can happen, but where's the line when it comes to bad guys. You know, on the complete other-side of that scale, you have people who kill people, who mame and rob and steal, the obvious, bad guys. Then somewhere in the middle of, there's gotta be some sort of a line. The problem is you cannot define that line, frankly.
[00:08:08]Where is it? How do they know what you're using it for? And that gets to be a real problem. So if you want to keep your data safe, you can. And probably the best way to do this is to use signal. Use this basic blur face functionality that it has and use it to remove kids faces, or are there people who might be in the shot who might not want their information, you know, their face to be spread out on your Facebook page or wherever it might be a, but.
[00:08:42] Will you remember that it is secure end to end. So unless the person receiving it then shares it, you aren't in any trouble of having shared data. You did not want to share, but if they receive one of these blurred messages, well, It's removed everything from that photo, the date, the time, the camera information, the GPS, everything else.
[00:09:05] So there you go. There's a little bit of about what you can do right now. That is free software. By the way, is open-source. It's turned by the nonprofit signal foundation. And if you don't have Signal installed, you might want to do it.
[00:09:19] I use it to communicate with some of my clients and some of my friends and have for quite a few years, I haven't found any real problems. Now, a word of caution. There are some other apps out there. For instance, I found one online for the iPhone and it's a shortcut. Now Apple's iPhone has this concept of shortcuts, which is really rather cool. It lets you tie apps together to do different things.
[00:09:45]this particular shortcut. Remove some of these geoinformation and other things from pictures. So you might want to set yourself up a shortcut that does that. There are some apps that do that. In fact, on your iPhone. When you take a picture with that here I can mode where it is, including a little bit of video, basically, before the picture, a lot of places have trouble with that.
[00:10:10] So you can use one of these converters to turn it that picture into a regular JPEG and remove all of the personal information that's on it. This blur faces shortcuts, gallery.com. Shortcut that I found I do not as I went through it. I looked at the code that's behind it and it actually sends it up to an Amazon web server.
[00:10:33] That picture. That you've taken, which now means, who knows just how much that, how secure it is, how much that could be shared. Right. It really could be a problem for you. So keep that in mind as well. Don't use some of these things. Be very careful. Be very cautious. Hey, when we come back, we're going to talk about some new security settings that have come into Chrome and are turned on by default in Firefox.
[00:11:04] We'll tell you what they are when you should use them. And frankly, when you should not use them, it is causing. All kinds of fits and panics in the security world out there. So stick around, you're listening to Craig Peterson and we'll be back in just a couple of minutes.
[00:11:22]Also if you do sign up on my website, Craig peterson.com. Subscribe, I will be sending you a bunch of free stuff, some great checklists that you can use some information about what you should be doing to stay safe, including your password. So again, go right now. Craig peterson.com/subscribe and stick around because we're coming right back, talking about secure DNS.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed