Dear listeners, this is Indra Hardat, Interim General Manager of WBAI, asking for your support as we begin our Fall Fund Drive, which runs from Wednesday, October 4th through Saturday, October 28th. The goal for this drive is $900,000. We are counting on you during the entire drive to help us take telephone pledges, especially between the hours of 7 a.m. and 12 noon. Please remember, we can only keep WBAI the strong, compelling, provocative, and uncensored radio that you are accustomed to with your help. So please spread the word around, and thank you for your continued support. And you're listening to radio station W, sorry about that, WBAI New York, where the time is 7 o'clock on a Wednesday night. Time once again for Off the Hook. And you're listening to radio station W, sorry about that, WBAI New York, where the time is 7 o'clock on a Wednesday night. And very good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you on this Wednesday evening. And it's actually the first of two fundraiser shows we're going to be doing during this football marathon that we have here at the radio station, which just began today. And I must say, I'm a little disappointed by the numbers so far. We're at zero. Well, I guess, in all fairness, Mike, we didn't ask anybody to call yet, did we? I thought I turned your mic on, but go ahead. Should we just give the number right now for people who already know how wonderful things are? Yes. If you know that you just want to give us lots of money and keep the station going, keep the show going, then the number to call is 212-209-2950. We've also given that number out over the internet so that those of you who listen to the show in some sort of delay, days or even weeks from now, can call during this time slot and pledge your support to the program. And the tally people at the other end will be happy to help you pick out the pledge level because we have all sorts of different items to give away. We'll be getting into that in just a little bit. But first, let's introduce people tonight. As pre-mentioned, we have Mike over there. Hello. And it looks like Redbird over in the distance. Good evening. And Lynn, is that you over here from Atlanta, right? Yes, I'm here. You came all the way up for the marathon. If we can have that kind of commitment from our listeners, then I think we'll be in pretty good shape. And of course, Jim, you're here as well. Yes, I am. And we have a bunch of our usual staff people down in the tally room as well helping out. Of course, we can always use more help. And Bernie. Bernie joins us from Philadelphia on the telephone. Tally of one. What does that mean? Tally of one? Well, I'll be pledging later. Oh, you will be. See, that's the thing that's really so cool is that a lot of our people here on the show pledge. So we really believe in this as well. So people know none of us get paid for this. It's all volunteer. And we spend lots of time getting the show together. And hopefully, you get something out of it as well. That's what our main goal is in doing this show. We've been doing it in some form since 1988 as a regular series since, I believe, 1992. And hopefully, we'll be able to do it for many years to come. Let's look at a couple of pieces of news and then we'll go to some special guests that we have. How about this? And Jim, this might be of interest to you because it concerns the MTA, your former employer, the people who drive the subways and buses around the city of New York. Do you know that they're getting ready to test a laser system designed to detect trespassers in subway tunnels? I have a strange sense of deja vu. Didn't we mention this? Did we talk about this? You know, I guess you're right. But still, isn't it interesting? It's fascinating. It's so interesting we should talk about it twice. But yeah, OK, we did talk about this last week, I think. They're going to detect trespassers by shooting laser beams or something like that. Right. And the nice thing is that this is not only detection but suppression. All right, well, yeah. And also, another piece of news, which I don't think we talked about, is that the screaming cell phones, apparently in the United Kingdom, this company is hoping a cell phone security system will set off a high-pitched scream, which alerts people that this is in fact a stolen phone or a lost phone. And it halts, I guess it erases all the data on the phone. It's called remote XT technology. It's designed to make phones unusable. Can you imagine that? You invent technology just to make phones unusable and therefore worthless if they're stolen. It works by installing software onto the operating system of the phone, which is then activated via a call to a call center once users realize their phone has been snatched or lost. The phone is then remotely disabled and all the data held in the device is wiped and a high-pitched screech is triggered. You know, if it makes the phone unusable, what's the point of the screech at that point unless you're trying to get it back? Yeah, you could either try to get it back or at least have the guy arrested. Go to any of the major networks and look for this story. They will certainly have a clip. The sound is absolutely unbelievable. It is worth listening to. Oh, they have the sound. You haven't found this? No. I figured you'd have a clip. I was looking for it. I saw this a couple nights ago overnight on just about every channel, different story. Do you think you can go to the computer here and find it on the website? I might. I'll try. Okay. Jim's going to go over and try to find that. But yeah, they describe it this way. We set a small bomb off, if you like, that completely wipes the data. If it has genuinely been stolen, then it renders the phone useless to the thief and it makes a loud squealing noise, which is enough to distract a restaurant if it went off and it completely locks the phone. I can just imagine the fun we're going to have with this technology once we start playing with it. Well, one of the things that the cell phone companies, the providers, claim is that once you report a phone as stolen and depending on whatever protocol they use, like if they disable the IMEI of the phone, their claim is that they can- Disable the what? Disable the IMEI. It's a unique identifier for the phone. Okay. And different protocols use different identifiers and whatnot. But their claim is that once they disable it, or for the most part, the provider's claim is that once they disable it, they'll never be able to enable it again on their network once it propagates in the IMEI. Well, then what's the point? Well, that's what I'm worried about with this technology. How quick should you be to report your phone as stolen? Because there's a lot of instances where people have lost phones and the person who has found it calls the number marked home or calls a friend or something and asks whose phone it is. Well, and also, apparently what happens is the noise keeps continuing until you take the phone's battery out, but it starts again as soon as you put it back in. I am replacing the SIM card, has absolutely no effect on this. Emmanuel? Yeah, it's Bernie. So, if you get your phone back because it's screaming and the thief runs away in fear, then you can't even get it reactivated again, according to these carriers. That doesn't make a lot of sense. No, it doesn't. I have a feeling we're missing something in this story. This is just something that I've heard from U.S. carriers when you report your phone as stolen on their networks. They totally disable it on their network and theoretically cannot enable it again. Not theoretically, reportedly cannot. What would be fun is if you reported somebody else's phone stolen that isn't stolen and all of a sudden their phone starts screaming at them and they can't stop it. Yeah, you see, every bit of technology has the evil side and that's what we're here to reveal to people, how it can be misused. Emmanuel? Yes, Bernie. This is actually not a new technology. For probably over 10 years, law enforcement has been using a variation of this called OTAR, which is an acronym for Over-the-Air Reprogramming, on a lot of their handheld radios, particularly sensitive handheld 2-way radios like the Secret Service and FBI and DEA use, State Department, that sort of thing. All those 2-way radios, walkie-talkies, have special, unique identifiers in them and should one become lost or stolen, the system can deactivate the radio remotely using over-the-air reprogramming. They can also reprogram encryption keys on the phones remotely, that sort of thing for key distribution. But it's not a new technology, it's just new that it's being applied to consumer cell phones and we'll see how well they implement it. It's also interesting how, when a story does show up in the mass media, that all of a sudden it becomes news when, as you say, it's old technology, has been around in some form, and I guess the application might be a little bit different, but is this really something that is that big a story? I don't know. We'll find out when the phones start to scream. Jim, any luck? You've been Googling now for a few minutes. Not yet, no. The problem is that they don't take a lot of entries. Okay. If somebody else finds it, I think they should let us know, Errol. Well, why do you keep looking? It's not good to give up. It's not good to give up. We encourage people to keep trying. Could Jim simulate this sound? No, let's not ask that. Here's a letter, though. You can send us your email, questions, and comments by emailing oth at 2600.com. This is cell phone related from Bob. During a recent Off the Hook, you mentioned cell phone privacy and how the phone does not have to be making a call to reveal its location. On most of the Verizon cell phones I have access to, there is an undocumented menu option that gives access to some privacy settings. The basic menu options are 1 to 6, but if you enter 0, it prompts for a service code. If you enter all 0s, enter all 0s when it prompts for the service code, a new series of menus is revealed, a new secret list of options. Under the GPS menu, there is a privacy option with options of none, which is how they were set initially, medium, or high. I have no way of knowing if this has any effect or not. I've gotten into that menu a few times on different phones, and you're right, it is all 0s. I don't know if it has an effect. Redbird, you're shaking your head. It has no effect on their ability to track you using other methods like triangulation and reports from the cell phone towers that your phone is associated with. No, it doesn't disable that, but does it disable GPS? It may disable GPS, I don't know. But that still has no bearing on whether or not they're able to track you when your cell phone's on. Okay, well, again, Verizon phones go to the secret menu by hitting all 0s and play around. But you can do bad things to your phone if you're not careful, so just make sure it goes back the way you had it set. One thing you can change, I know this is kind of fun, you can change your screen to read the strength of the transmitter that you're currently using, and I think some other information local to your phone. Okay, Jim, any luck? No? Okay, we're going to move on. We're going to move on. We have some interesting things to discuss tonight as far as fundraising issues. We have several guests here to talk about various things that they're offering us today. With us on the phone, live from Hong Kong, the author of the book Hacking the Cable Modem, What Cable Companies Don't Want You to Know. Dear Engel, are you with us? Yes, I am. And you're in Hong Kong right now, correct? That's correct. Okay, we're sorry for calling you this early in the morning. It must be, what, about 7 in the morning there now? It's about 7, 15 a.m. You're exactly 12 hours ahead of us. So, yeah, it's Thursday morning where you are. Well, now you put out this book, which appears on No Storage Press, about hacking cable modems. First of all, what can you really do as far as hacking your cable modem? Are we talking about getting free internet access here or increased speeds? What kinds of things can we think about? Well, it's really a broad subject because kind of similar with cell phones, after a service provider gets a hold of the technology, after they have it integrated into their customers, after a while you see them start removing features and then selling it back to the customers to make more money. That is essentially what hacking the cable modem is about. It's about removing the restrictions and limitations that have been put on the cable modem since its original implementation. So what are some of those restrictions that we'd want to bypass? Well, there's a lot of... The most popular ones are the bandwidth restrictions and a lot of users who maybe have had broadband cable internet for maybe seven years will tell you that when they first installed them, the modems were just smoking fast. And that's because the service providers never restricted the upload or download speeds of them. But now almost every service provider in the U.S. does this. Okay, so now when you say it was smoking fast when you first hooked it up, what speed reduction are we talking about over time? Well, I remember it when at-home was big in the U.S. I remember speeds of 10 megabits down and up on their service. And I think Roadrunner, when they first... When Time Warner first had Roadrunner everywhere, it was also just, you know, 1 meg file transfers, you know, without any latency. Uh-huh. But now you hardly see those nowadays, especially on Comcast, Adelphia, and so on. Could this be because your next-door neighbor has opened up a porn site or something like that and everybody's going to it? If everyone in your neighborhood has, but possibly not. It's the fact that the service providers want to control their customers. They want to limit them. A popular feature that has been, you know, limited more recently is port filtering on cable modems. Right. The service provider doesn't want you running an FTP server or an HTTP server. Now, why don't they want you doing that? Why is that? Well, one reason that I have got from talking with administrators from various cable companies is that they want their business clients to have access to web servers or FTP servers. So, and those clients, obviously, the accounts to provision are much higher than regular customers. So they don't want regular customers at all having it. And if they call up, they'll try to sell it to them as a business package. And what kind of price difference are we talking about between the business package and the residential package? Well, residential packages vary between $40 to $60, and businesses range from $120 to $200. I see. So if you pay that excessive amount, then do you get any kind of filtering or controls or restrictions? From what I've seen, I've seen some do, but mostly they don't. There'll be no filtering whatsoever. One of the other claims that ISPs make a lot by blocking ports 80 and 21 and whatever and the NetBias ports is that they're protecting their customers from, quote-unquote, getting hacked by people and having them run servers on their machines and accidentally opening file-sharing ports and stuff like that. So that's a claim that they will make to ignorant users as far as why they're doing that. Yes, that's true, and I mention that in my book as well. Especially with port 135, they originally, and may have actually, they originally implemented that filter to block a virus. But a year, two years down the line, they don't remove it. So that's another problem. Now what's interesting for me to learn is that they actually do this filtering in the cable modem that's in your house. They don't do it at their router or anywhere else. It's actually your equipment, and I guess if we read your book, we can find out how to change that? Yeah, correct. It's done through LLC filters, a protocol that's handled by the modem, because basically a cable modem is just a router with bridging to the cable provider. So, you know, they want to have some cable modems not filtered, and they want to have the majority filtered. So that's how they do it. Now tell us something about your book, Hacking the Cable Modem. When did you start to write it? What made you decide that this was an issue that needed to be addressed? Well, originally Bill Pollack from No Search Press, he approached me with the idea, and he talked with me and asked me if I thought there was enough information available to put together a book. And I thought about it, and I realized that there is a lot of information. Maybe not all of it is relevant to hacking cable modems, but I think there's definitely a lot to put together that would make a really nice book that wouldn't just be completely about cable modems, but could also be used towards other devices as well. Because a lot of the methods and procedures are very similar. So I gave him basically back some outlines of what I thought would be a good book, and we went from there. Now, there are 23 chapters in your book. I imagine a lot of people listening now who have cable modems had no idea there were so many different aspects, so many different things to talk about insofar as simply hacking your cable modem. You're talking about how to get a faster internet, what's inside your cable modem, reverse engineering, the security inside the cable modem, buffer overflows, how to change the firmware, hacking something called Webstar, D-Link modems, all sorts of things. There's a lot of information in here. What kind of background do you have as far as playing with cable modems? When did you first encounter one? I think the first cable modem I encountered was LandCity. It was in Phoenix, Arizona. Those were non-DOCSIS back in 1998, I believe, or 1999. It was a long time ago. What does that mean, DOCSIS? DOCSIS is a standard that basically the cable companies all got together and said, we need to make a standard so that modems purchased over here will work on our system and have complete compatibility. That kind of spawned its own little creation there, but before that happened, there were lots of modems that were like, for example, LandCity and CyberSurfer, I believe, was also non-DOCSIS. So a whole bunch of companies from like Motorola and from I think Bay Network owned LandCity, and they had these different modems that were not compatible. So if you purchased a LandCity modem in Phoenix and you went over to somewhere in California, it wouldn't work with the local provider. And that's what DOCSIS, the standard which almost all modems in USA now use. Emmanuel? Yes, Bernie? I have a copy of this book here, which I've got to say, it's almost 300 pages long, and it's not just for people who want to hack their cable modem, even though that's the title, Hacking the Cable Modem, What Cable Companies Don't Want You to Know. The subtitle here is What the Cable Companies Don't Want You to Know. There's a lot of really interesting information here about what companies, corporations can do to hardware that you have connected to their network. And there's a lot of good information in there, just general information about reverse engineering, equipment that you might know. It's really a very interesting book just for people who are curious, just who are hackers at heart, who may not want to physically hack their cable modem, but really want to understand what's going on in that relationship between themselves and their ISP. This is pretty interesting stuff, and I imagine, Dr. Engel, didn't you run into some legal hurdles trying to publish a book like this? I understand the Electronic Frontier Foundation and some other lawyers really had to scrutinize this book and give some suggestions to keep you from being prosecuted. Let me just step in here, though, before you answer that question, because I do want to point out to the listeners that we are offering this book. It's been kindly donated to the radio station, and you can get a copy of it for yourself. Hacking the Cable Modem, What the Cable Companies Do Not Want You to Know by simply calling 212-209-2950. Pledge level is $75 for a copy of this book, which you won't find in very many places, and which is upsetting a lot of the cable companies, no question about that, throughout this country and probably others as well. 212-209-2950. The pledge level is $75 for this book, and with that you also get an exclusive off-the-hook t-shirt, which you can only get by pledging to the radio station. So again, 212-209-2950. Please light up our phones and help us keep this radio show on the air, keep this radio station going. Copies of Hacking the Cable Modem from No Storage Press. Again, 212-209-2950. Now, Durango, if you could answer Bernie's question as far as how, what kinds of legal things were you facing? Well, I think any book that has the word hacking in the title is going to have complications when it comes to legal. Tell me about it. I guess the reason is because the freedom in America is being taken away at a rapid rate, and the First Amendment guarantees freedom of the press. Let me just step in here. We have six calls on the line already, so people really seem to want this. I think you're striking a nerve as far as people's curiosity and hunger for information. 212-209-2950. Get yours before they're gone, because this might happen very soon. So please continue, Durango. And this book is an example of that freedom in action. Because originally I wanted to have the book completely uncensored and just tell all. And by tell all, I basically included everything I thought the average user would need to know in the book. And that includes hardware schematics, software examples, and originally I had actually links to every piece of software you would need in the book. However, after NoStart sent a copy of this to the Electronic Frontier Foundation, who, as you know, they do a lot of legal work with electronic laws and such. So I've heard. They thought a lot of the content was very needed to be done with a light touch, because they felt that having direct links to software, for example, would in a courtroom be considered encouraging someone. What if you just told people keywords to look for on Google or something like that? How they could get this information? Is that considered risky as well? I think anything is risky if you're talking about circumventing security, breaking protocols inside the modem. I think any of that is risky and is also why of how I set the book up. Pretty much 50% of the book is just information-based, where the reader can have a nice time enjoying certain chapters that maybe are not hacking chapters, but then later the book goes into more hardcore hacking chapters as it gets a little dirty within opening up the modem, looking at the firmware, exploring with the code, trying to figure out what's the best way to break the modem, basically. You're telling people how to break the modem, huh? I have broken hundreds of modems. Now, what happens when you break a modem? Doesn't the cable company get a little peeved? Well, you don't want to break their modem. That's why you should always have a couple of spares lying around. And where do you get the spares? You can actually purchase them in Walmart or in any computer store in America. Oh, you can purchase cable modems in Walmart? I didn't know that. I thought you had to get it through the cable company. Well, I learned something. Most cable modems, there are four cable modems you can find at almost any electronics store. Fry's Electronics, CompUSA, S5, they all have them available for sale. Okay, just to remind people again, 212-209-2950 is our phone number. We're down to four calls now. We're offering copies of hacking the cable modem. What the cable companies don't want you to know, we only have 20 copies of these, and the pledge level is $75. So if we keep up this rate, we're going to be out of these pretty soon. So please give us a call. 212-209-2950. You'll also get an off-the-hook t-shirt. And most importantly, you'll be supporting WBAI, keeping this place where it has been since 1960 and hopefully many years into the future where we can talk about things like this. I don't think you could have this kind of conversation on a commercial station Time Warner would probably either own you outright or be taking out sponsor Time. Mass media seems to be pretty much all in one particular corner on items like this. I think we learned that with the net neutrality thing that happened a few weeks ago where basically every commercial you saw on television was telling you how net neutrality was a bad thing and how it was great that it was being defeated because the channels that you would hear this on, or the radio stations you would hear this on, were owned by the mass media companies Time Warner and Viacom and all these people. You're not going to have a conversation like this. You're not going to be able to have someone like Durangle be on the air talking about this book that he wrote and the kind of I guess dismay it might cause in the boardrooms of the big cable companies. Do you think it has caused a lot of problems? Well, I've been publishing papers and software for about five years now on this subject and it has definitely caused problems in the past. I know there's one instance when a cable provider who I won't mention they removed my domain name from their server and people who were trying to email me couldn't email me or come to the website or any of that. And that's an example of basically corporations trying to decide what they think people should listen to or watch or go to. And that's the kind of thing that they do. They erase you from their records. That's their tactics, their way of fighting back. Yes, Bernie. Go ahead, Bernie. I just wanted to say this is a pretty amazing book. It's about 300 pages. It's really kind of down and dirty. I like the writing style you use, Durangle, and there's got to be well over 100 photographs and diagrams of what's inside a cable modem and what makes them tick and why the cable ISPs want to make them tick the way they do tick. That sort of thing. It's really kind of a down and dirty insider's look of what's going on between a cable modem and your carrier. You can just flip through this thing and it's really like a tour of what's inside your cable modem, how it works, how you can make it do what you want to do, and why you would want to do that and why the cable companies wouldn't want you to do that. So I encourage listeners to, if you're a cable modem user, just curious about how a cable modem works and that relationship between the subscriber and the corporation who wants to control what they do, if you're interested in that, please call 212-209-2950. 212-209-2950. This is really worth pledging $75 for. It's a great book. My question is, do you have to have some kind of technical knowledge or background to understand the points that are being raised in this book? No. I mean, it helps if you have a lot of technical knowledge if you want to actually do the hacking of your modem, but a layperson could read this book and get a lot out of it because it talks about the concepts and why a cable company would want to control what you do. Okay. Yeah, there's definitely a lot of chapters that are some are technical, some are not. I think chapters 10 which discuss buffer overflows, that's kind of a hard concept I think for most people to grasp and chapter 21 which discusses a very difficult hack to perform. But other than that, I think every other chapter is very self-explanatory, very useful and can be applied not just to cable modems but to any embedded device. Because the book is very diverse and I believe anyone who is willing to look past the cover will get more out of it than someone who is only interested in hacking cable modems. We have six calls on the line. 212-209-2950 As I said, we only have 20 of these, so Tali, if you can let us know if that gets exhausted, we'll make sure to pass that along. Now, Durango, if you could tell us, when did you actually first write this book? When did it come out? It was first written back in I believe it's early 2005 and it was published in stores I think about September 10th. Just out. It was actually the book was finished actually in December 2005 but there was a lot of editing, a lot of changes made Well, I imagine you probably have to update things quite a bit because cable modems are always changing, right? That's true. A good example of that is when the book was actually published it talked about DOCSIS 1 DOCSIS 2 and briefly talked about DOCSIS 3 Well, by the time it was published, DOCSIS 3 specification had already came out and was officially announced by CableLab So it kind of shows you that the information changes very quickly and very rapidly. I've never seen this kind of reaction so quickly to anything we've offered. We have 9 calls on the line right now, 212-209-2950 So I would caution people if you're thinking about this, you'd better think quickly because they're not going to last very much longer 212-209-2950 a pledge of $75 gets you a copy of the book Hacking the Cable Modem What Cable Companies Don't Want You to Know written by Der Engel who's speaking to us live very early in the morning from Hong Kong and I want to thank you very much for both writing the book donating the book and talking to us on the phone. And of course this book comes from No Storage Press Can you tell us something about that publishing outfit? Yeah, actually I flew to San Francisco to meet with them on 2 different occasions and discuss several layouts of the book That is an awesome company in America and I can't tell people enough how important a company like that is because like you mentioned earlier how big media is controlling the media and controlling citizens without a company like No Storage Press, how could this book ever have existed today? Because it is such a taboo subject and it will offend many people in the cable industry and it just amazes me that there are still good companies in America who still believe in the freedom of free speech Yes, absolutely, and fortunately we have organizations like EFF to advise you and keep you from straying into territory where you might wind up regretting it or getting in trouble with some legal entity Now, so far the book has just come out Have you gotten any kind of fierce backlash of any sort? No, not yet I was expecting some, you know outlash from several cable frauders in America but I haven't actually received any hate mail yet All the reviews that I have read have been very positive and that's about it That's great 212-209-2950 I see a couple of people are calling the on-air line Don't call that line because you won't be able to pledge on that line The phone number is not our usual on-air number, it's 212-209-2950 And again, for a $75 pledge you'll get a copy of Hacking the Cable Modem what cable companies don't want you to know along with an off-the-hook t-shirt an exclusive t-shirt that tells the world that you listen to this particular radio program on this particular radio station Durango, I want to thank you very much for being on No problem Any closing words you'd like to give us? Yes I'd like to say that people should purchase this book for the information and they should purchase it to learn how the cable modem works and to learn hacking techniques that can be applied to other devices as well and not to use it as something to break the law that is something that I have never condoned Theft of Service is a very serious crime in every state in America and this book is just to express freedom of speech and to express hacking in general Gathering knowledge learning about how something works You raise a very good point here Opponents to this always raise the issue what other possible use could you have for knowledge like this except to rip somebody off or get something for nothing but I think an understanding of how the technology works and how perhaps it's being abused by those companies and how we as consumers are being victimized I think that's something we all have the right to know Exactly It is knowledge It is a tool and it should not be used inappropriately Okay Durango Thank you again It's 7.36 in the morning over there in Hong Kong I want to thank you for taking time out from over there to talk with us Best of luck with the book Will you be working on any other volumes, any other topics in the future? I have a couple of side projects that I'm working on but before I start doing anything else I like to get a very strong grasp of the subject and hopefully these projects come out and I will be able to show them to more people Okay again, thanks so much and best of luck Okay, thank you very much for having me on And that was Durango the author of Hacking the Cable Modem What Cable Companies Don't Want You to Know and I don't know if we have any available still We might have gone through that in lightning fast speed but give it a shot 212-209-2950 for a pledge of $75 You may still be able to get a copy of the book Hacking the Cable Modem and an off-the-hook t-shirt and I believe Mike you can just get the off-the-hook t-shirt if that's what you want to If you just want the t-shirt or you maybe can't afford to spend $75 supporting the station we do have just the t-shirt available with your pledge of $25 We also have a membership to WBAI which lets you vote in the famous elections Puts you on all sorts of lists doesn't it FBI, CIA the agencies we don't even know about It's great Because they're always watching They're spying on us right now And it helps keep us on the air Absolutely So join this select group of people and give us a call 212-209-2950 The people who call during this particular period I feel like it happens a lot but really when you consider how many times commercials are on other radio stations it doesn't happen all that often These are the people who keep this radio station going The people who make the phone call now 212-209-2950 You are the people that we thank for making it all possible and since 1960 that's what's been going on here in New York City We have a 50,000 watt radio station that broadcasts in the middle of the FM band and if you know anything about commercial radio We're right in the middle of the commercial band Not the non-commercial ghetto below 92 We're in the middle of the commercial band That's not possible You could never get a radio station at that frequency and have it be non-commercial It just does not happen So you guys make it possible You make it continue to happen for us And whether you're listening over the radio or over the internet I know that this radio station inspires people wherever they happen to turn it on Keep it going You're the only way we can do that 212-209-2950 We have a couple different pledge options $25 for the t-shirt and $75 for the cable modem book plus the t-shirt And we have another guest who's going to be joining us live in the studio We have Mike Aiello You're the founder of Differware Am I right in saying that? Differware Did I say it right or wrong? It's spelled D-I-F-R-W-E-A-R Now what you may ask is Differware You guys were at Hope, right? We were at Hope selling wallets and passport cases But these aren't just any wallets and passport cases What you've come up with is a way of blocking RFID Now this may be something that people are unfamiliar with at this stage but I guarantee you this is something that's going to be playing more and more a part of all of our lives in the years ahead RFID is a technology that is going to be appearing on credit cards and very soon on passports probably on driver's licenses and I guess eventually in our skin We're going to be tracked and monitored everywhere we go and I think more and more people are going to want to figure out ways of getting around that Mike, can you tell us something about a typical application of RFID and maybe something about the whole technology in general Sure. RFID has been around a long time. It's just a little radio transmitter that companies use to control inventory essentially. Walmart requires you to have RFID if you're going to be a supplier to them so they can do their supply chain management properly It's sort of creeped its way into the personal lives of many of us. A lot of us have ID cards to get into buildings If you have a Dutch or German passport, you definitely have an RFID tag in your passport and essentially what it does is it allows entities like corporations and governments and franchises to track and uniquely identify these tags as they're used throughout their systems So for example, when you're coming into the San Francisco airport with a U.S. passport or a Dutch or German passport you scan it remotely. You do not touch the San Francisco passport reader and you actually transmit information about your person to these readers An interesting attack on this that was shown at Black Hat over the summer was by a group called Felixus that brought a U.S. passport by a reader that they built themselves and they were able to pseudo-detonate an IED based on this information which is in the passport It's quite a frightening situation where you have a unique identifier on yourself all the time read by unknown entities to you and we put our products together in the hopes of allowing people to choose when they're exposing themselves to these kinds of identifications Do you have any RFID things on you right now? Is it something we can some of us might have without realizing it? Yeah, absolutely. Like I go to went to university here in the city and I have an RFID card on my person right now and basically I walked into the school, swiped it six or eight inches away from the reader and I was beeped in. So a little green light came on that said it hit a database and said yes, this person has paid his fees. The door is allowed to open for him. I have one for a corporation I work for These RFID cards are actually going to be implemented in the MTA and the New Jersey transit system. I was playing with one before actually. Some of the stops along the number 6 line, Lexington Avenue line, have little RFID entry points where you can use a Citibank credit card that has an RFID tag. Now I happen to have a different kind of credit card that has an RFID tag. It was able to recognize that and put a nice big red X on the turnstile saying no you can't enter. But to be honest, I don't see the advantage. Maybe it just hasn't been developed enough. But swiping, holding your credit card over the turnstile, you don't get a transfer for one thing. That's my pet peeve. But do you think that's how most people will be getting into mass transit systems by touching their card to the turnstile? That is the hopes by the transit system directors where you're able to not have to pay to have your users of the transit system have cards. It's cards that they own and corporations who do the banking own. That's a cost savings for them. And also they perceive it as easier for individuals to have a common payment item on them. And that's sort of the motivation behind it. So it seems like this is something that's geared for our convenience. We can get into things quicker, get into buildings. You say you walk up to a building. I think lots of times you don't even have to take it out of your pocket, right? It somehow reads it no matter where it is on your person. Door opens for you. No flashing of ID. No having to fumble for keys. What could the possible bad thing about this be? So my basic idea here is I ride the subway all the time. I was part of several projects at my university dealing with RF security. And I realized that I could definitely build a reader that would scan, copy the tags that are on the people that I'm with in the subway and then follow them to work and walk in right behind them. Jonathan Wethedis, who is at Hope, demonstrated that this is a very simple thing to do even with the tags that people embed in their own skin. There was a Wired article on that. Wow. So what this wallet that I'm looking at, I guess our listeners can't see it, but it's right there. Oh, there it is. It's a microphone. It sounds great. Maybe we can whack it. I put some there's money in here. I put my RFID enabled badge or my credit card or whatever in here and what happens? So what essentially happens is that there is a layer of RF shielding. You can actually see it. It reflects in light. There's a meshing in there. What it does is when the wallet is closed it creates an effective Faraday cage around all the RF devices that block the frequencies used by RFID, the ISO frequencies and most frequencies that any normal RFID reader will use and some scary ones. We've done testing. We've had a function generator. So you're on the subway with this cloner that you're going to make and I have this wallet. You won't be able to get my card. Absolutely not. It's not going to happen. What's the egregious example of privacy invasion that you've heard of so far in the RFID world? Egregious example of privacy invasion so far is tracking of folks in a store based on an item that they pick up. This was the Gillette example. This sort of spawned a few books by a woman from Harvard and there was a later privacy summit on RFID at MIT. So what did they do in the store? They picked up a Gillette razor refill and you were able to at the front of the store, it shows a monitor of where the person is in the store and if you're seeing people leave the store, you see a little circle leave the store. Oh my God! So you're able to literally track people with this. There's a screenshot online of the monitor interface if you search for Gillette RFID and security What was their motivation for this? Was it theft or was it to see if people went to the shaving cream aisle next or... So the funny thing is the most often stolen item retail is razor refills. Really? Yes. And this is the motivation behind Gillette. They wanted to stop this. Another egregious example just from retail is people will pick up an item and there's a camera in the area and it takes a picture and you visualize who's doing it and you can approach them later in the store. We talked a few weeks ago about smarter technology to combat shoplifting. Correct. If you do certain things and all of a sudden a computer will say this is suspicious. If you take a lot of things off a shelf at once or stand in a particular place RFID technology is definitely a tool in that monitoring. What we have here, we have RFID wallets RFID, I guess, prevention wallets is probably a better term for them We're offering here at the radio station as well if you call up now, 212-209-2950 for a different $75 pledge you'll get one of those in addition to the off-the-hook t-shirt and I'm not sure, I haven't heard from Tally in a while I think they're kind of shell-shocked down there from all the calls that just came in but if there are any more cable modem books down there, you can also call for those 212-209-2950 and again, we're just offering this between the hours of 7 and 8 o'clock tonight so if you're thinking of doing this later tonight probably not a good idea, I doubt they'll be there 212-209-2950 show your support for WBAI for off-the-hook, for freedom of speech for developing technology, ways of combating privacy invasions, all sorts of things like that. Many reasons to call only one number you have to call 212-209-2950 So if I want the wallet and the book I can pledge $150? If you can handle addition like that, yeah you can do both I guess you'll get two t-shirts I imagine you would if you did that You know, I might have to go down the hall and see if there's another book. Do you want me to do that? Would you go down the hall and just make sure they're okay down there? Because we haven't heard a peep from them since all those calls came in and who knows, they might be unconscious on the floor 212-209-2950 our lines are open right now so you won't have any trouble reaching people assuming that they are still there and didn't run out in panic and again, we are offering thanks to Mike Aiello from Differware, the RFID wallets that can you give us an example of people who have used these wallets and have benefited from their use? Great, one of the great examples that folks tell us about is that sometimes the RFID readers at their job if they have multiple cards, it'll just not work and they have to take one card out or whatever we have a slot on the side of the wallet that separates a card if you want it to be separated and it's easier to get access to so that's one good thing there folks are totally assured that they're not going to have their privacy invaded while riding the subway or walking down the street that's another good example of why people are Does that happen a lot? On the subway walking down the street, people are scanning looking for your RFID tags of various sorts? So, as an example at Hope, Jonathan went out, purchased something from a vendor and was able to read the unique identifier off of a card embedded in someone's skin and has shown it's possible all over the place Wow It is going to happen, it does happen there have been readers built into floor tiles, there have been readers built into pretty much any kind of device to sort of make it look like the environment so people don't realize that they're being read It's kind of like EasyPass we use this for cars going through toll booths but now people have these devices on them and there are little readers in various places so yeah, you better be careful because apparently this technology is being used to violate your privacy all over the place Jim? So if I'm a criminal, I could make myself conceivably an RFID reader and I could pass by somebody and thereby I could get access to his bank accounts, his credit cards, his employee ID and I could probably as this continues along, figure out where he works which means I could get access to his place of employment, this is a giant security risk. Absolutely, that's why we came up with our product. The more interesting attack on that is if you sit in one place and you keep track of who passes by you, you may not even be able to get their credit card number but if you just get a unique identifier, you're able to understand when that person hits that point and if you can track that across multiple read locations, you're able to track a person based on any RFID that they have online. So it's an incredible security risk and you're saying that those little cards that we use to get into our office buildings you can read those and are you saying that you can duplicate them? Is it possible to duplicate them as well? Absolutely There have been several demonstrations of this and RFID vendors have claimed that they're enabling encryption and things of that measure but there's a fundamental limitation on the number of computations you can embed in a cheap card. The more encryption you have, the more expensive the card is and the driver right now is to send it down It's been shown that most vendors leave the password on even the encrypted cards the same as in the user manual. Oh boy. So there was a tool shown at- We always go back to that, don't we? Absolutely. People not changing passwords. It's always the same thing. So just to jump on the terror bandwagon here if I was a member of Al-Qaeda and I was just sitting downstairs at Wall Street I could literally scan people walking past me who have RFID cards and get enough information where if I was technically adept enough I could duplicate those cards and just sail right through the office buildings that they're supposedly only allowed to go into. Is that correct? Without a question. Now if they had an RFID wallet like we're offering here tonight that would not be possible. If you keep your card in the RFID wallet, it's protected from this kind of thing. Yes. 212 209 2950. We only have two calls on the line. I think we should have many times that amount. 212 209 2950. A pledge of $75 will yield you an RFID wallet that you can protect your company yourself and your peace of mind just by calling us. 212 209 2950. Again you also get the off-the-hook t-shirt with that and if there are any left for a $75 pledge you can instead get the Hacking the Cable Modem book along with the off-the-hook t-shirt. $25 pledge. Just the t-shirt. 212 209 2950. I'm sorry, this meshes very well, no pun intended, with something we were discussing the other week which is whether or not it's legal to modify passports. And so with products like this it doesn't matter anymore. You can just stick them in there and be sure that nobody can read them. But I actually have a question. I've noticed your wallets are made of leather and I'm vegan and so I'm wondering if you have any plans on making a wallet that would be compatible with that? Six calls on the line. Apparently leather isn't bothering them but 212 209 2950. I'll keep those calls coming in and yes, the leather question. Yes, the leather question. So as you can probably tell we're a small company to begin with, hoping to grow a lot. We're expanding our product line. We just recently added different colors to our leathers and as the demand we have had several questions for non leather products we will be introducing a vinyl RFID blocking product. Six calls on the line. 212 209 2950. Call now. $75 pledge gets you an RFID wallet. Bernie, I believe you had a point. I just wanted to mention that I met Mike at the HOPE conference this past July and it was great to meet you Mike. Thanks Bernie. You really have an amazing product. I was looking at how well made these wallets are. The fineness of the mesh that provides the Verity cage for shielding your RFID and it's a really nice wallet. I mean you were kind enough to give some of them away as door prizes for the HOPE conference and I gotta say a couple of women attendees won these as door prizes and they were ecstatic. They were thrilled. These are really nice wallets in their own right but they have sort of this stealth feature that they protect your privacy by shielding your RFID card. So it's really sort of a cool secret you don't have to tell people about but you can whip this thing out and say look this wallet has some amazing technology. It protects my privacy and it's a very nice wallet on top of that. You can be ecstatic and thrilled if you just make a phone call and you'll be supporting the radio station. You'll be getting a really cool device, an RFID wallet and an off the hook t-shirt. 212-209-2950 This is an excellent gift for our conservative listeners and members of the armed forces. It's already been demonstrated that Al-Qaeda who always seems to think ahead could theoretically use this to attack Americans. So rather than wait for that to happen and lock the barn door afterwards, be ahead of the curve. Get this wallet. They won't be able to read you as an American off your passport. They won't be able to sneak into your office building and plant the bomb. I can't believe we're using these scare tactics to reach out to people but I gotta say it's working because we have nine calls on the line. It almost makes you scream, doesn't it? Well I guess so. 212-209-2950 That's our phone number and again we want to thank Mike Ayala for coming in and donating these to the radio station because it's just incentive for calling up and helping keep the radio station on the air. Really the main reason for you to call should be to keep the show on to keep the radio station going. We're offering these things and we have people coming in being generous with the things that they're making as an incentive so that you guys will have even less of a problem dialing those numbers. We gotta get out of here. Our time is up. We're gonna be back again next week with even more special things but again you have three minutes to call. 212-209-2950 I see we have something like nine, ten calls on the line so hopefully people are taking advantage of this terrific offer. Mike, I want to thank you so much for coming by and best of luck. Anything else you guys are working on? We have a few products coming up. Check the website. I really hope you guys call in and pledge. Definitely call in and pledge. Don't go to our website and do it. We're here to help out 2600 and off the hook. Thanks. Thanks so much again for coming in and doing this. Again, 212-209-2950 is our telephone number. We will be offering these items for just a few minutes more. Join the 50 or so people on the phone line now. You can still get the cable modem book, I believe. Is that true, Lynn? You're filling out the pledge form as we speak. You might have to compete with us to get these items. 212-209-2950 Make those phone calls now. See you next week. Good night. ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... Hey Cat, hey, hey, how you doing out there in WBAI land? Hey Cat, hey, hey, how you doing out there in WBAI land? Hey Cat, hey, hey, how you doing out there in WBAI land? Hey Cat, hey, hey, how you doing out there in WBAI land? Hey Cat, hey, hey, how you doing out there in WBAI land? Hey Cat, hey, hey, how you doing out there in WBAI land?