A truth-telling great guy came to Washington and tried to be president, tried to be a senator. He would be eaten alive. What do you think about Bill Bradley? Bill Bradley was, of course, a person who voted with the Contras, and he was a key swing vote for President Reagan. He was one of the key Democrats who broke ranks, and I think because of the pressure from the Washington elite at the time, which was swinging very increasingly pro-Contra. Open up your eyes, eyes, eyes, if Mumia dies. This Saturday, September 25th, come join the March for Justice for death row journalist Mumia Abu-Jamal. Next month, Mumia will begin the final legal road to the Supreme Court, and Governor Ridge is poised to set a new date for execution. We must not let this happen. Join us, 12 noon, 125th Street and Adam Clayton Powell Boulevard at the State Office Building, or meet up with the March at 2.30 p.m. at Columbus Circle, 59th Street and 8th Avenue. We must make a strong presence on Saturday, September 25th. Mumia's life depends on it. For more information, please call 212-330-8029 or 718-398-1766. This has been a public service on behalf of the Free Mumia Abu-Jamal Coalition, a non-profit organization. And a very good evening to everybody. The program is off the hook. Emmanuel Goldstein here with you for the next hour. Isaac's here, too. How you doing? How you doing, sir? It's been a busy week. It's been a fun week. Fun week? Well, it's been fun for me. It's been fun for me. Well, of course, we had the big storm move in and cause all kinds of mayhem, and mayhem is always fun. So I guess some people sitting on top of their roofs in North Carolina don't think that way, but you got to look at it with a different perspective, you know. It's interesting when weather does weird things, and this week was no exception. But that's not what we're here to talk about tonight. We're here to talk about technological things and how technological things can get all messed up, especially when you have human beings in charge. That's right. I think this week the theme is stupidity. Isn't that every week's theme? Yeah, but this is real stupidity. This is aggressive stupidity. Exceptionally. This is the kind of stupidity that reaches out and touches you. In ways you'd rather not be touched. And we're going to show exactly what we're talking about. In fact, we've got two massive examples. The first example pretty much has been used for the last couple of days. The second example nobody knows about yet. In fact, you don't even know about it. I don't know about it? No, you don't know anything about it. I don't know anything about anything. Nobody ever tells me anything, but that's another story. You really don't know anything about this. I think you're going to be shocked. I'm going to be shocked? The last time you tried to shock me, you did something very strange to my Sprint phone. They fixed that for me. Yeah, I think so. Well, you know, these things happen. Anyway, if you have been accessing the 2600 website over the past couple of days, you might have seen a rather interesting, humorous story go flying by concerning NSI. Isaac, why don't you tell us who NSI is? That would be Network Solutions Incorporated, the fun people who seem to think that you have to give them lots of money to register something.com. Well, yeah, but you do, don't you? Well, yeah, but it shouldn't be that way. No, it shouldn't be that way, but basically if you want something on the net, you kind of have to go through them. Actually, that's not entirely true anymore because new companies are sprouting up. Competition is actually here. Well, that's debatable. That's true. It's not as here as we would like it to be, but it's getting to the point where you might actually be able to not have to use NSI. Well, you are using NSI, just indirectly. All these other people are just reselling access to the NSI database, so they still have a stranglehold, but it's not as obvious anymore. Right. Anyway, last week the people at NSI did something really phenomenally stupid. Is that the email I got? Yeah, if you're a system administrator, if you have a site registered to your name, you got an email from NSI. Why don't you tell us about the email you got? Oh, the email I got was informing me that I now have a special email account with NSI, and it gave me my username and my password, which were very strangely very similar, with, in fact, the only difference being the appending of the three letters NSI to my password. Yeah, you know, I got the same kind of mail. I got the same kind of mail. It had basically my last name. What was your password? Well, I'll tell you, I don't care, because I'm not going to use it. It was goldsteinnsi. That was my password. Wait a second. You mean they just took everyone's username and added NSI to make it the password? Yeah, the last name. And you can easily find out this information just by doing a whois on any Internet site. And yeah, they basically made your last name plus NSI as your password. And your username would be your last name followed by a number, assuming that there is more than one of you. Right. So, yeah, it was, I think, goldstein25. I don't care. Take it. I don't want that account. Take that account. But the thing is, they said you need this account. You have to have this account in order to stay in touch with us about your, you know, Internet settings and things like that. All right, so I decided to decline the account, and when they, like, just turn off service at some point, I will scream bloody murder. Well, that's not going to happen, but I just decided to ignore it, because I thought the whole thing was pretty stupid to start with. Well, I saved it. It was kind of funny. Yeah, it was one of these, like, you know, stupid pieces of email that you get, and increasingly a lot of them seem to be coming from NSI, or, as they're known in some circles, the intranet. But that's going to change. It used to be netsol. Yeah, I think that website's still... I don't even know. I think they're looking for identity now, and they're certainly getting the identity that we think they deserve, but I don't know if they want that identity. Anyway, this is nothing, folks. This is nothing. Yeah, it's stupid sending passwords in clear text, especially if you're, you know, the people running the Internet, and it's especially stupid adding NSI to a last name as the password. Almost anybody can guess a password. But the real advanced-level stupidity that they succeeded in passing on to us has to do with a little hole, rather a big hole, in their email accounts. First of all, these are the domains that were affected. .express.com, mymailbag.com, nsimail.com, and .comnow.com. That sounds horrible when you say that. Yes, it does. .comnow.com, but that's what they got. So I'll read you their little blurb. Network Solutions now offers two email services for your communication needs. Both give you the same reliability and security that has become synonymous with Network Solutions. I think right there... Ooh, there's a foot-and-mouth thing right there. Right there. They just dug their grave with that little remark. Same reliability and security. Okay, our premier offering is .commailservice, a personalized business email solution for growing businesses. And I haven't actually explored .com, but if their security is anything like their .comnow and all the other ones, it's definitely... I don't know if it's a solution, but it's a problem, that's for sure. There were problems. If you are just looking for a simple-to-use communication tool to access before you decide to launch your business on the Internet, Network Solutions' free webmail is just for you. Get an email account using one of our domain names and give it a try today for free. You know, they should be paying me for that. Oh, golly gee. It's so easy to get started. In fact, folks, it's so easy that you don't even need a password. That's what we discovered. Actually, some people mailed us a very interesting bit of documentation. They told us that all you have to do is type a line. Maybe you could explain what this line is when I read it out loud. You can tell people what exactly it is I'm reading. You enter this as your URL. All right, http://mail..comnow.com. Now I'm confused. You're going to have to realize that mail is followed by a period, which is what I said, dot, and then the word .comnow.com, so .comnow.com, slash signup, slash poll, slash new account. Now the thing is you take that word new account and put in whatever name you want. All right, follow that with a question mark, then the word dlang, d-l-a-n-g, equals default. Now when you type that in, the word that you substitute for new account is basically someone's account. You're logged in as them. No password, no check, no nothing. You can read mail to them. You can send mail as them. You can do all kinds of things. The one thing you can't do is protect the account against anybody else doing the exact same thing. So basically the free account that was so generously given to me by NSI could conceivably be used by anyone to send mail as though they were me? That's right. That's absolutely right. Oh, that makes me feel very secure and efficient. Yeah. Well, God knows what they were thinking when they hit us with all these different things. They weren't thinking. Yeah, but this goes beyond not thinking. This is like thinking in a very bad way, like how do I completely destroy a company? That's the kind of thinking we're seeing here. But anyway, tell me something about that line I just read. What exactly is going on there? I'm assuming that you're just calling a CGI with the question mark and you are submitting the name as a query. I'm not sure. This is the first I'm hearing of it. But why does it work? Why does it work? Yeah. What does it tell you? What do you mean what does it tell me? What is going on here when you type that line in? When you type in that line you are telling the server something and something is happening. I was really hoping for a more technical explanation than that. You're just giving this to me now with like three minutes and I don't exactly have a machine in front of me that I can do any analysis with. We talked about it before, but I guess your memory is about as short as NSI's memory at this point. Well anyway, regardless, the point is all you have to do, actually they sort of fixed it. They sort of fixed it? Yeah. If you type that now you get the login screen, which I guess is what you're supposed to get. But if you happen to have any of the accounts in cache, if you've done it before, such as I have, you can simply click on that, enter that URL, along with a very long number, which I'm going to read out. I'm going to read out one of them just as an example. This one I don't think works because we put it up on the website and within a couple of minutes it stopped working. In fact, we're going to do that in just a moment. So if you have access to a web browser, we're going to add an account that you can click on and be logged in as a user, whose name I won't give out yet. But we have people standing by that are not here who actually have access. I'll explain the concept of people being somewhere else to you after the show. But the one that stopped working only a little while ago, and I don't know why, I think they're watching, mail.com now.com slash mail slash compose slash Microsoft. It's a fun account to have. And then these numbers, 0D472389DB5E137350829516AA7E8C32. Now, if you typed all that in, you bypassed the password. You didn't have to enter the password. And the way the system is set up, this is yet another act of stupidity, the way the system is set up, if you have that information, you can just bypass the password. So what we're about to do right now, and hopefully the person doing this is listening, we're going to stick a link on our website. You have to go to the news section where you'll see the big security hole, NSI. And all you have to do, it should become active pretty soon, just keep hitting reload on your screen, just click on the site, click on the link. Oh, so you didn't have to memorize that long string that you just read. No, the person on the other end has done that. It's a different string, it's a different account. So basically all you have to do is click on that, and you'll be logged in as that account, and you can send mail and do all kinds of neat things. It's my account, isn't it? No, it's not your account. It's an interesting account. Oh, an interesting account. Not interesting? So far, NSI has not said a thing about this. They've quietly, you know, fixed it in kind of a haphazard way, but they haven't said a word about it. And in fact, you know, we're trying, this is the thing that really frustrates me, is the mass media, the mass media just does not get it. This, to them, is not a story. In fact, Wired sent us mail saying, well, we don't think this is a security issue or a privacy issue. It's like, what do you want? What exactly do you consider to be a security or privacy issue? Being able to log in as anybody with no password and send mail from their account and pretend to be them. Kind of like Hotmail? And at the same time, at the same time, be affiliated with the people running the Internet, you know, running the name service and all that kind of thing, and having them believe that this is in fact you. All that, and that's not a security or privacy issue. Actually, that's interesting. If somebody were to send email from the account that they gave me, would they instantly, like, be able to do updates to my domain or anything like that? Well, I think that was the idea, that this would be a trusted email in the eyes of NSI. I think maybe now, after we've made a big fuss about it, they might not believe it quite so readily, hopefully not. I hope not. But we were trying to get the mass media to, you know, to pay attention to this, to warn people. They didn't do it. Well, the mass media is busy doing their own thing. You know what the top story on that Wired News page was, the day that they said this was not an issue, this was not a security issue, not a privacy issue? No. It was a sex scandal involving some guy that, like, tried to communicate with a fake 13-year-old. A fake 13-year-old? Yeah, that's the latest thing with law enforcement people. They make, they, basically, they sit a cop in front of IRC. Okay. And they have that cop pretend to be, like, a 13-year-old girl. And then some guy, some, you know, person tries to, like, entice this 13-year-old girl into having sex or something like that. So, basically, by making plans with a fake 13-year-old who's actually a cop on IRC, this guy committed a felony. Yeah. It's been going on for a while. So why is it news? I don't know. It was a top story on Wired, so you go figure. Okay. I think it's kind of weird that you don't need to have a victim anymore. You can just make up, I mean, why even have cops? Why not just have bots do it? Why not just have, you know, computerized accounts that respond in a certain way? But what if your thing, what if your thing is picking up cops, you know? What if that's what you're into? And it turns out to be a 13-year-old impersonating a cop. What crime have you committed then, you know? All kinds of potential questions you could ask. Anyway, we have some mail here that's kind of interesting. One of the accounts that we accessed was Webmaster. You can just type in any name you want. Webmaster? Webmaster was one of them. And anybody could get into Webmaster. Anybody could read the mail to Webmaster. Let's look at some of the pieces of mail that were floating around. Keep in mind, all these pieces of mail... Whose Webmaster is this? This was Webmaster at .comnow.com. Oh, okay. It wasn't a real Webmaster account. It was apparently somebody set it up to be, you know, the name Webmaster. But because of that flaw, anybody could log in as that person, read whatever mail was going in there, and send mail out. Interesting. Yeah. It was extremely easy, extremely simple, extremely embarrassing. Listen to some of these messages. Again, these came before this was revealed. This was simply people angry at the fact that passwords were sent out clear text. To Webmaster. Screwed that one up, eh? I accidentally type in the wrong username, put the matching password, random passwords, and I get into the wrong account. Dearie me, I'd better leave before someone notices. Well, that's somebody that actually figured it out on their own. So, obviously, people were figuring this out. Here's another piece of mail entitled Problem with Email Account. The following is what I sent my vacation message to after changing my password to some random garbage. I decided to entertain myself by sending you a copy. The idiots at Network Solutions decided to open thousands of accounts for its customers using easily guessable passwords. Hint, really easy. These accounts were created without any input, and NSI was kind enough not to provide any means of removing them. With noise on the Internet account about the account making it easier to hijack domain names, gee, thanks, NSI, I was forced to log in and change my password, as were thousands of other people. Guess what? That didn't do you any good whatsoever. Well, a lot of the servers were, like, becoming overloaded and not exactly working from what I read. Network Solutions, yes. We're in monopoly, dammit. If you wish to contact me, do a Whois lookup for, uh, well, then they give a name here, which was the domain that I registered with NSI that got me all this neat spam and free unsolicited wide-open email accounts. Another piece of mail entitled Get Your Security Right. This webmail service is one big security hole. I can log into over two dozen accounts just using last name and password, last name, NSI. Webmaster with Webmaster NSI did work as well, just like Admin with Admin NSI. Geez, man, wake up and smell the fire. P.S. The password for this account has been changed to tra-la-la. There is a lot of email here from concerned netizens trying to warn you guys. I suggest you read them. Of course, the password doesn't make any difference, and I'm sure they never logged in. Let's see. Here's another one. What in the heck were you thinking? What in the world were you thinking? You set up an email account in my name and gave me a password, which was the same for every domain name, account name, and NSI after it, and emailed me the account and password without me setting it up, clearing it, or accessing it first. This has got to be the worst example of exploitation I've ever seen with a business in your position and trust. Wait a second. I fear for the safety of my domain name, my good name, and my checkbook with you in charge of domain names now. I do not want any mail account opened without my okay. Man, what in the name of God in all that is holy was your company thinking when it pulled this idiotic stunt? Did you just feel some marketing guy get fired? Oh, I think... I think a lot of... I hear a vacuum. Aren't these supposed to be soundproof studios? Anyway, I think a lot of people are getting fired for this. I mean, come on. Where are your brains here? Unbelievable. A couple more pieces of mail here. Dear Network Solutions, I do not appreciate getting email messages like this. I sincerely hope you will never bother me again in the future. As far as your web-based email service is concerned, I think it's an unprecedented fiasco by generating easy-to-guess passwords. I strongly suggest you immediately take action and modify all passwords in that system. I've heard several reports of people breaking into the .comNow email service that weren't supposed to. I'm stunned and shocked to see your company do such an utterly dumb thing. Please correct it now. Here's another piece of mail. God, you guys suck. Nice default passwords. Morons. What in the hell were you people thinking by sending out generic passwords for every account? Are your security people just stupid or what? Since you've been monopolizing the domain world for so long, has all common sense gone to the wayside? I can't believe the number of idiots that work there and that anyone thought this was a good idea. Since I'm up for renewal in three months, I'll have to seriously contemplate staying with people who are ignorant and stupid. A problem? Yes. That's true. No, that's not true. That's not true. How is it not true? There is competition. Go to the NSI webpage and you will see for yourself. It's not competition. You don't have to give your money to NSI. You will indirectly. That's not the way it's supposed to be working in the very near future. NSI is not going to be the monopoly. But that's the way it is working because they still run the root servers. That's changing. That is changing. It's not. We can have this discussion some other time. There are all kinds of websites that are dedicated. I'm sure our listeners can call in and advise you on how this is moving. The point is NSI is not going to be a monopoly for very much longer, hopefully. A couple more pieces of mail here. You've got to be kidding me. Your lack of any foresight in assigning passwords has turned a potentially useful system into a potentially large problem. Here's the funny thing. Somebody actually replied to the guy that said, God, you guys suck. Nice default passwords. Keep in mind he replied as webmaster. Hi there. That ain't the half of it. Why don't you be webmaster? And gave out the URL so he could just log in as webmaster. Here's a piece of mail entitled, You boneheads. Thanks for nothing. You create an email account in my name without my consent and assign it a password that is incredibly easy to hack. What have you been inhaling? I have no intention of using this service. I configured my password simply to protect myself. Furthermore, when my domains expire, I'll be sure to re-register them with another service. You morons. And one final piece of mail. How stupid can you be? First off, what right does Network Solutions have spamming my mailbox with your web-based mail service? Just because I have to use your monopolistic service to register domains does not give you the right to spam my work email account. Second, is there cow manure in place of brains in your head? How dare you send out a clear text password that affects my domains and email. What Mickey Mouse security course did you take? I will be writing my congressman and senator to ensure that Network Solutions loses all ability to manage domain names. This behavior is the absolute worst and should not be rewarded. Sincerely, yours, a very disgruntled domain owner. Won't happen. That doesn't give you a sense as to some of the feeling out there. And also, it raises a couple of very important issues. Now, the people that got in, including us, people that figured out ways of getting into the system and manipulating and becoming other people, who caused the damage here? Is it us or is it them? Should we be going to prison now for doing this? I mean, is this not what hackers do? They find security holes and they publicize them. And, of course, the mass media ignores them. The mass media instead prints stories about the latest hacker gang and what kind of threat it is to international security. That's all they're interested in. They're interested in portraying hackers as evil people that are potential threats. But whenever hackers come around and say, look at this, this is wide open, there is no excuse for this. You see the public. The public pretty much has the same stance. They are saying, hey, this is extremely bad and stupid and it's your fault. No, the public is too busy trying to follow who won last night's boxing match. Well, the public I quoted here seem pretty awake. They're not public. Well, they seem like the public to me. They're administrators. That's why they got the email. Isaac, I got news for you. Administrators are part of the public. All right? I mean, you know, maybe, yeah, the people that you're talking about, we're not reaching them, but, you know, maybe they don't care in the first place. I'm talking about people. Right, which is why the mainstream media isn't reporting it. I'm talking about people that use the Internet. I'm talking about the Internet media. I'm talking about people who have webpages, you know, organizations that have webpages, such as Wired, such as CNN, people that are online that have plenty of stories about the Internet. So their audience already is into the Internet. So I think they're doing them a disservice by ignoring stories like this. Anyway, it's more or less fixed and we'll just see if they ever say anything. I mean, I think they owe a big apology to all the users, but I doubt we're going to get anything like that. Well, they'll probably offer us another account for, you know, our trouble. Unbelievable. This person, I actually found this piece of mail earlier in the Microsoft mailbox on .com. Now it was sent out to abuse at Microsoft.com. This is being sent from NSI's free email service. I have no idea who or how this got here. I got here by following a link on a random webpage. It wasn't us this time. You might want to consider sending a cease and desist order to NSI. They appear to be using Microsoft's registered trademark in the email address on this account. That'll cause all kinds of confusion and problems down there in Washington. Yeah, so a lot of fun. A lot of fun on the Net this week. So I'm curious what people's reaction to that is and I'm also curious if that link on our webpage actually worked and got people logged in as a mystery account. All right, you thought that was fun. You thought that was interesting. That's nothing. That's nothing compared to what we're about to do. What are we about to do? Well, I'm about to find a piece of paper I wrote the information down on. This is actually something that I did on the way over here. While I was driving, I was experimenting with this. So this is a telephone service. You know, I really dislike people like you. What do you mean? Who are like on the phone while they're driving. Oh, well. Yeah, some cop gave me the finger too. It's like there's a lot of people out there that don't seem to like people talking on phones. I don't just talk on phones. I send email. I read the news. Do some web browsing. You're supposed to be driving. Yeah, I know, I know. But, you know, it just gets so boring when, you know, everybody's driving in a straight line. There's no real maniacs on the road. Okay, this is so big, folks, and we're going to not give out the phone number to this. That's how big it is, all right? Ordinarily, we give out phone numbers, but this is something that actually affects people in a very, very bad way. And what I hope happens, I hope that the people listening contact the mass media. I hope the mass media listening remembers that they are the mass media and follows up on this and gets it fixed and looks around to other places and see if this kind of thing is happening there, too. No doubt it is. This kind of thing happens all the time. What is this kind of thing? Oh, boy. What do you think the absolute worst thing out there could be? Well, can you launch nuclear missiles from touch tones? All right, no, we're not launching nuclear missiles. But Kevin can. How about, yeah, well, Kevin's in prison, so. How about you as an individual? What would be the one thing you do not want to get out about you? I would say my social security number. That's kids' stuff, Isaac. Your social security number is on the bathroom wall down the hall. No, I'm talking about... What? After the show. I'm talking about, you know, much more information. Much more information? Point to something that you would not want getting out that anybody could listen to. Uh, hmm. My private voicemail? Perhaps my medical records? My credit rating. Very good. My medical records. Very good. Now, let's get a dial tone here. You're going to use me as an example, aren't you? No, actually, I'm not going to use you as an example because, um, well, this is not about individual people. This is about random people, really. This is about random people? Yeah. Again, we're not giving out the phone number, but we are giving out how we got the information afterwards. Listen carefully. It did work before. I guarantee it did. I don't know what's, uh, maybe all our numbers didn't go through. Is it a criminal record? Well, it's kind of hard when, uh, when you can't hear the digits, so maybe one of them didn't go through. All right, I'm going to hang up and try again. Let's get a dial tone. Okay. While you're doing that, I'll still try and figure out what the heck it is. Yeah, you keep pondering that. Hmm. My shoe size? All right, hopefully this one went through. Welcome. You have reached the St. Joseph Mercy Hospital digital dictating system. Please enter your identification number followed by the pound key. The pound key is located in the lower right-hand corner of your telephone keypad. We know where it is. We know where it is. Any four digits, folks. Those are my favorite four digits. Dictation service. Press one to dictate, two to listen, three for open reports. Let's listen. Press three to listen by patient medical record number. Sounds good to me. Enter the patient's seven-digit medical record number followed by the pound key. Okay, we're just going to enter random digits. And it's a good thing to know that there are seven digits. That's a bit of helpful information. Do you hear that beeping? Yes, I do. I'm not sure what the beeping is. Are we recording now? I don't think so. I hope not. Okay, I'm going to enter those numbers again. I had to do this before, too. Enter work type followed by the pound key. Work type one, discharge summary or expiration date. Enter work type followed by the pound key. Work type one, discharge summary or expiration date. Work type one, discharge summary or expiration summary. Work type two, H&P. Work type three, OR. Work type four, consultation. Work type five, admit notes. Work type six, OB delivery. Work type eight, cardiac cath. Work type nine, echo. Work type 10, exercise stress test. Work type 11, holters. Work type 12, EEG. Work type 14, stress thallium. Work type 15, diagnostic psych summary. Work type 16, pulmonary exercise test. Work type 17, PME. Work type 18, clinic dictation. Work type 19, stat discharge summary. Work type 20, staff clinic discharge. Okay, we're going to enter five. This is not making me very comfortable. All of this accessible without a password. This goes on for about ten minutes. All kinds of information. And this is only one of the choices. This is just the admittance information. You get psychiatric reports. You can get anything on anybody in this particular hospital. This is a big deal, folks. This is your private information out there for anybody to see. Toll-free phone numbers, no passwords. Extremely easy to access. Let's see this on the front page of some newspapers. And remember, hackers didn't do this. This is out there. You hear all kinds of funny things with the doctors fumbling for notes. Yeah, and that's only one. You know, I guessed this number, seven-digit number. I just guessed it off the top of my head. And no password, actually, just a four-digit number. Any number works. All right, enough of that. It shakes me up to hear things like that. You know, that's major personal information, right? Personal information right there for anybody to hear at any time. That's not good. It's not good at all, and it's not atypical. That's the thing that a lot of people don't seem to realize is that this kind of thing happens all the time. And you might throw people in prison for finding it, for exposing it, for using it, but they're not the ones that did it. They're not the ones that made it. They're not the ones that took your personal information and hung it out on a clothesline for everybody to see. All right, let's take some phone calls. 212-209-2900. Like I said, it's been a fun week. It's kind of good to do something like this and wake people up. I hope we're waking people up. I'm still trying to process this at the moment. Yeah, you're in shock. You're in shock. I imagine a lot of our listeners are too. 212-209-2900. Good evening. You're on the air. Yes, hi, Emanuel. Great to know. How are you doing? Thank you. I just want to ask you, isn't there a place where you can access a specific individual's medical record rather easily, something called Dig Dirt I once read about, a service that will get you just about any information? You can get credit records on somebody. You can get their medical records, which are all in computerized data banks if you use an HMO. I have a buddy who works on Wall Street doing counseling there for mostly substance abusers. Well, I'll tell you, if you know something like that, I think the best thing you could possibly do is make it public. Tell everybody exactly how it works. And the only reason we didn't give out that 800 number is because it's really private information here, and we want to give them at least a chance to get it fixed. This can only hurt people. Now, of course, the way you did this, of course, was random. If you wanted a specific individual, it would be kind of hard to do. No, it would not be hard at all. I bet I could call the hospital and find out somebody's patient number very easily. That's true. It's not hard. But I'm just saying, this guy I know works on Wall Street, the reason they hide him is because they don't want anybody using an HMO because then it goes on a computerized database. This way it stays strictly in-house. So if you're a rich drug addict on Wall Street, you have privacy because you're treated by their own in-house private drink. But, of course, if you're an average schtuck who has regular ordinary medical insurance, which most of us have, then you're at the whims of the computerized goldfish bowl, which is pretty scary, what you just showed us today. Right. A lot of people try to avoid computers for just that reason. But as you can see, this has nothing to do with computers. Even if this person walked in and paid cash, they'd still be on that stupid dictation system. Yeah, that is an outrage. It's so accessible to just about almost anybody who knows the 800 number just dialed it in and makes up some randomized code, you know, and picks up somebody's record at random. That is pretty frightening. But that's the way it is today. Basically, isn't everything pretty much out there? A good hacker can pretty much get access to them. Explain to me why it's necessary to have this confidential information available on an 800 number that can be reached nationwide by anybody without any password. That's a good question. That's a very good question. But that seems to be the trend in recent years, that we are living in a goldfish bowl, and they have satellites that track all the faxes, email. Do they also have phone calls? Are all those also supposedly recorded by the satellite? Because I heard about it. I forget the name of it, but it will. All of this is available to government. They actually track email. And they have code words plugged in. If the computer picks up some kind of a code word, then they'll scrutinize it more closely. Obviously, they can't read every fax and email that goes through. Isaac, tell us about Echelon, the word you're muttering there. I'm just trying to whisper it into the mic because it sounds very kind of cosmic. Okay, well, tell us about it, Echelon. It's a national security agency project which basically parses through digital data, looking for keywords, and flags them for later analysis. There was some big scandal recently, wasn't there, in the last couple of weeks involving nations admitting that it was being used? New Zealand was publicly admitting that they were a collection. New Zealand's a real troublemaker. Yeah, you know, they're New Zealanders. Are there any people listening from New Zealand? Please shoot us off an email if you are because your country's kind of cool. All right, thanks for the call. Can I just ask one quick question? Yes, very quickly. Does that satellite also track landline phone calls? It's not a satellite. Well, the different collection that they use are base stations that listen to satellite-routed calls. They pick stuff straight out of the air, so far as microwave relays, stuff like that, not to mention taps on transatlantic cables and things of that nature. So it sounds like the Stasi in East Germany, they were doing that. Except this is efficient. Well, I don't know. The Stasi did have mayonnaise jars with everyone's smell, which was kind of inspiring. On the History Channel, how they showed the Stasi, they kept people's scents in case they needed to be tracked by dogs. You both watch the same program, obviously, but that is kind of interesting. It's amazing. It's the ultimate spy state. Well, the difference is that the NSA isn't supposed to be doing this to the people of the United States. They're only supposed to be doing it so far as extra-national communications. Please notice the word I used twice or three times, supposed. Right. It's the decade of abuse of authority, actually. Maybe it's a century of that. All right, let's take another phone call. 212-209-2900. Good evening. You're on the air. Yes, Emmanuel. Are you talking about lack of security? Is that our phone ringing? Yeah, that is our phone ringing in the background. Hang up the other lines. All right, hold on. I've got to put it on hold. Hold on. No, you've got to put it on hang up. All right. Well, that's where you're going next. All right. And, you know, maybe it's a good idea to move the phone away from the radio. Or turn down your radio. Yeah, Emmanuel? Yes. Now, talk about lack of security. All the lights just went out on the switchboard phone, so everybody can call in now. I was trying to make a delivery in a building today, and, you know, I did not have the apartment number. You know why? It sounds like our phone is still ringing there. Hold on for a minute. Hold on. Can we, like, not listen to feedback? All right. You've got one more chance. This is your last chance. Okay. Do you know why the building didn't have a name? Why what building didn't have a name? Why the apartment didn't have a name? Because they said it's for security reasons. In other words, the building does not have names on the directory. There's no directory for security reasons. So I cannot find this name to find out who it belonged to, what apartment. Tell us where this apartment building is, because I'm sure a lot of people will want to move in knowing that you can't find them. The exact address, because I don't have it. But you have security like that. That is a lack of security. I think that's a lack of convenience. I mean, why would that be a lack of security? If given the choice, I will take security over convenience any day. Over what? Over convenience any day. I, in fact, removed myself from my apartment building's directory. Why, though? How could somebody find you to deliver to? If they have to find me, I will give them the information they need. Yeah, like wave a sheet out the window or something. No, I will tell them that I am in apartment XYZ. Yeah, I mean, if somebody wants you to deliver to their apartment, why won't they tell you their apartment number? Well, it happened to be a clerical error, but anyway. Well, it's a lack of security. AT&T puts third-number calls through because it's convenient. It was just foolish, I tend to think. We're returning to a theme of the third-party numbers. Anyway, thanks for the call. We're going to move on over here. Good evening. You're on the air. Hi, good evening, Adam. Just a quick thing. If you're worried about New Zealand, don't worry about it. They're going to be the first country to go when Y2K crashes everything. Oh, that's true. They're next off the dateline. That's right. Actually, in all seriousness, a lot of folk are watching what's going to happen there just in case, you know, for early warning stuff and so on. Anyway, just what I'd like to know. Well, we just have 24 hours to deal with it. It's not like we have very much time. Then, of course, you have, like, Japan, who's got to start having heart attacks immediately. Yeah, that's going to be fun. Right. But in all seriousness, you read Risk's Digest, you may remember a few years ago with the February 29th issue, the iron smelter, the iron plant over in New Zealand, which came to a crashing halt December 31st. Yes. And there were a whole bunch of other foundries that used similar software. And, yes, the one in New Zealand crumpled, but the others got a little bit of warning. Interesting. All right. We'll be monitoring that situation as the year draws to a close. Good evening. You're on the air. Hi, Emanuel. Oh, please. What is the problem? Is it not enough to do outside? Good evening. You're on the air. Hello. Yes, go ahead. Hey, who's this? Hey, Emanuel. Hey, Paul Guerin here from Namespace. How are you? How are you? Okay, not bad. Yeah, we heard some interesting news, courtesy of your website yesterday, about the dot-come-on-in mail, as we like to call it. I like that. That's good. And we're actually very happy because I can't really give you details now, but next week we're about to release what we like to think is the most robust web-based email security out there. And we'll invite you guys to give it a, like, bang on the doors and see how you like it. Okay, well. We definitely won't be giving out clear-text passwords or, you know, very easily guessable ones, that's for sure. Uh-huh. Well, we're happy to do that. I'll always, you know, kick in some doors and see if we can. Yeah, I'll drop you a line. It's pretty good, and that's a little hint about what we're doing. And other things. Just a comment about something coming up this weekend. I don't know if you folks are aware, but the CPSR, the Computer Professionals for Social Responsibility, is holding a conference down in the heart of Spook Alley, Alexandria, Virginia, basically talking about the transition of the domain system and the ICANN situation and things like that. It'll be a two-day panel. People should take a look at the cpsr.org website for more information about that. And especially the issue of new top-level domains is on the agenda and how that will bring true market competition. What is the deal with the new top-level domains? I've been hearing things about them now for two years, and no one seems to know when they're going to be implemented. Well, you know, for folks who are not familiar with namespace, we're one of the foremost pioneers of actually creating and implementing new top-level domains and putting forth what we consider to be a very fair model of non-proprietary TLDs that are shared and based on what's called a decentralized root. Now, with the situation with Network Solutions Monopoly, they're the sole control of the root of the Internet, which has to do with which domain names, top-level domains, like countries like UK for Britain, et cetera, are recognized by the whole net. What domains are recognized are determined by a simple text file called the root zone file. So far, under government contract, Network Solutions has had the exclusive control over that file, actually makes the updates to that file. The Commerce Department has given this corporation ICANN, stands for the Internet Corporation for Assigned Names and Numbers, their blessing to assume private control of the root in 2002. Part of the charter of ICANN is to sanction or find a way to create new top-level domains, for example, like .mag, like 2600.mag, for example, or .media or .art, for example. And so far, there has been very little movement on this because basically Network Solutions sought to brand .com as the definitive domain for the Internet. And as well, there's been a heavy effort on the part of intellectual property interests who want to prevent any new top-level domains because they believe it will open the door to trademark infringement and what they call cyber-squatting, things like that. Well, they'd have to register their name on every top-level domain there is then. Well, not necessarily. Microsoft.mag, for instance. Well, if there was such a thing, you know, but also what would stop somebody from registering Microsoft.sucks, which is also protected by the First Amendment, you know, as a parody? You know, the .sucks domain would have a hell of a lot of takers. I think so. Actually, you know, the way we actually generated the TLDs that we service, which, by the way, are accessible if individual users change their control panel settings to our DNS. So if you want to go to namespace.org slash switch, there's simple instructions for virtually every operating system. And for those people who use Windows, they go to namespace.org slash software, and we have a very easy-to-use GUI application that will switch. But regarding a - so anyway, the way we arrived at new top-level domains is we took suggestions from people basically for the last several years. We had thousands of email requests, and we moderated what we actually activated. And we have around 528 new TLDs. So if you go to the website vote.global-namespace.net, you'll see a list of the new top-level domains ranked in the order of their popularity. So basically nobody has recommended sucks. So if anybody out there wants to recommend the TLD sucks, just go to vote.global-namespace.net and search for sucks in the search form. And since it's not available, it will return a requested TLD form. Simply send that in, and we'll run it by our secret-behind-closed-doors review committee. That's a joke. And we'll probably activate it. Cool. So we have a free one-year trial. If anybody wants to try registering under the new TLDs with namespace, they can do that. The waiver code, the waiver is NoPayToday, capital N, capital P, capital T. And it only allows people to do it once. So that's why this password is not a secret. And if people want to support our cause, it's $30 for a year. And with that, you get a free virtual host that runs under your namespace. So if you were like 2600.mag, for example, which I believe we assigned for you as a courtesy a while back, you will also be resolved under one of our other domains, the xs2.net domain, as 2600.mag.xs2.net, provided we do your DNS. If you do your own DNS, you can piggyback it on whatever you want. Okay. Let's move on. But just give us your website one more time for people who might be interested. Okay. That would be namespace.org. And go to slash software or slash switch to learn how to switch to the new TLDs or slash free to get the free offer. Okay. Hey, talk to you soon. Best of luck, and we'll check in to that. And thanks for uncovering that. That was the best PR that could have happened for NSI that they couldn't have paid for. Oh, yeah. I'm sure they're cursing our names even as we speak. Thanks for calling. Let's take another phone call. Let's go all the way over here this time. Good evening. You're on the air. Oh, yeah. I have a gripe with Bell Atlantic as far as - let me just turn down my radio. As far as the - under the old NYNEX system, the recording would come on at the end when your time was expired and say something like, what, put in additional coins for the next whatever, right? Right. And you could put in as little as a nickel, and you'd get a nickel's worth of credit. If you put in a quarter, the recording registered that and gave you extra credit. Under certain circumstances, yes. Under all circumstances that I have ever used the phone. No, no, not on a local call. That will not happen on a local call. That only happens when the actual - what we call the AXE ACTS operator comes on and says, but if you call something that's in your local zone that only requires a quarter or 35 cents, putting in extra money will never be credited as more than a nickel. It will never be credited now since Bell Atlantic took over. Right. That's not a Bell Atlantic thing. That's always been the case. I've been griping about this for years. It's one of the many ways- It couldn't have been the case. I mean, distinctly - well, okay. What you're saying is that that's not the case and- Well, you can test it. This is only happening on local calls, right? It doesn't happen, say, if you call - where are you located? In Manhattan. In Manhattan. If you call, say, 516, that will not happen, I guarantee it, and that's still Bell Atlantic. You see, it only happens on calls 2212 or 2718 because they only require a quarter. That's always been one of the biggest scams that the phone companies have going, and you'll find that works everywhere, not just here. Okay. Or it doesn't work. Are you saying that if I call 516- Right. - and the recording comes on, put in an additional quarter for the next three minutes - Yeah, you'll get the recording saying the specific amount you have to deposit for a specific amount of time. Please deposit $0.15 for the next one minute. Right, but if you call locally, you'll just get - if you don't put the money in, you'll get a recording saying the call you have made requires a $0.25 deposit, or it won't say anything if you put the money in. No, you're mistaken. Okay. What does it tell you? It says you have to put in another - I forget the amount - $0.05 for the next minute or so. No, that's after you've connected. I'm saying before you make the connection. No, yes. I'm talking about after I've connected. Under the 9X system, when you were on the phone, you were talking for X amount of time, recording would come on and say you have to put in $0.05 for the next minute or whatever the case is. Or your call will be terminated, right? Or your call will be terminated. Right. That is the local threat. The other threat says you have to put in this amount of money. Just bear with me one second. I want to make it very clear. Under the NYNEX - that was the NYNEX system. Or your call will be terminated. When Bell Atlantic bought 9X, they did not put in any new hardware. Right. It's the same system, different name. Well, then how do you account for the fact that when I put a quarter in, I got extra time? Because you were making a long-distance call. No, wrong. Well, this has always been the case. We can debate this for hours, but the fact is we've been griping about this for years, that when you put a quarter in on a local call as extra time, it's only credited as a nickel. And that's always been the case. It's something I'd really like to see change. It may have changed, but it just wasn't because 9X was bought by Bell Atlantic. Well, if it changed, it had to change for the better, not for the worse, because it already was the worst. But anyway, let's move on to another phone call. Good evening. You're on the air. Hi. One thing about the echelon, if anybody wants to read about that thoroughly, the COVID action quarterly, winter 96, 97, the whole thing on the NSA and surveillance and echelon, it's all in there. So it's been around for a while. Yep. Last week you gave out a number, a 700 number, to find out who our regional caller was. Yes, 700 plus four digits really will work anywhere. Right, but the line says 9X. That's interesting. Now, I saw that on a pay phone once. That actually happened on a pay phone. They didn't change the recording or something. I remember you saying that on the subway. So that's interesting that you live in an area where that's the case. Yeah. Now, I wanted to ask you about the call that you made that you said you were going to give the number. I understand why you're not giving the number, but can you give a little more information so that we can effectively contact the right people to stop it? Well, it did say the name of the hospital at the beginning. Oh. Did anybody catch it? St. Joseph something? But I don't even know where it is. I'm hoping that they'll find out about it by tomorrow morning and change it. Yeah, it would be rather inspiring to pick up a copy of the Times. But you know what? To make you happy, I'll call it right now, and you can hear the name again, and that might give a little more specific information, and then maybe somebody can do something about this. Okay. And you think that this is effective in not just this hospital? Oh, I know things like this happen all the time. Yeah. So it's a question of finding the phone number and, you know, figuring out a minimal amount of stuff to get the system to work. Okay, let's give that number one more call. Dial tone. Okay. And hopefully this will work the first time. I don't want to spend a lot of time dialing numbers here. And we're just going to hear the name of the place so people know who to report to, whoever the authorities may be. Dial tone. Welcome. You have reached the St. Joseph Mercy Hospital digital dictating system. Okay, St. Joseph Mercy Hospital. All right. So let's show them some mercy and get this fixed. I'm waiting for my county to get the same system so they can just randomly read off people's criminal records. I'm sure these systems exist all over the place. Two. Driving. It's really silly. Yeah, did you see the message? Good evening. You're on the air. Hello? Yes, go ahead. Yes, I have a question about the security codes and an idea. Now, a password would be, say it's five strokes that you would enter into your machine. Probably more, but let's just say it's five. They could be letters or numbers, correct? I'm not sure what you're referring to. What system? To make a password. On where? For anything, say. Well, it's different for all kinds of different systems. Are we talking about a computer system here? Right, right, like with this, you know, Parado that you were just talking about. Okay. Now, is it possible technically to not just have letters and numbers but to interject through some sort of a timing device, a space, say like five seconds or like 20 seconds before entering another part of the password? There are systems which monitor the speed and the technique of the person typing whatever passphrase so as to verify that it is the right person. Right. What I'm saying is like say it's A, B, C, D, E. If it's A, B, C, and then after the third entry, you have to wait like say half a minute and then enter. The amount of resources that would be required to keep track of something like that would not make it worth it where you could just simply put in extra characters, make the entire thing case sensitive, you know, add a bang or a tilde or like a character. That's not to say it can't be done. It's just, you know, you're not able to find it on CompuServe or anything like that. No, it's not worth it. You could certainly design something like this. You won't have very many users, but you could definitely do it. I mean, would that be harder for somebody to get into? I mean, not that you guys would want to. Yeah, it would be a lot harder to get into because first off, the only place you could implement that would be at the console of the machine because network latency would screw up that entire timing thing very well. Well, then you wouldn't be able to log in from anywhere but the console, right? Exactly. Okay. You could still sniff the password perhaps if it went out over a net and maybe guess it somehow. Well, what I mean is like say you had to wait 20 seconds and then within a 10-second period following that 20 seconds, then enter the rest of the numbers. It's doable, but it's not exactly practical. It's that convenience versus security thing again. Except this time I think he's coming out on the side of convenience. I mean, but this would be for a more secure system if such a thing were possible. Well, you don't even have to use passwords as authentication. Yeah, retinal scans and fingerprints. Well, biometrics is its own ball of wax. Yeah. Yes, I've seen systems where you type a long passphrase and it will measure the amount of latency between keystrokes where it can identify the individual. All right. Thanks for the call. Thanks for the ideas and suggestions. If you have any feedback or ideas or suggestions or demands or whatever it is you want to send to us, our email address is oth at 2600.com. We look forward to hearing some feedback, and I know I'm going to be checking cnn.com and seeing if they do anything with this story. I think Rebel gave us enough feedback. Oh, boy. I'll be back again next week with another exciting show. Who knows what we'll uncover by then. Of course, if you have something to uncover, mail it to us. See you next week. Good night. The telephone keeps ringing So I ripped it off the wall I cut myself while shaving Now I can't make a call It couldn't get much worse But if they could, they would For Billy Bond, for the best, expect the worst I hope that's understood By Billy Bond